Live feed · updated daily

Recent policy changes

361 policy changes detected across 352 platforms. Most platforms don't announce policy changes — these updates were detected automatically.

Stay ahead of the changes

Start monitoring platform changes

Free: research letter. Monitor: same-day alerts on the platforms you choose.

352 Entities monitored
838 Documents tracked
361 Changes detected
Showing the most important changes (medium + high severity). Show all changes including minor updates
June 16, 2026
Whatnot
Whatnot Privacy Policy
high
Replaced court-based dispute resolution with mandatory arbitration for Australian sellers under main Terms of Service.
Why it matters: The updated terms eliminate court access and jury trial rights for Australian sellers, consolidating all disputes under mandatory individual arbitration. This materially changes the dispute resolution mechanism available to sellers and may affect how they evaluate risk and enforce claims against Whatnot.
Whatnot
Whatnot Terms of Service
high
Replaced court-based dispute resolution with mandatory arbitration for Australian sellers, removing Los Angeles venue language and jury trial waiver.
Why it matters: This change materially alters how disputes between Australian sellers and Whatnot will be resolved, shifting from court-based proceedings with defined venue to mandatory individual arbitration. The change consolidates dispute governance into cross-referenced provisions, meaning sellers must now review the main Terms of Service arbitration sections to understand their rights, creating additional complexity for dispute resolution.
AWS Bedrock
AWS Service Terms
medium
Adds explicit metadata sharing authorization with Anthropic models and launches WAF AI traffic monetization payment facilitation feature.
Why it matters: The updated terms establish explicit authorization for AWS to share request metadata with Anthropic for usage tracking, which modifies the data-processing relationship and may require organizations to update their privacy notices and data-processing agreements if they handle regulated data. The introduction of AWS WAF AI traffic monetization formalizes a new optional payment-facilitation service that involves sharing user configuration and payment information with third parties, requiring organizations to understand their own vendor relationships and liability frameworks.
Inflection AI
Inflection AI Privacy Policy
medium
Expanded data collection scope to include voice, audio, precise location, and third-party platform access (contacts, emails, calendar, documents).
Why it matters: The updated policy establishes explicit authorization for collection of voice, audio, and location data, moving beyond the previously disclosed text-based input model. This expansion affects the scope of personal data Inflection AI may process and requires users and organizations relying on the service to understand the full range of data collection practices now authorized under the policy.
Coinbase
Coinbase Fee Schedule
medium
Removes fixed 1% fee disclosure for instant unstaking; fee now shown only at time of request.
Why it matters: The updated terms shift fee disclosure from the published schedule to point-of-transaction, affecting how users encounter pricing information before committing to a transaction. This change alters cost predictability and comparison, as users can no longer review the exact fee in advance through the published schedule.
Stay ahead of the changes

You're seeing a fraction of what's changing

ConductAtlas monitors every tracked platform and captures every policy update.

June 15, 2026
Dun & Bradstreet
D&B Privacy Policy
high
Removes detailed governance, ethics, certifications, and rights procedures from privacy statement; policy now contains only 5 sentences.
Why it matters: The updated privacy statement removes substantive governance disclosures that organizations typically rely on for vendor due diligence, DPA compliance, and regulatory transparency. The removal of certification confirmations, cross-border privacy framework adherence, data processing descriptions, and individual rights contact procedures reduces publicly available evidence of Dun & Bradstreet's privacy governance posture and may affect downstream compliance obligations for organizations that depend on Dun & Bradstreet as a data processor or vendor. Organizations in regulated jurisdictions may need to confirm these commitments through alternative documentation.
June 12, 2026
NVIDIA NIM
NVIDIA Privacy Policy
high
Removed cookie consent mechanisms and tracking technology disclosures from Privacy Policy
Why it matters: The removal of cookie and tracking technology disclosures from NVIDIA's Privacy Policy eliminates explicit user notice about data collection practices that were previously stated. Privacy regulations in the EU, UK, and California require transparent disclosure of tracking technologies before data collection. If NVIDIA continues to deploy cookies and tracking tools without updated disclosure language, the company may lack compliant notice mechanisms to satisfy legal requirements or obtain user consent.
Ticketmaster
Ticketmaster Privacy Policy
medium
Added disclosures for biometric information collection, messaging service communications, and event photography and video capture for marketing use.
Why it matters: The updated policy establishes explicit authorization and disclosure for biometric data collection and event photography practices that were not previously detailed. These additions create transparency regarding sensitive data practices and establish objection mechanisms, but also signal that Ticketmaster may implement these practices at events. Organizations that use Ticketmaster for customer data should evaluate whether these disclosed practices require updates to their own privacy notices or data processing agreements.
SoFi
SoFi Privacy Notice (Retired URL)
medium
Clarified tracking technology disclosure and data sharing with advertising partners; continued use constitutes acceptance unless user opts out.
Why it matters: The updated Privacy Notice clarifies SoFi's tracking and data-sharing practices with explicit disclosure that user information is shared with advertising and analytics partners. The revised language establishes that continued site use constitutes acceptance of these practices unless users take action to opt out, which changes the operational default from prior implied choice language to explicit consent-on-continued-use.
OpenAI
OpenAI Privacy Policy
medium
Added disclosure of advertiser data sharing and explicit ad personalization controls for Free and Go users.
Why it matters: The updated policy explicitly discloses that OpenAI receives data from advertisers and personalizes ads for Free and Go users. This clarification affects how users understand their data flows and makes available controls more transparent; users can now explicitly manage ad personalization through documented settings rather than relying on general cookie controls.
June 10, 2026
SoFi
SoFi Terms of Service
medium
Added granular cookie controls and Privacy Preference Center; replaced implicit consent model with explicit category-based opt-in/opt-out framework.
Why it matters: The updated terms establish explicit user control over tracking and data collection on SoFi's website, replacing a prior model where non-selection of preferences implied consent. This shift reflects regulatory alignment with GDPR and CCPA requirements for affirmative consent to non-essential tracking. For users, it creates actionable control over what data is collected and shared; for SoFi, it establishes a documented consent mechanism that may reduce privacy liability.
AWS Bedrock
AWS Service Terms
medium
Added explicit consent requirement for Anthropic model abuse detection; clarified 30-day content retention for abuse detection on identified Bedrock models.
Why it matters: The updated terms introduce a material change in data flow governance: abuse detection on Anthropic models now requires explicit user consent and involves third-party data transfer, rather than remaining an implicit AWS-internal function. This operationally requires organizations to implement consent collection, disclose Anthropic's involvement in user agreements, and review third-party processing addenda. For compliance teams, this expands third-party risk governance and may trigger DPA amendment requirements.
Palantir
Palantir Privacy Statement
medium
Added promotional partner contact authorization to third-party data sharing disclosures.
Why it matters: The updated Privacy Statement establishes a new third-party data-sharing and contact pathway for promotional code partners. This expands the disclosed recipients of customer personal data beyond Palantir's previously disclosed third-party categories, creating a new contact vector that users should understand before signing up via promotional offers.
Cursor
Cursor Data Use & Privacy Overview
medium
Clarifies zero data retention with model providers but adds disclosure that abuse detectors may store data for investigation.
Why it matters: The updated policy clarifies Cursor's data handling practices by explicitly disclosing that abuse detection systems may store data for investigation, even under Privacy Mode. This represents a more specific articulation of actual data handling practices compared to the previous blanket statement, but signals that absolute zero retention is qualified by abuse detection exceptions.
Target
Target Terms and Conditions
medium
Target revises 899 sentences in Terms and Conditions, including dispute resolution, account management, and service policies.
Why it matters: Target's comprehensive revision of 899 sentences in its Terms and Conditions on June 10, 2026 materially affects the legal framework governing website use, account management, service access, and dispute resolution for all users. The scope of changes (442 added, 216 removed, 241 modified) suggests substantive policy revisions beyond routine updates; users should review the complete updated terms to understand how modified provisions affect their rights regarding account termination, service access, arbitration obligations, and other material terms.
Stay ahead of the changes

You're seeing a fraction of what's changing

ConductAtlas monitors every tracked platform and captures every policy update.

Airbnb
Airbnb Terms of Service
high
Removed explicit 18+ age requirement statement; added Host Recommendations Directory supplemental terms.
Why it matters: The removal of the explicit 18+ age eligibility statement eliminates a clearly stated contractual requirement that served as a foundational eligibility criterion for both booking and hosting. This change creates regulatory uncertainty under child protection frameworks and leaves users without clear contractual notice of age restrictions, which may complicate platform enforcement and expose Airbnb to regulatory challenge.
June 9, 2026
Rumble
Rumble Privacy Policy
medium
Changed notification language in privacy policy from 'will attempt' to 'may attempt' notification of data disclosure.
Why it matters: The updated terms reduce the stated commitment to notify users before Personal Information disclosure, shifting from an intent to attempt notification to a discretionary option. This change affects operational clarity around when and whether users will receive advance notice of data sharing and may have implications for organizations that rely on Rumble's practices as part of their own data governance or vendor management frameworks.
Apple
Apple App Store Review Guidelines
medium
Adds mandatory age-appropriate content requirements for child users and escalating enforcement (removal threat) for non-compliant user-generated content.
Why it matters: The updated guidelines establish explicit, enforceable content moderation obligations for developers and introduce app removal as a direct consequence of non-compliance. This clarifies Apple's enforcement authority and creates a formal escalation pathway (notice, plan, removal) that developers must respond to operationally. For developers with user-generated content features or child-focused apps, this change requires proactive content governance infrastructure and compliance response processes.
June 8, 2026
Ford
Ford Privacy Policy
medium
Modified notice requirement for material policy changes from guaranteed advance notice to notice 'as required by law'
Why it matters: The updated terms establish a material shift in Ford's obligation to notify you of privacy policy changes. The prior language created a standalone contractual commitment to provide advance notice; the revised language conditions Ford's notice obligation on legal requirements. This change affects how and when you will be informed of future modifications to Ford's data practices, particularly regarding connected vehicle data collection and use.
June 7, 2026
OpenAI
OpenAI Privacy Policy
medium
Added explicit disclosures of advertiser data collection and ad personalization practices for Free and Go users, plus new account controls to manage ad targeting.
Why it matters: The updated policy adds explicit documentation of a commercial data processing practice (advertiser partnerships and ad targeting) that directly affects Free and Go users' data use. This change establishes a clear, disclosed legal basis for processing user data for advertising purposes and introduces user controls, which aligns the policy with actual operational practice and meets transparency expectations under privacy regulations like GDPR and CCPA.
June 6, 2026
American Airlines
American Airlines Terms of Use
medium
Removes cookie and data collection disclosures from website terms
Why it matters: The updated terms establish a reduced disclosure posture regarding cookie and data collection methods on the American Airlines website. Previously, the terms explicitly stated that certain cookies are essential and cannot be rejected, explained how performance cookies track site usage, and described how functional cookies store user preferences. The removal of these disclosures narrows the transparency available to users in the public-facing terms, which may create compliance questions under CCPA, GDPR, and FTC standards that require clear, accessible disclosure of data collection practices.
Ideogram
Ideogram Privacy Policy
medium
Adds explicit data-sharing recipient table disclosing user identifiers, images, and location data shared with other users, vendors, service providers, and social partners.
Why it matters: The updated policy establishes more explicit, structured disclosure of which personal information categories are collected and shared with specific recipient types. This shifts from a referential approach requiring readers to locate information across multiple sections to a consolidated table format, which may strengthen compliance with state privacy law transparency requirements and provides users clearer visibility into data sharing practices.
Ancestry
Ancestry Terms and Conditions
medium
Removed 'Do Not Sell or Share My Personal Information' link from footer; CCPA disclosure navigation changed.
Why it matters: The updated Terms footer removes a direct navigation link to CCPA 'do not sell or share' disclosures, which may affect how readily California residents can locate and exercise their statutory privacy rights. California law requires covered businesses to provide an accessible mechanism for such requests; removing a prominent footer link could complicate that access and create regulatory compliance questions.
Binance.US
Binance.US Terms of Use
high
Auto-enrolls users in Soft-Staking of eligible tokens; requires 14-day advance notice for material fee and policy changes starting July 1, 2026.
Why it matters: The updated terms establish automatic enrollment in asset staking for eligible tokens, shifting from the prior language that stated staking was optional and required explicit user designation. This change means users must take affirmative action (opt out) to prevent their assets from being moved into staking arrangements, and it introduces a July 1, 2026 deadline for users to take that action. The 14-day advance notice requirement for material changes starting July 1, 2026 also creates a new notification window for future policy modifications, though the scope and enforceability of that requirement will depend on applicable state and federal regulations.
June 5, 2026
Smartsheet
Smartsheet Privacy Policy
medium
Restricts Data Privacy Framework participation to U.S. affiliates only; may affect cross-border data transfer mechanisms
Why it matters: The updated policy narrows the stated scope of Data Privacy Framework participation, which may affect the legal mechanisms available for transferring personal data from regulated regions to Smartsheet. Organizations processing EU, UK, or Swiss data through Smartsheet should verify whether this change introduces gaps in documented lawful transfer mechanisms, particularly if non-U.S. affiliates are involved in data handling.
Mixpanel
Mixpanel Terms of Use
medium
Removes exclusion for individually identifiable data from Usage Data definition in terms
Why it matters: The updated terms expand the category of data Mixpanel may classify and use as Usage Data by removing the prior contractual exclusion of individually identifiable information. Organizations that relied on this exclusion to limit how Mixpanel could use personal data must now reassess their vendor agreements and privacy controls. Under privacy regulations like GDPR and CCPA, the reclassification of individually identifiable data may trigger new obligations if the organization lacks a lawful basis for such expanded use.
WhatsApp
WhatsApp Privacy Policy
medium
Removes explicit commitment against ads in Status and Channels; now reserves right to introduce them pending policy update
Why it matters: The updated terms eliminate a prior commitment against advertising in Status and Channels, signaling that these features may be subject to future monetization. This shifts the company's stated position from 'no intention' to 'possible if policy is updated,' which materially changes the expected user experience of these features.
SoFi
SoFi Terms of Service
medium
Removed Arbitration Agreement from core Terms acceptance language; updated navigation with section links.
Why it matters: The removal of the Arbitration Agreement from the primary Terms acceptance language creates ambiguity about whether new users are explicitly bound to resolve disputes through arbitration rather than court litigation. This change affects the clarity and enforceability of SoFi's dispute resolution terms and may trigger regulatory review regarding how prominently arbitration is disclosed at onboarding.
Cash App
Cash App Terms of Service
medium
Adds minor account authorization rules and new Cash App Tag fees ($25 purchase, $15 expedited shipping)
Why it matters: The updated terms shift authorization for teen payment products from per-action parental approval to blanket delegation at account creation. This changes the operational friction for teens accessing Cards and Tags, which may increase usage of Cash App's payment and wearable products among minors. Parents should understand that authorizing a Sponsored Account now constitutes consent for teens to independently request and activate these products. The introduction of Cash App Tag fees also creates a new cost consideration for parents evaluating whether to allow teens to use the wearable payment service.
Stay ahead of the changes

You're seeing a fraction of what's changing

ConductAtlas monitors every tracked platform and captures every policy update.

June 3, 2026
Affirm
Affirm Privacy Policy
medium
Added detailed privacy disclosures including data sharing with fraud prevention and identity verification providers; clarified GLBA regulatory status.
Why it matters: The updated policy establishes that Affirm qualifies as a financial institution under federal banking law, which may limit the applicability of state privacy laws to Affirm's core lending operations. The policy also newly discloses sharing of personal information with fraud prevention and identity verification providers, expanding transparency about third parties that receive consumer data.
Stay ahead of the changes

Don't manually check every platform

Get alerts when policies change, before it affects you.

Updated daily. New changes added as detected.

← Newer Page 6 of 13 Older →