Live feed · updated daily

Recent policy changes

361 policy changes detected across 352 platforms. Most platforms don't announce policy changes — these updates were detected automatically.

Stay ahead of the changes

Start monitoring platform changes

Free: research letter. Monitor: same-day alerts on the platforms you choose.

352 Entities monitored
838 Documents tracked
361 Changes detected
Showing the most important changes (medium + high severity). Show all changes including minor updates
May 28, 2026
Cash App
Cash App Terms of Service
medium
Clarifies that Cash App will aggregate account limits, spending caps, and transaction restrictions across multiple accounts and cards a user holds.
Why it matters: The updated terms establish explicit authority for Cash App to enforce limits across multiple accounts and cards a user holds simultaneously. This changes how account holders should understand their effective spending capacity and may affect the success of transactions when a user maintains multiple accounts with independent per-account limits.
OpenAI
OpenAI Enterprise Privacy
high
Expands workspace admin authority to view, access, export, delete end user conversations and control retention durations in OpenAI Enterprise.
Why it matters: The updated terms establish that workspace administrators, not individual employees, control access to conversations and data retention periods within enterprise accounts. This represents a material shift in data governance authority that affects how enterprise customers must document employee monitoring practices and may create compliance implications under privacy regulations. The expanded retention exception also permits OpenAI to retain deleted conversations longer than previously stated, creating operational discretion that may complicate data deletion commitments.
OpenAI
OpenAI API Data Usage Policies [RETIRED: redirects to /enterprise-privacy/ (CA-D-000825)]
medium
Workspace admins gain authority to view, export, and delete end user conversations; retention now controlled by admins rather than users
Why it matters: The updated terms transfer control over conversation data retention from individual users to workspace admins and expand OpenAI's authority to retain deleted data beyond the standard 30-day window. Organizations using ChatGPT Business need to clarify how admins will exercise this new authority and may need to update privacy notices or vendor agreements if they previously represented that users controlled retention or that data would be deleted after 30 days.
May 27, 2026
eBay
eBay User Agreement
medium
Updated User Agreement effective June 28, 2026 adds policy incorporation requirements, identifies jurisdiction-specific eBay entities, and emphasizes arbitration and class action waiver provisions.
Why it matters: The updated agreement restructures how eBay's policies bind users by explicitly incorporating external policies into the core User Agreement, clarifies which eBay legal entity users contract with by jurisdiction, and emphasizes mandatory arbitration and class action waiver provisions. This materialization of dispute resolution and policy incorporation provisions in the main agreement makes the terms more prominent and may affect users' understanding of their rights and obligations.
Poshmark
Poshmark Privacy Policy
medium
Adds detailed prohibited and restricted items categories, explicit seller obligations, and enforcement powers including account suspension and payment withholding.
Why it matters: The updated policy explicitly establishes enforcement mechanisms (account suspension, payment withholding, item destruction) and detailed product restrictions that create clear seller liability and operational risk. Sellers now have specific, documented compliance obligations for cosmetics, electronics, mystery boxes, and other restricted categories, along with explicit notice that violations may result in permanent account suspension and payment withholding.
Poshmark
Poshmark Terms of Service
medium
Expanded prohibited items policy with detailed conditions for restricted categories and explicit enforcement penalties including account suspension and payment withholding.
Why it matters: The updated policy establishes detailed operational requirements for selling certain product categories and explicit enforcement authority, creating material compliance obligations for sellers. Non-compliance can result in account suspension, payment withholding, and item destruction, making it operationally significant for anyone listing cosmetics, electronics, mystery boxes, or socks and underwear on the platform.
Coursera
Coursera Terms of Use
high
Removed refund eligibility for prepaid specializations and Coursera Plus plans purchased by India-based users
Why it matters: The removal of explicit refund language eliminates previously disclosed consumer protections for prepaid purchases in India, creating operational uncertainty about refund eligibility and exposing both the company and downstream organizations to potential regulatory or consumer protection challenges in a jurisdiction with active consumer protection enforcement.
Duolingo
Duolingo Privacy Policy
medium
Removes platform-specific audio collection exemptions; establishes unified opt-out for all users
Why it matters: The updated policy removes explicit language that previously protected Android and web users from audio collection, replacing it with language that allows all users to opt out within app Settings. This change expands the stated scope of audio collection authorization and removes contractual certainty about which platforms are subject to collection. Organizations incorporating Duolingo's services into privacy compliance frameworks should clarify whether this policy change reflects a shift in actual collection practices or simply a clarification of existing practices.
Stay ahead of the changes

You're seeing a fraction of what's changing

ConductAtlas monitors every tracked platform and captures every policy update.

May 25, 2026
Medium
Medium Terms of Service
medium
Expanded scope of personal data collection warranty to cover all user-provided information, not limited to newsletter editors.
Why it matters: The updated terms now require users to warrant that all personal information they provide to Medium has been lawfully collected with required notices and consents obtained. This expanded warranty creates liability exposure for users who submit third-party data without proper consent documentation and may increase Medium's ability to enforce data compliance requirements across all user submissions, not just newsletter editor materials.
May 24, 2026
Cohere
Cohere Usage Policy
high
Removed entire acceptable use policy including child safety, sexually explicit content prohibitions, and enforcement procedures.
Why it matters: The complete removal of Cohere's Usage Policy eliminates the primary posted reference document defining prohibited conduct and enforcement procedures. Organizations relying on this policy as part of vendor governance, data processing agreements, or child safety compliance frameworks will need to identify alternative documentation or establish independent usage restrictions. The removal of child safety prohibitions from the public policy creates potential regulatory and reputational risk, particularly under COPPA if Cohere Services are used by or on behalf of minors.
May 23, 2026
Unity
Unity Terms of Service
medium
Reorganizes dispute resolution and governing law across regions; adds England with London arbitration and New York law
Why it matters: The updated terms explicitly establish that England-based users will have disputes administered through London arbitration under New York law, removing prior ambiguity about which arbitration institution and governing law would apply to England-based disputes. For organizations using Unity as a vendor, this clarification may require verification that customer-facing terms accurately reflect the arbitration procedures now stated in Unity's updated terms.
Snowflake
Snowflake Privacy Notice
medium
Removed explicit unsubscribe guarantee and adjusted pronoun and cookie terminology in Privacy Notice.
Why it matters: The removal of explicit unsubscribe language eliminates a documented mechanism users could rely on to manage communications. Under GDPR, CCPA, and CAN-SPAM, clear opt-out mechanisms are generally required for marketing communications; the removal of this disclosure may create compliance questions if unsubscribe functionality is no longer available or if the company's actual practice diverges from the new silence on the topic.
RunPod
RunPod Terms of Service
medium
Removes promotional bonuses and product marketing from Terms of Service; restructures document with formal legal binding language and explicit update date.
Why it matters: The restructured Terms of Service clarifies the document's function as a binding legal agreement and removes marketing content that may have created ambiguity about what constitutes contractual obligations versus promotional messaging. This formalization generally improves clarity about the legal framework governing service use, though users should verify the current status of promotional programs through non-terms channels.
AWS Bedrock
AWS Service Terms
medium
Adds noncancellation obligation for Reserved Capacity purchases; establishes 60-day input retention for Kiro Free Tier abuse detection
Why it matters: The updated terms establish that reserved capacity purchases create binding noncancellable payment obligations that persist even if the AWS agreement terminates, removing any termination-based exit mechanism for these commitments. The explicit authorization to retain Kiro Free Tier inputs for 60 days establishes a data retention and processing practice that may affect privacy compliance obligations for organizations processing regulated data through Kiro.
TurboTax
TurboTax Privacy Statement
medium
Adds explicit disclosure of cookie tracking, advertising partner data sharing, and user opt-out mechanisms for third-party advertising cookies.
Why it matters: The updated terms establish explicit disclosure of a previously less-detailed advertising data-sharing practice: TurboTax now states it may share IP addresses and device identifiers with advertising partners. This disclosure creates transparency about how user data is used for targeted advertising and acknowledges that such practices may trigger privacy law requirements in certain jurisdictions. The addition of an opt-out control for advertising cookies provides users a mechanism to limit certain tracking, though the policy makes clear that essential website cookies cannot be refused.
Stay ahead of the changes

You're seeing a fraction of what's changing

ConductAtlas monitors every tracked platform and captures every policy update.

May 22, 2026
LangChain
LangChain Terms of Service
medium
Adds BYOC deployment option, clarifies hybrid deployment architecture, and extends data-protection commitment to explicitly exclude LLM training.
Why it matters: The introduction of BYOC Deployment and redefinition of Hybrid Deployment clarify infrastructure control options, allowing enterprises to evaluate data residency and operational control tradeoffs more precisely. The explicit extension of data-use restrictions to exclude LLM training directly addresses a key concern in AI governance and may affect how organizations assess vendor compliance with their own AI governance frameworks. The expanded non-warranty clause removes guarantees of accuracy and completeness, which affects what assurances customers can rely on operationally.
Segment
Segment Privacy Policy
medium
Adds opt-out mechanism for third-party data disclosure and explicit FTC oversight notice; clarifies dispute resolution framework reference.
Why it matters: The updated terms establish a new user control mechanism over data sharing and secondary use, which operationally empowers users to restrict how their data flows to third parties and how it is deployed for new purposes. The explicit FTC oversight disclosure establishes regulatory transparency about which federal authority has enforcement jurisdiction over Segment's privacy practices. For organizations using Segment as a vendor, these changes may require privacy notice updates to ensure customer-facing representations remain accurate.
Twilio
Twilio Privacy Notice
medium
Adds FTC oversight disclosure and opt-out mechanism for third-party data sharing and materially different uses
Why it matters: The updated terms establish explicit FTC oversight disclosure and introduce a user-accessible opt-out mechanism for third-party data sharing and materially different uses. These additions operationalize user data control rights and clarify regulatory accountability, which may affect how Twilio customers communicate data practices in their own policies and how data subject requests are processed.
May 21, 2026
Ford
Ford Privacy Policy
medium
Privacy policy restructure: added California disclosure requirements, OneTrust consent management, and expanded data governance language while removing standalone review moderation details.
Why it matters: The updated privacy policy establishes a legally compliant disclosure framework for state privacy laws by consolidating information and implementing OneTrust consent management, which reflects Ford's commitment to meet evolving regulatory requirements. The restructuring affects how users encounter and manage their consent choices, and the removal of specific review moderation details creates a need to ensure those practices are documented elsewhere to avoid regulatory exposure for deceptive omissions.
Ford
Ford Terms and Conditions
medium
Removed detailed disclosures describing customer review collection, moderation criteria, and third-party vendor involvement.
Why it matters: The updated Terms eliminate prior disclosures about how Ford collects and moderates customer reviews and which third-party vendor administers the process. This reduction in transparency may affect consumer confidence in review authenticity and could expose Ford to regulatory scrutiny if the prior disclosures were considered material under consumer protection law.
Google Gemini
Gemini Apps Privacy Notice
medium
Adds disclosures for Gemini Spark remote access, Avatar creation, and AI task execution data collection.
Why it matters: The updated notice expands transparency around two new Gemini capabilities (Spark with remote access and Avatars) and clarifies that data collection includes information about AI reasoning and task execution steps. This allows users to understand what data flows occur when using these features, though it does not establish new user controls or opt-out mechanisms for the disclosed practices.
Coursera
Coursera Terms of Use
medium
Removes standardized 7-day free trial guarantee; now states certain subscriptions 'may' include variable trial periods with details on checkout pages.
Why it matters: The updated terms establish that free trial availability and duration are now variable by subscription type rather than standardized. This shifts trial information discovery from the main contract terms to individual checkout pages, requiring users to verify specifics at the point of purchase. The change does not eliminate trials entirely but removes the explicit guarantee that was previously stated in the standard terms.
Meta
Llama API Terms of Service
medium
Adds automatic content retention authority when internal systems flag data for potential policy violations
Why it matters: The updated terms establish a new, automated basis for Meta to retain user-submitted content without explicit time limits. This expands Meta's unilateral control over data lifecycle in the Llama API context and may create compliance complexity for organizations that process personal data through the API and operate under regulatory frameworks imposing data retention limits.
Stay ahead of the changes

You're seeing a fraction of what's changing

ConductAtlas monitors every tracked platform and captures every policy update.

May 19, 2026
Segment
Segment Privacy Policy
medium
Added explicit Data Privacy Framework certifications and opt-out rights for third-party data disclosure and non-authorized uses.
Why it matters: The updated terms establish explicit legal compliance commitments and international transfer mechanisms for personal data from regulated jurisdictions. By certifying DPF compliance and stating that DPF Principles take precedence, Segment provides clearer legal grounding for cross-border data transfers from the EU, UK, and Switzerland to the U.S. The addition of specific opt-out rights for third-party disclosure and non-authorized uses strengthens transparency and user control mechanisms for affected data subjects. Organizations relying on Segment must ensure their own compliance documentation and vendor management accurately reflect these mechanisms.
Twilio
Twilio Privacy Notice
medium
Expands DPF compliance disclosures and specifies that Data Privacy Framework Principles take precedence over other policy terms.
Why it matters: The updated language clarifies Twilio's legal basis for processing EU, UK, and Swiss personal data in the United States by making explicit its Data Privacy Framework certifications and establishing that DPF Principles take precedence over conflicting policy terms. This affects the validity of data transfers and any organization relying on Twilio for cross-border personal data processing must confirm that this framework aligns with their own data transfer justifications.
Bumble
Bumble Terms and Conditions
medium
Narrows content distribution license to app-only use, adds account verification disclosure, clarifies app deletion does not remove accounts.
Why it matters: The narrowing of Bumble's content distribution rights from the general public to app-only use materially reduces the company's stated contractual authority over user-generated content and may affect third-party content access or licensing. The added verification disclosure provides transparency regarding account security and age compliance procedures, which reflects regulatory pressure around account verification practices and may clarify the lawful basis for collection and processing of verification data.
SoFi
SoFi Terms of Service
medium
Updated SoFi Plus billing to monthly cycles and added right to modify fees upon advance notice. Payment authorization now ends on payment method change or cancellation.
Why it matters: The updated terms explicitly authorize SoFi to modify subscription fees and billing intervals upon advance notice, establishing a contractual right to unilateral modification that was not previously stated. This affects pricing predictability for subscribers and may engage state automatic renewal laws that impose specific requirements for how and when subscription modifications can be communicated and implemented. The clarification that payment authorization terminates upon payment method change (not just cancellation) affects how recurring charges are processed and how subscribers can control ongoing billing.
May 16, 2026
Indeed
Indeed Terms of Service
medium
Removed auto-apply activity from pricing factors; added explicit tax billing obligations and premium feature loss on budget reduction
Why it matters: The updated terms establish explicit tax obligations and calculation procedures that affect the true cost of sponsored ads. Users are now directly responsible for applicable taxes determined by Indeed based on location, and the terms clarify that budget reductions trigger loss of premium features. The removal of auto-apply from pricing factors reduces transparency about what determines ad pricing.
May 15, 2026
Supabase
Supabase Privacy Policy
medium
Adds disclosure of business contact use for marketing outreach and Customer.io data sharing; requires consent for location-based and cross-source marketing analysis.
Why it matters: The updated policy establishes explicit disclosure of a specific marketing vendor (Customer.io) and clarifies the consent framework for marketing uses of personal information, including location-based and cross-source data analysis. This provides greater specificity about third parties receiving data and establishes granular controls over marketing-related uses, which affects how users and downstream organizations must document vendor relationships and consent mechanisms.
RapidAPI
RapidAPI Terms of Use
medium
Adds GenAI Features section with as-is provision, output verification requirement, and chatbot data restrictions.
Why it matters: The updated terms establish a new liability and verification framework for GenAI functionality that shifts responsibility for output accuracy and verification to users while limiting RapidAPI's liability. Organizations and users relying on GenAI outputs for decision-making, recommendations, or business operations need to understand that these outputs carry no warranty and require independent verification. The explicit data restriction on chatbots also creates a compliance and operational boundary that users and organizations must respect to avoid inadvertent personal data exposure.
Stay ahead of the changes

Don't manually check every platform

Get alerts when policies change, before it affects you.

Updated daily. New changes added as detected.

← Newer Page 8 of 13 Older →