Live feed · updated daily
Recent policy changes
361 policy changes
detected across 352 platforms. Most platforms don't announce policy changes — these updates were detected automatically.
June 2, 2026
Replaced general privacy opt-out language with formal GDPR-aligned data subject rights framework including access, rectification, erasure, restriction, portability, objection, consent withdrawal, and
Why it matters: The updated policy formalizes ClickUp's recognition of data subject rights under GDPR and equivalent frameworks, providing users and regulators with explicit legal reference points for exercising control over personal data. Organizations that process customer data through ClickUp should verify the formalized rights are reflected in their DPAs and privacy notices to ensure compliance obligations are accurately stated.
Added Licensed Materials licensing terms for locally installed software and ChatGPT Sites website creation feature with separate terms reference.
Why it matters: The updated terms establish binding license restrictions for organizations deploying OpenAI's downloadable software components, including prohibitions on modification, redistribution, and sublicensing, and mandate permanent deletion upon service termination. The introduction of ChatGPT Sites creates a new reference to separately published terms, requiring organizations to audit both document sets if offering website creation capabilities. These changes formalize the licensing framework for locally installed materials and introduce new operational governance requirements for customers using downloadable components or the ChatGPT Sites feature.
Removes detailed personal data recipient table, directs users to other policy sections instead
Why it matters: The updated policy consolidates transparency disclosures from a detailed, accessible table into cross-references to other sections. This change reduces the granularity of upfront data-sharing disclosure, potentially affecting how users and organizations understand which parties receive personal information. Depending on regulatory interpretation and jurisdiction, this reduction in accessible transparency may create compliance questions around CCPA, GDPR, and FTC Act standards requiring specific, clear disclosure of data recipients.
Removes 'Do Not Sell or Share My Personal Information' link from privacy policy footer; opt-out access may require alternate navigation.
Why it matters: The removal of the footer link affects how users can access CCPA opt-out controls from the privacy policy itself. Under the CCPA, companies must make opt-out mechanisms easy to find. The removal of this direct link from the policy footer may create compliance questions unless the opt-out control is prominently linked elsewhere on the site.
Adds minor data collection disclosure for beneficiaries and AI feature training authorization with non-advice disclaimer.
Why it matters: The updated policy establishes explicit authorization for two practices previously described in narrower or negative terms: collection of minor beneficiary information and use of client data for AI training. This clarification affects how clients should understand what data Wealthfront processes and how it may be used, and creates materiality for compliance teams assessing whether vendor data practices align with their own privacy policies and regulatory obligations. The AI output disclaimer is operationally significant because it establishes that AI-generated recommendations should not be treated as investment advice, which affects how financial advisors and clients may use such outputs.
Stay ahead of the changes
You're seeing a fraction of what's changing
ConductAtlas monitors every tracked platform and captures every policy update.
Expanded cookie tracking disclosure and restructured consent interface to require affirmative opt-in for performance and targeting cookies
Why it matters: The updated privacy notice establishes clearer disclosure of third-party advertising and analytics data sharing and restructures the consent mechanism to require affirmative selection for optional cookies. This shifts the operational model from assumed consent to explicit choice, affecting how user tracking data flows to external partners and creating a new procedural requirement for users to actively configure their tracking preferences.
Adds VeraSafe dispute resolution process for DPF complaints and Right to Restriction for processing limits.
Why it matters: The updated policy establishes a concrete, third-party mechanism for resolving Data Privacy Framework complaints that were previously unresolved through internal processes, providing users an escalation path that is transparent and free. The introduction of an explicit Right to Restriction also operationalizes a user control that strengthens personal data governance, particularly for sensitive information.
Extended seller payment withholding from 30 to 60 days for non-compliance in EU/UK Terms of Service
Why it matters: The updated terms extend Whatnot's authority to withhold seller payments by 100 percent, from a maximum of 30 days to 60 days during compliance disputes. For sellers dependent on regular payment cycles, this doubles the potential cash flow disruption window and may affect financial planning, working capital, and operational continuity. The longer withholding period is material for high-volume sellers and may warrant review under EU unfair contract terms law depending on how the provision is applied.
Extended payment withholding period from 30 to 60 days for non-compliant sellers in EU/UK terms
Why it matters: The updated terms establish a doubled enforcement window during which sellers cannot access withheld payments when they violate platform rules. This extends the period sellers must manage without access to transaction proceeds, affecting working capital and liquidity planning for sellers operating in the EU and UK.
Added 30-day retention period for abuse detection; clarified review process for child safety reports.
Why it matters: The updated terms establish explicit operational practices for how AWS Bedrock processes and retains service data for safety purposes. The 30-day retention window is now formally documented, which clarifies data handling practices for organizations that must disclose retention periods in their own customer agreements or privacy policies. The two-step CSAM reporting process (review before reporting) reflects a procedural refinement that may affect how organizations communicate about safety practices to their own customers.
Adds AI autonomy liability framework requiring users to configure settings, monitor output, and accept legal responsibility for AI-driven actions and third-party tool costs.
Why it matters: The updated terms establish a new contractual liability framework for autonomous AI actions. Users are now legally bound by AI-driven actions taken according to their configured settings and must actively manage safeguards, monitor settings, and evaluate output. This creates operational and compliance obligations that require developers to implement approval workflows, cost controls, and human oversight before deploying AI features or third-party integrations. The liability disclaimer for AI-driven consequences shifts risk entirely to users and may create conflicts with downstream customer agreements or regulatory frameworks.
Restructures mass arbitration procedures with mandatory mediation phase and batch consolidation instead of individual claims resolution.
Why it matters: The updated terms establish a more structured and predictable framework for resolving large volumes of similar claims against Square, moving from flexible ad-hoc procedures to a defined multi-stage process with mandatory mediation and batch consolidation. This change affects the timeline, cost allocation, and procedural complexity for any user or merchant involved in a mass proceeding, potentially making resolution faster for large claim groups but reducing individual procedural flexibility.
Removes fee waiver for eligible Cash App Green customers on Paper Money Deposits; $1 fee now applies to all users effective June 29, 2026
Why it matters: The updated terms establish a uniform fee structure for Paper Money Deposit services, removing a previously available benefit for Cash App Green account holders. This change directly affects the value proposition of the Green account tier and increases the cost of using Paper Money Deposit for customers who previously qualified for the waiver.
May 30, 2026
Redirects strategic seller disputes from California courts to mandatory arbitration under main Terms of Service
Why it matters: The updated terms eliminate the ability for sellers to litigate contract disputes in California courts and instead require all disputes to proceed through arbitration as defined in Whatnot's main Terms of Service. This change affects how sellers can seek remedies for breach of contract, payment disputes, or other claims, and likely reduces their access to discovery, jury trial, and appeal procedures available through traditional litigation. Additionally, the explicit definition of a 30-day programming/content gap as a material breach clarifies grounds for suspension or termination that previously may have been less defined.
Redirects seller dispute resolution from courts to mandatory arbitration under main Terms of Service.
Why it matters: The updated terms establish mandatory individual arbitration as the exclusive dispute resolution method for sellers, removing access to California courts and jury trial rights. This materially changes the cost, timeline, and procedural options available to sellers if conflicts arise with Whatnot regarding content commitments, account status, or contract interpretation.
Adds database engine upgrade requirements and scanning rights for RDS extensions
Why it matters: The updated terms establish new customer obligations to manage database engine lifecycle and upgrade to supported versions, with AWS authorized to take unilateral action (delete instances) on unsupported software after notice. This creates operational risk for customers with legacy databases or limited maintenance resources, and shifts liability for extension-related failures from AWS to customers.
Adds privacy policy disclosure for BeePitched feature, processing names, phone numbers, and photos in user-generated pitch content.
Why it matters: The updated terms establish that BeePitched processes personal data from users and non-users, including names, phone numbers, and photos, in a feature that enables shared profiles about individuals. The disclosure describes what data is collected and how it is used, which addresses transparency requirements under privacy frameworks like GDPR and CCPA. However, the disclosure does not explicitly describe consent mechanisms, user rights, or controls to opt out of being featured, which may create compliance gaps depending on jurisdiction.
Expanded tracking disclosures and shifted consent from opt-in to opt-out for pixels, cookies, and ad partner data sharing
Why it matters: The updated terms establish a material change in how SoFi collects consent for tracking technologies. The shift from opt-in to opt-out consent means users must now affirmatively decline tracking rather than affirmatively accept it. The explicit disclosure of data sharing with advertising partners provides clarity about downstream data destinations, but the opt-out consent structure may create compliance risk under CCPA/CPRA, which generally requires affirmative opt-in consent for nonessential tracking.
Stay ahead of the changes
You're seeing a fraction of what's changing
ConductAtlas monitors every tracked platform and captures every policy update.
May 29, 2026
Removes documented opt-out mechanism for advertising cookies and explicit mention of IP address/device ID sharing with ad partners.
Why it matters: The updated statement removes a documented opt-out mechanism for advertising cookies and eliminates explicit disclosure of data sharing (IP addresses, device identifiers) with advertising partners. These removals reduce transparency about consent options and data practices previously disclosed to users, creating potential compliance exposure under FTC Act Section 5 (material omissions) and state privacy laws (CCPA, CPRA) that require disclosure of data practices and opt-out rights.
Adds employment compliance obligations and consent requirements for Amazon Connect Talent AI hiring tool
Why it matters: The updated terms establish explicit compliance obligations for customers using Amazon Connect Talent, a generative AI tool for employment decisions. Rather than treating Connect Talent as a standard AWS service, the terms now require customers to independently ensure legal compliance with employment discrimination law, data privacy regulation, and emerging AI governance frameworks, implement documented consent and appeal processes for job applicants, review all AI recommendations before making hiring decisions, and notify AWS of legally mandated data deletions. This represents a shift toward customer accountability for AI-driven hiring outcomes and creates material compliance and operational obligations that organizations must integrate into their HR processes and vendor management.
Adds risk-based funds availability holds (1-4 business days) for Mercury Invoicing ACH payments, determined at Mercury's sole discretion.
Why it matters: The updated terms formalize Mercury's ACH payment processing timeline for merchants, establishing that incoming invoice payments will not be immediately available. Merchants relying on Mercury Invoicing for cash flow should understand that funds may be held for up to 4 business days while Mercury assesses transaction risk, which directly affects liquidity management and payment reconciliation.
Expands data handling authority for third-party service integrations; adds explicit user responsibility for requested actions.
Why it matters: The updated terms establish a significantly broader scope of data operations Mistral AI may perform when third-party services are connected, moving from narrowly defined access and retrieval to an expansive 'otherwise act upon' authorization. For organizations processing customer data, this expanded scope may require evaluating compliance with existing data processing agreements and regulatory frameworks that limit permissible data operations.
Expands permissions for third-party service integrations to include data modification, deletion, and execution; clarifies user responsibility for requested actions and extends liability disclaimers to
Why it matters: The updated terms establish broader authority for Mistral to perform data modifications, deletions, and system executions through third-party services beyond the previous scope of retrieval and storage. This expanded contractual authority is paired with an enlarged liability disclaimer that explicitly excludes Mistral's responsibility for data corruption, deletion, and unauthorized disclosure by third parties, shifting all liability to users. For users integrating multiple services through Mistral, this change creates operational risk if third-party services mishandle or improperly act upon data during execution of user-requested actions.
Stay ahead of the changes
You're seeing a fraction of what's changing
ConductAtlas monitors every tracked platform and captures every policy update.
Reduces secondary-tier APY from 3.30% to 3.10% on SoFi Savings balances exceeding $20,000
Why it matters: The updated terms reduce annual interest earnings on SoFi Savings balances exceeding $20,000 by 20 basis points. This directly affects the yield on deposits held in these accounts, lowering the effective return for account holders relative to the previous rate structure.
May 28, 2026
Adds explicit user responsibility for verifying digital asset eligibility in own jurisdiction; disclaims Uniswap liability for asset availability determinations
Why it matters: The updated terms clarify that Uniswap does not verify whether digital assets are legally available for you to trade in your jurisdiction, and places responsibility on you to make that determination independently. This shifts a potential compliance burden from Uniswap to users and may create practical friction for users in jurisdictions with strict digital asset restrictions, as they can no longer assume that Uniswap's availability of an asset constitutes a determination of its legality for them.
Restricts children's data use for AI training; requires education agreements; prohibits targeted advertising and third-party tracking of minors
Why it matters: The updated terms establish explicit restrictions on AI training, targeted advertising, and third-party tracking of child users, creating new operational obligations for educational institutions and AI service providers. This change also expands Figma's defined child age range across multiple jurisdictions, potentially triggering compliance reviews for organizations serving minors in California, the EU, and Japan.
Restricts use of children's personal data for AI training and targeted advertising; requires educational institution agreements for child users
Why it matters: The updated terms establish enforceable restrictions on how children's personal information may be processed, moving beyond general principles to specific contractual prohibitions around AI training, advertising, and tracking. The mandatory institutional agreement requirement for child users creates a new gating mechanism that affects any organization using Figma in an educational context. The explicit AI training prohibition directly addresses a significant regulatory and public policy concern regarding use of minors' data in machine learning.
Reduced APY on savings accounts: 3.30% to 3.10% for direct deposit members, 1.00% to 0.80% for non-deposit members.
Why it matters: The updated terms establish lower earning rates across all savings account tiers, reducing the annual yield available to both direct deposit and non-deposit account holders. This operational change affects the financial return customers receive on funds held in savings accounts and Vaults, making the product materially less competitive from a yield perspective compared to the prior terms.
Adds Community Localization program requiring users to assign all translation rights to Midjourney royalty-free.
Why it matters: The updated terms establish explicit ownership and monetization rights for user-submitted translations, fundamentally reshaping what happens to localization work contributed by the community. This clarifies that translations are uncompensated intellectual property transfers rather than collaborative contributions, which may affect participation incentives and the scope of user control over derivative uses of their localization work.
Stay ahead of the changes
You're seeing a fraction of what's changing
ConductAtlas monitors every tracked platform and captures every policy update.
Updated daily. New changes added as detected.