{
  "meta": {
    "kit": "ledger-kit",
    "buildDate": "2026-09-15",
    "lastVerified": "2026-09-15",
    "license": "CC BY 4.0",
    "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
    "cadence": "weekly, every Monday, and the same day for any terms change a vendor announces",
    "note": "Five verdicts carry every row. Verified means the document was fetched at the vendor's own publisher on the date given. Reported means a reliable secondary carries the fact and the primary could not be reached, and a reported row never prints as verified. Announced means a vendor said it will act and no document exists. Absent means the ledger searched and the documents say nothing, and the search is written into the record. Open means a question nobody has settled. Every facet quotes the vendor's own document, never a reputation, never a press summary, and a facet the document does not answer is marked absent rather than guessed.",
    "vocab": {
      "idPrefix": "AVD",
      "root": "/tools/ai-vendor-data-ledger",
      "title": "The AI Vendor Data Handling Ledger",
      "short": "AI Vendor Data Ledger",
      "claim": "What each AI product tier contractually says happens to your data: training use, retention, deletion, region, subprocessors, human review, opt outs and the DPA. Read at the vendor's own terms, dated, never inferred from reputation.",
      "changesHeading": "For a buyer or a workplace AI policy",
      "kinds": [
        {
          "key": "consumer",
          "label": "Consumer tier",
          "question": "What happens to what a person types on a free or personal plan?"
        },
        {
          "key": "business",
          "label": "Business tier",
          "question": "What happens to what a team or an enterprise puts in?"
        },
        {
          "key": "api",
          "label": "API and platform",
          "question": "What happens to what a developer sends through the API?"
        },
        {
          "key": "question",
          "label": "Open question",
          "question": "What has nobody settled?"
        }
      ],
      "jurisdictions": [
        {
          "code": "US",
          "name": "United States"
        },
        {
          "code": "EU",
          "name": "European Union"
        },
        {
          "code": "FR",
          "name": "France"
        },
        {
          "code": "CN",
          "name": "China"
        },
        {
          "code": "GLOBAL",
          "name": "Global"
        }
      ],
      "facets": [
        {
          "key": "training_use",
          "label": "Used for training by default"
        },
        {
          "key": "retention",
          "label": "Retention period"
        },
        {
          "key": "deletion",
          "label": "Deletion on request"
        },
        {
          "key": "region",
          "label": "Storage region and residency"
        },
        {
          "key": "subprocessors",
          "label": "Subprocessor list published"
        },
        {
          "key": "human_review",
          "label": "Human review of content"
        },
        {
          "key": "opt_out",
          "label": "Opt out available"
        },
        {
          "key": "dpa",
          "label": "DPA available"
        },
        {
          "key": "memory",
          "label": "Persistent memory across sessions"
        },
        {
          "key": "terms_changed",
          "label": "Last change to the terms"
        }
      ]
    },
    "source": "https://www.gage.academy/tools/ai-vendor-data-ledger",
    "attribution": "GAGE (Global Academy of Generative-AI Education), AI Vendor Data Ledger",
    "documentation": "https://www.gage.academy/tools/ai-vendor-data-ledger/data",
    "methodology": "https://www.gage.academy/tools/ai-vendor-data-ledger/method"
  },
  "records": [
    {
      "id": "AVD-2026-0001",
      "slug": "openai-chatgpt-free-plus-pro",
      "title": "ChatGPT Free, Plus and Pro",
      "kind": "consumer",
      "verdict": "verified",
      "jurisdiction": "US",
      "answer": "OpenAI's help centre states that content from ChatGPT for individuals may be used to train its models, so training is the default and the person must switch off Improve the model for everyone. Deleted data leaves OpenAI systems within 30 days. Content is stored in the United States and around the world. No data processing addendum covers this tier.",
      "key_facts": [
        "Training is on by default on the consumer plans. The help centre says OpenAI may use content from services for individuals to train its models.",
        "The privacy policy commits to removing deleted personal data from OpenAI systems within 30 days.",
        "Saved memories sit apart from chat history, so deleting a chat does not delete a memory drawn from it.",
        "The enterprise privacy page names ChatGPT Business, ChatGPT Enterprise and the API as the products OpenAI will sign a DPA for. No consumer plan is on that list."
      ],
      "figures": [
        {
          "label": "Deletion of personal data from OpenAI systems",
          "value": 30,
          "unit": "days",
          "as_of": "2026-02-06",
          "source": 0
        }
      ],
      "facets": [
        {
          "key": "training_use",
          "value": "Yes by default. The help centre states that when you use services for individuals such as ChatGPT, OpenAI may use your content to train its models.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "retention",
          "value": "Kept until the person deletes it, then removed from OpenAI systems within 30 days, with longer retention where law, safety or fraud work requires it.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "deletion",
          "value": "Individual chats, whole history, single saved memories or the account can be deleted. Content already de identified for model improvement is not pulled back.",
          "verdict": "verified",
          "source": 2
        },
        {
          "key": "region",
          "value": "No residency guarantee. The consumer FAQ says content is stored on OpenAI and service provider systems in the United States and around the world.",
          "verdict": "verified",
          "source": 2
        },
        {
          "key": "subprocessors",
          "value": "The published list is scoped to the business products and names Plus and Pro only for web hosting of ChatGPT Sites, so consumers get categories rather than a list.",
          "verdict": "verified",
          "source": 4
        },
        {
          "key": "human_review",
          "value": "Yes. Authorised staff and service providers may access content for abuse work, support, legal matters and model improvement, and the page warns against entering sensitive information.",
          "verdict": "verified",
          "source": 2
        },
        {
          "key": "opt_out",
          "value": "Yes. Improve the model for everyone under Settings and Data Controls, reversible at any time. Submitting thumbs up or thumbs down feedback re enables training on that conversation.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "dpa",
          "value": "None for the consumer plans. The enterprise privacy page lists ChatGPT Business, ChatGPT Enterprise and the API as the DPA products and no consumer tier appears.",
          "verdict": "absent",
          "source": 4
        },
        {
          "key": "memory",
          "value": "Yes, on by default, stored separately from chats. The memory article says a saved memory can still be used in future conversations even after the chat is deleted.",
          "verdict": "verified",
          "source": 3
        },
        {
          "key": "terms_changed",
          "value": "The privacy policy prints Updated 6 February 2026. The help centre articles that govern training and controls print a relative age only and no absolute date.",
          "verdict": "verified",
          "source": 0
        }
      ],
      "what_it_changes": "If your workplace policy says staff may use a personal ChatGPT account for work, this row is the reason to stop. The consumer tier trains on what is typed unless each person finds a setting, there is no contract you can sign, there is no residency choice, and a memory survives the deletion of the chat that created it. A policy that permits personal accounts is permitting an uncontrolled disclosure with no processor agreement behind it.",
      "sources": [
        {
          "name": "OpenAI privacy policy",
          "url": "https://openai.com/policies/row-privacy-policy/",
          "type": "primary",
          "date": "2026-02-06"
        },
        {
          "name": "OpenAI Help Center, how your data is used to improve model performance",
          "url": "https://help.openai.com/en/articles/5722486-how-your-data-is-used-to-improve-model-performance",
          "type": "primary",
          "date": "2026-09-15"
        },
        {
          "name": "OpenAI Help Center, data usage for consumer services FAQ",
          "url": "https://help.openai.com/en/articles/7039943-data-usage-for-consumer-services-faq",
          "type": "primary",
          "date": "2026-09-15"
        },
        {
          "name": "OpenAI Help Center, memory FAQ",
          "url": "https://help.openai.com/en/articles/8590148-memory-faq",
          "type": "primary",
          "date": "2026-09-15"
        },
        {
          "name": "OpenAI enterprise privacy",
          "url": "https://openai.com/enterprise-privacy/",
          "type": "primary",
          "date": "2026-01-08"
        }
      ],
      "related_ids": [
        "AVD-2026-0002",
        "AVD-2026-0003",
        "AVD-2026-0004",
        "AVD-2026-0031"
      ],
      "tags": [
        "openai",
        "chatgpt",
        "consumer",
        "training default",
        "memory"
      ],
      "date_added": "2026-09-15",
      "last_verified": "2026-09-15",
      "last_modified": "2026-09-15"
    },
    {
      "id": "AVD-2026-0002",
      "slug": "openai-chatgpt-business",
      "title": "ChatGPT Business, the plan formerly called Team",
      "kind": "business",
      "verdict": "verified",
      "jurisdiction": "US",
      "answer": "OpenAI does not train on inputs or outputs from ChatGPT Business by default and treats sharing as an opt in. Deleted or unsaved conversations leave its systems within 30 days. Workspace admins can view, export and delete end user conversations. A data processing addendum is available, and the subprocessor list carries a 30 day objection window.",
      "key_facts": [
        "The training article states that by default OpenAI does not train on inputs or outputs from its products for business users, including ChatGPT Business.",
        "The help centre records that the ChatGPT Team plan was renamed ChatGPT Business on 29 August 2025.",
        "Workspace admins can view, access, export and delete end user conversations.",
        "The DPA gives the customer 30 days to object to a new subprocessor after notice."
      ],
      "figures": [
        {
          "label": "Removal of deleted or unsaved conversations",
          "value": 30,
          "unit": "days",
          "as_of": "2026-01-08",
          "source": 0
        },
        {
          "label": "Window to object to a new subprocessor",
          "value": 30,
          "unit": "days",
          "as_of": "2026-01-01",
          "source": 2
        }
      ],
      "facets": [
        {
          "key": "training_use",
          "value": "No by default, opt in only. The article says OpenAI does not train on any inputs or outputs from its products for business users, including ChatGPT Business.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "retention",
          "value": "Admins control the period. Deleted or unsaved conversations are removed within 30 days unless longer retention is required by law or is needed to protect the service or a third party.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "deletion",
          "value": "Yes, and the admin reach is broad. Workspace admins can view, access, export and delete end user conversations.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "region",
          "value": "No residency selector is documented for this tier. Processing locations are disclosed per entity in the subprocessor table rather than chosen by the customer.",
          "verdict": "verified",
          "source": 3
        },
        {
          "key": "subprocessors",
          "value": "Yes, published and dated, with ChatGPT Business named against each entity, a change notification subscription and a 30 day objection right in the DPA.",
          "verdict": "verified",
          "source": 3
        },
        {
          "key": "human_review",
          "value": "Yes, and wider than on Enterprise. Specialised third party contractors bound by confidentiality may review solely for abuse and misuse.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "opt_out",
          "value": "Not the usual direction. The default is already out, and the available action is opting in to share data, after which OpenAI may use the shared data to train its models.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "dpa",
          "value": "Yes. OpenAI states it is able to execute a data processing addendum with customers for their use of ChatGPT Business, with standard contractual clauses and the UK addendum.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "memory",
          "value": "Yes, per user and not shareable, with a workspace level switch. Workspace data, including conversations and memories, is not used to train OpenAI models.",
          "verdict": "verified",
          "source": 4
        },
        {
          "key": "terms_changed",
          "value": "The enterprise privacy page prints Updated 8 January 2026. The DPA prints Updated 1 December 2025 and Effective 1 January 2026, and the subprocessor list prints Last updated 9 July 2026.",
          "verdict": "verified",
          "source": 0
        }
      ],
      "what_it_changes": "This is the cheapest OpenAI tier a workplace policy can actually name, because it is the first one with a signable contract, an admin who can delete, and a subprocessor list you can subscribe to. Two things a buyer should still write down: third party contractors may read flagged content on this tier, which is not true of Enterprise, and there is no residency choice, so a team with a data location requirement has not solved it by buying this plan.",
      "sources": [
        {
          "name": "OpenAI enterprise privacy",
          "url": "https://openai.com/enterprise-privacy/",
          "type": "primary",
          "date": "2026-01-08"
        },
        {
          "name": "OpenAI Help Center, how your data is used to improve model performance",
          "url": "https://help.openai.com/en/articles/5722486-how-your-data-is-used-to-improve-model-performance",
          "type": "primary",
          "date": "2026-09-15"
        },
        {
          "name": "OpenAI data processing addendum",
          "url": "https://openai.com/policies/data-processing-addendum/",
          "type": "primary",
          "date": "2026-01-01"
        },
        {
          "name": "OpenAI subprocessor list",
          "url": "https://openai.com/policies/subprocessors/",
          "type": "primary",
          "date": "2026-07-09"
        },
        {
          "name": "OpenAI Help Center, memory FAQ for business",
          "url": "https://help.openai.com/en/articles/9295112-memory-faq-business-version",
          "type": "primary",
          "date": "2026-09-15"
        }
      ],
      "related_ids": [
        "AVD-2026-0001",
        "AVD-2026-0003",
        "AVD-2026-0004",
        "AVD-2026-0029"
      ],
      "tags": [
        "openai",
        "chatgpt business",
        "dpa",
        "subprocessors",
        "admin controls"
      ],
      "date_added": "2026-09-15",
      "last_verified": "2026-09-15",
      "last_modified": "2026-09-15"
    },
    {
      "id": "AVD-2026-0003",
      "slug": "openai-chatgpt-enterprise-edu",
      "title": "ChatGPT Enterprise and ChatGPT Edu",
      "kind": "business",
      "verdict": "verified",
      "jurisdiction": "US",
      "answer": "OpenAI states it does not train on your data by default and that the customer controls how long data is retained. Deleted conversations go within 30 days unless the law requires otherwise. Access is limited to authorised OpenAI employees. Enterprise is covered by a data processing addendum, while Edu is handled under a student data privacy agreement instead.",
      "key_facts": [
        "The enterprise privacy page states plainly that OpenAI does not train its models on your data by default.",
        "Retention is a customer control on Enterprise, Edu and Healthcare, and deleted conversations are removed within 30 days unless OpenAI is legally required to retain them.",
        "Edu does not travel with Enterprise on contracts. OpenAI processes Edu and Teachers data under a student data privacy agreement, not the DPA.",
        "Improved memory is disabled by default in regulated Enterprise workspaces and in ChatGPT for Healthcare."
      ],
      "figures": [
        {
          "label": "Removal of deleted conversations",
          "value": 30,
          "unit": "days",
          "as_of": "2026-01-08",
          "source": 0
        }
      ],
      "facets": [
        {
          "key": "training_use",
          "value": "No by default. The enterprise privacy page states that OpenAI does not train its models on your data by default, and dates the business and API exclusion to 1 March 2023.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "retention",
          "value": "Customer controlled, and stated as a headline commitment. Deleted conversations are removed within 30 days unless OpenAI is legally required to retain them.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "deletion",
          "value": "Yes, admin controlled, with an audit trail through the compliance API. At the end of the contract OpenAI returns or deletes customer data at the customer's instruction.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "region",
          "value": "No per workspace residency selector is documented for these tiers. European data runs through OpenAI Ireland on standard contractual clauses or an adequacy decision.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "subprocessors",
          "value": "Yes. ChatGPT Enterprise and ChatGPT Edu are named per entity, per country and per purpose, with two entries marked as at the election of the customer.",
          "verdict": "verified",
          "source": 2
        },
        {
          "key": "human_review",
          "value": "Narrowest of the OpenAI tiers. Authorised OpenAI employees access conversations only to resolve incidents, and no third party abuse contractors appear in this clause.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "opt_out",
          "value": "Already excluded by default. Automated classifiers still run over business data and the classification result is kept as metadata rather than content.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "dpa",
          "value": "Yes for Enterprise. For Edu and for Teachers, OpenAI says it processes data under its student data privacy agreement rather than the DPA.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "memory",
          "value": "Available, but improved memory is disabled by default in regulated Enterprise workspaces and in ChatGPT for Healthcare, and is excluded from the BAA.",
          "verdict": "verified",
          "source": 3
        },
        {
          "key": "terms_changed",
          "value": "The enterprise privacy page prints Updated 8 January 2026, the DPA prints Effective 1 January 2026, and the subprocessor list prints Last updated 9 July 2026.",
          "verdict": "verified",
          "source": 0
        }
      ],
      "what_it_changes": "A school and a bank buy different things here even though the marketing pairs them. Enterprise gets the DPA, the narrowest access clause on any OpenAI tier and customer controlled retention. Edu gets a student data privacy agreement instead, which a procurement checklist that only asks for a DPA will record as a gap that does not exist and will miss the terms that actually govern. Ask which instrument you are signing before you compare.",
      "sources": [
        {
          "name": "OpenAI enterprise privacy",
          "url": "https://openai.com/enterprise-privacy/",
          "type": "primary",
          "date": "2026-01-08"
        },
        {
          "name": "OpenAI data processing addendum",
          "url": "https://openai.com/policies/data-processing-addendum/",
          "type": "primary",
          "date": "2026-01-01"
        },
        {
          "name": "OpenAI subprocessor list",
          "url": "https://openai.com/policies/subprocessors/",
          "type": "primary",
          "date": "2026-07-09"
        },
        {
          "name": "OpenAI Help Center, memory FAQ",
          "url": "https://help.openai.com/en/articles/8590148-memory-faq",
          "type": "primary",
          "date": "2026-09-15"
        }
      ],
      "related_ids": [
        "AVD-2026-0002",
        "AVD-2026-0004",
        "AVD-2026-0028"
      ],
      "tags": [
        "openai",
        "chatgpt enterprise",
        "edu",
        "retention control",
        "dpa"
      ],
      "date_added": "2026-09-15",
      "last_verified": "2026-09-15",
      "last_modified": "2026-09-15"
    },
    {
      "id": "AVD-2026-0004",
      "slug": "openai-api-platform",
      "title": "The OpenAI API and platform",
      "kind": "api",
      "verdict": "verified",
      "jurisdiction": "US",
      "answer": "Since 1 March 2023 data sent to the OpenAI API is not used to train its models. Abuse monitoring logs are kept up to 30 days unless longer retention is required by law. Zero data retention and modified abuse monitoring exist but need prior approval. Ten data residency regions are offered, and non United States regions require approval.",
      "key_facts": [
        "The platform guide states that as of 1 March 2023, data sent to the OpenAI API is not used to train or improve OpenAI models.",
        "Abuse monitoring logs are generated for all API feature usage and retained for up to 30 days unless longer retention is required by law.",
        "Objects that are not deleted through the API or the dashboard are retained indefinitely.",
        "Flagged image and file inputs are retained for manual review even where zero data retention, modified abuse monitoring or eyes off is enabled."
      ],
      "figures": [
        {
          "label": "Abuse monitoring log retention",
          "value": 30,
          "unit": "days",
          "as_of": "2026-09-15",
          "source": 0
        },
        {
          "label": "Prompt cache expiry",
          "value": 24,
          "unit": "hours",
          "as_of": "2026-09-15",
          "source": 0
        },
        {
          "label": "Data residency regions offered",
          "value": 10,
          "unit": "regions",
          "as_of": "2026-09-15",
          "source": 0
        }
      ],
      "facets": [
        {
          "key": "training_use",
          "value": "No, and dated. The platform guide states that as of 1 March 2023 data sent to the OpenAI API is not used to train or improve OpenAI models unless you opt in.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "retention",
          "value": "Not one number. Abuse logs up to 30 days, audio outputs one hour, prompt caches 24 hours, and stored conversations, files and vector stores until deleted.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "deletion",
          "value": "Files can be deleted or set to expire and Assistants objects go 30 days after deletion, but objects never deleted through the API or dashboard are retained indefinitely.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "region",
          "value": "The only OpenAI tier with a residency control. Ten regions, per project or per request, and any region other than the United States requires approval for abuse monitoring controls.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "subprocessors",
          "value": "Yes, with the API named per entity and a marker on the entries that do not apply where zero data retention is used.",
          "verdict": "verified",
          "source": 2
        },
        {
          "key": "human_review",
          "value": "Yes by default and never zero. Even under zero data retention or modified abuse monitoring, an image flagged as potential child sexual abuse material is retained for manual review.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "opt_out",
          "value": "Already out of training. The further controls, zero data retention and modified abuse monitoring, are subject to prior approval by OpenAI and acceptance of additional requirements.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "dpa",
          "value": "Yes, plus a business associate agreement for HIPAA work and enterprise key management for customer held encryption keys.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "memory",
          "value": "No cross session memory feature. Persistence is a developer choice through the store parameter, the conversations endpoints or vector stores, and zero data retention forces store to false.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "terms_changed",
          "value": "The guide that defines API retention, zero data retention and residency prints no date at all. The nearest dated instruments are the DPA effective 1 January 2026 and the enterprise privacy page of 8 January 2026.",
          "verdict": "absent",
          "source": 0
        }
      ],
      "what_it_changes": "If you are choosing where to put regulated workloads, the API is the only OpenAI surface with a residency control, and it is also the surface whose governing document carries no date. Write the approval requirements into your plan: zero data retention and modified abuse monitoring are granted by OpenAI, not switched on by you, and a flagged image is reviewed by a person whatever you have been granted. Build the schedule around the approval, not the launch.",
      "sources": [
        {
          "name": "OpenAI platform, data controls in the OpenAI platform",
          "url": "https://developers.openai.com/api/docs/guides/your-data",
          "type": "primary",
          "date": "2026-09-15"
        },
        {
          "name": "OpenAI enterprise privacy",
          "url": "https://openai.com/enterprise-privacy/",
          "type": "primary",
          "date": "2026-01-08"
        },
        {
          "name": "OpenAI subprocessor list",
          "url": "https://openai.com/policies/subprocessors/",
          "type": "primary",
          "date": "2026-07-09"
        }
      ],
      "related_ids": [
        "AVD-2026-0003",
        "AVD-2026-0026",
        "AVD-2026-0030"
      ],
      "tags": [
        "openai",
        "api",
        "zero data retention",
        "data residency",
        "abuse monitoring"
      ],
      "date_added": "2026-09-15",
      "last_verified": "2026-09-15",
      "last_modified": "2026-09-15"
    },
    {
      "id": "AVD-2026-0005",
      "slug": "anthropic-claude-free-pro-max",
      "title": "Claude Free, Pro and Max",
      "kind": "consumer",
      "verdict": "verified",
      "jurisdiction": "US",
      "answer": "The privacy policy effective 10 September 2026 says Anthropic may use consumer inputs and outputs to train its models unless you opt out in account settings. Allowing training extends retention to five years in de identified form, against 30 days otherwise. Flagged material is used for safety work even if you opt out. Memory is on by default.",
      "key_facts": [
        "The privacy policy states Anthropic may use your inputs and outputs to train and improve its models unless you opt out through your account settings.",
        "Data may be retained in de identified form for up to five years in model training pipelines where the person allows training.",
        "A deleted conversation leaves the history at once and the back end within 30 days.",
        "Flagged chats carry inputs and outputs for up to two years and trust and safety classification scores for up to seven years."
      ],
      "figures": [
        {
          "label": "Retention in model training pipelines when training is allowed",
          "value": 5,
          "unit": "years",
          "as_of": "2026-07-01",
          "source": 2
        },
        {
          "label": "Back end deletion after a person deletes a chat",
          "value": 30,
          "unit": "days",
          "as_of": "2026-07-01",
          "source": 2
        },
        {
          "label": "Retention of inputs and outputs when a chat is flagged",
          "value": 2,
          "unit": "years",
          "as_of": "2026-07-01",
          "source": 2
        },
        {
          "label": "Retention of trust and safety classification scores",
          "value": 7,
          "unit": "years",
          "as_of": "2026-07-01",
          "source": 2
        }
      ],
      "facets": [
        {
          "key": "training_use",
          "value": "Yes unless you act. The policy says Anthropic may use your inputs and outputs to train and improve its models unless you opt out through your account settings.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "retention",
          "value": "Five years de identified in training pipelines for those who allow training, 30 days in the back end otherwise, two years for flagged content and seven for classification scores.",
          "verdict": "verified",
          "source": 2
        },
        {
          "key": "deletion",
          "value": "A deleted conversation is removed immediately from the history and automatically deleted from the back end within 30 days.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "region",
          "value": "No residency choice. The policy says personal data is transferred to servers in the United States or to other countries outside the European Economic Area.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "subprocessors",
          "value": "The policy points to a published list of the third parties Anthropic engages, but the trust centre page that now hosts it returned only its heading, so the entries are unread.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "human_review",
          "value": "Material flagged for safety review is used to train trust and safety classification and generative models even for people who opt out, disassociated from the user id.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "opt_out",
          "value": "Yes, in account settings. Two exceptions survive it: feedback you submit on a response, and materials flagged for safety review.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "dpa",
          "value": "None on the consumer plans. The DPA article scopes itself to the commercial products such as Claude for Work and the Claude API.",
          "verdict": "absent",
          "source": 3
        },
        {
          "key": "memory",
          "value": "On by default on the consumer plans, with pause and reset controls, and incognito chats are excluded from memory.",
          "verdict": "verified",
          "source": 4
        },
        {
          "key": "terms_changed",
          "value": "The privacy policy prints Effective 10 September 2026 and the consumer terms print Effective 8 October 2025. The retention article prints Last Updated 1 July 2026.",
          "verdict": "verified",
          "source": 0
        }
      ],
      "what_it_changes": "The consumer choice here is not binary, it is a retention lever. Leaving training on stretches retention from 30 days to five years in de identified form, so a person who allows it is agreeing to a different lifecycle, not just a different use. A workplace policy that tells staff to use a personal Claude account for anything confidential is choosing the five year path by default, with no DPA behind it and no residency choice.",
      "sources": [
        {
          "name": "Anthropic privacy policy",
          "url": "https://www.anthropic.com/legal/privacy",
          "type": "primary",
          "date": "2026-09-10"
        },
        {
          "name": "Anthropic consumer terms of service",
          "url": "https://www.anthropic.com/legal/consumer-terms",
          "type": "primary",
          "date": "2025-10-08"
        },
        {
          "name": "Anthropic privacy centre, how long do you store my data",
          "url": "https://privacy.claude.com/en/articles/10023548-how-long-do-you-store-my-data",
          "type": "primary",
          "date": "2026-07-01"
        },
        {
          "name": "Anthropic privacy centre, the data processing addendum",
          "url": "https://privacy.claude.com/en/articles/7996862-how-do-i-view-and-sign-your-data-processing-addendum-dpa",
          "type": "primary",
          "date": "2026-03-16"
        },
        {
          "name": "Claude support, how Claude's memory works",
          "url": "https://support.claude.com/en/articles/11817273-how-does-claude-s-memory-work",
          "type": "primary",
          "date": "2026-09-15"
        }
      ],
      "related_ids": [
        "AVD-2026-0006",
        "AVD-2026-0007",
        "AVD-2026-0001",
        "AVD-2026-0031"
      ],
      "tags": [
        "anthropic",
        "claude",
        "consumer",
        "five year retention",
        "opt out"
      ],
      "date_added": "2026-09-15",
      "last_verified": "2026-09-15",
      "last_modified": "2026-09-15"
    },
    {
      "id": "AVD-2026-0006",
      "slug": "anthropic-claude-for-work",
      "title": "Claude for Work, Team and Enterprise",
      "kind": "business",
      "verdict": "verified",
      "jurisdiction": "US",
      "answer": "The commercial terms state flatly that Anthropic may not train models on customer content from the services. Inputs and outputs are deleted from the back end within 30 days, with two year and seven year carve outs for flagged material. The DPA with standard contractual clauses is incorporated automatically. Memory is off by default and an owner must enable it.",
      "key_facts": [
        "The commercial terms state that Anthropic may not train models on customer content from the services.",
        "Anthropic deletes inputs and outputs on its back end within 30 days of receipt or generation for commercial products.",
        "Flagged content carries two year retention of inputs and outputs and seven year retention of trust and safety classification scores.",
        "The DPA with standard contractual clauses is automatically incorporated into the commercial terms of service."
      ],
      "figures": [
        {
          "label": "Back end deletion of commercial inputs and outputs",
          "value": 30,
          "unit": "days",
          "as_of": "2026-07-01",
          "source": 1
        },
        {
          "label": "Retention of flagged inputs and outputs",
          "value": 2,
          "unit": "years",
          "as_of": "2026-07-01",
          "source": 1
        },
        {
          "label": "Retention of trust and safety classification scores",
          "value": 7,
          "unit": "years",
          "as_of": "2026-07-01",
          "source": 1
        }
      ],
      "facets": [
        {
          "key": "training_use",
          "value": "No. The commercial terms say Anthropic may not train models on customer content from the services, and the privacy centre repeats it for the commercial products.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "retention",
          "value": "Conversations persist while the organisation keeps them, and inputs and outputs are deleted from the back end within 30 days of receipt or generation.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "deletion",
          "value": "Admins and users delete chats from the dashboard and they leave the history immediately, with the 30 day back end window behind them.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "region",
          "value": "No residency commitment is printed for Team or Enterprise. The documented geography controls belong to the API workspace, not to Claude for Work.",
          "verdict": "absent",
          "source": 3
        },
        {
          "key": "subprocessors",
          "value": "A list is referenced but could not be read. The trust centre page returned only its heading and the legal path returns a not found response.",
          "verdict": "absent",
          "source": 4
        },
        {
          "key": "human_review",
          "value": "No general human review of business content is stated. Feedback the customer explicitly reports may be reviewed and used for training.",
          "verdict": "verified",
          "source": 2
        },
        {
          "key": "opt_out",
          "value": "The posture is opt in rather than opt out. Training happens only where the customer reports feedback or otherwise chooses to allow it.",
          "verdict": "verified",
          "source": 2
        },
        {
          "key": "dpa",
          "value": "Yes. The DPA with standard contractual clauses is automatically incorporated into the commercial terms of service.",
          "verdict": "verified",
          "source": 3
        },
        {
          "key": "memory",
          "value": "Off by default on Team and Enterprise. An owner has to turn it on for the organisation.",
          "verdict": "verified",
          "source": 5
        },
        {
          "key": "terms_changed",
          "value": "The commercial terms print Effective 17 June 2025, the organisation retention article prints Last Updated 1 July 2026, and the DPA article prints 16 March 2026.",
          "verdict": "verified",
          "source": 0
        }
      ],
      "what_it_changes": "The no training line here is unusually strong because it sits in the contract rather than in a help article, which matters when your auditor asks what is enforceable. Two gaps belong in the same note. There is no residency commitment for this tier, so a data location requirement is not met by buying it, and the subprocessor list could not be read at the publisher on the day of checking, which is a due diligence item rather than a defect.",
      "sources": [
        {
          "name": "Anthropic commercial terms of service",
          "url": "https://www.anthropic.com/legal/commercial-terms",
          "type": "primary",
          "date": "2025-06-17"
        },
        {
          "name": "Anthropic privacy centre, how long do you store my organisation's data",
          "url": "https://privacy.claude.com/en/articles/7996866-how-long-do-you-store-my-organization-s-data",
          "type": "primary",
          "date": "2026-07-01"
        },
        {
          "name": "Anthropic privacy centre, is my data used for model training",
          "url": "https://privacy.claude.com/en/articles/7996868-is-my-data-used-for-model-training",
          "type": "primary",
          "date": "2026-09-15"
        },
        {
          "name": "Anthropic privacy centre, the data processing addendum",
          "url": "https://privacy.claude.com/en/articles/7996862-how-do-i-view-and-sign-your-data-processing-addendum-dpa",
          "type": "primary",
          "date": "2026-03-16"
        },
        {
          "name": "Anthropic trust centre, subprocessors",
          "url": "https://trust.anthropic.com/subprocessors",
          "type": "primary",
          "date": "2026-09-15"
        },
        {
          "name": "Claude support, how Claude's memory works",
          "url": "https://support.claude.com/en/articles/11817273-how-does-claude-s-memory-work",
          "type": "primary",
          "date": "2026-09-15"
        }
      ],
      "related_ids": [
        "AVD-2026-0005",
        "AVD-2026-0007",
        "AVD-2026-0029"
      ],
      "tags": [
        "anthropic",
        "claude for work",
        "commercial terms",
        "dpa",
        "memory off"
      ],
      "date_added": "2026-09-15",
      "last_verified": "2026-09-15",
      "last_modified": "2026-09-15"
    },
    {
      "id": "AVD-2026-0007",
      "slug": "anthropic-claude-developer-platform",
      "title": "The Anthropic API and Claude Developer Platform",
      "kind": "api",
      "verdict": "verified",
      "jurisdiction": "US",
      "answer": "Retained data is never used for model training without express permission. The default is 30 day retention, with zero data retention and HIPAA arrangements available and an eligibility table per feature. Flagged data may be kept up to two years even under zero data retention. Workspace storage geography is United States only and cannot be changed after creation.",
      "key_facts": [
        "The API retention page states that retained data is never used for model training without your express permission.",
        "Default commercial retention is 30 days, and code execution container data is retained up to 30 days and is not eligible for zero data retention.",
        "Flagged inputs and outputs may be retained for up to two years even under zero data retention or HIPAA arrangements.",
        "Workspace geography is set at creation and cannot be changed afterwards, and United States only inference is priced above the standard rate."
      ],
      "figures": [
        {
          "label": "Default retention of API inputs and outputs",
          "value": 30,
          "unit": "days",
          "as_of": "2026-07-01",
          "source": 1
        },
        {
          "label": "Retention of flagged data even under zero data retention",
          "value": 2,
          "unit": "years",
          "as_of": "2026-09-15",
          "source": 2
        },
        {
          "label": "Code execution container data retention",
          "value": 30,
          "unit": "days",
          "as_of": "2026-09-15",
          "source": 2
        }
      ],
      "facets": [
        {
          "key": "training_use",
          "value": "No. The retention page states that retained data is never used for model training without your express permission, and the commercial terms carry the same restriction.",
          "verdict": "verified",
          "source": 2
        },
        {
          "key": "retention",
          "value": "30 days by default, zero data retention and HIPAA arrangements available per feature, and code execution container data retained up to 30 days with no zero retention option.",
          "verdict": "verified",
          "source": 2
        },
        {
          "key": "deletion",
          "value": "Commercial deletion applies outside zero data retention, and a zero retention organisation can re enable 30 day retention for a single workspace without changing the others.",
          "verdict": "verified",
          "source": 2
        },
        {
          "key": "region",
          "value": "Two controls. An inference geography per request and a workspace storage geography that is United States only, set at creation and not changeable afterwards.",
          "verdict": "verified",
          "source": 3
        },
        {
          "key": "subprocessors",
          "value": "A list is referenced from the privacy policy but the trust centre page returned only its heading on the day of checking, so the entries are unread.",
          "verdict": "absent",
          "source": 4
        },
        {
          "key": "human_review",
          "value": "Flagged data may be retained and assessed even under zero data retention or HIPAA arrangements, for up to two years.",
          "verdict": "verified",
          "source": 2
        },
        {
          "key": "opt_out",
          "value": "Nothing to opt out of on training. The controls are zero data retention and the geography settings, and the older global routing opt out was migrated into the workspace geography setting.",
          "verdict": "verified",
          "source": 3
        },
        {
          "key": "dpa",
          "value": "Yes. The same DPA with standard contractual clauses is incorporated through the commercial terms and is reachable from the console.",
          "verdict": "verified",
          "source": 5
        },
        {
          "key": "memory",
          "value": "Managed agent memory stores remain stored by Anthropic and are copied into the session sandbox for the life of the session.",
          "verdict": "verified",
          "source": 3
        },
        {
          "key": "terms_changed",
          "value": "The commercial terms print Effective 17 June 2025 and the DPA article prints 16 March 2026. The API retention and data residency pages print no date at all.",
          "verdict": "verified",
          "source": 0
        }
      ],
      "what_it_changes": "Zero data retention is the control most buyers ask for and the one most often misread. On this platform it does not cover everything: code execution containers are excluded, and flagged inputs and outputs can still be held for two years. If your requirement is that nothing survives the call, name the features you will use and check each against the eligibility table before you write the commitment into a policy or a customer answer.",
      "sources": [
        {
          "name": "Anthropic commercial terms of service",
          "url": "https://www.anthropic.com/legal/commercial-terms",
          "type": "primary",
          "date": "2025-06-17"
        },
        {
          "name": "Anthropic privacy centre, how long do you store my organisation's data",
          "url": "https://privacy.claude.com/en/articles/7996866-how-long-do-you-store-my-organization-s-data",
          "type": "primary",
          "date": "2026-07-01"
        },
        {
          "name": "Anthropic platform docs, API and data retention",
          "url": "https://platform.claude.com/docs/en/manage-claude/api-and-data-retention",
          "type": "primary",
          "date": "2026-09-15"
        },
        {
          "name": "Anthropic platform docs, data residency",
          "url": "https://platform.claude.com/docs/en/manage-claude/data-residency",
          "type": "primary",
          "date": "2026-09-15"
        },
        {
          "name": "Anthropic trust centre, subprocessors",
          "url": "https://trust.anthropic.com/subprocessors",
          "type": "primary",
          "date": "2026-09-15"
        },
        {
          "name": "Anthropic privacy centre, the data processing addendum",
          "url": "https://privacy.claude.com/en/articles/7996862-how-do-i-view-and-sign-your-data-processing-addendum-dpa",
          "type": "primary",
          "date": "2026-03-16"
        }
      ],
      "related_ids": [
        "AVD-2026-0006",
        "AVD-2026-0004",
        "AVD-2026-0030"
      ],
      "tags": [
        "anthropic",
        "api",
        "zero data retention",
        "workspace geography",
        "flagged data"
      ],
      "date_added": "2026-09-15",
      "last_verified": "2026-09-15",
      "last_modified": "2026-09-15"
    },
    {
      "id": "AVD-2026-0008",
      "slug": "google-gemini-app-consumer",
      "title": "The Gemini app on a personal Google account",
      "kind": "consumer",
      "verdict": "verified",
      "jurisdiction": "US",
      "answer": "Google says Gemini Apps data is used to develop and improve its services, expressly including the generative AI models. A subset of chats is read by human reviewers, and reviewed chats are kept up to three years and are not deleted when you delete your activity. Activity auto deletes after 18 months, and 72 hours when the setting is off.",
      "key_facts": [
        "Google states that a subset of chats is reviewed by human reviewers, including trained reviewers from its service providers.",
        "Reviewed chats are retained for up to three years and are not deleted when you delete your activity.",
        "Gemini Apps Activity auto deletes after 18 months by default and can be set to 3 or 36 months or switched off.",
        "With the keep activity setting off, future chats are still saved for 72 hours so Gemini can respond and process feedback."
      ],
      "figures": [
        {
          "label": "Default auto deletion of Gemini Apps Activity",
          "value": 18,
          "unit": "months",
          "as_of": "2026-08-10",
          "source": 0
        },
        {
          "label": "Retention of human reviewed chats",
          "value": 3,
          "unit": "years",
          "as_of": "2026-08-10",
          "source": 0
        },
        {
          "label": "Retention when the keep activity setting is off",
          "value": 72,
          "unit": "hours",
          "as_of": "2026-08-10",
          "source": 0
        }
      ],
      "facets": [
        {
          "key": "training_use",
          "value": "Yes. The privacy hub says these uses extend to the generative AI models and other machine learning technologies powering Google services.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "retention",
          "value": "Activity auto deletes after 18 months by default, 72 hours with the setting off, and human reviewed chats are kept up to three years.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "deletion",
          "value": "You can delete activity at any time, but reviewed chats and related data are not deleted when you delete your activity.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "region",
          "value": "No storage region or residency commitment is printed on the Gemini Apps privacy hub.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "subprocessors",
          "value": "No list. Reviewers are described as trained reviewers from Google's service providers, without naming them.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "human_review",
          "value": "Yes and stated openly. A subset of chats is reviewed by human reviewers, including trained reviewers from Google's service providers, who rate and annotate them.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "opt_out",
          "value": "The keep activity setting controls saving, but turning it off still leaves a 72 hour operational window and does not reach chats already reviewed.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "dpa",
          "value": "None on the consumer tier. The privacy hub describes settings and reviewers, not a processor agreement.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "memory",
          "value": "Persistent memory is not addressed as a named feature on this page.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "terms_changed",
          "value": "The Gemini Apps privacy hub prints Last updated 10 August 2026.",
          "verdict": "verified",
          "source": 0
        }
      ],
      "what_it_changes": "Three numbers and three conditions, and they get conflated constantly. Eighteen months is the default activity clock, 72 hours is what survives turning the setting off, and three years is how long a chat lives once a human reviewer has seen it. Only the last one is beyond the user's reach, because reviewed chats are not deleted when activity is deleted. If your policy says staff may delete anything they typed by mistake, that is not true here.",
      "sources": [
        {
          "name": "Google, Gemini Apps privacy hub",
          "url": "https://support.google.com/gemini/answer/13594961",
          "type": "primary",
          "date": "2026-08-10"
        }
      ],
      "related_ids": [
        "AVD-2026-0009",
        "AVD-2026-0010",
        "AVD-2026-0001"
      ],
      "tags": [
        "google",
        "gemini",
        "consumer",
        "human review",
        "activity retention"
      ],
      "date_added": "2026-09-15",
      "last_verified": "2026-09-15",
      "last_modified": "2026-09-15"
    },
    {
      "id": "AVD-2026-0009",
      "slug": "google-gemini-for-workspace",
      "title": "Gemini for Google Workspace",
      "kind": "business",
      "verdict": "verified",
      "jurisdiction": "US",
      "answer": "Google states Workspace does not use customer data for training models without the customer's prior permission or instruction, and that content is not human reviewed or used for training outside the domain without permission. Retention is admin controlled, from 90 days upward for Gemini in Workspace and up to 36 months for the Gemini app. The Cloud Data Processing Addendum governs.",
      "key_facts": [
        "Google states Workspace does not use customer data for training models without the customer's prior permission or instruction.",
        "Content is not human reviewed or otherwise used for generative AI model training outside the customer's domain without permission.",
        "Retention for Gemini in Workspace runs from 90 days to indefinite as determined by admins, and the Gemini app for Workspace users up to 36 months.",
        "Existing Workspace protections, including data regions policies, apply automatically to these features."
      ],
      "figures": [
        {
          "label": "Floor of the admin controlled retention range for Gemini in Workspace",
          "value": 90,
          "unit": "days",
          "as_of": "2026-08-14",
          "source": 0
        },
        {
          "label": "Ceiling of admin controlled retention for the Gemini app under Workspace",
          "value": 36,
          "unit": "months",
          "as_of": "2026-08-14",
          "source": 0
        }
      ],
      "facets": [
        {
          "key": "training_use",
          "value": "No without permission. The privacy hub says Workspace does not use customer data for training models without the customer's prior permission or instruction.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "retention",
          "value": "Admin controlled and surface dependent. Gemini in Workspace runs 90 days to indefinite, the Gemini app up to 36 months, and Gemini Notebook keeps nothing after the session.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "deletion",
          "value": "Deletion is handled through the admin set retention controls. No separate deletion promise is printed on the privacy hub.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "region",
          "value": "Existing Workspace protections, which include data regions policies, are applied automatically to these features.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "subprocessors",
          "value": "The privacy hub names none. The published register is the Google Cloud Platform subprocessors page, which prints a modification date of 20 August 2026.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "human_review",
          "value": "Chats and uploaded files are not reviewed by human reviewers or used to train generative AI models outside the domain without permission.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "opt_out",
          "value": "Framed as permission rather than an opt out. Nothing is used for training without the customer's prior permission or instruction.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "dpa",
          "value": "The Cloud Data Processing Addendum is named as the governing instrument for these features.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "memory",
          "value": "Persistent memory is not addressed as a named feature on the privacy hub.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "terms_changed",
          "value": "The generative AI in Google Workspace privacy hub prints 14 August 2026, and the Cloud subprocessors register prints Last modified 20 August 2026.",
          "verdict": "verified",
          "source": 0
        }
      ],
      "what_it_changes": "The load bearing phrase is outside your domain. Google's commitment is that content is not reviewed or trained on beyond the organisation without permission, which is a different promise from nothing is processed. Retention is your admin's decision, not Google's, so the honest line in a workplace policy is the number your own administrator set, not the vendor's range. Write that number down and review it when the admin changes.",
      "sources": [
        {
          "name": "Google Workspace, generative AI privacy hub",
          "url": "https://knowledge.workspace.google.com/admin/generative-ai/generative-ai-in-google-workspace-privacy-hub",
          "type": "primary",
          "date": "2026-08-14"
        },
        {
          "name": "Google Cloud Platform subprocessors",
          "url": "https://cloud.google.com/terms/subprocessors",
          "type": "primary",
          "date": "2026-08-20"
        },
        {
          "name": "Google, how Gemini in Workspace protects your data",
          "url": "https://support.google.com/docs/answer/14615114",
          "type": "primary",
          "date": "2026-09-15"
        }
      ],
      "related_ids": [
        "AVD-2026-0008",
        "AVD-2026-0011",
        "AVD-2026-0013"
      ],
      "tags": [
        "google",
        "workspace",
        "gemini",
        "admin retention",
        "cloud dpa"
      ],
      "date_added": "2026-09-15",
      "last_verified": "2026-09-15",
      "last_modified": "2026-09-15"
    },
    {
      "id": "AVD-2026-0010",
      "slug": "google-gemini-api-unpaid-tier",
      "title": "The Gemini API on the unpaid tier",
      "kind": "api",
      "verdict": "verified",
      "jurisdiction": "US",
      "answer": "On the unpaid tier Google uses the content you submit and the generated responses to provide, improve and develop its products, and human reviewers may read, annotate and process your API input and output. There is no opt out on this tier. Developers serving the European Economic Area, Switzerland or the United Kingdom must use the paid services.",
      "key_facts": [
        "On unpaid services Google uses submitted content and generated responses to provide, improve and develop Google products and services.",
        "Human reviewers may read, annotate and process API input and output on the unpaid tier.",
        "The terms tell developers not to submit sensitive, confidential or personal information to the unpaid services.",
        "Only paid services may be used when making API clients available to users in the European Economic Area, Switzerland or the United Kingdom."
      ],
      "figures": [
        {
          "label": "Storage of prompts and output under grounding with Google Search",
          "value": 30,
          "unit": "days",
          "as_of": "2026-03-23",
          "source": 0
        }
      ],
      "facets": [
        {
          "key": "training_use",
          "value": "Yes. Google uses the content you submit and any generated responses to provide, improve and develop Google products and services on the unpaid tier.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "retention",
          "value": "No period is printed for the improvement use. Grounding with Google Search stores prompts, context and output for thirty days on both tiers.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "deletion",
          "value": "When you delete a tuned model the related tuning content is also deleted. No broader deletion commitment is printed for unpaid tier logs.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "region",
          "value": "No residency commitment. The terms instead bar the unpaid tier for clients serving the European Economic Area, Switzerland or the United Kingdom.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "subprocessors",
          "value": "No list appears in these terms. The Google Cloud subprocessors register applies through the Cloud terms, not through this document.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "human_review",
          "value": "Yes. Human reviewers may read, annotate and process your API input and output, after it is disconnected from the account.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "opt_out",
          "value": "None on this tier. The stated remedy is to move to paid quota, and the terms warn against submitting sensitive, confidential or personal information.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "dpa",
          "value": "Not on this tier. The data processing addendum for products where Google is a data processor is named for the paid services.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "memory",
          "value": "No memory feature is named. Caching is referenced only as content covered by the licence grant.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "terms_changed",
          "value": "The Gemini API additional terms print Effective 23 March 2026, with a footer line of Last updated 28 April 2026.",
          "verdict": "verified",
          "source": 0
        }
      ],
      "what_it_changes": "Free quota is the single most common route by which confidential text leaves an organisation without anyone signing anything. The distinction is contractual, not technical: the same endpoint behaves differently depending on whether the project is billed. If your developers prototype on free keys, your policy should say that prototypes carry no confidential data, because on this tier a human reviewer may read the prompt and there is no way to switch that off.",
      "sources": [
        {
          "name": "Google, Gemini API additional terms of service",
          "url": "https://ai.google.dev/gemini-api/terms",
          "type": "primary",
          "date": "2026-03-23"
        }
      ],
      "related_ids": [
        "AVD-2026-0011",
        "AVD-2026-0008",
        "AVD-2026-0028"
      ],
      "tags": [
        "google",
        "gemini api",
        "unpaid tier",
        "human review",
        "no opt out"
      ],
      "date_added": "2026-09-15",
      "last_verified": "2026-09-15",
      "last_modified": "2026-09-15"
    },
    {
      "id": "AVD-2026-0011",
      "slug": "google-gemini-api-paid-and-vertex",
      "title": "The paid Gemini API and Vertex AI",
      "kind": "api",
      "verdict": "verified",
      "jurisdiction": "US",
      "answer": "On the paid tier Google does not use prompts or responses to improve its products, and logs them for a limited period solely to detect violations of the prohibited use policy. On the cloud platform Google states it will not train or fine tune models on customer data without prior permission. Abuse monitoring logs are held up to 90 days in the selected region.",
      "key_facts": [
        "On paid services Google states it does not use prompts, system instructions, cached content or files, or responses to improve its products.",
        "The cloud data governance page states Google will not use customer data to train or fine tune AI models without prior permission or instruction.",
        "Abuse monitoring prompt logs are stored securely for up to 90 days in the same region or multi region the customer selected.",
        "Customers on a Google Cloud Master Agreement are exempt from prompt logging for abuse monitoring by default."
      ],
      "figures": [
        {
          "label": "Abuse monitoring prompt log retention",
          "value": 90,
          "unit": "days",
          "as_of": "2026-09-14",
          "source": 2
        },
        {
          "label": "Advanced model prompt and response logging",
          "value": 30,
          "unit": "days",
          "as_of": "2026-09-14",
          "source": 2
        },
        {
          "label": "Default in memory cache lifetime",
          "value": 24,
          "unit": "hours",
          "as_of": "2026-09-09",
          "source": 1
        }
      ],
      "facets": [
        {
          "key": "training_use",
          "value": "No. Paid Gemini API prompts and responses are not used to improve Google products, and the cloud page says Google will not train or fine tune on customer data without permission.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "retention",
          "value": "Conditional rather than single valued. Abuse logs up to 90 days, advanced models up to 30 days, grounding with Search three days, and caches with a 24 hour lifetime.",
          "verdict": "verified",
          "source": 2
        },
        {
          "key": "deletion",
          "value": "Zero retention is reached by configuration: decline request and response logging, set the store parameter to false, and request the abuse logging exception.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "region",
          "value": "Abuse logs stay in the region or multi region the customer selected, and the in memory cache is described as adhering to data residency requirements.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "subprocessors",
          "value": "The Google Cloud Platform subprocessors register is published and dated, though its entity tables sit behind collapsed sections that did not render.",
          "verdict": "verified",
          "source": 3
        },
        {
          "key": "human_review",
          "value": "Authorised Google employees may assess flagged prompts and may contact the customer for clarification.",
          "verdict": "verified",
          "source": 2
        },
        {
          "key": "opt_out",
          "value": "Customers on the Cloud Platform terms may request an abuse logging exception, and customers on a Google Cloud Master Agreement are exempt from that logging by default.",
          "verdict": "verified",
          "source": 2
        },
        {
          "key": "dpa",
          "value": "The Cloud Data Processing Addendum governs, and the paid Gemini API terms name the data processing addendum for products where Google is a data processor.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "memory",
          "value": "No memory product. The nearest features are the conversation state of the interactions API and a live session resumption cache with a 24 hour lifetime.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "terms_changed",
          "value": "The paid terms print Effective 23 March 2026, the cloud data governance page prints Last updated 9 September 2026 and the abuse monitoring page 14 September 2026.",
          "verdict": "verified",
          "source": 0
        }
      ],
      "what_it_changes": "Zero retention on this platform is a configuration you assemble, not a plan you buy. Three separate switches have to line up, one of which is a request to Google for an abuse logging exception, and the exception is automatic only for customers on the master agreement. If a customer questionnaire asks whether you retain nothing, the honest answer names the contract you hold and the switches you actually set.",
      "sources": [
        {
          "name": "Google, Gemini API additional terms of service",
          "url": "https://ai.google.dev/gemini-api/terms",
          "type": "primary",
          "date": "2026-03-23"
        },
        {
          "name": "Google Cloud, generative AI data governance",
          "url": "https://docs.cloud.google.com/vertex-ai/generative-ai/docs/data-governance",
          "type": "primary",
          "date": "2026-09-09"
        },
        {
          "name": "Google Cloud, abuse monitoring",
          "url": "https://docs.cloud.google.com/vertex-ai/generative-ai/docs/learn/abuse-monitoring",
          "type": "primary",
          "date": "2026-09-14"
        },
        {
          "name": "Google Cloud Platform subprocessors",
          "url": "https://cloud.google.com/terms/subprocessors",
          "type": "primary",
          "date": "2026-08-20"
        }
      ],
      "related_ids": [
        "AVD-2026-0010",
        "AVD-2026-0009",
        "AVD-2026-0030"
      ],
      "tags": [
        "google",
        "vertex ai",
        "paid tier",
        "abuse logging",
        "zero retention"
      ],
      "date_added": "2026-09-15",
      "last_verified": "2026-09-15",
      "last_modified": "2026-09-15"
    },
    {
      "id": "AVD-2026-0012",
      "slug": "microsoft-copilot-consumer",
      "title": "Microsoft Copilot on a personal account",
      "kind": "consumer",
      "verdict": "verified",
      "jurisdiction": "US",
      "answer": "Microsoft states that except for certain categories of users or users who have opted out, it uses data from Bing, MSN, Copilot and ad interactions for AI training. Conversation activity is stored for 18 months by default and can be deleted at any time. Some conversations are subject to both automated and human review. A signed in user can opt out.",
      "key_facts": [
        "Microsoft states that except for certain categories of users or users who have opted out, it uses data from Bing, MSN, Copilot and ad interactions for AI training.",
        "Conversation activity is stored for 18 months by default, and uploaded files for no longer than 18 months.",
        "Some Copilot conversations are subject to both automated and human review.",
        "Signed out users, users under 18, Entra ID accounts and users in six named countries are excluded from training."
      ],
      "figures": [
        {
          "label": "Default storage of conversation activity",
          "value": 18,
          "unit": "months",
          "as_of": "2026-09-15",
          "source": 0
        }
      ],
      "facets": [
        {
          "key": "training_use",
          "value": "Yes by default for signed in consumers. Microsoft uses data from Bing, MSN, Copilot and ad interactions for AI training except for named categories and users who opted out.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "retention",
          "value": "Conversation activity is stored for 18 months by default, and uploaded files for no longer than 18 months.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "deletion",
          "value": "You can delete individual conversations or your entire conversation history at any time, and erasure rights run through the Microsoft privacy dashboard.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "region",
          "value": "The consumer Copilot pages print no storage region. The privacy statement says data may be stored and processed in your region, the United States and other jurisdictions.",
          "verdict": "verified",
          "source": 2
        },
        {
          "key": "subprocessors",
          "value": "No subprocessor list or named processor appears on either consumer Copilot page.",
          "verdict": "absent",
          "source": 1
        },
        {
          "key": "human_review",
          "value": "Yes. Some Copilot conversations are subject to both automated and human review, for product improvement and digital safety.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "opt_out",
          "value": "Yes for a signed in user, in the app under memory and personalisation or under account privacy training options, and personalisation can stay on independently.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "dpa",
          "value": "No data processing addendum exists for the consumer tier and none is referenced on either page.",
          "verdict": "absent",
          "source": 1
        },
        {
          "key": "memory",
          "value": "Yes. With personalisation enabled Copilot remembers key details you share, such as your name, interests and goals, and memory can be switched off and cleared.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "terms_changed",
          "value": "The consumer Copilot support pages print no effective date, only an app availability notice of 18 August 2026. The Microsoft privacy statement prints Last Updated September 2026.",
          "verdict": "verified",
          "source": 2
        }
      ],
      "what_it_changes": "Note who is already excluded before you write a rule. Signed out users, under eighteens, work accounts and six named countries are outside training already, so the population your policy actually needs to reach is signed in adults on personal accounts in the remaining markets. For them the opt out is per person and per device, which means a policy that relies on it needs a way to check it, not just a sentence telling staff to set it.",
      "sources": [
        {
          "name": "Microsoft, privacy FAQ for Microsoft Copilot",
          "url": "https://support.microsoft.com/en-us/microsoft-copilot/privacy-faq-for-microsoft-copilot",
          "type": "primary",
          "date": "2026-09-15"
        },
        {
          "name": "Microsoft, Copilot privacy controls",
          "url": "https://support.microsoft.com/en-us/microsoft-copilot/microsoft-copilot-privacy-controls",
          "type": "primary",
          "date": "2026-09-15"
        },
        {
          "name": "Microsoft privacy statement",
          "url": "https://www.microsoft.com/en-us/privacy/privacystatement",
          "type": "primary",
          "date": "2026-09-15"
        }
      ],
      "related_ids": [
        "AVD-2026-0013",
        "AVD-2026-0014",
        "AVD-2026-0001"
      ],
      "tags": [
        "microsoft",
        "copilot",
        "consumer",
        "training default",
        "eighteen months"
      ],
      "date_added": "2026-09-15",
      "last_verified": "2026-09-15",
      "last_modified": "2026-09-15"
    },
    {
      "id": "AVD-2026-0013",
      "slug": "microsoft-365-copilot",
      "title": "Microsoft 365 Copilot, now named Microsoft Copilot",
      "kind": "business",
      "verdict": "verified",
      "jurisdiction": "US",
      "answer": "Microsoft states that prompts, responses and data accessed through Microsoft Graph are not used to train foundation models. European Union traffic stays within the EU Data Boundary, with models supplied by one named subprocessor excluded from it. Abuse monitoring with human review is available in Azure but these services have opted out of it. Retention is set by the customer through Purview.",
      "key_facts": [
        "Prompts, responses and data accessed through Microsoft Graph are not used to train foundation large language models.",
        "European Union traffic stays within the EU Data Boundary, while worldwide traffic can be sent to the EU and other regions for model processing.",
        "Models provided by Anthropic as a subprocessor are excluded from the EU Data Boundary.",
        "Abuse monitoring including human review of content is available in Azure OpenAI, and Microsoft Copilot services have opted out of it."
      ],
      "figures": [
        {
          "label": "Date Copilot became a covered workload in the Product Terms residency commitments",
          "value": 2024,
          "unit": "year",
          "as_of": "2026-07-09",
          "source": 0
        }
      ],
      "facets": [
        {
          "key": "training_use",
          "value": "No. Prompts, responses and data accessed through Microsoft Graph are not used to train foundation models, and optional customer feedback is excluded too.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "retention",
          "value": "Interaction content is stored as Copilot activity history, encrypted, and governed by the Purview retention policies the admin sets. No fixed vendor period is printed.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "deletion",
          "value": "Users delete their own Copilot activity history, including prompts and responses, from the My Account portal.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "region",
          "value": "EU traffic stays within the EU Data Boundary and other traffic may be processed in the United States, the EU or elsewhere. One named model subprocessor is excluded from the boundary.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "subprocessors",
          "value": "Named rather than listed. Anthropic and OpenAI are identified as model subprocessors, each with its own page describing the terms that apply.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "human_review",
          "value": "None on this service. Abuse monitoring including human review is available in Azure OpenAI and Microsoft Copilot services have opted out of it.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "opt_out",
          "value": "Nothing to opt out of on training, because there is no training use. Admin controls cover feedback and connected experiences instead.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "dpa",
          "value": "Residency commitments are stated as coming from the Microsoft Product Terms and the Data Protection Addendum.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "memory",
          "value": "No memory feature is described. The page describes working context and an activity history rather than a persistent memory store.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "terms_changed",
          "value": "The page prints no effective line in its body. Its document metadata carries a date of 9 July 2026 and a last update of 18 August 2026.",
          "verdict": "verified",
          "source": 0
        }
      ],
      "what_it_changes": "The EU Data Boundary is the selling point and the exception is the thing to write down: models from one named third party subprocessor sit outside it. A European organisation that chose this product for the boundary has to decide, as an administrator, whether to enable those models, because enabling them moves that traffic out of the commitment the rest of the service makes.",
      "sources": [
        {
          "name": "Microsoft Learn, data, privacy and security for Microsoft Copilot",
          "url": "https://learn.microsoft.com/en-us/microsoft-365/copilot/microsoft-365-copilot-privacy",
          "type": "primary",
          "date": "2026-08-18"
        }
      ],
      "related_ids": [
        "AVD-2026-0012",
        "AVD-2026-0014",
        "AVD-2026-0009"
      ],
      "tags": [
        "microsoft",
        "m365 copilot",
        "eu data boundary",
        "purview",
        "subprocessors"
      ],
      "date_added": "2026-09-15",
      "last_verified": "2026-09-15",
      "last_modified": "2026-09-15"
    },
    {
      "id": "AVD-2026-0014",
      "slug": "azure-openai-foundry-models",
      "title": "Azure OpenAI Service and models sold by Azure in Microsoft Foundry",
      "kind": "api",
      "verdict": "verified",
      "jurisdiction": "US",
      "answer": "Microsoft states prompts and completions are not used to train, retrain or improve the base models and are not available to the model providers. Data at rest stays in the customer designated geography. Flagged content may be read by authorised Microsoft employees unless the customer is approved for modified abuse monitoring, which is limited to account managed customers.",
      "key_facts": [
        "The models are stateless, no prompts or completions are stored in the model, and prompts and completions are not used to train, retrain or improve the base models.",
        "Prompts and completions are not available to OpenAI or other providers of models sold by Azure.",
        "Data stored at rest, including the abuse monitoring data store, is held in the customer designated geography.",
        "Human reviewers are authorised Microsoft employees using secure access workstations and just in time approval, and are located in the European Economic Area for deployments there."
      ],
      "figures": [],
      "facets": [
        {
          "key": "training_use",
          "value": "No. Prompts, completions, embeddings and training data are not used to train generative AI foundation models without your permission or instruction.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "retention",
          "value": "The current pages print no number of days. They describe a stateless model and an abuse monitoring data store for flagged content without stating how long it is held.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "deletion",
          "value": "Stored data and fine tuned models can be deleted by the customer at any time.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "region",
          "value": "Processing is in the customer geography for standard deployments, anywhere within the zone for data zone deployments, and data at rest stays in the customer designated geography.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "subprocessors",
          "value": "Model providers are named and walled off. Prompts and completions are not available to OpenAI or to other providers of models sold by Azure.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "human_review",
          "value": "Review is automated by default, and human review is an escalation by authorised Microsoft employees using secure access workstations and just in time approval.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "opt_out",
          "value": "Modified abuse monitoring removes the storage and human review, and it is an application gated on limited access eligibility for account managed customers.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "dpa",
          "value": "The Microsoft Products and Services Data Protection Addendum is named as the instrument governing data processing for these models.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "memory",
          "value": "Statefulness is opt in per feature. The responses API, assistants threads and stored completions each create a data store the customer configures.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "terms_changed",
          "value": "The page carries a document date of 18 May 2026 and a last update of 5 June 2026, and its own change log names 3 October 2025 as the most recent substantive revision.",
          "verdict": "verified",
          "source": 0
        }
      ],
      "what_it_changes": "The widely repeated thirty day abuse retention figure is not on Microsoft's current pages. They were reachable and simply do not print a duration, which makes this an absent facet rather than a disputed one. If your risk register carries thirty days for this service, it is carrying a number the vendor no longer publishes, and the right move is to get the period in writing from your account team rather than to keep citing a document that does not say it.",
      "sources": [
        {
          "name": "Microsoft Learn, data, privacy and security for Foundry models sold by Azure",
          "url": "https://learn.microsoft.com/en-us/azure/ai-foundry/responsible-ai/openai/data-privacy",
          "type": "primary",
          "date": "2026-06-05"
        },
        {
          "name": "Microsoft Learn, abuse monitoring",
          "url": "https://learn.microsoft.com/en-us/azure/ai-foundry/openai/concepts/abuse-monitoring",
          "type": "primary",
          "date": "2026-06-05"
        }
      ],
      "related_ids": [
        "AVD-2026-0013",
        "AVD-2026-0004",
        "AVD-2026-0030"
      ],
      "tags": [
        "microsoft",
        "azure openai",
        "abuse monitoring",
        "data residency",
        "foundry"
      ],
      "date_added": "2026-09-15",
      "last_verified": "2026-09-15",
      "last_modified": "2026-09-15"
    },
    {
      "id": "AVD-2026-0015",
      "slug": "meta-ai-consumer",
      "title": "Meta AI on Facebook, Instagram and WhatsApp",
      "kind": "consumer",
      "verdict": "verified",
      "jurisdiction": "US",
      "answer": "Meta's AI terms say information shared with its AIs may be retained and used, that review may be automated or human, and that deleting messages, conversations or an account may not delete Meta's copy. Meta trains on public content shared by adults and on interactions with the AI. An objection route is published for the European Union and the United Kingdom.",
      "key_facts": [
        "The AI terms state that when information is shared with the AIs, the AIs will sometimes retain and use that information.",
        "Review of interactions with the AI may be automated or human.",
        "Deleting individual messages, entire conversations or an account may not delete Meta's copy of the information.",
        "Meta says it trains on public content, such as public posts and comments, shared by adults on its products."
      ],
      "figures": [
        {
          "label": "Minimum age for public content used in European training",
          "value": 18,
          "unit": "years",
          "as_of": "2026-09-15",
          "source": 2
        }
      ],
      "facets": [
        {
          "key": "training_use",
          "value": "Yes. Meta says it trains its AIs on public content shared by adults on its products and on people's interactions with the AI itself.",
          "verdict": "verified",
          "source": 2
        },
        {
          "key": "retention",
          "value": "No period is printed. The terms say only that the AIs will sometimes retain and use information shared with them, and warn against sharing what you do not want retained.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "deletion",
          "value": "You may request deletion through the privacy centre, but the terms warn that deleting messages, conversations or the account may not delete Meta's copy.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "region",
          "value": "No storage region is printed. What is region specific is the objection right, which Meta's help page scopes to the European Union and the United Kingdom.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "subprocessors",
          "value": "Partners are described by category, such as search engines that supply relevant information, rather than named in a published list.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "human_review",
          "value": "Yes and explicit. Meta says it will in some cases review interactions with the AI, including the content of conversations, and that the review may be automated or human.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "opt_out",
          "value": "An objection form is published for people in the European Union and the United Kingdom. No training opt out appears in the terms for other regions, where using the AI is framed as an instruction to share.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "dpa",
          "value": "None. This is a consumer service and no processor agreement is offered or referenced.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "memory",
          "value": "The privacy policy update note refers to personalising AI experiences, but no memory store, retention period or control is described.",
          "verdict": "absent",
          "source": 3
        },
        {
          "key": "terms_changed",
          "value": "The Meta AI terms print Effective 13 May 2026 and the Meta privacy policy prints Effective 23 July 2026.",
          "verdict": "verified",
          "source": 0
        }
      ],
      "what_it_changes": "This is the only vendor in the ledger whose own terms warn that deletion may not reach its copy. That single line should decide whether a workplace allows staff to paste anything work related into an assistant embedded in a social app. There is no processor agreement to sign, no retention period to point at, and outside Europe no published route to object, so the only control available is not using it for work.",
      "sources": [
        {
          "name": "Meta AI terms of service",
          "url": "https://www.facebook.com/legal/ai-terms",
          "type": "primary",
          "date": "2026-05-13"
        },
        {
          "name": "Meta, information about objections on Meta products",
          "url": "https://www.meta.com/help/quest/126192406164229/",
          "type": "primary",
          "date": "2026-09-15"
        },
        {
          "name": "Meta newsroom, making AI work harder for Europeans",
          "url": "https://about.fb.com/news/2025/04/making-ai-work-harder-for-europeans/",
          "type": "primary",
          "date": "2026-03-27"
        },
        {
          "name": "Meta privacy policy",
          "url": "https://www.facebook.com/privacy/policy/",
          "type": "primary",
          "date": "2026-07-23"
        }
      ],
      "related_ids": [
        "AVD-2026-0016",
        "AVD-2026-0001",
        "AVD-2026-0031"
      ],
      "tags": [
        "meta",
        "consumer",
        "objection right",
        "human review",
        "deletion limits"
      ],
      "date_added": "2026-09-15",
      "last_verified": "2026-09-15",
      "last_modified": "2026-09-15"
    },
    {
      "id": "AVD-2026-0016",
      "slug": "grok-consumer-app",
      "title": "Grok on the consumer app and website",
      "kind": "consumer",
      "verdict": "verified",
      "jurisdiction": "US",
      "answer": "The consumer FAQ says content and interactions may be used to train the models and that the person controls it through an Improve the model setting. Private Chat conversations are deleted within 30 days and are never used for training. Authorised personnel may review conversations. Grok used inside X is governed by X's own policies, not this one.",
      "key_facts": [
        "The consumer FAQ states the vendor may use your content and interactions with Grok, along with Grok's responses, to train its models, and that you control whether it does.",
        "Private Chat conversations do not appear in history and are deleted from the vendor's systems within 30 days.",
        "Deleting conversations or the account triggers deletion within 30 days unless retention is needed for legal, compliance or safety purposes.",
        "Unauthenticated use is different. In some regions outside the European Union and the United Kingdom there is no option to opt out when signed out."
      ],
      "figures": [
        {
          "label": "Deletion of Private Chat conversations",
          "value": 30,
          "unit": "days",
          "as_of": "2026-08-24",
          "source": 1
        },
        {
          "label": "Deletion after a person deletes conversations or the account",
          "value": 30,
          "unit": "days",
          "as_of": "2026-08-24",
          "source": 1
        }
      ],
      "facets": [
        {
          "key": "training_use",
          "value": "Yes by default for signed in users, with a setting to turn it off. Content, interactions and Grok's responses may be used to train the models.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "retention",
          "value": "No general period. Retention runs on an ongoing legitimate business need, and the only fixed clocks are the 30 days for Private Chat and for deletion requests.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "deletion",
          "value": "Conversations or the whole account can be deleted, and the data is deleted within 30 days unless retention is needed for legal, compliance or safety purposes.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "region",
          "value": "No storage region is printed. The policy identifies a United States company and routes European questions to a separate Europe addendum.",
          "verdict": "absent",
          "source": 1
        },
        {
          "key": "subprocessors",
          "value": "Categories only. Service providers for hosting, cloud, analytics, content delivery, support and safety monitoring and payments are described but not named in a list.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "human_review",
          "value": "Yes. A limited number of authorised personnel may review conversations for improving model performance, investigating security incidents and misuse, and legal obligations.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "opt_out",
          "value": "Yes, under Settings and Data Controls as Improve the model, or by using Private Chat. Feedback you volunteer may still be used for training after you opt out.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "dpa",
          "value": "None on this tier. The privacy policy states it does not apply to data processed on behalf of customers of the business offerings such as the API.",
          "verdict": "absent",
          "source": 1
        },
        {
          "key": "memory",
          "value": "No memory feature is described. Personalisation is offered separately, using X data, and conversation history is recorded as technical data.",
          "verdict": "absent",
          "source": 1
        },
        {
          "key": "terms_changed",
          "value": "The privacy policy prints Effective 24 August 2026 and the consumer FAQ prints 12 May 2025. The documents are published by SpaceXAI LLC at x.ai.",
          "verdict": "verified",
          "source": 1
        }
      ],
      "what_it_changes": "Two traps for a policy writer. First, the assistant inside X is a different controller under different terms, so a rule written against this policy does not cover staff who use Grok on the social platform. Second, the opt out only exists for a signed in account, and in some regions an unauthenticated user has no option at all, which makes anonymous use the riskiest way to use it rather than the safest.",
      "sources": [
        {
          "name": "SpaceXAI consumer FAQs, published at x.ai",
          "url": "https://x.ai/legal/faq",
          "type": "primary",
          "date": "2025-05-12"
        },
        {
          "name": "SpaceXAI privacy policy, published at x.ai",
          "url": "https://x.ai/legal/privacy-policy",
          "type": "primary",
          "date": "2026-08-24"
        },
        {
          "name": "SpaceXAI consumer terms of service, published at x.ai",
          "url": "https://x.ai/legal/terms-of-service",
          "type": "primary",
          "date": "2026-09-11"
        }
      ],
      "related_ids": [
        "AVD-2026-0017",
        "AVD-2026-0015",
        "AVD-2026-0001"
      ],
      "tags": [
        "grok",
        "consumer",
        "private chat",
        "improve the model",
        "human review"
      ],
      "date_added": "2026-09-15",
      "last_verified": "2026-09-15",
      "last_modified": "2026-09-15"
    },
    {
      "id": "AVD-2026-0017",
      "slug": "grok-api-enterprise",
      "title": "The Grok API and enterprise platform",
      "kind": "api",
      "verdict": "verified",
      "jurisdiction": "US",
      "answer": "The enterprise FAQ says the vendor does not use business data, inputs or outputs, to train its models, though free credits may be offered in exchange for permission. Inputs and outputs are automatically deleted within 30 days unless otherwise agreed or legally required. A data processing addendum with standard contractual clauses is incorporated into the enterprise terms.",
      "key_facts": [
        "The enterprise FAQ states the vendor does not use business data, including inputs or outputs, to train its models.",
        "Free credits may be offered in exchange for permission to train on business data, so the exclusion is a default that can be traded away.",
        "Inputs and outputs are automatically deleted within 30 days unless otherwise agreed in writing or retention is legally required.",
        "The data processing addendum applies automatically and its security measures sit in an appendix to that addendum."
      ],
      "figures": [
        {
          "label": "Automatic deletion of business inputs and outputs",
          "value": 30,
          "unit": "days",
          "as_of": "2025-02-25",
          "source": 0
        }
      ],
      "facets": [
        {
          "key": "training_use",
          "value": "No by default, and tradeable. The FAQ says business inputs and outputs are not used for training, and that free credits may be offered in exchange for permission.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "retention",
          "value": "Inputs and outputs are automatically deleted within 30 days unless otherwise agreed in writing or the vendor is legally required to keep them, for example where content is flagged.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "deletion",
          "value": "Deletion is automatic at the 30 day mark rather than a request you file, with the flagged content and legal carve outs named.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "region",
          "value": "The enterprise FAQ prints no storage region. The consumer privacy policy identifies a United States company and expressly excludes the business offerings from its scope.",
          "verdict": "absent",
          "source": 1
        },
        {
          "key": "subprocessors",
          "value": "A subprocessor list is published and linked from the site's own trust section, and the DPA operates on a general written authorisation with change notice.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "human_review",
          "value": "Automated classifiers and safety tools run by default, and a limited number of authorised personnel may review business data when legally required or to investigate incidents and misuse.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "opt_out",
          "value": "Nothing to opt out of on training. The controls are the 30 day deletion default and whatever is agreed in writing on top of it.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "dpa",
          "value": "Yes. The data processing addendum applies automatically and is incorporated into the enterprise terms where personal data is submitted.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "memory",
          "value": "No memory product is described for the API. The FAQ covers ownership, retention and review, and names no persistent memory feature.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "terms_changed",
          "value": "The enterprise FAQ prints Last updated 25 February 2025 and the privacy policy prints Effective 24 August 2026.",
          "verdict": "verified",
          "source": 0
        }
      ],
      "what_it_changes": "Read the free credits clause before you treat the no training line as settled. The exclusion is a default the vendor will trade for commercial consideration, which means a team that accepted promotional credits may already be outside it. If you are answering a customer questionnaire about this vendor, the accurate answer names your contract and any credits arrangement, not the general statement on the FAQ.",
      "sources": [
        {
          "name": "SpaceXAI enterprise FAQs, published at x.ai",
          "url": "https://x.ai/legal/faq-enterprise",
          "type": "primary",
          "date": "2025-02-25"
        },
        {
          "name": "SpaceXAI privacy policy, published at x.ai",
          "url": "https://x.ai/legal/privacy-policy",
          "type": "primary",
          "date": "2026-08-24"
        }
      ],
      "related_ids": [
        "AVD-2026-0016",
        "AVD-2026-0004",
        "AVD-2026-0029"
      ],
      "tags": [
        "grok",
        "api",
        "thirty day deletion",
        "dpa",
        "free credits"
      ],
      "date_added": "2026-09-15",
      "last_verified": "2026-09-15",
      "last_modified": "2026-09-15"
    },
    {
      "id": "AVD-2026-0018",
      "slug": "mistral-consumer-assistant",
      "title": "The Mistral consumer assistant",
      "kind": "consumer",
      "verdict": "verified",
      "jurisdiction": "FR",
      "answer": "Mistral's privacy policy says inputs and outputs are used to train its models under legitimate interest, subject to an opt out in user preferences. Conversations are kept until you delete the conversation or the account. The controller is French, providers inside the European Union are prioritised, and transfers outside it carry standard contractual clauses.",
      "key_facts": [
        "Inputs and outputs are used to train Mistral's models under legitimate interest, subject to the user's opt out.",
        "Feedback is the exception. Rating a response surrenders the associated input and output for training regardless of the setting.",
        "Conversations are kept until the person deletes the account or deletes the conversation from the assistant.",
        "The September 2026 privacy policy names the consumer assistant Vibe and the developer platform Mistral AI Studio."
      ],
      "figures": [
        {
          "label": "Retention of civil identity data after account termination",
          "value": 5,
          "unit": "years",
          "as_of": "2026-09-03",
          "source": 0
        },
        {
          "label": "Retention of account data after deletion",
          "value": 1,
          "unit": "year",
          "as_of": "2026-09-03",
          "source": 0
        }
      ],
      "facets": [
        {
          "key": "training_use",
          "value": "Yes by default under legitimate interest, subject to opt out. Feedback is carved out, so rating a response gives up that input and output for training either way.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "retention",
          "value": "No automatic clock on conversations. Inputs and outputs are kept until the person deletes the account or deletes the conversation from the assistant.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "deletion",
          "value": "User driven, with fixed periods afterwards for identity and account data, and permanent deletion once the legal retention periods have expired.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "region",
          "value": "A French controller that prioritises providers within the European Union, and attaches standard contractual clauses to contracts with providers outside it.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "subprocessors",
          "value": "Audited, each under a dedicated data protection agreement, and listed on Mistral's trust centre rather than inside the policy.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "human_review",
          "value": "No human review of conversations is described in the privacy policy or the consumer terms. The only human obligation runs the other way, on labelling output.",
          "verdict": "absent",
          "source": 1
        },
        {
          "key": "opt_out",
          "value": "Yes, a toggle in user preferences on the account, separate from the platform toggle, and separate again from the personalisation setting.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "dpa",
          "value": "Out of scope by the policy's own terms. It does not apply where the products are used to process personal data in the course of business activities.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "memory",
          "value": "Yes and named. The memory feature is described as becoming a knowledge base, and previous memories are retained in it.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "terms_changed",
          "value": "The privacy policy prints Effective 3 September 2026 and the European consumer terms print Effective 7 August 2026.",
          "verdict": "verified",
          "source": 0
        }
      ],
      "what_it_changes": "A European vendor is not automatically the conservative choice on the consumer tier. Training is on by default here, the legal basis is legitimate interest rather than consent, and there is no automatic retention clock on conversations at all. What you do get is a French controller, European hosting preference and a real opt out, which is a meaningfully different transfer story from the United States vendors even where the training default matches.",
      "sources": [
        {
          "name": "Mistral AI privacy policy",
          "url": "https://legal.mistral.ai/terms/privacy-policy",
          "type": "primary",
          "date": "2026-09-03"
        },
        {
          "name": "Mistral AI terms of service for European consumers",
          "url": "https://legal.mistral.ai/terms/eu-consumers-terms-of-service",
          "type": "primary",
          "date": "2026-08-07"
        },
        {
          "name": "Mistral AI help centre, opting out of training",
          "url": "https://help.mistral.ai/en/articles/455207-can-i-opt-out-of-my-input-or-output-data-being-used-for-training",
          "type": "primary",
          "date": "2026-09-15"
        }
      ],
      "related_ids": [
        "AVD-2026-0019",
        "AVD-2026-0001",
        "AVD-2026-0029"
      ],
      "tags": [
        "mistral",
        "consumer",
        "france",
        "legitimate interest",
        "opt out"
      ],
      "date_added": "2026-09-15",
      "last_verified": "2026-09-15",
      "last_modified": "2026-09-15"
    },
    {
      "id": "AVD-2026-0019",
      "slug": "mistral-ai-studio-api",
      "title": "The Mistral developer platform",
      "kind": "api",
      "verdict": "verified",
      "jurisdiction": "FR",
      "answer": "Mistral acts as controller for training unless the customer has opted out, and feedback is carved out of that opt out. Standard API calls are kept for thirty rolling days to monitor abuse unless zero data retention is activated, and fine tuning data is kept until the customer deletes it. Zero data retention is granted on request, not self serve.",
      "key_facts": [
        "The addendum says Mistral trains its models in accordance with its privacy policy unless the customer is or has opted out.",
        "Standard API traffic is kept for thirty rolling days to monitor abuse unless zero data retention is activated.",
        "Fine tuning data is kept until the customer deletes it from the platform or terminates the account, and agent traffic until account termination.",
        "The opt out does not travel to laboratory and preview models, and zero data retention is unavailable on the consumer assistant at any subscription level."
      ],
      "figures": [
        {
          "label": "Rolling abuse monitoring retention for standard API calls",
          "value": 30,
          "unit": "days",
          "as_of": "2026-09-03",
          "source": 0
        }
      ],
      "facets": [
        {
          "key": "training_use",
          "value": "Mistral trains in accordance with its privacy policy unless the customer is or has opted out. Feedback is excluded from the opt out, as are laboratory and preview models.",
          "verdict": "verified",
          "source": 2
        },
        {
          "key": "retention",
          "value": "Thirty rolling days for abuse monitoring on standard calls unless zero data retention is on, and open ended for fine tuning data and the agents API.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "deletion",
          "value": "Fine tuning data is kept until the customer deletes it from the platform or terminates the account, so deletion is an action rather than a schedule.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "region",
          "value": "A French processor with European infrastructure preference, and the current standard contractual clauses attached to every contract involving processing outside the European Union.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "subprocessors",
          "value": "Defined in the addendum with a general authorisation, and published on the trust centre rather than inside the contract.",
          "verdict": "verified",
          "source": 2
        },
        {
          "key": "human_review",
          "value": "Only automated moderation is described. The addendum names automated moderation including abuse monitoring on the APIs, and no human review clause appears.",
          "verdict": "absent",
          "source": 2
        },
        {
          "key": "opt_out",
          "value": "Two mechanisms. An account level training opt out, and zero data retention, which is gated: the customer must give sufficient detail of a legitimate reason and Mistral approves or denies it.",
          "verdict": "verified",
          "source": 3
        },
        {
          "key": "dpa",
          "value": "Yes. A full data processing addendum with the European standard contractual clauses, supplementing the commercial agreement and referencing the trust centre.",
          "verdict": "verified",
          "source": 2
        },
        {
          "key": "memory",
          "value": "Statefulness on the platform is the agents API, where inputs and outputs are kept until the account is terminated. The knowledge base feature belongs to the consumer assistant.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "terms_changed",
          "value": "The privacy policy prints Effective 3 September 2026, the commercial terms 5 August 2026, the addendum 27 July 2026 and the zero retention help article 12 August 2026.",
          "verdict": "verified",
          "source": 0
        }
      ],
      "what_it_changes": "Opt outs on this platform do not travel. The consumer toggle, the platform toggle and zero data retention are three separate decisions, and none of them reaches the laboratory and preview models, where the terms simply say not to use them if you do not want training. Any workplace rule here has to name the surface, and any customer answer about zero data retention has to say it was approved, since it is granted on request rather than switched on.",
      "sources": [
        {
          "name": "Mistral AI privacy policy",
          "url": "https://legal.mistral.ai/terms/privacy-policy",
          "type": "primary",
          "date": "2026-09-03"
        },
        {
          "name": "Mistral AI commercial terms of service",
          "url": "https://legal.mistral.ai/terms/commercial-terms-of-service",
          "type": "primary",
          "date": "2026-08-05"
        },
        {
          "name": "Mistral AI data processing addendum",
          "url": "https://legal.mistral.ai/terms/data-processing-addendum",
          "type": "primary",
          "date": "2026-07-27"
        },
        {
          "name": "Mistral AI help centre, activating zero data retention",
          "url": "https://help.mistral.ai/en/articles/347612-can-i-activate-zero-data-retention-zdr",
          "type": "primary",
          "date": "2026-08-12"
        }
      ],
      "related_ids": [
        "AVD-2026-0018",
        "AVD-2026-0007",
        "AVD-2026-0030"
      ],
      "tags": [
        "mistral",
        "api",
        "zero data retention",
        "france",
        "standard clauses"
      ],
      "date_added": "2026-09-15",
      "last_verified": "2026-09-15",
      "last_modified": "2026-09-15"
    },
    {
      "id": "AVD-2026-0020",
      "slug": "deepseek-consumer-app",
      "title": "The DeepSeek consumer app",
      "kind": "consumer",
      "verdict": "verified",
      "jurisdiction": "CN",
      "answer": "DeepSeek's privacy policy states that it directly collects, processes and stores personal data in the People's Republic of China. Training and improving its models is a named purpose of processing, with a printed right to opt out. No retention period, deletion window or other number appears anywhere in the policy, and the terms are governed by mainland Chinese law.",
      "key_facts": [
        "The privacy policy states that to provide its services DeepSeek directly collects, processes and stores personal data in the People's Republic of China.",
        "The controller is named as a company registered in China, and the terms of use are governed by the laws of the People's Republic of China in the mainland.",
        "Training and improving the models is a named processing purpose, and the policy prints a right to opt out of it.",
        "Neither the privacy policy nor the terms of use prints a retention period, a deletion window or any other number."
      ],
      "figures": [],
      "facets": [
        {
          "key": "training_use",
          "value": "Yes. Improving and developing the services and training and improving the technology, such as the machine learning models, is a named purpose of processing.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "retention",
          "value": "Purpose bound with no period printed. The policy says only that personal data is retained for as long as necessary to provide the services.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "deletion",
          "value": "Deletion is described as a process without a clock, and account deletion is irreversible, with no ability to reactivate or retrieve content.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "region",
          "value": "China, stated directly. Personal data is collected, processed and stored in the People's Republic of China, and the terms are governed by mainland Chinese law.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "subprocessors",
          "value": "Categories only, and one of them shares user input outward. Third party search APIs are integrated and the input keywords are shared with them.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "human_review",
          "value": "No human review of user content is described. The only human review clause runs the other way, requiring the user to review consequential outputs.",
          "verdict": "absent",
          "source": 1
        },
        {
          "key": "opt_out",
          "value": "Yes, printed as a right. The policy states a right to opt out of using personal data for training the models or optimising the technologies.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "dpa",
          "value": "No data processing addendum, no standard contractual clauses and no adequacy mechanism is named. The transfer language is conditional on what may be required.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "memory",
          "value": "No memory product. Chat history is user manageable and can be copied or deleted from settings.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "terms_changed",
          "value": "The privacy policy prints Last Update 10 February 2026 and the terms of use print Last Update 27 March 2026.",
          "verdict": "verified",
          "source": 0
        }
      ],
      "what_it_changes": "Do not let a secondary source lend this vendor a retention period it never published. The documents print no number at all, which is the finding, and a risk register that records thirty days here is recording something the vendor does not say. What the vendor does say plainly is where the data lives, which for a European or United Kingdom organisation is the transfer question that has to be answered before any of the rest matters.",
      "sources": [
        {
          "name": "DeepSeek privacy policy",
          "url": "https://cdn.deepseek.com/policies/en-US/deepseek-privacy-policy.html",
          "type": "primary",
          "date": "2026-02-10"
        },
        {
          "name": "DeepSeek terms of use",
          "url": "https://cdn.deepseek.com/policies/en-US/deepseek-terms-of-use.html",
          "type": "primary",
          "date": "2026-03-27"
        }
      ],
      "related_ids": [
        "AVD-2026-0021",
        "AVD-2026-0001",
        "AVD-2026-0029"
      ],
      "tags": [
        "deepseek",
        "consumer",
        "china",
        "no printed retention",
        "transfers"
      ],
      "date_added": "2026-09-15",
      "last_verified": "2026-09-15",
      "last_modified": "2026-09-15"
    },
    {
      "id": "AVD-2026-0021",
      "slug": "deepseek-open-platform-api",
      "title": "The DeepSeek open platform and API",
      "kind": "api",
      "verdict": "verified",
      "jurisdiction": "CN",
      "answer": "The open platform terms are silent on whether developer inputs and outputs are used to train DeepSeek's own models. They print no retention period, no zero retention option and no data processing addendum, and they are governed by the laws of the People's Republic of China in the mainland. Controller duties are pushed onto the developer.",
      "key_facts": [
        "The open platform terms do not say whether developer inputs and outputs are used to train DeepSeek's own models.",
        "The only training language in the terms runs outward, permitting the developer to use outputs for training other models.",
        "The terms are governed by the laws of the People's Republic of China in the mainland.",
        "Developers must establish organisational and technical measures, including user management, data security and monitoring, so the controller duty sits with them."
      ],
      "figures": [],
      "facets": [
        {
          "key": "training_use",
          "value": "The terms say nothing about DeepSeek training on developer traffic. The only training clause permits the developer to train other models on the outputs.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "retention",
          "value": "No retention period, no zero retention option and no audit window appears in the open platform terms. The privacy policy's open ended line is the only text that applies.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "deletion",
          "value": "Deletion appears only as an enforcement action against content, not as a data lifecycle commitment to the developer.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "region",
          "value": "China. The terms are governed exclusively by the laws of the People's Republic of China in the mainland, and the privacy policy places storage there.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "subprocessors",
          "value": "No list and no flow down. The privacy policy excludes the processing rules for personal data collected from end users of downstream systems.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "human_review",
          "value": "No human review by the vendor is described. The duty is placed on the developer, whose consequential outputs are required to undergo human review.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "opt_out",
          "value": "No opt out is printed at this tier. The training opt out lives in the consumer privacy policy and nothing in the platform terms carries it to API traffic.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "dpa",
          "value": "No data processing addendum and no standard contractual clauses. The terms instead push organisational and technical duties onto the developer.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "memory",
          "value": "No memory feature is offered or described in the open platform terms.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "terms_changed",
          "value": "The open platform terms print Effective date 29 April 2026 and the privacy policy prints Last Update 10 February 2026.",
          "verdict": "verified",
          "source": 0
        }
      ],
      "what_it_changes": "Seven of the ten facets here are absent, and that pattern is itself the answer for a procurement file. You cannot write a vendor answer about retention, training or subprocessors from documents that do not address them, so an organisation that needs those commitments has to obtain them in a negotiated contract or choose another vendor. Silence is not permission and it is not prohibition, it is an unanswered question you are carrying.",
      "sources": [
        {
          "name": "DeepSeek open platform terms of service",
          "url": "https://cdn.deepseek.com/policies/en-US/deepseek-open-platform-terms-of-service.html",
          "type": "primary",
          "date": "2026-04-29"
        },
        {
          "name": "DeepSeek privacy policy",
          "url": "https://cdn.deepseek.com/policies/en-US/deepseek-privacy-policy.html",
          "type": "primary",
          "date": "2026-02-10"
        }
      ],
      "related_ids": [
        "AVD-2026-0020",
        "AVD-2026-0004",
        "AVD-2026-0029"
      ],
      "tags": [
        "deepseek",
        "api",
        "china",
        "silent terms",
        "no dpa"
      ],
      "date_added": "2026-09-15",
      "last_verified": "2026-09-15",
      "last_modified": "2026-09-15"
    },
    {
      "id": "AVD-2026-0022",
      "slug": "perplexity-consumer",
      "title": "Perplexity on the free and paid consumer plans",
      "kind": "consumer",
      "verdict": "verified",
      "jurisdiction": "US",
      "answer": "The privacy notice last updated 8 July 2026 lists improving or creating services and products, including its AI models, among the uses of collected data. It prints no fixed retention period, saying only that data is kept as long as necessary. Incognito avoids saving search activity across sessions. Transfers run to the United States under the data privacy framework.",
      "key_facts": [
        "The privacy notice lists improving or creating services and products, including its AI models, among the uses of data collected.",
        "The notice prints no fixed retention period. It says personal data is kept only as long as necessary to fulfil the purposes in the notice.",
        "Incognito increases privacy by not saving search activity across use sessions, and is the only content control the notice names.",
        "Perplexity certifies to the European Union to United States data privacy framework and the United Kingdom extension, and offers copies of its standard contractual clauses on request."
      ],
      "figures": [],
      "facets": [
        {
          "key": "training_use",
          "value": "Yes as a stated use. The notice lists improving or creating services and products, including its AI models, among the purposes for which collected data is used.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "retention",
          "value": "No period printed. Personal data is kept only as long as necessary to fulfil the purposes in the notice, weighed against amount, nature and sensitivity.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "deletion",
          "value": "Rights are exercised through a data privacy request form, with identity verification, and an appeal route if a request is denied. No deletion window is printed.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "region",
          "value": "Transfers to the United States are described, with data privacy framework certification for the European Union and United Kingdom and standard contractual clauses available on request.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "subprocessors",
          "value": "A subprocessor notification subscription is published alongside the notice in the legal centre, though the notice itself names service providers only by category.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "human_review",
          "value": "No human review of user content is described anywhere in the privacy notice.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "opt_out",
          "value": "The notice names incognito, objection and restriction rights and revocation of consent, but prints no training opt out setting of its own.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "dpa",
          "value": "A data processing addendum is published in the same legal centre, and the notice states it does not apply to the enterprise and API offerings where Perplexity acts as processor.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "memory",
          "value": "No persistent memory feature is described. The notice records collections, pages and spaces as user created content rather than as a memory store.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "terms_changed",
          "value": "The privacy notice prints Last updated 8 July 2026, and states that the effective date is when the current version took effect and the last updated date when it last changed substantively.",
          "verdict": "verified",
          "source": 0
        }
      ],
      "what_it_changes": "Product settings and contractual commitments are not the same thing, and this row is where that gap shows. A training control exists in the account interface, but the document that binds the vendor does not name it, and the notice prints no retention period at all. If your policy relies on a toggle, record where the commitment behind it is written, because a setting the notice does not mention can change without the notice changing.",
      "sources": [
        {
          "name": "Perplexity privacy notice",
          "url": "https://www.perplexity.ai/hub/legal/privacy-notice",
          "type": "primary",
          "date": "2026-07-08"
        }
      ],
      "related_ids": [
        "AVD-2026-0023",
        "AVD-2026-0001",
        "AVD-2026-0031"
      ],
      "tags": [
        "perplexity",
        "consumer",
        "no printed retention",
        "incognito",
        "data privacy framework"
      ],
      "date_added": "2026-09-15",
      "last_verified": "2026-09-15",
      "last_modified": "2026-09-15"
    },
    {
      "id": "AVD-2026-0023",
      "slug": "perplexity-enterprise-and-sonar-api",
      "title": "Perplexity enterprise and the Sonar API",
      "kind": "business",
      "verdict": "verified",
      "jurisdiction": "US",
      "answer": "The developer documentation states that Perplexity does not use customer data to train its models or for any purpose beyond processing the immediate request, and maintains a zero data retention policy for the chat completions API. Only billing metadata is kept, with no prompt or response content. The document reached governs the API rather than a seat licence.",
      "key_facts": [
        "The developer documentation states Perplexity does not use customer data to train its models or for any purpose beyond processing the immediate request.",
        "Perplexity maintains a zero data retention policy for the chat completions API and does not retain data sent through it.",
        "Only billing metadata is collected, being token counts, model used, request timestamp and duration and the API key identifier, and it carries no prompt or response content.",
        "The page names a SOC 2 Type II report, a HIPAA gap assessment and a CAIQlite assessment."
      ],
      "figures": [],
      "facets": [
        {
          "key": "training_use",
          "value": "No. The documentation states Perplexity does not use customer data to train its models or for any purpose beyond processing the immediate request.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "retention",
          "value": "Zero for content on the chat completions API. Billing metadata is kept and is described as carrying no content from prompts, responses or other user data.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "deletion",
          "value": "No deletion process is described because no content is retained to delete. The page addresses retention rather than a deletion right.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "region",
          "value": "No storage region or residency commitment is printed on the developer page. The consumer notice describes transfers to the United States under the data privacy framework.",
          "verdict": "absent",
          "source": 1
        },
        {
          "key": "subprocessors",
          "value": "A subprocessor notification subscription is published in the legal centre, and the developer page directs readers to the trust centre for the list itself.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "human_review",
          "value": "No human review is described on the developer page or in the legal centre notice.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "opt_out",
          "value": "Nothing to opt out of. Zero data retention is presented as the standing posture of the API rather than a setting the customer enables.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "dpa",
          "value": "A data processing addendum is published in the legal centre, and the privacy notice states it does not cover the enterprise and API offerings, which the addendum governs instead.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "memory",
          "value": "No memory feature is described for the API or the enterprise tier.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "terms_changed",
          "value": "The developer privacy and security page prints no date at all. The privacy notice in the legal centre prints Last updated 8 July 2026.",
          "verdict": "absent",
          "source": 0
        }
      ],
      "what_it_changes": "The strong no training and zero retention language here belongs to the API documentation, which is not the same instrument as a seat licence. If you are buying enterprise seats, ask for the commitment in the enterprise agreement rather than citing a developer page, and note that the page carrying the strongest statements carries no date, so you cannot tell from its face when it last changed.",
      "sources": [
        {
          "name": "Perplexity developer documentation, privacy and security",
          "url": "https://docs.perplexity.ai/docs/resources/privacy-security",
          "type": "primary",
          "date": "2026-09-15"
        },
        {
          "name": "Perplexity privacy notice",
          "url": "https://www.perplexity.ai/hub/legal/privacy-notice",
          "type": "primary",
          "date": "2026-07-08"
        }
      ],
      "related_ids": [
        "AVD-2026-0022",
        "AVD-2026-0030"
      ],
      "tags": [
        "perplexity",
        "enterprise",
        "sonar api",
        "zero data retention",
        "undated page"
      ],
      "date_added": "2026-09-15",
      "last_verified": "2026-09-15",
      "last_modified": "2026-09-15"
    },
    {
      "id": "AVD-2026-0024",
      "slug": "cursor-privacy-mode",
      "title": "Cursor and its privacy mode",
      "kind": "business",
      "verdict": "verified",
      "jurisdiction": "US",
      "answer": "Cursor's terms state in capitals that it will not use content to train any AI models unless you have explicitly agreed, and its data use page says it maintains zero data retention agreements with all providers. File contents are cached only for the duration of a request. No numeric retention period is printed. Admins can enforce privacy mode so members cannot disable it.",
      "key_facts": [
        "The terms of service state that Cursor will not use content to train any AI models unless you have explicitly agreed.",
        "The data use page says customer data will not be used for training by Cursor and that zero data retention agreements are maintained with all providers.",
        "File contents are cached temporarily on Cursor servers and the encryption keys exist there only for the duration of a request.",
        "Where a customer supplies its own model provider key, data handling follows that provider's policy rather than Cursor's agreements."
      ],
      "figures": [],
      "facets": [
        {
          "key": "training_use",
          "value": "No, and stated in the contract rather than a help page. The terms say Cursor will not use content to train any AI models unless you have explicitly agreed.",
          "verdict": "verified",
          "source": 2
        },
        {
          "key": "retention",
          "value": "Qualitative only. Cached file contents are described as temporary and never permanently stored, and no numeric retention period is printed on any page read.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "deletion",
          "value": "The privacy policy commits to a process without a deadline, and the terms reserve deletion as an option Cursor may exercise rather than an obligation it owes.",
          "verdict": "verified",
          "source": 2
        },
        {
          "key": "region",
          "value": "United States only data residency is offered to enterprise customers, against a default of processing in various jurisdictions, and no infrastructure is maintained in China.",
          "verdict": "verified",
          "source": 3
        },
        {
          "key": "subprocessors",
          "value": "A list is published on the trust portal, each subprocessor is under a data processing agreement and is reviewed annually, but the portal renders client side and the entries were unreadable.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "human_review",
          "value": "Inputs may be retained where flagged for security review, explicitly reported by the user, or where the user consents.",
          "verdict": "verified",
          "source": 4
        },
        {
          "key": "opt_out",
          "value": "Privacy mode is the control, it is available to every tier, and administrators can enforce it so members cannot disable it.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "dpa",
          "value": "A data processing agreement with data protection commitments is offered for commercial relationships, though the terms of service point to the privacy policy rather than to it.",
          "verdict": "verified",
          "source": 3
        },
        {
          "key": "memory",
          "value": "No memory or chat history retention statement appears on the pages read. Cloud agent data is described as stored while the agent runs and deleted when it completes, with no period.",
          "verdict": "absent",
          "source": 3
        },
        {
          "key": "terms_changed",
          "value": "The data use page and the terms of service print Last updated 3 September 2026, the security page 25 August 2026, and the privacy policy 6 October 2025.",
          "verdict": "verified",
          "source": 1
        }
      ],
      "what_it_changes": "This is the clearest no training commitment in the ledger because it sits in the contract and an administrator can lock it on. Two qualifications belong in the same paragraph. There is no numeric retention period anywhere, so a questionnaire asking how long code is held has no printed answer, and bringing your own provider key moves you outside the zero retention agreements that make the promise work.",
      "sources": [
        {
          "name": "Cursor security",
          "url": "https://www.cursor.com/security",
          "type": "primary",
          "date": "2026-08-25"
        },
        {
          "name": "Cursor, how your data is used",
          "url": "https://www.cursor.com/data-use",
          "type": "primary",
          "date": "2026-09-03"
        },
        {
          "name": "Cursor terms of service",
          "url": "https://www.cursor.com/terms-of-service",
          "type": "primary",
          "date": "2026-09-03"
        },
        {
          "name": "Cursor docs, enterprise privacy and data governance",
          "url": "https://www.cursor.com/docs/enterprise/privacy-and-data-governance",
          "type": "primary",
          "date": "2026-09-15"
        },
        {
          "name": "Cursor privacy policy",
          "url": "https://www.cursor.com/privacy",
          "type": "primary",
          "date": "2025-10-06"
        }
      ],
      "related_ids": [
        "AVD-2026-0025",
        "AVD-2026-0030"
      ],
      "tags": [
        "cursor",
        "privacy mode",
        "zero data retention",
        "code",
        "enforced setting"
      ],
      "date_added": "2026-09-15",
      "last_verified": "2026-09-15",
      "last_modified": "2026-09-15"
    },
    {
      "id": "AVD-2026-0025",
      "slug": "github-copilot-business-enterprise",
      "title": "GitHub Copilot Business and Enterprise",
      "kind": "business",
      "verdict": "verified",
      "jurisdiction": "US",
      "answer": "GitHub states it does not use Copilot Business or Copilot Enterprise customer data to train AI models, and names zero data retention agreements with its model providers. Copilot Chat on GitHub keeps up to 100 recent conversations with messages deleted after 28 days. Copilot falls under the GitHub data protection agreement. No residency commitment is printed.",
      "key_facts": [
        "GitHub states it does not use Copilot Business or Copilot Enterprise customer data to train AI models.",
        "GitHub names a zero data retention agreement with OpenAI, and equivalent arrangements for generally available features with other model providers.",
        "Copilot Chat on GitHub stores up to 100 recent conversations, and messages within each conversation are kept for 28 days before being permanently deleted.",
        "Copilot memory entries are automatically deleted after 28 days when unused."
      ],
      "figures": [
        {
          "label": "Retention of Copilot Chat messages on GitHub",
          "value": 28,
          "unit": "days",
          "as_of": "2026-09-15",
          "source": 1
        },
        {
          "label": "Conversations kept in Copilot Chat history",
          "value": 100,
          "unit": "conversations",
          "as_of": "2026-09-15",
          "source": 1
        },
        {
          "label": "Automatic deletion of unused Copilot memory entries",
          "value": 28,
          "unit": "days",
          "as_of": "2026-09-15",
          "source": 2
        }
      ],
      "facets": [
        {
          "key": "training_use",
          "value": "No for these tiers. GitHub states it does not use Copilot Business or Copilot Enterprise customer data to train AI models, and the restriction extends to third party models.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "retention",
          "value": "The terms acknowledge retention outside the editor. Copilot Chat on GitHub keeps up to 100 conversations and deletes messages after 28 days.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "deletion",
          "value": "A conversation with no messages left is removed from history automatically, and memory entries can be deleted by the user, the repository owner or an administrator.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "region",
          "value": "No residency commitment is printed. Hosting is described per model provider and spans several clouds rather than a region the customer chooses.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "subprocessors",
          "value": "Model providers are named per model together with their data posture, including a zero data retention agreement with OpenAI.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "human_review",
          "value": "No human review clause appears in the generative AI services terms or in the model hosting reference.",
          "verdict": "absent",
          "source": 3
        },
        {
          "key": "opt_out",
          "value": "Nothing to opt out of on these tiers because there is no training use. The opt out exists on individual subscriptions, through account settings.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "dpa",
          "value": "Yes. Copilot falls under the GitHub data protection agreement, which is named in the approval resources and the generative AI services terms.",
          "verdict": "verified",
          "source": 3
        },
        {
          "key": "memory",
          "value": "Copilot memory stores repository level facts and user level preferences, and entries are automatically deleted after 28 days when unused.",
          "verdict": "verified",
          "source": 2
        },
        {
          "key": "terms_changed",
          "value": "The generative AI services terms print Version March 2026 and the general privacy statement prints Effective date 27 April 2026. The documentation pages print no dates.",
          "verdict": "verified",
          "source": 3
        }
      ],
      "what_it_changes": "Two different 28 day figures circulate for this product and only one of them was readable at the publisher. The verified one is Copilot Chat message retention on GitHub. A separate figure for prompts and suggestions sits on a trust portal that renders client side and could not be read, so a questionnaire answer should cite the documentation figure and say which surface it describes rather than quoting a number for the editor that the vendor's readable pages do not carry.",
      "sources": [
        {
          "name": "GitHub docs, Copilot model hosting",
          "url": "https://docs.github.com/en/copilot/reference/ai-models/model-hosting",
          "type": "primary",
          "date": "2026-09-15"
        },
        {
          "name": "GitHub docs, chat with Copilot on GitHub",
          "url": "https://docs.github.com/en/copilot/how-tos/copilot-on-github/chat-with-copilot/chat-in-github",
          "type": "primary",
          "date": "2026-09-15"
        },
        {
          "name": "GitHub docs, Copilot memory",
          "url": "https://docs.github.com/en/copilot/concepts/agents/copilot-memory",
          "type": "primary",
          "date": "2026-09-15"
        },
        {
          "name": "GitHub generative AI services terms",
          "url": "https://github.com/customer-terms/github-generative-ai-services-terms",
          "type": "primary",
          "date": "2026-03-01"
        },
        {
          "name": "GitHub general privacy statement",
          "url": "https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement",
          "type": "primary",
          "date": "2026-04-27"
        }
      ],
      "related_ids": [
        "AVD-2026-0024",
        "AVD-2026-0013",
        "AVD-2026-0031"
      ],
      "tags": [
        "github copilot",
        "business",
        "zero data retention",
        "memory",
        "code"
      ],
      "date_added": "2026-09-15",
      "last_verified": "2026-09-15",
      "last_modified": "2026-09-15"
    },
    {
      "id": "AVD-2026-0026",
      "slug": "amazon-bedrock",
      "title": "Amazon Bedrock",
      "kind": "api",
      "verdict": "verified",
      "jurisdiction": "US",
      "answer": "Amazon Bedrock uses a zero operator access and zero data retention model, so by default it does not store model inputs or outputs. Some models require retention for abuse detection, capped at 30 days within the AWS boundary and never shared with the model provider. Retention is set by mode at account or project level and can be locked by policy.",
      "key_facts": [
        "Amazon Bedrock uses a zero data retention security model, so by default it does not store model inputs or outputs.",
        "Where a model requires retention, prompts and completions are held within the AWS boundary for up to 30 days and are not shared with the model provider.",
        "Model providers have no access to the deployment accounts, so they see neither logs nor customer prompts and completions.",
        "Retention is a mode set at account or project level, and an organisation can require the zero retention mode through a service control policy."
      ],
      "figures": [
        {
          "label": "Retention cap for models that require review",
          "value": 30,
          "unit": "days",
          "as_of": "2026-09-15",
          "source": 1
        },
        {
          "label": "Abuse detection retention for flagged traffic",
          "value": 30,
          "unit": "days",
          "as_of": "2026-09-15",
          "source": 2
        }
      ],
      "facets": [
        {
          "key": "training_use",
          "value": "Providers are structurally excluded. They have no access to the deployment accounts and therefore none to Bedrock logs or to customer prompts and completions.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "retention",
          "value": "Zero by default, with named models requiring up to 30 days for abuse detection, and per feature behaviour where the customer chooses to store responses.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "deletion",
          "value": "Expressed as an automatic cap rather than a deletion right. No customer initiated deletion of retained abuse data is described.",
          "verdict": "absent",
          "source": 1
        },
        {
          "key": "region",
          "value": "Retained inputs and outputs are stored in the destination region where the request is processed, and a model deployment account exists per provider per region.",
          "verdict": "verified",
          "source": 2
        },
        {
          "key": "subprocessors",
          "value": "The model providers are the third parties and they are walled off. Bedrock does not share customer content with model providers today.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "human_review",
          "value": "Only where a provider requires it as a condition of access, performed by AWS inside the AWS boundary, and the content does not leave AWS.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "opt_out",
          "value": "Zero retention is set by API and can be enforced across an organisation by policy, and for models that require retention it is evaluated per account and per model.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "dpa",
          "value": "The Bedrock data protection pages point to the service terms and a regulatory centre rather than naming a data processing addendum.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "memory",
          "value": "Persistence is a request level choice through the responses API, and the documentation warns that setting store to false does not guarantee zero retention.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "terms_changed",
          "value": "The Bedrock user guide pages print no date. The AWS service terms print Last Updated 15 September 2026.",
          "verdict": "verified",
          "source": 3
        }
      ],
      "what_it_changes": "Retention here is a property of the model you call, not of the platform you bought. A single account can be zero retention for one model and thirty days with human review for another, because each model declares the modes it allows, and the more permissive setting is what unlocks certain models at all. Any statement you make to a customer about retention has to name the models in the deployment, not the service.",
      "sources": [
        {
          "name": "AWS documentation, Amazon Bedrock data protection",
          "url": "https://docs.aws.amazon.com/bedrock/latest/userguide/data-protection.html",
          "type": "primary",
          "date": "2026-09-15"
        },
        {
          "name": "AWS documentation, Amazon Bedrock data retention",
          "url": "https://docs.aws.amazon.com/bedrock/latest/userguide/data-retention.html",
          "type": "primary",
          "date": "2026-09-15"
        },
        {
          "name": "AWS documentation, Amazon Bedrock abuse detection",
          "url": "https://docs.aws.amazon.com/bedrock/latest/userguide/abuse-detection.html",
          "type": "primary",
          "date": "2026-09-15"
        },
        {
          "name": "AWS service terms",
          "url": "https://aws.amazon.com/service-terms/",
          "type": "primary",
          "date": "2026-09-15"
        }
      ],
      "related_ids": [
        "AVD-2026-0004",
        "AVD-2026-0007",
        "AVD-2026-0030"
      ],
      "tags": [
        "aws",
        "bedrock",
        "zero data retention",
        "abuse detection",
        "per model"
      ],
      "date_added": "2026-09-15",
      "last_verified": "2026-09-15",
      "last_modified": "2026-09-15"
    },
    {
      "id": "AVD-2026-0027",
      "slug": "cohere-platform-api",
      "title": "The Cohere platform and API",
      "kind": "api",
      "verdict": "verified",
      "jurisdiction": "GLOBAL",
      "answer": "Cohere automatically deletes logged prompts and generations after 30 days and lets customers opt out of training in dashboard settings. Enterprise retention of inputs and outputs is described as generally 30 days. A subprocessor list is published and a data processing addendum is available on request. The four governing documents were last updated across four different years.",
      "key_facts": [
        "Cohere automatically deletes logged prompts and generations after 30 days.",
        "Customers can opt out of prompts and generations being used to train Cohere models in dashboard settings at any time.",
        "Retention of inputs and outputs on the platform is described as generally 30 days for enterprise users.",
        "Cohere is a Canadian company and names Canada, the United States and the United Kingdom among the countries it transfers personal information to."
      ],
      "figures": [
        {
          "label": "Automatic deletion of logged prompts and generations",
          "value": 30,
          "unit": "days",
          "as_of": "2025-12-05",
          "source": 1
        },
        {
          "label": "Post termination deletion window on request",
          "value": 30,
          "unit": "days",
          "as_of": "2025-04-08",
          "source": 2
        }
      ],
      "facets": [
        {
          "key": "training_use",
          "value": "Trial and research input and output may be used for research and development, while enterprise customers control training on their data and can opt out.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "retention",
          "value": "Logged prompts and generations are automatically deleted after 30 days, and platform retention for enterprise users is described as generally 30 days.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "deletion",
          "value": "Self serve account deletion in the dashboard or by email, and deletion on request within 30 days of termination, with API data and fine tuning data carved out.",
          "verdict": "verified",
          "source": 2
        },
        {
          "key": "region",
          "value": "No residency commitment. Transfers are disclosed by example, naming Canada, the United States and the United Kingdom among others, and deployment choice is offered instead.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "subprocessors",
          "value": "Yes. The privacy policy directs platform and API users to a published subprocessor list on the trust centre.",
          "verdict": "verified",
          "source": 0
        },
        {
          "key": "human_review",
          "value": "Safety and security teams may review user prompts, generations and logs to enforce the customer agreements where misuse is suspected.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "opt_out",
          "value": "Yes, a dashboard setting that can be changed at any time, covering prompts and generations being used to train Cohere models.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "dpa",
          "value": "Available on request to platform customers by contacting the privacy address. The software agreement itself does not incorporate one.",
          "verdict": "verified",
          "source": 1
        },
        {
          "key": "memory",
          "value": "No memory or persistent personalisation feature is described in any of the governing documents read.",
          "verdict": "absent",
          "source": 0
        },
        {
          "key": "terms_changed",
          "value": "The privacy policy prints Last Updated 1 May 2026, the enterprise data commitments 5 December 2025, the software agreement 8 April 2025 and the terms of use 7 September 2022.",
          "verdict": "verified",
          "source": 0
        }
      ],
      "what_it_changes": "Four documents govern this vendor and they do not agree with each other. The oldest, from 2022, grants a broad training and sharing licence in capitals, while the newer ones describe a thirty day deletion and a dashboard opt out. A buyer should establish in writing which instrument governs their account, because citing the newest page while signing under the oldest terms is how a commitment evaporates during an audit.",
      "sources": [
        {
          "name": "Cohere privacy policy",
          "url": "https://cohere.com/privacy",
          "type": "primary",
          "date": "2026-05-01"
        },
        {
          "name": "Cohere enterprise data commitments",
          "url": "https://cohere.com/enterprise-data-commitments",
          "type": "primary",
          "date": "2025-12-05"
        },
        {
          "name": "Cohere software as a service agreement",
          "url": "https://cohere.com/saas-agreement",
          "type": "primary",
          "date": "2025-04-08"
        },
        {
          "name": "Cohere terms of use",
          "url": "https://cohere.com/terms-of-use",
          "type": "primary",
          "date": "2022-09-07"
        }
      ],
      "related_ids": [
        "AVD-2026-0026",
        "AVD-2026-0004",
        "AVD-2026-0029"
      ],
      "tags": [
        "cohere",
        "api",
        "thirty days",
        "opt out",
        "conflicting terms"
      ],
      "date_added": "2026-09-15",
      "last_verified": "2026-09-15",
      "last_modified": "2026-09-15"
    },
    {
      "id": "AVD-2026-0028",
      "slug": "does-no-training-cover-safety-classifiers",
      "title": "Does a promise not to train on your data cover the safety classifiers?",
      "kind": "question",
      "verdict": "open",
      "jurisdiction": "GLOBAL",
      "answer": "Vendors promise not to train foundation models on business data, then separately describe running that data through classifiers and keeping the result. Anthropic states that flagged material trains its trust and safety classification models even for people who opted out. Nobody has settled whether a buyer reading no training understands that the safety layer is excluded from the promise.",
      "key_facts": [
        "OpenAI's enterprise page says business data may be run through automated content classifiers and safety tools, with the classification kept as metadata rather than content.",
        "Anthropic's consumer terms say material flagged for safety review is used to improve detection of harmful content even where the person has opted out of training.",
        "Google's paid tier terms say prompts and responses are not used to improve products, and separately that they are logged to detect violations of the prohibited use policy.",
        "No vendor document read for this ledger defines whether improving a safety classifier counts as training for the purposes of its own no training commitment."
      ],
      "figures": [],
      "facets": [],
      "what_it_changes": "When a customer questionnaire asks whether the vendor trains on your data, the honest answer has two halves: no for the foundation models, and a separate sentence about the safety layer, which several vendors describe in language that does sound like training. Write both halves. An answer that quotes only the headline promise will be read as broader than the contract supports, and the gap surfaces in an audit rather than in the sale.",
      "sources": [
        {
          "name": "OpenAI enterprise privacy",
          "url": "https://openai.com/enterprise-privacy/",
          "type": "primary",
          "date": "2026-01-08"
        },
        {
          "name": "Anthropic consumer terms of service",
          "url": "https://www.anthropic.com/legal/consumer-terms",
          "type": "primary",
          "date": "2025-10-08"
        },
        {
          "name": "Google, Gemini API additional terms of service",
          "url": "https://ai.google.dev/gemini-api/terms",
          "type": "primary",
          "date": "2026-03-23"
        }
      ],
      "related_ids": [
        "AVD-2026-0003",
        "AVD-2026-0005",
        "AVD-2026-0011"
      ],
      "tags": [
        "open question",
        "training",
        "safety classifiers",
        "contract language"
      ],
      "date_added": "2026-09-15",
      "last_verified": "2026-09-15",
      "last_modified": "2026-09-15"
    },
    {
      "id": "AVD-2026-0029",
      "slug": "is-a-subprocessor-notice-period-enforceable",
      "title": "Is a subprocessor change notice period actually enforceable?",
      "kind": "question",
      "verdict": "open",
      "jurisdiction": "EU",
      "answer": "Article 28 of the General Data Protection Regulation says a processor may not engage another processor without the controller's authorisation, and vendors implement that as a notice email plus an objection window. What the controller can do if the objection is refused, short of terminating a contract it depends on, is the part nobody has settled in practice.",
      "key_facts": [
        "Article 28 of the General Data Protection Regulation states that the processor shall not engage another processor without prior specific or general written authorisation of the controller.",
        "OpenAI's addendum gives the customer 30 days to object after notice of a new subprocessor.",
        "Mistral's addendum operates on a general authorisation with a change notice, and the list itself lives on a trust centre outside the contract.",
        "Several vendors publish the list on a client side portal that did not render its entries on the day of checking, so the notice arrives faster than the list can be read."
      ],
      "figures": [
        {
          "label": "Objection window after notice of a new subprocessor in one vendor addendum",
          "value": 30,
          "unit": "days",
          "as_of": "2026-01-01",
          "source": 1
        }
      ],
      "facets": [],
      "what_it_changes": "Subscribe to the notification feed for every vendor you depend on and record who in your organisation reads it, because the window starts when the notice is sent, not when someone notices. Then decide in advance what an objection would actually mean for you. A right you would never exercise because the service is load bearing is a governance line item, not a control, and it is better to know that before an auditor asks.",
      "sources": [
        {
          "name": "General Data Protection Regulation, Article 28",
          "url": "https://gdpr-info.eu/art-28-gdpr/",
          "type": "secondary",
          "date": "2026-09-15"
        },
        {
          "name": "OpenAI data processing addendum",
          "url": "https://openai.com/policies/data-processing-addendum/",
          "type": "primary",
          "date": "2026-01-01"
        },
        {
          "name": "Mistral AI data processing addendum",
          "url": "https://legal.mistral.ai/terms/data-processing-addendum",
          "type": "primary",
          "date": "2026-07-27"
        }
      ],
      "related_ids": [
        "AVD-2026-0002",
        "AVD-2026-0019",
        "AVD-2026-0006"
      ],
      "tags": [
        "open question",
        "subprocessors",
        "gdpr",
        "notice period"
      ],
      "date_added": "2026-09-15",
      "last_verified": "2026-09-15",
      "last_modified": "2026-09-15"
    },
    {
      "id": "AVD-2026-0030",
      "slug": "does-zero-retention-survive-an-abuse-investigation",
      "title": "Does zero data retention survive an abuse investigation?",
      "kind": "question",
      "verdict": "open",
      "jurisdiction": "GLOBAL",
      "answer": "Every platform that offers zero data retention also describes a case where content is kept anyway. OpenAI retains a flagged image for manual review even under zero retention, and Anthropic may keep flagged inputs and outputs for up to two years. Whether a buyer can call that zero retention in a customer answer is unsettled.",
      "key_facts": [
        "OpenAI states a flagged image is retained for manual review even where zero data retention, modified abuse monitoring or eyes off is enabled.",
        "Anthropic states flagged inputs and outputs may be retained for up to two years even under zero data retention or HIPAA arrangements.",
        "Amazon Bedrock offers a zero retention mode, and separately requires retention for certain models whose providers make review a condition of access.",
        "Mistral grants zero data retention only on request, after the customer gives sufficient detail of a legitimate reason, and only for stateless calls."
      ],
      "figures": [
        {
          "label": "Retention of flagged data under zero data retention at one vendor",
          "value": 2,
          "unit": "years",
          "as_of": "2026-09-15",
          "source": 1
        }
      ],
      "facets": [],
      "what_it_changes": "Zero retention is a default rather than an absolute on every platform in this ledger, and the exception is always the abuse path. If your contract with a customer promises that nothing is retained, the promise you can actually keep is narrower than the phrase, so write the exception into your own commitment rather than inheriting a claim you cannot honour when a classifier fires.",
      "sources": [
        {
          "name": "OpenAI platform, data controls in the OpenAI platform",
          "url": "https://developers.openai.com/api/docs/guides/your-data",
          "type": "primary",
          "date": "2026-09-15"
        },
        {
          "name": "Anthropic platform docs, API and data retention",
          "url": "https://platform.claude.com/docs/en/manage-claude/api-and-data-retention",
          "type": "primary",
          "date": "2026-09-15"
        },
        {
          "name": "AWS documentation, Amazon Bedrock data retention",
          "url": "https://docs.aws.amazon.com/bedrock/latest/userguide/data-retention.html",
          "type": "primary",
          "date": "2026-09-15"
        },
        {
          "name": "Mistral AI help centre, activating zero data retention",
          "url": "https://help.mistral.ai/en/articles/347612-can-i-activate-zero-data-retention-zdr",
          "type": "primary",
          "date": "2026-08-12"
        }
      ],
      "related_ids": [
        "AVD-2026-0004",
        "AVD-2026-0007",
        "AVD-2026-0026",
        "AVD-2026-0019"
      ],
      "tags": [
        "open question",
        "zero data retention",
        "abuse monitoring",
        "flagged content"
      ],
      "date_added": "2026-09-15",
      "last_verified": "2026-09-15",
      "last_modified": "2026-09-15"
    },
    {
      "id": "AVD-2026-0031",
      "slug": "who-owns-the-memory-record",
      "title": "Who owns the memory record an assistant builds about you?",
      "kind": "question",
      "verdict": "open",
      "jurisdiction": "GLOBAL",
      "answer": "Memory is a derived record about a person that no vendor document in this ledger assigns ownership of. OpenAI says a saved memory survives the deletion of the chat it came from. Microsoft describes remembering names, interests and goals. Whether that profile is the user's personal data, the vendor's work product, or both, is unsettled.",
      "key_facts": [
        "OpenAI states that even if you delete a chat, any saved memories from it can still be used in future conversations.",
        "Microsoft describes consumer Copilot remembering key details such as your name, interests and goals when personalisation is enabled.",
        "Anthropic runs memory on by default for consumer plans and off by default on Team and Enterprise, where an owner must enable it.",
        "GitHub deletes unused Copilot memory entries after 28 days and lets a user, a repository owner or an administrator delete them."
      ],
      "figures": [
        {
          "label": "Automatic deletion of unused memory entries at one vendor",
          "value": 28,
          "unit": "days",
          "as_of": "2026-09-15",
          "source": 3
        }
      ],
      "facets": [],
      "what_it_changes": "A memory store is a profile, and the ordinary controls do not reach it. Deleting a conversation does not necessarily delete what was learned from it, and an export of chats is not an export of the profile. A workplace policy that covers conversations should name memory separately, say who may switch it on, and say what happens to the record when a person leaves.",
      "sources": [
        {
          "name": "OpenAI Help Center, memory FAQ",
          "url": "https://help.openai.com/en/articles/8590148-memory-faq",
          "type": "primary",
          "date": "2026-09-15"
        },
        {
          "name": "Microsoft, privacy FAQ for Microsoft Copilot",
          "url": "https://support.microsoft.com/en-us/microsoft-copilot/privacy-faq-for-microsoft-copilot",
          "type": "primary",
          "date": "2026-09-15"
        },
        {
          "name": "Claude support, how Claude's memory works",
          "url": "https://support.claude.com/en/articles/11817273-how-does-claude-s-memory-work",
          "type": "primary",
          "date": "2026-09-15"
        },
        {
          "name": "GitHub docs, Copilot memory",
          "url": "https://docs.github.com/en/copilot/concepts/agents/copilot-memory",
          "type": "primary",
          "date": "2026-09-15"
        }
      ],
      "related_ids": [
        "AVD-2026-0001",
        "AVD-2026-0005",
        "AVD-2026-0012",
        "AVD-2026-0025"
      ],
      "tags": [
        "open question",
        "memory",
        "profiles",
        "deletion"
      ],
      "date_added": "2026-09-15",
      "last_verified": "2026-09-15",
      "last_modified": "2026-09-15"
    }
  ]
}