{
  "version": 1,
  "generated_at": "2026-09-18T12:00:38.702Z",
  "cells": [
    {
      "app": "chatgpt",
      "question": "no_training_default",
      "value": "no",
      "quote": "When you use our services for individuals such as ChatGPT and Codex, we may use your content to train our models.",
      "evidence_url": "https://help.openai.com/en/articles/5722486-how-your-data-is-used-to-improve-model-performance",
      "notes": "Consumer ChatGPT (Free, Go, Plus, Pro) trains on conversations by default; the same article states ChatGPT 'improves by further training on the conversations people have with it, unless you opt out'. The US privacy policy likewise says Content may be used to train the models subject to an opt-out. Business, Enterprise, Edu and API are excluded by default (see business_no_training).",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "chatgpt",
      "question": "training_opt_out",
      "value": "yes",
      "quote": "After you opt out, we won’t train our models on your new conversations.",
      "evidence_url": "https://help.openai.com/en/articles/5722486-how-your-data-is-used-to-improve-model-performance",
      "notes": "Self-service toggle 'Improve the model for everyone' under Settings > Data Controls (web, mobile and while signed out) or 'Do not train on my content' in the privacy portal; chat history is kept when opted out and either control is enough for ChatGPT and Codex tasks. The commitment covers only new conversations from the point of opt-out, which the revised rubric accepts as YES, and says nothing about chats already collected; conversations attached to thumbs up/down feedback, and support conversations while training is enabled, may still be used. Business, Enterprise, Edu and API customers are excluded by default without any setting.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "chatgpt",
      "question": "uploads_excluded",
      "value": "partial",
      "quote": "Content may include files that are uploaded.",
      "evidence_url": "https://help.openai.com/en/articles/8555545-file-uploads-faq",
      "notes": "Uploaded files and images are part of 'Content' and follow the same rule as chats: used for training by default on consumer plans and covered by the same 'Improve the model for everyone' opt-out, so exclusion depends on a setting that is on by default. Business/Enterprise/API uploads are not used for training.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "chatgpt",
      "question": "business_no_training",
      "value": "yes",
      "quote": "By default, we do not train on any inputs or outputs from our products for business users, including ChatGPT Business, ChatGPT Enterprise, and the API.",
      "evidence_url": "https://help.openai.com/en/articles/5722486-how-your-data-is-used-to-improve-model-performance",
      "notes": "Covers ChatGPT Business, Enterprise, Edu, Healthcare and the API Platform; API customers can explicitly opt in to share data (for example Playground feedback). The Enterprise Privacy page itself returns 403 to the crawler, so the help article is the citable source.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "chatgpt",
      "question": "temporary_chat",
      "value": "yes",
      "quote": "Chats from Temporary Chat won't appear in history, use or create memories, or be used to train our models.",
      "evidence_url": "https://help.openai.com/en/articles/5722486-how-your-data-is-used-to-improve-model-performance",
      "notes": "Temporary Chat (pill button in a new chat) is available on all consumer plans; the Data Controls FAQ and privacy policy state Temporary Chats are deleted from OpenAI systems within 30 days (safety copy) and 'may be reviewed only to monitor for abuse'. A 'personalized' Temporary Chat can read existing memories but does not create new ones; saving a Temporary Chat converts it to a regular chat subject to the account's training setting.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "chatgpt",
      "question": "memory_controls",
      "value": "partial",
      "quote": "While the memory summary should capture the most important details, it will not include everything that ChatGPT remembers based on your chats.",
      "evidence_url": "https://help.openai.com/en/articles/8590148-memory-faq",
      "notes": "Memory can be disabled in Settings > Personalization > Memory and cleared via 'Delete and turn off memory'; the current memory summary is editable but is a synthesis that by OpenAI's own statement does not show everything remembered, and item-by-item deletion is documented only for the legacy 'saved memories' system. A log of deleted saved memories may be kept up to 30 days; 'Delete and turn off memory' control is on web and 'rolling out on mobile'.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "chatgpt",
      "question": "user_deletion",
      "value": "yes",
      "quote": "Delete your account directly in ChatGPT. If you cannot sign in, use the Privacy Portal to submit a verified deletion request.",
      "evidence_url": "https://help.openai.com/en/articles/6378407-how-can-i-delete-my-account",
      "notes": "Individual chats are deleted from the sidebar (three-dot menu > Delete) or all at once in Settings > Data controls; account deletion is in Settings > Account > Delete account on web and mobile. Self-service account deletion is not available in Business, Enterprise, Edu or Healthcare workspaces.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "chatgpt",
      "question": "data_export",
      "value": "yes",
      "quote": "Use ChatGPT settings to request an export from an eligible signed-in account or workspace.",
      "evidence_url": "https://help.openai.com/en/articles/7260999-how-do-i-export-my-chatgpt-history-and-data",
      "notes": "Settings > Data controls > Export data emails a ZIP with chat history and account data (link valid 24 hours, may take up to 7 days); available on Free, Go, Plus, Pro and eligible Edu, not while logged out and not in Business/Enterprise/Healthcare workspaces, where the workspace owner controls exports. The Privacy Portal offers an alternative 'Download my data' request.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "chatgpt",
      "question": "deletion_timeline",
      "value": "partial",
      "quote": "Deleted chats are permanently removed from OpenAI systems within 30 days, unless they were already de-identified and disassociated from your account or must be retained for security or legal reasons.",
      "evidence_url": "https://help.openai.com/en/articles/6378407-how-can-i-delete-my-account",
      "notes": "30-day commitment applies to deleted chats, deleted accounts and Temporary Chats, but the exceptions go beyond legal/security holds: content already de-identified for model training (the default for consumer accounts with training on) is not removed, and content or accounts banned for usage-policy violations may be kept to protect against abuse.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "chatgpt",
      "question": "no_ads_use",
      "value": "no",
      "quote": "It considers multiple signals, including the context and intent of your current conversation, the ad’s landing page, title, copy, advertiser-provided context hints and targeting selections, and, when ads personalization is enabled, select signals from your broader ChatGPT experience.",
      "evidence_url": "https://help.openai.com/en/articles/20001047-ads-in-chatgpt",
      "notes": "Ads are shown to Free and Go users (US test from February 9, 2026; not to under-18s, Plus, Pro, Business, Enterprise or Edu); the current conversation's context is always used to select ads, and with ad personalization on, past chats and memories may be used too. Settings > Ad Controls lets users turn off personalization and clear ads data (retained up to 30 days), but current-thread context still drives ads; personalized ads are initially unavailable in the EEA and Switzerland; conversations are not shared with advertisers.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "chatgpt",
      "question": "no_sale_sharing",
      "value": "partial",
      "quote": "We also share limited information with select marketing partners who are not service providers in order to promote our products and services on third-party properties and help us assess the effectiveness of those efforts.",
      "evidence_url": "https://openai.com/policies/privacy-policy/",
      "notes": "The ads FAQ says OpenAI never sells data to advertisers, but hashed emails/phone numbers, cookie IDs, IP address and basic commercial info are shared with social networks and ad platforms to market OpenAI's own products, which OpenAI's help article 'How we promote OpenAI on third-party properties' says qualifies as 'targeted advertising' or 'sharing for cross-context behavioral advertising' under US state laws, with an opt-out at Settings > Data Controls > Marketing Privacy. The older ROW policy (Feb 2026) still states OpenAI does not 'sell' or 'share' personal data, so the documents are inconsistent across regions.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "chatgpt",
      "question": "human_review_limited",
      "value": "partial",
      "quote": "Our team may review flagged content to determine appropriate actions.",
      "evidence_url": "https://openai.com/transparency-and-content-moderation/",
      "notes": "OpenAI discloses a combination of automated systems and human review for monitoring content that may violate its terms, and the Data Controls FAQ says Temporary Chats 'may be reviewed only to monitor for abuse'; however the consumer documents contain no general statement that staff or contractors cannot otherwise read conversations (for example during model-training data preparation), so the limits are only partially stated. The Enterprise Privacy page, which addresses employee access for business plans, could not be fetched (403).",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "chatgpt",
      "question": "no_precise_location",
      "value": "partial",
      "quote": "In addition, some of our Services allow you to choose to provide more precise location information from your device, such as location information from your device’s GPS.",
      "evidence_url": "https://openai.com/policies/privacy-policy/",
      "notes": "By default only the general area derived from IP address is determined (for security and better responses); precise GPS location is collected only if the user chooses to grant it for a feature. The ads FAQ adds that advertisers never receive precise location or IP address.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "chatgpt",
      "question": "rights_channel",
      "value": "yes",
      "quote": "You can exercise some of these rights through your OpenAI account using the tools described in the Data controls section, or you can submit your request through privacy.openai.com",
      "evidence_url": "https://openai.com/policies/privacy-policy/",
      "notes": "The privacy policy offers the Privacy Portal (privacy.openai.com) and the designated mailbox dsar@openai.com to all users for access, deletion, correction, portability and objection requests, while noting that statutory rights depend on where you live, which does not demote under the revised rubric; in-product controls also cover export, chat and account deletion, and the training and marketing opt-outs. The portal itself returns 403 to the crawler, so the policy sentence is the citable evidence; the DPO is reachable at dpo@openai.com.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "claude",
      "question": "no_training_default",
      "value": "no",
      "quote": "We may use your Inputs and Outputs to train and improve Anthropic AI models, unless you opt out through your account settings.",
      "evidence_url": "https://www.anthropic.com/legal/privacy",
      "notes": "For Claude Free, Pro and Max the 'Help improve our AI models' setting under Settings > Privacy is an opt-out: the Privacy Policy and Consumer Terms say Inputs and Outputs may be used to train 'unless you opt out', and the Privacy Center settings article says that if you 'turn off the model training setting' new chats stop being used, so training is on unless the user acts. The consumer Privacy Center article phrases it as chats 'you choose to allow us to use' and no document states the default in so many words, so confidence stays medium; conversations flagged by safety classifiers and thumbs up/down feedback may be used even when opted out. Team, Enterprise and API are excluded by default.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "claude",
      "question": "training_opt_out",
      "value": "yes",
      "quote": "We may use your Inputs and Outputs to train and improve Anthropic AI models, unless you opt out through your account settings.",
      "evidence_url": "https://www.anthropic.com/legal/privacy",
      "notes": "Self-service toggle at Settings > Privacy > 'Help improve our AI models' on web and mobile; the Privacy Center retention article states that after turning it off Anthropic 'will not use your previous or new chats or coding sessions for future model training', and chat history is unaffected. Caveats: data already in training runs in progress or in trained models is not removed, and safety-flagged or explicitly reported (feedback) conversations may still be used.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "claude",
      "question": "uploads_excluded",
      "value": "partial",
      "quote": "The content you submit to the Services through these interactions, including via third-party applications, services, and content you choose to upload, integrate or interact with using our Services, are your “Inputs”.",
      "evidence_url": "https://www.anthropic.com/legal/privacy",
      "notes": "Uploaded files are 'Inputs' and follow the same rule as chats: used for model improvement unless the single Privacy setting is turned off, so exclusion depends on a setting that is on by default; the Privacy Center says training data includes 'the entire related conversation, along with any content' but excludes raw content pulled from connectors and MCP servers unless copied into the chat.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "claude",
      "question": "business_no_training",
      "value": "yes",
      "quote": "By default, we will not use your inputs or outputs from our commercial products",
      "evidence_url": "https://privacy.claude.com/en/articles/7996868-is-my-data-used-for-model-training",
      "notes": "Applies to Claude for Work (Team, Enterprise), the Anthropic API and Claude Gov; the Commercial Terms add 'Anthropic may not train models on Customer Content from Services.' Exceptions are explicit feedback (thumbs up/down, which owners can disable) or an opt-in such as the Development Partner Program.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "claude",
      "question": "temporary_chat",
      "value": "yes",
      "quote": "While incognito chats aren't saved to your chat history, they are retained for either 30 days (default), or longer in accordance with your organization's custom data retention setting (available for Enterprise plans).",
      "evidence_url": "https://support.claude.com/en/articles/12260368-use-incognito-chats",
      "notes": "Incognito chats (ghost icon, available on Free, Pro, Max, Team and Enterprise) are not saved to history or memory and the article states 'Incognito chats are not used for training' even if model improvement is enabled; default retention is 30 days. On Team/Enterprise they are included in owner data exports and the Compliance API and may be retained longer under custom retention; incognito is not available inside Projects.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "claude",
      "question": "memory_controls",
      "value": "yes",
      "quote": "When a conversation expires or is deleted, related memory entries generated from it won’t be removed, but you can delete individual memories at any time.",
      "evidence_url": "https://support.claude.com/en/articles/11817273-use-claude-s-chat-search-and-memory-to-build-on-previous-context",
      "notes": "Memory is on by default for Free, Pro and Max; Settings > Memory lists everything remembered under Topics where each entry can be read, edited or deleted, and the toggle offers 'Pause memory' (stop using and creating memories) or 'Reset memory' (delete all). A separate 'Search and reference chats' toggle (paid plans) can also be turned off; sensitive topics are excluded from memory unless opted in.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "claude",
      "question": "user_deletion",
      "value": "yes",
      "quote": "Click \"Delete Account\" and follow the prompts. Please note that deleting your account is permanent and you will no longer have access to saved chats.",
      "evidence_url": "https://privacy.claude.com/en/articles/10023660-deleting-claude-accounts",
      "notes": "Conversations can be deleted individually (chat title menu > Delete) or in bulk from Recents; account deletion is at Settings > Account > Delete Account. Pro/Max subscribers must cancel and wait for the subscription period to end first, some accounts are told in-product to contact support, and accounts created via third parties (e.g. Poe, Slack) must delete through that provider.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "claude",
      "question": "data_export",
      "value": "yes",
      "quote": "Data exports are available to individual Claude users on Free, Pro, and Max plans. Data exports include conversation data and the user data for your account.",
      "evidence_url": "https://privacy.claude.com/en/articles/9450526-export-your-claude-data",
      "notes": "Settings > Privacy > Export data on web or Claude Desktop emails a download link valid 24 hours (not available from the iOS/Android apps); memory entries are included. On Team/Enterprise only the organization's Primary Owner can export.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "claude",
      "question": "deletion_timeline",
      "value": "partial",
      "quote": "which will be removed immediately from your conversation history and automatically deleted from our back-end within 30 days",
      "evidence_url": "https://www.anthropic.com/legal/privacy",
      "notes": "The 30-day back-end deletion commitment is stated for deleted conversations; no period is stated for account deletion beyond 'as long as reasonably necessary'. Exceptions include legal requirements, dispute resolution and Usage Policy enforcement (flagged inputs/outputs kept up to 2 years, classifier scores up to 7 years), and chats already used for training remain in in-progress runs and trained models, with training-enabled data kept de-identified for up to 5 years.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "claude",
      "question": "no_ads_use",
      "value": "yes",
      "quote": "Your data is used solely to make Claude better for everyone - we do not use such personal data to contact people, build profiles about them, to try to sell or market anything to them, or to sell the information itself to any third party.",
      "evidence_url": "https://privacy.claude.com/en/articles/10023555-how-do-you-use-personal-data-in-model-training",
      "notes": "Claude shows no ads. The Privacy Center states that chat data allowed for training is used solely to improve Claude and not to sell or market anything to users or build profiles, and the Privacy Policy's legal-bases table lists only identity, contact, communication, technical and study data (not Inputs and Outputs) for service updates, tailored recommendations and direct marketing. Cookies and advertising identifiers are used to market Anthropic's own services with an opt-out honouring Global Privacy Control, but that is technical data rather than conversation content; confidence stays medium because the explicit statement sits in the model-training article rather than a general advertising clause.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "claude",
      "question": "no_sale_sharing",
      "value": "partial",
      "quote": "Anthropic does not “sell” your personal data as that term is defined by applicable laws and regulations. You can opt-out of sharing your personal data for targeted advertising to promote our products and services, and we will honor global privacy controls.",
      "evidence_url": "https://www.anthropic.com/legal/privacy",
      "notes": "No sale of personal data, but the policy acknowledges 'sharing' (cookie/identifier data with advertising partners) for targeted advertising of Anthropic's own products, with an opt-out via the cookie controls and Global Privacy Control; disclosure to affiliates and service providers is for stated business purposes, not third-party marketing.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "claude",
      "question": "human_review_limited",
      "value": "yes",
      "quote": "By default, Anthropic employees cannot access your conversations unless:",
      "evidence_url": "https://privacy.claude.com/en/articles/10458704-how-does-anthropic-protect-the-personal-data-of-claude-users",
      "notes": "The two stated exceptions are conversations the user submits as feedback and review needed to enforce the Usage Policy, where only designated Trust & Safety staff have need-to-know access under strict controls. Aggregate usage analysis (Clio) is described as giving employees no access to raw conversations, while safety-focused Clio runs can be linked to accounts and are restricted to a small number of authorized staff.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "claude",
      "question": "no_precise_location",
      "value": "partial",
      "quote": "Consent (for example for precise device location or for health app integrations)",
      "evidence_url": "https://www.anthropic.com/legal/privacy",
      "notes": "Coarse location is inferred from IP address for security/anti-abuse (cannot be disabled) and optionally for features like web search (toggle in the privacy dashboard); precise device location is collected only 'consistent with your device or browser permissions' on consent basis, managed at the device level for the mobile app and browser extension per the Privacy Center location article.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "claude",
      "question": "rights_channel",
      "value": "yes",
      "quote": "If you have any questions or comments about our processing of your personal data, or to exercise your rights as outlined in Section 4 (“Rights and Choices”), please contact us at privacy@anthropic.com.",
      "evidence_url": "https://www.anthropic.com/legal/privacy",
      "notes": "The Privacy Policy designates privacy@anthropic.com for exercising access, portability, deletion, correction, objection and restriction rights and for appeals of denied requests, with a Data Protection Officer at dpo@anthropic.com, and offers it to all users while noting that the specific rights depend on local law, which does not demote under the revised rubric. In-product Privacy Settings also provide export, the model-training opt-out and chat/account deletion without a request; no web form or portal is documented.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "gemini",
      "question": "no_training_default",
      "value": "no",
      "quote": "Google uses your activity to provide, develop, and improve its services (including training generative AI models), as well as to protect Google, its users, and the public with the help of human reviewers.",
      "evidence_url": "https://support.google.com/gemini/answer/13594961",
      "notes": "The Keep Activity setting is on by default for users 18 or over (help article 13278892: 'If you're 18 or over, Keep Activity is on by default.'), and while it is on chats and shared files are used to improve services including training generative AI models. Only audio and Gemini Live video/screenshare recordings are excluded from improvement by default; work/school accounts are covered by separate Workspace terms.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "gemini",
      "question": "training_opt_out",
      "value": "partial",
      "quote": "Your future chats won’t appear in your Activity, and won’t be used to train our AI models, unless you choose to send Google feedback.",
      "evidence_url": "https://support.google.com/gemini/answer/13594961",
      "notes": "Self-service: turn off Keep Activity in Gemini Apps Activity. Qualified because it applies only to future chats, is voided if you submit feedback, disables chat history and most Connected Apps (e.g. Google Workspace) as a side effect, and does not stop processing to create anonymized data or safety/abuse review; already-reviewed chats are kept up to 3 years.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "gemini",
      "question": "uploads_excluded",
      "value": "partial",
      "quote": "Your chats and what you share with Gemini (like files, videos, screens, and photos) will be saved in your Activity.",
      "evidence_url": "https://support.google.com/gemini/answer/13594961",
      "notes": "Uploaded files, photos, videos and screens are treated like chats: saved to Gemini Apps Activity and used to improve services (including model training) while Keep Activity is on, which is the default. Exclusion depends on turning Keep Activity off (same opt-out as chats); audio and Gemini Live video/screenshares are excluded by default under a separate off-by-default setting.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "gemini",
      "question": "business_no_training",
      "value": "partial",
      "quote": "Workspace does not use customer data for training models without customer's prior permission or instruction.",
      "evidence_url": "https://support.google.com/a/answer/15706919?hl=en",
      "notes": "Google Workspace (business, education, public sector) and Paid Gemini API services are excluded from training by default; however, Unpaid Gemini API and Google AI Studio use submitted content 'to provide, improve, and develop' Google products and may be human-reviewed (Gemini API Additional Terms), except in the EEA, Switzerland and UK where paid-service terms apply to all API use.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "gemini",
      "question": "temporary_chat",
      "value": "yes",
      "quote": "Temporary chats are not used to train Google’s AI models. If Keep Activity is off and you don’t submit feedback, Google also does not use your future chats to improve its AI models.",
      "evidence_url": "https://support.google.com/gemini/answer/13594961",
      "notes": "Temporary chat is available in the Gemini web and mobile apps for personal accounts (not Gemini in Chrome, Gemini in Google Messages, or work/school accounts); such chats do not appear in recent chats or Gemini Apps Activity, are not used for personalization or training, and are retained with the account for 72 hours to respond and for safety/abuse protection (which can include human review).",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "gemini",
      "question": "memory_controls",
      "value": "partial",
      "quote": "You can change whether Gemini Apps use memory of your past chats to personalize your experience at any time.",
      "evidence_url": "https://support.google.com/gemini/answer/16598469?hl=en",
      "notes": "The Memory feature (personalization from past chats, 18+ personal accounts, requires Keep Activity on) can be turned off via the Personal Intelligence setting, but there is no documented list of stored memory items to inspect or delete individually; to remove something Gemini remembered you must delete all chats containing that information from Gemini Apps Activity (there 'might be a short delay'). Separate 'Instructions/Saved info' can be managed and deleted individually.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "gemini",
      "question": "user_deletion",
      "value": "yes",
      "quote": "You can review your prompts, delete your Gemini Apps activity, and turn off Keep Activity in My Activity at any time.",
      "evidence_url": "https://support.google.com/gemini/answer/13278892?hl=en",
      "notes": "Individual chats can be deleted in Gemini Apps Activity (per activity item, per day, custom range or all) and from Recent chats, and the Google Privacy Policy in the sources states 'You can edit or delete your account at any time through your Google Account settings', so both conversation and account deletion are self-service for personal accounts. Caveats: chats already reviewed by human reviewers are disconnected from the account and kept up to 3 years regardless of deletion, and work/school accounts are controlled by the Workspace administrator.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "gemini",
      "question": "data_export",
      "value": "yes",
      "quote": "You can export a copy of content in your Google Account if you want to back it up or use it with a service outside of Google.",
      "evidence_url": "https://policies.google.com/privacy",
      "notes": "Self-service export via Google Takeout ('Download your data'); the Gemini Apps Privacy Notice also states 'You can also export your information.' Gemini Apps Activity is exported as part of the account's My Activity data.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "gemini",
      "question": "deletion_timeline",
      "value": "partial",
      "quote": "This process generally takes around 2 months from the time of deletion. This often includes up to a month-long recovery period in case the data was removed unintentionally.",
      "evidence_url": "https://policies.google.com/technologies/retention?hl=en-US",
      "notes": "Removal from view is immediate, but complete deletion from storage 'generally takes around 2 months' and encrypted backups can hold data up to 6 months; the Gemini Privacy Hub adds that human-reviewed chats are not deleted with your activity and are kept up to 3 years, and some data is kept for business/legal purposes. Default auto-delete of Gemini Apps Activity is 18 months (3/36 months or never selectable).",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "gemini",
      "question": "no_ads_use",
      "value": "yes",
      "quote": "Your Gemini Apps chats are not being used to show you ads. If this changes, we will clearly communicate it to you.",
      "evidence_url": "https://support.google.com/gemini/answer/13594961",
      "notes": "Explicit statement in the Gemini Apps Privacy Hub FAQ; note the forward-looking caveat ('If this changes'). Other Google settings (Web & App Activity etc.) continue to govern ad personalization elsewhere in Google services.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "gemini",
      "question": "no_sale_sharing",
      "value": "partial",
      "quote": "We take your privacy seriously, and we do not sell your personal information to anyone.",
      "evidence_url": "https://support.google.com/gemini/answer/13594961",
      "notes": "No-sale statement is explicit, and the Google Privacy Policy says Google does not share information that personally identifies you with advertisers unless you ask; however the same policy allows 'specific partners to collect information from your browser or device for advertising and measurement purposes using their own cookies' and shares non-personally identifiable information with partners, so third-party advertising data flows exist without a documented opt-out in these documents.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "gemini",
      "question": "human_review_limited",
      "value": "partial",
      "quote": "A subset of chats are reviewed by human reviewers (including Google’s trained service providers) to help improve Google services.",
      "evidence_url": "https://support.google.com/gemini/answer/13594961",
      "notes": "Human review is disclosed but covers quality/model-improvement purposes as well as safety and Terms enforcement; reviewed chats are disconnected from the account and retained up to 3 years. Turning Keep Activity off or using temporary chats stops review for improvement, but chats may still be reviewed to protect Google, users and the public.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "gemini",
      "question": "no_precise_location",
      "value": "partial",
      "quote": "With your permission, Gemini Apps also process precise location data from your device.",
      "evidence_url": "https://support.google.com/gemini/answer/13594961",
      "notes": "By default Gemini uses only the general area from IP address or Home/Work addresses; precise device location requires the device/browser permission and is not stored in Gemini Apps Activity (stored location is coarsened to a >3 km² area). Caveat: Gemini may still receive precise location from another Google service such as Google Maps or Android Auto to fulfil a request even if the Gemini/Google app precise-location setting is off.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "gemini",
      "question": "rights_channel",
      "value": "yes",
      "quote": "You can export a copy of your information or delete it from your Google Account at any time",
      "evidence_url": "https://policies.google.com/privacy",
      "notes": "In-product controls for access/portability (Takeout) and deletion (My Activity, Gemini Apps Activity, account deletion) are available to all signed-in users regardless of region; objection/correction requests are additionally documented for GDPR/UK users via a Help Center request form and the in-app 'Report legal issue' option.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "copilot",
      "question": "no_training_default",
      "value": "partial",
      "quote": "Prompts, responses, and your file contents when using the Microsoft Copilot app aren't used to train foundation models.",
      "evidence_url": "https://support.microsoft.com/en-us/privacy/microsoft-copilot/activity-history",
      "notes": "Scored on the updated Copilot app (released August 18, 2026 for web, desktop and mobile, personal Microsoft account), whose activity-history article says prompts, responses and file contents are not used to train foundation models. That statement is scoped to foundation models, and the September 2026 Privacy Statement still says Copilot uses prompts 'to provide and improve services' and conversation data 'to provide and improve Microsoft Copilot' without saying whether that includes other models, which is the revised rubric's licence-to-improve-services partial branch (confidence low). The still-published Privacy FAQ, now labelled as applying only to the older app, describes default-on training of conversation activity and uploads with a self-service opt-out; unauthenticated users, under-18s and users in Brazil, China, Israel, Nigeria, South Korea and Vietnam were never trained on.",
      "confidence": "low",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "copilot",
      "question": "training_opt_out",
      "value": "partial",
      "quote": "Opting out will exclude your future conversations from being used for training these AI models, unless you choose to opt back in.",
      "evidence_url": "https://support.microsoft.com/en-us/microsoft-copilot/privacy-faq-for-microsoft-copilot",
      "notes": "For the updated app the documents describe no training toggle because prompts, responses and files are stated not to be used to train foundation models, but that statement does not cover the Privacy Statement's 'provide and improve services' use, so it does not establish that no opt-out is needed. The older app, still documented in the Privacy FAQ that Microsoft now labels as applying only to that version, has a self-service toggle under profile > Account > Privacy ('Training on conversation activity' / 'Training on voice conversations') covering future conversations, which the revised rubric would count as yes on its own. Partial because the current-version documents neither confirm a complete training exclusion nor document a control, and the documented toggle belongs to a version the vendor says the FAQ no longer describes.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "copilot",
      "question": "uploads_excluded",
      "value": "partial",
      "quote": "Prompts, responses, and your file contents when using the Microsoft Copilot app aren't used to train foundation models.",
      "evidence_url": "https://support.microsoft.com/en-us/privacy/microsoft-copilot/activity-history",
      "notes": "File contents are explicitly named alongside prompts and responses as not used to train foundation models in the updated app, but the statement carries the same qualifications as the chat cell (foundation models only; the Privacy Statement's licence to use prompts and related data 'to provide and improve services'), so uploads cannot be graded more protectively than chats. The older app's Privacy FAQ says an uploaded file 'will be treated just like any other conversation, subject to your choices about whether to permit model training', i.e. trained on by default with the same opt-out, which is the revised rubric's partial branch; Copilot Vision captures are stated not to be used for training or stored after the session.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "copilot",
      "question": "business_no_training",
      "value": "yes",
      "quote": "Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs, including those used by Microsoft Copilot.",
      "evidence_url": "https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy",
      "notes": "Commercial Microsoft 365 Copilot and Copilot Chat with a work/school (Entra ID) account are covered by Enterprise Data Protection; the enterprise-data-protection page repeats that prompts, responses and Graph data 'aren't used to train foundation models' and web queries are sent with identifiers removed. Statement is scoped to foundation LLMs; optional customer feedback may be used to improve the product.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "copilot",
      "question": "temporary_chat",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "None of the Copilot privacy articles (privacy controls, activity history, Privacy FAQ, Transparency Note) or the Privacy Statement document a temporary, incognito or history-off chat mode; the older FAQ only notes that unauthenticated (signed-out) use is not used for training, which is not a documented mode. Silence is recorded as unknown.",
      "confidence": "medium",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "copilot",
      "question": "memory_controls",
      "value": "yes",
      "quote": "Microsoft Copilot can offer you tailored experiences by remembering key details and preferences from your conversations.",
      "evidence_url": "https://support.microsoft.com/en-us/privacy/microsoft-copilot/privacy-controls",
      "notes": "The same article documents Settings > Personalization > Manage next to 'Saved memories' to view the memory list, a Delete icon per memory, a 'Delete all memories' button, and a 'Saved memories' toggle to turn memory off (turning it off does not automatically delete existing memories). Personalization is on by default where available and unavailable in Brazil, China, Israel, Nigeria, South Korea and Vietnam.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "copilot",
      "question": "user_deletion",
      "value": "yes",
      "quote": "At any time, you can delete a prior Copilot conversation from your conversation history.",
      "evidence_url": "https://support.microsoft.com/en-us/microsoft-copilot/privacy-faq-for-microsoft-copilot",
      "notes": "Individual chats are deleted in-product (Chats list > More > Delete per the current privacy-controls article) and all history via the Microsoft privacy dashboard; the Microsoft account itself can be closed self-service at account.microsoft.com ('Mark account for closure' with a 30- or 60-day reopen window).",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "copilot",
      "question": "data_export",
      "value": "yes",
      "quote": "If you choose to export your activity history, a comma-separated values (CSV) file is downloaded to your device.",
      "evidence_url": "https://support.microsoft.com/en-us/privacy/manage-your-copilot-activity-history-in-the-privacy-dashboard",
      "notes": "Self-service 'Export all activity history' (CSV) for Copilot apps and for Copilot in Microsoft 365 apps under Privacy > Copilot on the Microsoft privacy dashboard (account.microsoft.com/privacy); the Privacy Statement also states you can view, access, export and delete Copilot activity history there.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "copilot",
      "question": "deletion_timeline",
      "value": "partial",
      "quote": "After requesting account closure, the account is marked for deletion, but we will wait 60 days before permanently deleting the account in case you change your mind or need to access information.",
      "evidence_url": "https://privacy.microsoft.com/en-us/privacystatement",
      "notes": "A fixed period is stated only for account closure (30- or 60-day reopen window chosen by the user, after which Microsoft deletes 'your data and your content' per the close-account help page); no purge period is stated for individually deleted Copilot chats. The older FAQ says conversation activity is stored 18 months by default and uploaded files no longer than 18 months; the Privacy Statement's general retention section gives no fixed timelines.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "copilot",
      "question": "no_ads_use",
      "value": "no",
      "quote": "Ads may be shown that relate to the current interaction you are having with us, such as your Copilot conversations (including files you share); your current location; transactions; product usage; search queries; or the content you’re viewing.",
      "evidence_url": "https://privacy.microsoft.com/en-us/privacystatement",
      "notes": "Copilot shows ads to users without a Microsoft 365 subscription; generic ads are selected from the most recent content of the current conversation, and personalized ads 'might use your chat history, saved memories' unless the 'Allow ads personalization' toggle (or the dashboard-wide personalized-ads setting) is turned off. The opt-out covers personalization only, not contextual ads based on the current conversation; no personalized ads for users under 18.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "copilot",
      "question": "no_sale_sharing",
      "value": "partial",
      "quote": "We also disclose personal data for digital advertising purposes.",
      "evidence_url": "https://privacy.microsoft.com/en-us/privacystatement",
      "notes": "The Privacy Statement contains no general 'we do not sell personal data' statement (only for student data); it discloses sharing data with third parties for personalized ads, with an opt-out via the 'Share my data with third parties for personalized ads' setting / third-party ad settings page and honouring the Global Privacy Control signal in certain jurisdictions. Vendors acting on Microsoft's behalf may not use data for other purposes.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "copilot",
      "question": "human_review_limited",
      "value": "partial",
      "quote": "Some Copilot conversations are subject to both automated and human review for product improvement and digital safety purposes.",
      "evidence_url": "https://support.microsoft.com/en-us/microsoft-copilot/privacy-faq-for-microsoft-copilot",
      "notes": "Human review is disclosed for product improvement and safety, plus Code of Conduct investigations, with no opt-out ('an opt-out of human review is not available'); 'Trained AI experts may review Copilot conversations to build, evaluate, and improve' the models. This FAQ is labelled as applying to the older app; the new-version articles only mention review of user-submitted feedback, and the Privacy Statement notes manual review of some results to train and improve automated systems.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "copilot",
      "question": "no_precise_location",
      "value": "partial",
      "quote": "Data about your device’s location, which may be either precise (typically based on GPS, cell tower, or Wi-Fi hotspot location) or imprecise (for example, inferred from an IP address, or city or postal code in your account profile).",
      "evidence_url": "https://privacy.microsoft.com/en-us/privacystatement",
      "notes": "The Microsoft Privacy Statement says Copilot uses the user's prompts, location, language and related settings, that location settings can be adjusted in the product, and defines location data as either precise (GPS, cell tower, Wi-Fi) or imprecise (IP address, profile city). No Copilot-specific document says whether the assistant collects precise location, so the cell is partial on the umbrella policy's setting-gated precise-location language, the same treatment applied to Kimi; confidence low.",
      "confidence": "low",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "copilot",
      "question": "rights_channel",
      "value": "yes",
      "quote": "Microsoft provides you with the following data protection rights regardless of your location:",
      "evidence_url": "https://privacy.microsoft.com/en-us/privacystatement",
      "notes": "Rights listed (access, erasure, correction, portability, objection, consent withdrawal) apply regardless of location; channels are the Microsoft privacy dashboard (account.microsoft.com/privacy, where Copilot activity can be viewed, exported and deleted), in-product controls, and the 'privacy support and requests' page (microsoft.com/concern/privacy) for anything not covered by the tools, with a 30-day response commitment; US residents also get a toll-free number.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "perplexity",
      "question": "no_training_default",
      "value": "no",
      "quote": "If you choose to downgrade to a Free or non-Enterprise plan, your data would then follow the standard consumer data policy, where AI data retention is enabled by default.",
      "evidence_url": "https://www.perplexity.ai/help-center/en/articles/11564572-data-collection-at-perplexity",
      "notes": "The same article states that for Free, Perplexity Pro and Perplexity Max users the 'AI Data Retention' setting is enabled by default and 'Some data may be used to train AI models and improve search quality, unless you opt out through Account Settings'. The Privacy Notice lists 'Improve or create services and products, including our AI models' as a use of data. Only Enterprise data is excluded without action.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "perplexity",
      "question": "training_opt_out",
      "value": "yes",
      "quote": "these users can control whether their data is used for AI model training",
      "evidence_url": "https://www.perplexity.ai/help-center/en/articles/11564572-data-collection-at-perplexity",
      "notes": "Free, Pro and Max users have a self-service 'AI data retention' toggle (Account settings > Preferences; the Memory article calls the same control Settings > Preferences > Artificial Intelligence) that stops their data being used for AI training. The article states that opt-outs apply only to data collected after the opt-out date and that previously collected training data cannot be deleted, which the revised rubric still counts as YES (prospective settings count; earlier conversations are not covered). Enterprise data is excluded without any action; Incognito mode is an additional per-session option.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "perplexity",
      "question": "uploads_excluded",
      "value": "partial",
      "quote": "Your files stay private. We use their content only to customize responses to your questions and tasks. They’re never accessed or shared for other purposes unless you share a session.",
      "evidence_url": "https://www.perplexity.ai/help-center/en/articles/10354810-security-and-privacy-with-file-uploads",
      "notes": "The help article says uploaded files are used only to customise responses, but the Privacy Notice lists 'uploads' under User Content that it processes and lists improving 'our AI models' as a purpose, and the training opt-out article never says whether the toggle covers files. Documents are not fully consistent, so partial rather than yes. Files attached to sessions are retained 30 days (7 days for Enterprise Pro).",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "perplexity",
      "question": "business_no_training",
      "value": "yes",
      "quote": "Perplexity shall not use (or authorize third parties to use) Customer Content to train, retrain, fine-tune or otherwise improve any generative artificial intelligence models.",
      "evidence_url": "https://www.perplexity.ai/hub/legal/enterprise-terms-of-service",
      "notes": "Enterprise Terms 'Model Training' clause; the help center repeats that Enterprise data is 'never' used for training and the API docs (docs.perplexity.ai/docs/resources/privacy-security) state a Zero Data Retention policy for the Chat Completions API with no training on customer data. Applies to Enterprise Pro/Max and API; does not cover individual Pro/Max plans.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "perplexity",
      "question": "temporary_chat",
      "value": "partial",
      "quote": "Memory and previous searches are always off when using incognito mode, and questions asked in incognito are not retained or used in memory ever.",
      "evidence_url": "https://www.perplexity.ai/help-center/en/articles/10968016-memory",
      "notes": "Incognito mode exists in the app and web; sessions 'expire within 24 hours and are not recoverable' (Incognito Mode Troubleshooting article) and are not saved to history or memory. No document explicitly states that incognito queries are excluded from model training, so the training half of the rubric is not confirmed.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "perplexity",
      "question": "memory_controls",
      "value": "yes",
      "quote": "You can clear any specific memory at any time in settings by clicking on the trash icon. You can also clear all your memories at once by selecting the clear all button.",
      "evidence_url": "https://www.perplexity.ai/help-center/en/articles/10968016-memory",
      "notes": "Settings > Memory offers separate toggles for 'Use search history' and 'Notes' (memory), a 'Manage memories' view to search and delete individual entries, and clear-all. Turning memory off does not clear existing memories; a log of cleared memories may be kept up to 30 days for safety/debugging. Memory content may be used for training unless 'AI Data Retention' is off.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "perplexity",
      "question": "user_deletion",
      "value": "yes",
      "quote": "You can initiate data deletion directly from your account settings, without the need to contact support or submit a separate request.",
      "evidence_url": "https://www.perplexity.ai/help-center/en/articles/11564562-self-serve-data-deletion",
      "notes": "Account deletion is self-service at perplexity.ai/account/details; individual threads, all threads, projects and pages can be deleted from the Library/History menu. Files can only be deleted by deleting the session (or via a form for immediate deletion).",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "perplexity",
      "question": "data_export",
      "value": "yes",
      "quote": "You will receive an email with a download link to your data.",
      "evidence_url": "https://www.perplexity.ai/help-center/en/articles/11564568-gdpr-compliance-at-perplexity",
      "notes": "Self-service 'Export my data' button at https://www.perplexity.ai/account/details, described as covering the Right to Access; the article does not itemise whether the export contains all threads. Formal portability requests can also go through the Data Privacy Form.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "perplexity",
      "question": "deletion_timeline",
      "value": "partial",
      "quote": "If you delete your account, your personal information will be removed from our servers within 30 days.",
      "evidence_url": "https://www.perplexity.ai/help-center/en/articles/10354873-how-long-does-perplexity-retain-my-search-history-profile-data-and-personal-information",
      "notes": "A 30-day window is stated for account deletion (and files expire after 30 days), but no timeline is given for deleting individual threads, and the Privacy Notice says data may be kept 'to comply with legal obligations, resolve disputes, enforce agreements, or for other business purposes' and in backups, which is broader than legal/safety holds.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "perplexity",
      "question": "no_ads_use",
      "value": "partial",
      "quote": "We also clarified that we do not sell your personal data or send your queries, prompts, or conversation content to advertisers.",
      "evidence_url": "https://www.perplexity.ai/hub/legal/privacy-notice",
      "notes": "The July 2026 Privacy Notice headline says queries, prompts and conversation content are not sent to advertisers, but its disclosure table lists 'Internet or other electronic network activity information', defined to include search history, under 'Sharing for Targeted Advertising' with Advertising Partners, and describes first-party advertising measurement with third parties that 'may use this data to serve ads tailored to your interests'. Because search history is conversation content for a search product, the documents contradict each other, so partial rather than yes; opt-outs exist via the cookie banner, Global Privacy Control and mobile settings. Enterprise plans are not affected.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "perplexity",
      "question": "no_sale_sharing",
      "value": "partial",
      "quote": "We do not “sell” your personal data for money.",
      "evidence_url": "https://www.perplexity.ai/hub/legal/privacy-notice",
      "notes": "No sale for money, but the disclosure table lists 'Sharing for Targeted Advertising' of identifiers, commercial information, internet activity and non-precise geolocation with Advertising Partners, and the notice says third parties may use it to serve ads tailored to your interests; opt-out via cookie consent, Global Privacy Control or mobile settings. Sensitive data is not sold or shared.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "perplexity",
      "question": "human_review_limited",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "Neither the Privacy Notice, the Terms of Service nor the help-center privacy articles say whether Perplexity staff or contractors can read conversations; the file-upload article only says files are 'never accessed or shared for other purposes'. Silence, so unknown.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "perplexity",
      "question": "no_precise_location",
      "value": "partial",
      "quote": "Share location: Opt in to precise location for location-aware answers.",
      "evidence_url": "https://www.perplexity.ai/help-center/en/articles/10352993-account-settings",
      "notes": "The Privacy Notice says the services collect only general location derived from the IP address, and the disclosure table lists geolocation as 'non-precise'; precise location is collected only when the user opts in through the 'Share location' setting documented in the Account Settings help article (an older account-settings article adds that browser-level permission must be granted first). Precise geolocation is otherwise mentioned only as sensitive data a user might type into a prompt. An explicit, declinable opt-in for a named feature is the rubric's partial branch, not yes.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "perplexity",
      "question": "rights_channel",
      "value": "yes",
      "quote": "To submit a data privacy request directly to Perplexity, please use",
      "evidence_url": "https://www.perplexity.ai/hub/legal/privacy-notice",
      "notes": "The sentence links to a Data Privacy Request form at https://perplexity.typeform.com/datarequest, offered in the Contact section without regional restriction, plus support@perplexity.ai and an EU/UK representative (VeraSafe). Access and deletion are also self-service in-product. The notice frames the rights themselves as depending on jurisdiction.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "grok",
      "question": "no_training_default",
      "value": "no",
      "quote": "We may use your content and interactions with Grok (e.g., prompts, searches, and other materials you submit) along with Grok's responses to train our models.",
      "evidence_url": "https://x.ai/legal/faq",
      "notes": "Training is on unless the user turns off 'Improve the model' (Settings > Data Controls); the Europe addendum lists training under legitimate interests rather than consent, and the Terms say unauthenticated users 'grant us full rights' to use their data for training. Private Chat content and business/enterprise data are excluded.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "grok",
      "question": "training_opt_out",
      "value": "yes",
      "quote": "On the mobile app, to select or deselect using your content for model training, go to Settings, Data Controls, and select or deselect “Improve the model.”",
      "evidence_url": "https://x.ai/legal/faq",
      "notes": "A self-service 'Improve the model' toggle exists in the mobile app (Settings > Data Controls) and on grok.com (Settings > Data); the FAQ says it stops training on new conversations only, that Private Chat is an alternative, and that voluntarily submitted feedback may still be used. Caveats: unauthenticated users in some regions outside the EU/UK cannot opt out, and Grok on X uses X's own setting. Under the revised rubric a documented prospective setting counts as YES; the unauthenticated limitation keeps confidence at medium.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "grok",
      "question": "uploads_excluded",
      "value": "partial",
      "quote": "You may provide personal information in prompts and other content you input, such as files, images, audio, voice, video, and other material",
      "evidence_url": "https://x.ai/legal/privacy-policy",
      "notes": "Files, images, audio and video are 'Input' and form part of User Content; the Privacy Policy lists 'to train our models' among its purposes and the Terms say logged-in users 'can select whether or not' User Content is used for training, so uploads are trained on by default and covered by the same 'Improve the model' opt-out. Google-connected content is never used for training and business/enterprise data is excluded. Default-on with a self-service opt-out is the rubric's partial branch, not yes.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "grok",
      "question": "business_no_training",
      "value": "yes",
      "quote": "SpaceXAI will not use any User Content to train any foundation models, large language models, or other artificial intelligence systems or to develop any new products, services, or features, subject to disclosures to Customer and Customer-controlled user settings.",
      "evidence_url": "https://x.ai/legal/terms-of-service-enterprise",
      "notes": "Enterprise Terms (API and business offerings); the Consumer FAQ likewise states 'we do not use content from our business and enterprise customers to improve our models'. The clause is 'subject to ... Customer-controlled user settings', i.e. a customer could enable it, but the default is no training.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "grok",
      "question": "temporary_chat",
      "value": "partial",
      "quote": "If you delete conversations from your account or if you use Private Chat, conversations will be removed from our systems within 30 days, unless they have been de-identified or pseudoanonymized and disassociated from your account or we have to retain them for safety, security, or legal reasons.",
      "evidence_url": "https://x.ai/legal/faq",
      "notes": "Private Chat (ghost icon) exists in the app and on grok.com, keeps conversations out of history and the FAQ says its content is not used for model training 'where available' (Grok on X may differ). The Privacy Policy promises deletion within 30 days except for legal, compliance or safety purposes, but the FAQ adds that de-identified or pseudonymised copies of Private Chat conversations may be kept beyond 30 days, an exception wider than safety retention and a contradiction between the two documents, so partial, consistent with the deletion_timeline cell.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "grok",
      "question": "memory_controls",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "None of the fetched xAI documents (Privacy Policy, Consumer FAQ, Terms, Europe addendum) mention a cross-conversation memory feature or controls for it; the only personalisation control documented is 'Personalize Grok using X'. grok.com itself is a JavaScript app with no fetchable help text, so memory behaviour and controls could not be verified from vendor documents.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "grok",
      "question": "user_deletion",
      "value": "yes",
      "quote": "At any time, you can choose to delete selected conversations or all of your conversation history.",
      "evidence_url": "https://x.ai/legal/faq",
      "notes": "FAQ also states 'you can delete your account at any time' and gives in-product steps: hold a conversation > 'Delete Conversation', Settings > Data Controls > 'Delete All Conversations' and 'Delete Account' (app), or the trash button and Settings buttons on grok.com. Grok on X deletion goes through X.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "grok",
      "question": "data_export",
      "value": "yes",
      "quote": "You are in control to access, download, and delete your data.",
      "evidence_url": "https://x.ai/legal/faq",
      "notes": "FAQ directs users to the Grok app or grok.com Settings > Data Controls to download their data; additional requests via https://x.ai/privacy-portal/. The documents do not itemise what the download contains.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "grok",
      "question": "deletion_timeline",
      "value": "partial",
      "quote": "If you delete conversations from your account or if you use Private Chat, conversations will be removed from our systems within 30 days, unless they have been de-identified or pseudoanonymized and disassociated from your account or we have to retain them for safety, security, or legal reasons.",
      "evidence_url": "https://x.ai/legal/faq",
      "notes": "The Privacy Policy commits to deleting conversations and accounts within 30 days except for legal, compliance or safety purposes, which alone would meet the rubric; the FAQ adds that de-identified or pseudonymised copies may be kept, an exception beyond legal/safety holds, hence partial.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "grok",
      "question": "no_ads_use",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "The xAI FAQ says xAI does not sell data or share it with third parties for marketing or advertising, and the Privacy Policy lists no advertising recipients for User Content, but no document states that conversation content is excluded from xAI's own ad targeting, and cookie data may be used to deliver targeted advertising. Grok itself shows no ads. Neither the yes branch (an explicit limit on conversation content) nor the partial branch (ads with exceptions) is met, so the cell is unknown. Grok on X falls under X's policy, which is out of scope.",
      "confidence": "medium",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "grok",
      "question": "no_sale_sharing",
      "value": "yes",
      "quote": "No. We do not sell your data or share it with third parties for marketing or advertising purposes.",
      "evidence_url": "https://x.ai/legal/faq",
      "notes": "Stated without regional limitation in the Consumer FAQ; the CCPA notice adds that xAI does not 'sell' or 'share' personal information as defined by the CCPA. Disclosures are limited to service providers, related companies, legal purposes, business transfers and third parties the user chooses to share with.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "grok",
      "question": "human_review_limited",
      "value": "partial",
      "quote": "A limited number of our authorized personnel may review your conversations with Grok for specific business purposes, including improving model performance, investigating security incidents and potential misuse of our services, and complying with our legal obligations.",
      "evidence_url": "https://x.ai/legal/faq",
      "notes": "Human review is disclosed and limited to 'authorized personnel', but the stated purposes include 'improving model performance' / 'improving product features' (Terms), which is broader than safety, abuse, legal or user-initiated support, so partial per the rubric.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "grok",
      "question": "no_precise_location",
      "value": "partial",
      "quote": "We obtain your consent prior to collecting precise location information.",
      "evidence_url": "https://x.ai/legal/privacy-policy",
      "notes": "By default only the general area derived from IP address is determined; precise data such as 'your device’s GPS location' is collected only if the user chooses to provide it and after consent. The policy does not tie it to one named feature.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "grok",
      "question": "rights_channel",
      "value": "yes",
      "quote": "If you forget that you are in control of your data or if you have additional requests regarding your personal data, you can submit a request at",
      "evidence_url": "https://x.ai/legal/faq",
      "notes": "The sentence links to the privacy portal https://x.ai/privacy-portal/, which the Privacy Policy names as the channel 'for world-wide requests and in the USA', alongside in-product access/download/delete controls, appeals via the same portal, a DPO address (privacy@x.ai) and UK/EU/Swiss representatives.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "meta-ai",
      "question": "no_training_default",
      "value": "no",
      "quote": "Info shared with AI at Meta features is used to improve AI at Meta unless you have objected.",
      "evidence_url": "https://mbasic.facebook.com/privacy/policy/printable/?locale=en_US",
      "notes": "Interactions with Meta AI are used to develop and improve AI at Meta by default; the only exclusion is an objection request. The GenAI page lists 'your interactions with features that are part of AI at Meta' as a training source; private messages with friends and family are excluded unless shared with the AI.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "meta-ai",
      "question": "training_opt_out",
      "value": "partial",
      "quote": "Info shared with AI at Meta features is used to improve AI at Meta unless you have objected.",
      "evidence_url": "https://mbasic.facebook.com/privacy/policy/printable/?locale=en_US",
      "notes": "There is no in-product toggle. The Privacy Policy says information shared with AI at Meta features is used to improve AI at Meta unless the user has objected, and the objection is a request form whose availability depends on the region: the EU and UK version of the GenAI page documents an objection form (submitted while logged in, covering the account and its Accounts Centre accounts, and not covering a training run that has already started), while the US version documents a request form only for personal information Meta obtained from third parties. A form-based, region-dependent objection is partial under the rubric.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "meta-ai",
      "question": "uploads_excluded",
      "value": "partial",
      "quote": "AIs allows you to provide materials for processing, which could include text, documents, images, or recordings, depending on the integration (together, “Prompts”) and will generate a response (“Outputs”) based on your Prompts, as well as any feedback you provide (“Feedback”) collectively, “Content”.",
      "evidence_url": "https://mbasic.facebook.com/legal/ai-terms?locale=en_US",
      "notes": "Uploaded documents, images and recordings are 'Prompts', which the Terms say form part of the 'interactions' the Privacy Policy uses to improve AI at Meta; they are not excluded by default and are covered only by the same objection request as conversations.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "meta-ai",
      "question": "business_no_training",
      "value": "no",
      "quote": "Information from third parties that provide content, including information from products and services built by external developers using our",
      "evidence_url": "https://mbasic.facebook.com/privacy/genai/?locale=en_US",
      "notes": "The GenAI privacy page lists information from products and services built by external developers on Meta's API models as a training source and states no exclusion, which the rubric scores as no. The sentence ends differently by region (\"contributor tier models provided through APIs\" in the US version, \"free models provided through APIs\" elsewhere), so the quote stops where the variants agree. The wording frames these as third parties that provide content, so it may describe developers who choose to contribute data; Meta's separate Llama API and Business AI terms are JavaScript-rendered and could not be checked, hence medium confidence.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "meta-ai",
      "question": "temporary_chat",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "None of the fetchable documents (Privacy Policy, GenAI page, AI Terms, newsroom post) mention a temporary, incognito or history-off mode for Meta AI; Messenger's vanish mode is referenced only for regular messages.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "meta-ai",
      "question": "memory_controls",
      "value": "partial",
      "quote": "To give you more control, we’ve built in commands that allow you to delete information shared in any chat with an AI across Messenger, Instagram, or WhatsApp. For example you can delete your AI messages by typing “/reset-ai” in a conversation.",
      "evidence_url": "https://about.fb.com/news/2023/09/privacy-matters-metas-generative-ai-features/",
      "notes": "The AI Terms state that AIs 'will sometimes retain and use' shared information; the only fetchable control is the /reset-ai command that clears information shared in a chat. Meta help articles describing per-memory viewing/deletion in the Meta AI app (meta.com/help/artificial-intelligence) are JS-rendered and could not be verified.",
      "confidence": "low",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "meta-ai",
      "question": "user_deletion",
      "value": "yes",
      "quote": "To give you more control, we’ve built in commands that allow you to delete information shared in any chat with an AI across Messenger, Instagram, or WhatsApp. For example you can delete your AI messages by typing “/reset-ai” in a conversation.",
      "evidence_url": "https://about.fb.com/news/2023/09/privacy-matters-metas-generative-ai-features/",
      "notes": "AI chat content can be deleted in-product (/reset-ai; delete tools) and the Privacy Policy offers a self-service 'Delete your information or account' tool. Caveat from the AI Terms: deleting messages, threads or the account 'may not delete our copy of your personal information'; the Privacy Center describes the correct deletion path.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "meta-ai",
      "question": "data_export",
      "value": "yes",
      "quote": "We offer you a variety of tools to view, manage, download and delete your information below.",
      "evidence_url": "https://mbasic.facebook.com/privacy/policy/printable/?locale=en_US",
      "notes": "The Privacy Policy lists self-service Download your information and Port your information tools for all users, alongside Access your information and Delete your information or account. The fetchable documents do not explicitly confirm that Meta AI conversations are included in the download.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "meta-ai",
      "question": "deletion_timeline",
      "value": "partial",
      "quote": "If you request that we delete your account or content, it may take up to 90 days to delete your information after we begin the account deletion process or receive a content deletion request. After the information is deleted, it may take us up to another 90 days to remove it from backups and disaster recovery.",
      "evidence_url": "https://mbasic.facebook.com/privacy/policy/printable/?locale=en_US",
      "notes": "Fixed period is up to 90 days plus up to another 90 days for backups (longer than 30 days); retention exceptions include legal obligations, preventing harm and investigating terms violations. The AI Terms add that deleting messages or the account may not delete Meta's copy of AI-related personal information.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "meta-ai",
      "question": "no_ads_use",
      "value": "no",
      "quote": "including how we use your interactions with AIs to personalize your experiences and ads, and improve AI at Meta.",
      "evidence_url": "https://mbasic.facebook.com/legal/ai-terms?locale=en_US",
      "notes": "The Privacy Policy lists 'Interactions with our features that are part of AI at Meta' among the information used to decide which ads to show; the EU AI Terms variant omits the ads wording, so regional practice may differ.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "meta-ai",
      "question": "no_sale_sharing",
      "value": "partial",
      "quote": "We don't sell your information and we never will.",
      "evidence_url": "https://mbasic.facebook.com/privacy/policy/printable/?locale=en_US",
      "notes": "Meta states it never sells information, but it shares information with advertisers, Audience Network publishers and 'select partners' such as search engines for AI responses, and runs an ad ecosystem with opt-outs via Ad preferences; the statement is not a no-sharing-for-marketing commitment.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "meta-ai",
      "question": "human_review_limited",
      "value": "partial",
      "quote": "In some cases, Meta will review your interactions with AIs, including the content of your conversations with or messages to AIs, and this review may be automated or manual (human).",
      "evidence_url": "https://mbasic.facebook.com/legal/ai-terms?locale=en_US",
      "notes": "Human review is disclosed but for broad purposes: the Terms list providing/improving services, research, and compliance monitoring (also via third-party vendors); the newsroom post says people review interactions to improve model performance. Chats using Private Processing are stated to be unreadable by Meta.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "meta-ai",
      "question": "no_precise_location",
      "value": "partial",
      "quote": "We use location-related information that you allow us to receive if you turn on the Location Services device setting.",
      "evidence_url": "https://mbasic.facebook.com/privacy/policy/printable/?locale=en_US",
      "notes": "GPS-level location is collected only when the device Location Services permission is granted, but it is then used for general personalisation including ads and Meta AI answers rather than one specific feature; IP-based general location is used regardless, and IP may be used to estimate specific location for safety.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "meta-ai",
      "question": "rights_channel",
      "value": "yes",
      "quote": "To exercise your rights, visit our Help Centers, your settings for Facebook and Instagram and your device-based settings.",
      "evidence_url": "https://mbasic.facebook.com/privacy/policy/printable/?locale=en_US",
      "notes": "In-product tools (Access, Download, Port and Delete your information) are documented for all users, plus an online contact form and a postal address (Meta Platforms, Inc., Privacy Operations, Menlo Park). The AI-training objection form is separate and region-dependent. The quoted sentence is from the US-English variant of the policy; other regions serve the same sentence with British spelling (\"Help Centres\").",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "deepseek",
      "question": "no_training_default",
      "value": "no",
      "quote": "we may, to a minimal extent, use Inputs and Outputs to provide, maintain, operate, develop or improve the Services or the underlying technologies supporting the Services.",
      "evidence_url": "https://cdn.deepseek.com/policies/en-US/deepseek-terms-of-use.html",
      "notes": "Terms 4.3: Inputs and Outputs are used (after stated de-identification) to improve the service unless the user turns off the 'Improve the model for everyone' setting; the Privacy Policy likewise lists 'to train and improve our technology, such as our machine learning models' as a default purpose for User Input.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "deepseek",
      "question": "training_opt_out",
      "value": "yes",
      "quote": "If you refuse to allow us to process the data in the manner described above, you can opt out by turning off \"Improve the model for everyone\".",
      "evidence_url": "https://cdn.deepseek.com/policies/en-US/deepseek-terms-of-use.html",
      "notes": "Self-service setting named 'Improve the model for everyone'; the Privacy Policy also lists 'the right to opt-out of using your Personal Data for training our models'. Documents do not say whether data already collected before opting out is removed from training sets.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "deepseek",
      "question": "uploads_excluded",
      "value": "partial",
      "quote": "we may collect your text input, voice input, prompt, uploaded files, photos, feedback, chat history, or other content that you provide to our model and Services",
      "evidence_url": "https://cdn.deepseek.com/policies/en-US/deepseek-privacy-policy.html",
      "notes": "Uploaded files and photos are defined as 'Prompts' or 'Inputs', and Terms 4.3 says Inputs and Outputs may be used, after stated de-identification, to develop or improve the Services unless the user turns off 'Improve the model for everyone'. Uploads are therefore trained on by default and covered by the same self-service opt-out as conversations, which is the rubric's partial branch. The documents do not say whether data collected before opting out is removed, and no plan or regional differences are described.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "deepseek",
      "question": "business_no_training",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "The Open Platform (API) Terms of Service address ownership of Inputs/Outputs and the developer's duties toward end users but contain no statement on whether API inputs are or are not used for training; the Privacy Policy explicitly excludes end users of developer applications from its scope. DeepSeek has no separate team/enterprise chat plan in the documents.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "deepseek",
      "question": "temporary_chat",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "Neither the Privacy Policy nor the Terms of Use mention a temporary, incognito or history-off chat mode.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "deepseek",
      "question": "memory_controls",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "The documents do not mention a cross-conversation memory feature or controls for one; they only describe managing, copying and deleting chat history in settings.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "deepseek",
      "question": "user_deletion",
      "value": "partial",
      "quote": "You can control and access some of your Personal Data directly through settings. For example, you can manage your chat history. Should you choose to do so, you may also copy or delete your chat history via your settings.",
      "evidence_url": "https://cdn.deepseek.com/policies/en-US/deepseek-privacy-policy.html",
      "notes": "Deleting chat history via settings is documented as self-service. Account deletion is referenced ('If you choose to delete your account, you will not be able to reactivate'; Terms 2.5 'delete your account') but neither document states whether it is done in-product or by request to privacy@deepseek.com.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "deepseek",
      "question": "data_export",
      "value": "yes",
      "quote": "Should you choose to do so, you may also copy or delete your chat history via your settings.",
      "evidence_url": "https://cdn.deepseek.com/policies/en-US/deepseek-privacy-policy.html",
      "notes": "Self-service copy of chat history in settings; a portable copy of other account Personal Data is available on request by emailing privacy@deepseek.com (rights 'depending on where you live').",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "deepseek",
      "question": "deletion_timeline",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "The Privacy Policy states account and input data are kept 'for as long as you have an account' and that data is destroyed or anonymised 'when no longer required', with retention for legal obligations, legitimate business interests (including improving the Services) and violations; no period after deletion is given.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "deepseek",
      "question": "no_ads_use",
      "value": "yes",
      "quote": "NOTE WE DO NOT ENGAGE IN TARGETED ADVERTISING",
      "evidence_url": "https://cdn.deepseek.com/policies/en-US/deepseek-privacy-policy.html",
      "notes": "The service shows no targeted advertising and the policy states no targeted advertising or profiling is performed, so conversation content is not used for ad personalisation; DeepSeek may still send its own 'commercial messages' to users.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "deepseek",
      "question": "no_sale_sharing",
      "value": "yes",
      "quote": "NOTE WE DO NOT ENGAGE IN TARGETED ADVERTISING, “SELL” PERSONAL DATA OR USE PERSONAL DATA FOR “PROFILING” OR OTHERWISE ENGAGE IN AUTOMATED PROCESSING OF PERSONAL DATA TO MAKE DECISIONS THAT COULD HAVE LEGAL OR SIMILARLY SIGNIFICANT IMPACT ON YOU OR OTHERS.",
      "evidence_url": "https://cdn.deepseek.com/policies/en-US/deepseek-privacy-policy.html",
      "notes": "Sharing is limited to service providers acting on instructions, the corporate group (including for 'foundation model training and optimization'), corporate transactions, legal requests and user-consented sharing; search keywords are shared with third-party search APIs to answer queries. No sharing for third-party marketing is described.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "deepseek",
      "question": "human_review_limited",
      "value": "partial",
      "quote": "During the optimization training phase, we typically need to construct or annotate a set of question-answer pair data manually or automatically to train the model. These question-answer pairs are produced by our research team, with a small portion potentially based on user input.",
      "evidence_url": "https://cdn.deepseek.com/policies/en-US/model-algorithm-disclosure.html",
      "notes": "Manual annotation of training data that may be based on (de-identified) user input is disclosed for model improvement, a broader purpose than safety/legal; Terms 3.3 also reserves the right to review user behaviour by 'technical means'. The Privacy Policy itself does not state whether staff read conversations.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "deepseek",
      "question": "no_precise_location",
      "value": "partial",
      "quote": "We will not obtain your precise geolocation information through other means without your explicit consent.",
      "evidence_url": "https://cdn.deepseek.com/policies/en-US/deepseek-privacy-policy.html",
      "notes": "Only approximate location derived from the IP address is collected automatically, for security and to answer location-related questions, and precise geolocation is listed among sensitive data the service is not designed to process. The policy nevertheless reserves collecting precise geolocation 'with your explicit consent', which is a consent gate rather than a statement that it is never collected; the rubric's YES branch requires no precise collection to be mentioned anywhere, so this is scored partial, the same treatment as Grok's consent-before-collection sentence.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "deepseek",
      "question": "rights_channel",
      "value": "yes",
      "quote": "To exercise your rights, you or an authorized agent may submit a request by emailing us at",
      "evidence_url": "https://cdn.deepseek.com/policies/en-US/deepseek-privacy-policy.html",
      "notes": "Dedicated address privacy@deepseek.com (wrapped in a mailto link, hence the quote ends before it) for access, correction, deletion, portability and opt-out requests from any user, with an appeal route; EU/UK users may also use the Prighter representative (rep_deepseek@prighter.com). Rights themselves apply 'depending on where you live'.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "le-chat",
      "question": "no_training_default",
      "value": "no",
      "quote": "Your Input and Output, subject to your opt-out.",
      "evidence_url": "https://legal.mistral.ai/terms/privacy-policy",
      "notes": "For the consumer Vibe (Free/Pro) plans input and output are used for model training by default unless the user disables the 'Allow your interactions to be used to train our models' toggle; the consumer Terms say 'We do not use Your Data to train our artificial intelligence models except (a) when you have not opted out of training or (b) when you provide Feedback to us.' Only Vibe Enterprise is opted out by default (admin-managed).",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "le-chat",
      "question": "training_opt_out",
      "value": "yes",
      "quote": "We’ve introduced a user control which allows you to object to the use of your input and output data for model training directly from your account.",
      "evidence_url": "https://legal.mistral.ai/terms/privacy-policy",
      "notes": "Self-service and documented for all consumer plans: web Admin panel > Vibe > Privacy > disable 'Allow your interactions to be used to train our models'; mobile Settings > Data & Account Controls > deselect 'Enable data sharing' (help article 455207). The help center says that once the opt-out is confirmed Mistral 'no longer uses your input or output data' for training, but no document says whether conversations collected before the opt-out are withdrawn from training, and thumbs-up/down Feedback (with its input and output) remains usable for training regardless of the toggle; the Vibe and API toggles are separate. Vibe Enterprise is opted out by default at admin level.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "le-chat",
      "question": "uploads_excluded",
      "value": "partial",
      "quote": "Therefore, you may wish to opt out to prevent such documents from being used to improve Mistral’s models.",
      "evidence_url": "https://help.mistral.ai/en/articles/455207-can-i-opt-out-of-my-input-or-output-data-being-used-for-training",
      "notes": "Documents attached or uploaded in Vibe are treated as input data, so they are used for training by default and are covered by the same training opt-out toggle as conversations; rated partial because exclusion requires the user to turn the default-on training setting off.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "le-chat",
      "question": "business_no_training",
      "value": "partial",
      "quote": "Mistral AI will not use Customer Data or Outputs to train its artificial intelligence models except (a) when you (i) opted-in to training on a Mistral AI Product set to opt-out by default or (ii) have not opted-out of training on a Mistral AI Product set to opt-in by default",
      "evidence_url": "https://legal.mistral.ai/terms/commercial-terms-of-service",
      "notes": "Defaults differ by product: Vibe Enterprise and Team admins are opted out by default, but Mistral AI Studio 'Free mode' API usage may be used for training unless opted out, Feedback is always usable, Order Forms may vary, and Labs/Preview models are always used for training (opt-outs and ZDR do not apply). Zero Data Retention is request-only and limited to pay-as-you-go stateless API endpoints.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "le-chat",
      "question": "temporary_chat",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "No temporary, incognito or history-off mode is mentioned in the Privacy Policy, the consumer Terms or the help center; conversations are kept until the user deletes them, and the help center states Zero Data Retention is not available for Vibe chat.",
      "confidence": "medium",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "le-chat",
      "question": "memory_controls",
      "value": "yes",
      "quote": "Access, add, delete or edit your Memories or your Knowledge Base at all time through your settings.",
      "evidence_url": "https://legal.mistral.ai/terms/privacy-policy",
      "notes": "Memories (being renamed Knowledge Base) is optional and can be turned off at any time in settings; items can be viewed, edited, deleted individually or cleared all at once. The help center warns that deactivating does not delete stored memories (clear them first) and that, unless the user has opted out of training, memories are treated like any other prompt.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "le-chat",
      "question": "user_deletion",
      "value": "yes",
      "quote": "we keep your Input and Output until you delete your account or until you delete the conversation from Vibe.",
      "evidence_url": "https://legal.mistral.ai/terms/privacy-policy",
      "notes": "Individual conversations are deleted from the conversation menu (three dots > Delete) and the account from the Admin panel 'Danger Zone' > Delete account; both are self-service per help articles 347613 and 347619, and the consumer Terms confirm account deletion 'by using the feature available on your account'.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "le-chat",
      "question": "data_export",
      "value": "yes",
      "quote": "We've introduced a user control which allows you to export your data at all times from your Mistral AI account.",
      "evidence_url": "https://legal.mistral.ai/terms/privacy-policy",
      "notes": "An Export button in Vibe downloads all Vibe data (help article 347623); the EEA consumer Terms state the export features 'include at least your Vibe conversations (prompts and outputs)'. Export is only possible before account termination.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "le-chat",
      "question": "deletion_timeline",
      "value": "partial",
      "quote": "we keep your Input and Output until you delete your account or until you delete the conversation from Vibe.",
      "evidence_url": "https://legal.mistral.ai/terms/privacy-policy",
      "notes": "No fixed purge window is stated for deleted chats: the help center only says conversations are removed 'typically after a short grace period' and may be retained to enforce the Usage Policy or as required by law. Fixed periods are stated only for account-related data after deletion (account data 1 year, civil identity 5 years, invoices 10 years, technical data 1 rolling year) under legal-obligation holds.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "le-chat",
      "question": "no_ads_use",
      "value": "yes",
      "quote": "does not use the content of your conversations",
      "evidence_url": "https://help.mistral.ai/en/articles/347633-do-you-use-my-conversations-with-vibe-to-show-me-ads",
      "notes": "Full sentence (split by formatting tags in the source): 'Mistral does not use the content of your conversations with Vibe for marketing or advertising purposes.' Partner marketing cookies, if the user consents to them, use browser/device identifiers rather than conversation content; the US notice adds that Mistral has not engaged in 'targeted advertising'.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "le-chat",
      "question": "no_sale_sharing",
      "value": "yes",
      "quote": "does not sell or share your personal data",
      "evidence_url": "https://help.mistral.ai/en/articles/347615-do-you-sell-or-share-my-data-for-marketing",
      "notes": "Full sentence: 'Mistral does not sell or share your personal data for marketing or advertising purposes.' The Privacy Policy lists only team members, financial institutions, regulators, legal professionals and audited service providers under DPAs as recipients, and the US notice states no sale/sharing in the preceding 12 months. Caveat: consent-based partner marketing cookies may be set for Mistral's own ads on other sites.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "le-chat",
      "question": "human_review_limited",
      "value": "yes",
      "quote": "People other than yourself may occasionally view your conversations, in the limited number of specific situations described below:",
      "evidence_url": "https://help.mistral.ai/en/articles/347632-can-other-people-view-my-conversations",
      "notes": "The help article lists the only situations in which people other than the user may view conversations: content the user reports (a limited number of authorised staff), conversations the user shares via link, and thumbs-up or thumbs-down feedback, where the related input and output are de-identified and used to improve models. All three are triggered by the user, which the rubric counts as yes even though the feedback case serves model improvement; the Terms also reserve automated monitoring that supports human review where required by law.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "le-chat",
      "question": "no_precise_location",
      "value": "yes",
      "quote": "Please note that we use part of your IP address to make your experience better, such as, for instance, to provide you with more accurate Outputs depending on where you use our Mistral AI Products.",
      "evidence_url": "https://legal.mistral.ai/terms/privacy-policy",
      "notes": "Location is derived only from the IP address (Technical Data) and the user can opt out of that processing in account preferences; no precise geolocation category appears in the data inventory or in the US state-law category list.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "le-chat",
      "question": "rights_channel",
      "value": "yes",
      "quote": "By using the user controls which are available from your Mistral AI Account settings and which allow you to: delete your account at all times, obtain a copy of your data, object to the use of your input and output data for model training.",
      "evidence_url": "https://legal.mistral.ai/terms/privacy-policy",
      "notes": "In-product controls plus a 'Privacy Requests' contact form and a postal address for the DPO/Privacy Team are offered to all users; US residents additionally get an email/online form and an appeal route. Requests concerning model training are subject to stated technical limitations.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "character-ai",
      "question": "no_training_default",
      "value": "no",
      "quote": "Analyze, maintain, improve, modify, customize, and measure the Services, including to train our artificial intelligence/machine learning models;",
      "evidence_url": "https://character.ai/_next/static/chunks/pages/privacy-645bfcb925495ab4.js",
      "notes": "User content including chat communications is used to train and improve models by default; the 'Improve the Model for Everyone' setting is on until the user de-selects it, and the Regional Privacy Disclosures state 'we train the AI systems and improve AI models that support our Services' before de-identification steps.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "character-ai",
      "question": "training_opt_out",
      "value": "partial",
      "quote": "If you are in the European Economic Area (“EEA”) or the United Kingdom (“UK”), and you would like to opt out of us using your chat content to train our generative AI models, you can follow the steps below.",
      "evidence_url": "https://support.character.ai/api/v2/help_center/en-us/articles/42788047758747.json",
      "notes": "Self-service toggle: Settings > Account > Manage Account & Data > Model Improvement > de-select 'Improve the Model for Everyone' (app: Settings > Data & Privacy). The FAQ frames the steps for EEA/UK users while the Regional Privacy Disclosures say covered users 'have the right to opt out at any time'; the opt-out applies only to new content, and data may still be used for search, recommendations and safety classifiers.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "character-ai",
      "question": "uploads_excluded",
      "value": "partial",
      "quote": "Your content you submit, such as chat communications, posted images or videos, biography description, and shared Characters;",
      "evidence_url": "https://character.ai/_next/static/chunks/pages/privacy-645bfcb925495ab4.js",
      "notes": "Submitted content including posted images/videos and voice recordings is collected and used for training by default; the training opt-out states 'new content will not be used to train our generative AI models', which covers content broadly, but it requires the user to act and is documented with the regional caveats noted for training_opt_out.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "character-ai",
      "question": "business_no_training",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "Character.AI has no business, team, enterprise or API offering: the support FAQ 'Is there an API?' states 'We don't currently have an API.' No document addresses business-customer data.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "character-ai",
      "question": "temporary_chat",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "No temporary, incognito or history-off chat mode is described in the Privacy Policy, the Regional Privacy Disclosures, the Terms of Service (fetched as the tos JS chunk; no occurrence of 'temporary' or 'incognito') or any support article in the help-center index. The under-18 'reading mode' article only says past chats remain saved and viewable. Silence, so unknown.",
      "confidence": "medium",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "character-ai",
      "question": "memory_controls",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "The privacy documents do not describe a cross-conversation memory profile of the user or a switch for it. Documented memory features (Pinned Memories, Chat Memories) are per-chat and user-authored: the user pins/unpins messages or edits a text box inside a specific chat.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "character-ai",
      "question": "user_deletion",
      "value": "partial",
      "quote": "You may delete your account through your account profile page.",
      "evidence_url": "https://character.ai/_next/static/chunks/pages/privacy-645bfcb925495ab4.js",
      "notes": "Account deletion is self-service (Settings > Account > Manage Account & Data > Delete Account; app: Remove Account) and permanent. No vendor document found describes deleting individual conversations, and the policy reserves the right to keep public Characters active after account deletion.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "character-ai",
      "question": "data_export",
      "value": "yes",
      "quote": "If you would like to export your data please go to your profile settings and follow the steps below for",
      "evidence_url": "https://support.character.ai/api/v2/help_center/en-us/articles/30299431702555.json",
      "notes": "Self-service export: Web Profile Settings > Account > Manage Account & Data > Export data; mobile app Settings > Export my data. The article title states the export covers chats.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "character-ai",
      "question": "deletion_timeline",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "Retention is described only as 'the time necessary for the purposes for which it is processed' plus legal/dispute holds; no deletion period is stated for chats or accounts, and characteristics of Characters made public may be preserved after the creator deletes their data.",
      "confidence": "medium",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "character-ai",
      "question": "no_ads_use",
      "value": "no",
      "quote": "Your content you submit Voice data, if you chose to use certain voice features Technical information Information we collect from other sources | To carry out advertising activities, including: recruiting new users; sending you advertising communications, including to inform you about features or aspects of the Services we believe might be of interest to you (sending tailored advertising)",
      "evidence_url": "https://character.ai/_next/static/chunks/pages/regional-d6d1e02db80cf5eb.js",
      "notes": "The EEA/UK legal-basis chart lists 'Your content you submit' (defined in the Privacy Policy to include chat communications) among the data processed 'To carry out advertising activities', a purpose that expressly includes 'sending tailored advertising' (legal basis: consent where legally required), and the global Privacy Policy lists 'provision of tailored advertising' as a purpose for the information it collects. Because the chart groups several data categories and three sub-purposes in one row, it does not say in so many words that chat content drives ad selection; the US State Privacy Notice shows chat content is not 'sold' to advertising providers. No document states that conversation content is excluded from advertising, so the cell stays no with medium confidence.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "character-ai",
      "question": "no_sale_sharing",
      "value": "partial",
      "quote": "While these disclosures may be considered sales under certain state laws, we do not sell personal information for monetary consideration, and Character.AI is not a data broker.",
      "evidence_url": "https://character.ai/_next/static/chunks/pages/regional-d6d1e02db80cf5eb.js",
      "notes": "The U.S. State Privacy Notice discloses that identifiers, demographic data, IP-based geolocation, device/activity data and inferences were 'sold' (state-law sense) to advertising providers in the preceding 12 months, with an opt-out via 'Your Privacy Choices'; chat content is not listed as sold.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "character-ai",
      "question": "human_review_limited",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "The Terms of Service reserve a right to access, review, screen, edit, modify and delete submitted content at any time and for any reason, a generic content-review clause that under the rubric is not a disclosure of human access to conversations. The Privacy Policy lists content-moderation vendors as recipients and the support FAQ says Character creators can never see users' conversations while moderators may review public Characters and posts; no document states whether staff read private chats or in which cases, so the cell is unknown.",
      "confidence": "medium",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "character-ai",
      "question": "no_precise_location",
      "value": "yes",
      "quote": "Geolocation data (i.e., approximate location based on IP address)",
      "evidence_url": "https://character.ai/_next/static/chunks/pages/regional-d6d1e02db80cf5eb.js",
      "notes": "The Privacy Policy lists 'general geolocation information' and 'geolocation data' (Technical Information, also received from ad platforms); the U.S. State Privacy Notice defines the geolocation category as approximate IP-based location. No precise/GPS location collection or device permission is documented.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "character-ai",
      "question": "rights_channel",
      "value": "yes",
      "quote": "If you would like information regarding your rights or would like to exercise any rights you may have under applicable law, contact us at [https://support.character.ai/hc/en-us/requests/new](https://support.character.ai/hc/en-us/requests/new)",
      "evidence_url": "https://character.ai/_next/static/chunks/pages/privacy-645bfcb925495ab4.js",
      "notes": "A support request form, the privacy@character.ai address and a postal address are given for all users, alongside in-product export and account deletion; the EEA/UK notice adds EU/UK representatives (VeraSafe) and identity verification may be required.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "poe",
      "question": "no_training_default",
      "value": "partial",
      "quote": "Only third-party developer bots and apps are permitted to use your chats to train their models.",
      "evidence_url": "https://poe.com/pages/privacy-center",
      "notes": "Official (fully-shaded shield) bots powered by OpenAI, Anthropic, Google and Meta are stated not to train on chats, but half-shield third-party developer bots and apps may view, store and train on them; Quora itself makes no statement about training its own models on chats, and the ToS grants a perpetual licence to use content to generally improve Poe.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "poe",
      "question": "training_opt_out",
      "value": "partial",
      "quote": "Third-party developer bots and apps can use your chats to train their AI models",
      "evidence_url": "https://poe.com/pages/privacy-center",
      "notes": "No account-level opt-out setting exists; training is avoided only by choosing full-shield bots (indicated by the privacy shield icon on the bot info card), and granting a bot new permissions can switch it to half-shield for that interaction.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "poe",
      "question": "uploads_excluded",
      "value": "partial",
      "quote": "Our third party AI model providers and third party developers may receive details about your interactions with bots and apps on Poe (including the contents of your chats and photos or documents you upload) to provide and generally improve their services, which they may process in their legitimate business interests, or based on the settings in your Poe account.",
      "evidence_url": "https://poe.com/pages/privacy",
      "notes": "Uploaded photos and documents are treated as part of the interaction and follow the same privacy-shield rules as chats (no training by official-bot providers, possible training by half-shield developers); there is no separate upload opt-out. Files uploaded to a temporary chat are kept up to 15 days for safety review.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "poe",
      "question": "business_no_training",
      "value": "partial",
      "quote": "We will not (i) use any content provided by Your Bot to train a large language model, or (ii) provide any content provided by Your Bot to a third-party service unless we have a contractual agreement in place with such service restricting their use of such content.",
      "evidence_url": "https://poe.com/api_terms",
      "notes": "The only non-consumer offering with documented terms is the creator/bot API, where Poe commits not to train an LLM on bot-provided content; no team, business or enterprise plan is documented (shared subscriptions are consumer plans). API Terms are dated October 3, 2023.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "poe",
      "question": "temporary_chat",
      "value": "yes",
      "quote": "Temporary chat messages are permanently deleted within 24 hours of creation. Files you upload to a temporary chat are retained for up to 15 days for safety review before being permanently deleted.",
      "evidence_url": "https://help.poe.com/api/v2/help_center/en-us/articles/19944206309524.json",
      "notes": "Temporary chats are not saved to history, cannot be shared or searched, are not used by Memory, and are available only with official bots (which are stated not to train on chats); content may be kept longer in limited cases for legal and safety obligations, and the model provider's own retention (e.g. 30 days) still applies.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "poe",
      "question": "memory_controls",
      "value": "partial",
      "quote": "It's off by default. You can turn it on in **Settings → Memory**, where you can also view or permanently delete your Memory at any time.",
      "evidence_url": "https://help.poe.com/api/v2/help_center/en-us/articles/19944206309524.json",
      "notes": "Memory is off by default and can be switched on/off, viewed and permanently deleted in Settings → Memory, but the documents describe deleting the memory summary as a whole rather than item by item; the Privacy Center notes deleted chat data may persist in memory summaries until memory is deleted.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "poe",
      "question": "user_deletion",
      "value": "yes",
      "quote": "If you want to clear your chat history, you have two options: delete the entire chat history or delete individual messages.",
      "evidence_url": "https://help.poe.com/api/v2/help_center/en-us/articles/19944206309524.json",
      "notes": "Per-message deletion and a Settings 'Delete all chats' option are self-service, and 'Delete account' in Settings deactivates the account immediately with a 14-day reactivation window (ToS: 'You may cease your use of Poe at any time by deleting your account in your settings'); deleting a Poe account also deletes a linked Quora account.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "poe",
      "question": "data_export",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "No export or download feature is described in the Poe Privacy Policy, Privacy Center, ToS or FAQs; rights handling is delegated to the Quora Privacy Policy (www.quora.com/about/privacy), which is Cloudflare-gated and could not be fetched by the crawler.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "poe",
      "question": "deletion_timeline",
      "value": "partial",
      "quote": "Your chats and personal data associated with your account are deleted from Poe’s systems and will not be used for any other purpose. If you use Poe’s memory feature, data you delete from a chat may persist in the background summaries generated from your Poe history.",
      "evidence_url": "https://poe.com/pages/privacy-center",
      "notes": "A purge period is stated only for one mode: temporary chat messages are deleted within 24 hours and their uploaded files within 15 days (FAQ), while ordinary chat deletion is described only as 'deleted from Poe's systems' with no timing, and account deletion begins after a 14-day reactivation window with no completion time. The Privacy Center also admits that deleted chat data may persist in Memory summaries until the user deletes Memory, a non-legal exception, and model providers keep chats on their own schedules (e.g. 30 days for OpenAI and Anthropic). Period stated for some data only plus a broad exception gives partial.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "poe",
      "question": "no_ads_use",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "The Poe Privacy Policy's Advertising section covers only Quora's own campaigns (ad-interaction data, hashed email shared with ad platform partners for programmatic ads and paid acquisition) and never says whether conversation content is used or excluded for ad personalisation. The ToS licence limits Quora's use of Your Content to providing and improving Poe (routing chats to models, display, promotion of shared content, understanding usage) with no marketing use listed, but no document states that Poe shows no ads, so the rubric's second YES branch cannot be established. The incorporated Quora Privacy Policy is Cloudflare-gated (HTTP 403) and cannot be checked.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "poe",
      "question": "no_sale_sharing",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "No 'do not sell' statement appears in the fetchable Poe documents; the policy discloses sharing a hashed email with ad platform partners for Quora's own advertising, and the API Terms require bot developers not to sell user personal data. The Quora Privacy Policy, where such statements would live, is Cloudflare-gated.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "poe",
      "question": "human_review_limited",
      "value": "partial",
      "quote": "Developers that create bots and apps on Poe using APIs may view and store your chats on their servers to train their models.",
      "evidence_url": "https://poe.com/pages/privacy",
      "notes": "The documents disclose that third-party developers of half-shield bots may view and store chats for broad purposes, while official bots' providers can use chats only to produce the response; whether Quora staff or contractors read conversations is not addressed.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "poe",
      "question": "no_precise_location",
      "value": "yes",
      "quote": "We also collect your IP address to help personalize the outputs you receive (i.e. some bots may receive your rough IP address to respond to location-specific questions).",
      "evidence_url": "https://poe.com/pages/privacy",
      "notes": "Only IP-derived rough location is described and precise geolocation is absent from the list of data collected in the Poe Privacy Policy; the incorporated Quora Privacy Policy could not be fetched, so its collection list is unverified.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "poe",
      "question": "rights_channel",
      "value": "partial",
      "quote": "Please contact our Data Protection Officer at",
      "evidence_url": "https://poe.com/pages/privacy",
      "notes": "A dedicated DPO address (privacy@quora.com) is given for questions and in-product chat/account deletion is available to all users, but the procedure for exercising access, deletion and portability rights is delegated to the Quora Privacy Policy, which the crawler cannot fetch.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "pi",
      "question": "no_training_default",
      "value": "no",
      "quote": "Provide, maintain, and improve the Services, including to develop and train our AI models / large language models that power our Services. You may opt out of model training in your Account settings page;",
      "evidence_url": "https://inflection.ai/privacy-policy",
      "notes": "Consumer inputs are used to train Inflection's models by default; the user must opt out in Account settings. The ToS grants a perpetual, irrevocable licence to use Inputs and Outputs to train and improve models, and for Europe the stated legal basis is legitimate interests.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "pi",
      "question": "training_opt_out",
      "value": "yes",
      "quote": "You may opt out of model training in your Account settings page",
      "evidence_url": "https://inflection.ai/privacy-policy",
      "notes": "A documented self-service setting exists: the Privacy Policy points to the Account settings page and the help center confirms 'you can opt out anytime', which the revised rubric counts as yes even if it only stops training on new conversations. The documents do not say whether conversations collected before the opt-out are withdrawn, and two statements sit uneasily beside it: outputs are retained indefinitely for the purposes in ToS Section 4 (a licence that includes training and improving models) and that content licence is perpetual and survives termination. No regional or plan limitation is stated.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "pi",
      "question": "uploads_excluded",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "Pi accepts no file, image or document uploads (help center, December 2025), so the practice does not apply and the cell is unknown by convention, not a penalty. The only non-text inputs are live voice and audio, which the Privacy Policy treats as 'inputs' used for training by default and covered by the general model-training opt-out; a separate Account-settings opt-out exists for inferring emotions from voice. If uploads are added later, the training default (no) and opt-out (yes) would apply to them.",
      "confidence": "medium",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "pi",
      "question": "business_no_training",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "The Privacy Policy states it does not apply where Inflection AI acts as a processor for commercial customers such as its API and refers to the customer agreement; no public document fetched states whether API or enterprise customer data is used for training.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "pi",
      "question": "temporary_chat",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "Neither the Privacy Policy, Terms of Service nor the help center describes a temporary, incognito or history-off mode for Pi.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "pi",
      "question": "memory_controls",
      "value": "partial",
      "quote": "You can add, delete, and update Pi's memories by going to Settings",
      "evidence_url": "https://help.pi.ai/en/articles/15425697-pi-s-memory",
      "notes": "Settings > Account > Manage Memories lets the user view, add, edit and delete individual memories, and Pi can be told in chat to forget a specific memory; no documented control turns the memory feature off entirely.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "pi",
      "question": "user_deletion",
      "value": "partial",
      "quote": "Users of Pi may also delete individual messages, which will be removed immediately from your conversation history.",
      "evidence_url": "https://inflection.ai/privacy-policy",
      "notes": "Account deletion is self-service (profile > Account > 'Delete my account', or typing '!delete' in chat) and the policy says individual messages can be deleted in-product, but the help center's deletion article says account deletion removes everything and 'there's no way to delete just part of your data', so the documents conflict on partial deletion.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "pi",
      "question": "data_export",
      "value": "yes",
      "quote": "Click on Download Chat history link to initiate the full chat retrieval.",
      "evidence_url": "https://help.pi.ai/en/articles/12988158-export-and-share-chat-history-safely-with-limits-and-tips",
      "notes": "Settings > Account > Download Chat history (web, Android, iOS) produces a pi-user-history.json file after processing; exporting individual chats is not supported. The Privacy Policy also lists access in a portable format as a right depending on residence.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "pi",
      "question": "deletion_timeline",
      "value": "partial",
      "quote": "For users of Pi, we generally retain inputs for at most 15 days after user deletion.",
      "evidence_url": "https://inflection.ai/privacy-policy",
      "notes": "Inputs are purged within 15 days of deletion, with exceptions for fraud and abuse, security, legal requirements and financial record-keeping, but the policy states outputs are retained indefinitely for the purposes in ToS Section 4 (including model training and improvement).",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "pi",
      "question": "no_ads_use",
      "value": "yes",
      "quote": "We do not engage in “sales” or “sharing” of personal information or process personal information for “targeted advertising” purposes as those terms are defined by U.S. state privacy laws.",
      "evidence_url": "https://inflection.ai/privacy-policy",
      "notes": "Pi shows no ads. The Privacy Policy states that Inflection does not process personal information for targeted advertising as defined by US state privacy laws, a statement offered to all users, and the Notice on Model Training says personal information in training data is not used for marketing. Service providers for marketing and advertising measurement are listed for Inflection's own promotion using non-conversation data, which does not count against this question.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "pi",
      "question": "no_sale_sharing",
      "value": "yes",
      "quote": "We do not engage in “sales” or “sharing” of personal information or process personal information for “targeted advertising” purposes as those terms are defined by U.S. state privacy laws.",
      "evidence_url": "https://inflection.ai/privacy-policy",
      "notes": "Stated for all users (not limited to a residency), using U.S. state-law definitions of sale and sharing; the disclosure list contains only processors, legal, advisors, corporate transactions and consent-based sharing, and the Notice on Model Training also says training-data personal information is not sold or used for marketing.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "pi",
      "question": "human_review_limited",
      "value": "partial",
      "quote": "Inflection AI uses a combination of automated technologies and human review to monitor activity on Inflection AI’s products and services, such as Pi.",
      "evidence_url": "https://inflection.ai/transparency-and-content-moderation",
      "notes": "Human review is disclosed in the content-moderation context, with the specific case described being the Pi support team reviewing content users flag; the general 'monitor activity' statement is not expressly limited to those cases, and the Privacy Policy lists content-moderation vendors.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "pi",
      "question": "no_precise_location",
      "value": "partial",
      "quote": "With your consent, we may collect information about the precise location of your device.",
      "evidence_url": "https://inflection.ai/privacy-policy",
      "notes": "Precise geolocation is collected only after a consent prompt when first launching a mobile app that collects it, and collection can be stopped at any time in device preferences; the policy does not name the specific feature that uses it.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "pi",
      "question": "rights_channel",
      "value": "yes",
      "quote": "To exercise your other rights, contact us by email at [privacy@inflection.ai](mailto:privacy@inflection.ai)",
      "evidence_url": "https://inflection.ai/privacy-policy",
      "notes": "A designated privacy address (privacy@inflection.ai) is documented for exercising rights and for appeals and is offered to all users; EEA and UK users additionally get the DataRep webform and inflectionai@datarep.com, and in-product controls cover deletion ('Delete my account' or typing '!delete') and chat-history export. The rights themselves are stated to depend on residence, which under the revised rubric does not demote when the channel is offered to everyone.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "you-com",
      "question": "no_training_default",
      "value": "no",
      "quote": "You agree that we may use Content to: (a) provide, maintain, train and improve the Services; (b) develop other products and services;",
      "evidence_url": "https://you.com/terms",
      "notes": "Terms 4.1 define Content as Prompts plus Outputs and 4.5 grants use of it to 'train and improve the Services' by default with no consumer opt-out; the only 'No Model Training' control documented (JS-only help center) is an admin toggle on Max/Enterprise plans that is off by default.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "you-com",
      "question": "training_opt_out",
      "value": "no",
      "quote": "You agree that we may use Content to: (a) provide, maintain, train and improve the Services; (b) develop other products and services;",
      "evidence_url": "https://you.com/terms",
      "notes": "Terms 4.5 grants use of Content (Prompts plus Outputs) to train and improve the Services by default and neither the Terms nor the Privacy Policy describe any setting, request route or objection tied to training for individual users, which the revised rubric scores as NO rather than UNKNOWN because the training default itself is documented. The Privacy Policy's EU/UK right to object to legitimate-interest processing is generic and not tied to training, and the only training control in the help center (a 'No Model Training' admin toggle on Max and Enterprise plans, off by default, JS-only) is a business-plan setting that does not count for a consumer cell.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "you-com",
      "question": "uploads_excluded",
      "value": "no",
      "quote": "You may be allowed to submit text, documents, or other materials to our Services for processing",
      "evidence_url": "https://you.com/terms",
      "notes": "Uploaded documents are part of 'Prompts' and therefore 'Content', which Terms 4.5 allows You.com to use to 'train and improve the Services'; no opt-out for individual users is documented. The Privacy Policy separately says data pulled from connected drives (Google Drive, Dropbox, SharePoint) is not used to train third-party models.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "you-com",
      "question": "business_no_training",
      "value": "partial",
      "quote": "It is enabled by You.com on request—there is no self-serve toggle.",
      "evidence_url": "https://you.com/docs/administration/zero-data-retention",
      "notes": "For the API platform, 'queries are not used to train models' only under ZDR, an optional enterprise-agreement add-on (Web Search and Answer APIs). For enterprise chat the MSA (PDF, 3.4.3) limits You.com's own use of Customer Data to providing the Services, law and safety, but the No Model Training/ZDR toggles that stop third-party model providers are admin settings that are off by default on Max/Enterprise plans (help center, JS-only).",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "you-com",
      "question": "temporary_chat",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "The Privacy Policy and Terms do not mention a temporary or history-off mode. The JS-only help center (Chat Settings article) describes a 'Nonpermanent mode' that disables chat history but says You.com 'may retain details of the chat for the purposes of product improvements and maintenance'; it cannot be cited because curl receives only a Salesforce loading shell.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "you-com",
      "question": "memory_controls",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "No cross-conversation memory feature is described in the Privacy Policy or Terms, and the documents do not confirm its absence. The JS-only help center describes only a user-written 'Personalization' bio that can be toggled off, not automatic memory.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "you-com",
      "question": "user_deletion",
      "value": "partial",
      "quote": "If you would like to delete your you.com account, please email us",
      "evidence_url": "https://you.com/privacy",
      "notes": "The Privacy Policy routes account deletion through an email request to Privacy@you.com and allows refusal for trust, safety or fraud issues; individual chat deletion is not mentioned in the policy. The JS-only help center documents in-product chat deletion and a 'Delete my account' control under Security & Privacy, which could not be cited.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "you-com",
      "question": "data_export",
      "value": "partial",
      "quote": "In some circumstances, you may have the right to obtain certain information in a portable format.",
      "evidence_url": "https://you.com/privacy",
      "notes": "Portability is offered only as a rights request by email or the privacy-requests form, framed as depending on applicable law; no self-service account export is documented. The help center (JS-only) describes per-response export to DOCX/RTF/Markdown, not a full data export.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "you-com",
      "question": "deletion_timeline",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "The You.com Platform Data Security Overview, a PDF linked from the privacy pages, states that conversation and file data are deleted when the conversation or the account is deleted, but the pipeline cannot verify text inside PDFs. The Privacy Policy itself gives no deletion period and says that after account deletion You.com may retain certain information for legitimate business purposes, a broad exception.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "you-com",
      "question": "no_ads_use",
      "value": "no",
      "quote": "The ads that you see may also be selected based on other information learned about you over time using demographic data, location data, and chat queries.",
      "evidence_url": "https://you.com/privacy",
      "notes": "Users without a paid subscription, which is the default consumer experience, see ads that may be selected using chat queries and de-identified chat data; the policy states that Enterprise Customers and Paid Subscribers are not subject to these advertisements. Email, documents, photos and personal files are not used for ad targeting. Because conversation content is used to select ads on the default tier, the cell is no; the paid-tier exemption is recorded here rather than in the value.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "you-com",
      "question": "no_sale_sharing",
      "value": "partial",
      "quote": "The disclosure of this information may constitute a data “sale” under certain privacy laws.",
      "evidence_url": "https://you.com/privacy",
      "notes": "The policy says You.com does not currently 'sell' personal information under CCPA-type laws and does not exchange information for financial incentives, yet also discloses sharing with third-party advertising companies for interest-based advertising that 'may constitute a data sale'; opt-outs are via NAI/DAA and US state rights requests. Paid Subscribers and Enterprise Customers are excluded from advertiser data collection.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "you-com",
      "question": "human_review_limited",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "Neither the Privacy Policy, the Terms nor the MSA state whether You.com staff or contractors can read conversations or under what conditions.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "you-com",
      "question": "no_precise_location",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "The Privacy Policy says device location sharing can be prevented through the device's system settings (with a warning that features may be affected), lists 'Geolocation data' as a collected California category and mentions 'location data' among the signals used to select ads for users without a paid subscription, but nowhere says whether the location collected is precise or approximate; the word 'precise' does not appear. Under the revised rubric a device-permission gate only earns PARTIAL when precise collection is stated, and location mentioned without a precise/approximate qualifier is UNKNOWN.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "you-com",
      "question": "rights_channel",
      "value": "yes",
      "quote": "If you would like to exercise your data subject rights (such as accessing, correcting, or deleting your data), we’ve made the process simple and accessible.",
      "evidence_url": "https://you.com/privacy-requests",
      "notes": "A dedicated Privacy Requests page with a request form (plus Privacy@you.com and a Data Privacy Officer postal address in the policy) is offered to all users regardless of region, with identity verification required for anything beyond a marketing opt-out.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "kimi",
      "question": "no_training_default",
      "value": "no",
      "quote": "We process this information to provide and improve the Services, including training and optimizing our artificial intelligence (“AI”) models.",
      "evidence_url": "https://www.kimi.ai/user/agreement/userPrivacy?version=v2",
      "notes": "'User Content' (prompts, audio, images, videos, files and generated content) is processed for training and optimizing Kimi's AI models by default; the Terms (section 3) grant a licence to 'use Content to train, evaluate, and improve the Services' subject only to an email opt-out. Legal basis is legitimate interest or consent 'depending on your jurisdiction', so EU/UK users may see a consent prompt.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "kimi",
      "question": "training_opt_out",
      "value": "partial",
      "quote": "Opt-out applies prospectively only and does not require us to delete or remove Content already used in prior training cycles.",
      "evidence_url": "https://www.kimi.ai/user/agreement/modelUse?version=v2",
      "notes": "The Terms let a user opt out of training by emailing support@moonshot.ai ('by contacting us at'), honoured 'in accordance with applicable law'; there is no in-product setting and the opt-out only covers future data.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "kimi",
      "question": "uploads_excluded",
      "value": "partial",
      "quote": "This includes prompts, audio, images, videos, files, and any content you input or generate while using our products and services.",
      "evidence_url": "https://www.kimi.ai/user/agreement/userPrivacy?version=v2",
      "notes": "Uploaded files are expressly part of User Content used for model training by default; the only exclusion is the email-based, prospective training opt-out in the Terms, which covers 'Content' (Input including 'other content' plus Output) rather than naming files. API-uploaded files are not used for training (help center).",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "kimi",
      "question": "business_no_training",
      "value": "yes",
      "quote": "Your data is used solely to fulfill the current API request and is not persistently stored for training purposes.",
      "evidence_url": "https://www.kimi.ai/help/kimi-api/api-data-security",
      "notes": "Help center states API input and output are not used to train or improve Kimi's models, and Kimi Business lists 'No model training on your content by default' and 'Enterprise data is not used for model training'. The formal Kimi Business Service Agreement and Open Platform privacy policy were not fetched; the consumer policy says its provisions also apply to the Open Platform unless that product's policy says otherwise.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "kimi",
      "question": "temporary_chat",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "No temporary, incognito or history-off chat mode is mentioned in the Privacy Policy, Terms or help center articles reviewed.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "kimi",
      "question": "memory_controls",
      "value": "yes",
      "quote": "Note: Memory is entirely under your control. It is not used for model training and can be turned off or cleared at any time.",
      "evidence_url": "https://www.kimi.ai/help/features/memory-space",
      "notes": "Memory Space (Settings → Personalization → Memory Space on web and mobile) lets users view all entries, edit or delete individual entries, clear all, and turn memory off; up to 50 entries of 500 characters. The help center, not the Privacy Policy, is the source.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "kimi",
      "question": "user_deletion",
      "value": "yes",
      "quote": "In the Kimi app or on the web, find the conversation and tap delete.",
      "evidence_url": "https://www.kimi.ai/help/others/chat-issues",
      "notes": "Single conversations are deleted in-product; account deletion is in-product via Settings → Account Security → Delete Account (help center) and the Terms confirm 'the account deletion process available in your settings'. The help article describes account deletion as a submitted request that is 'approved' before data enters the deletion workflow.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "kimi",
      "question": "data_export",
      "value": "partial",
      "quote": "the right to obtain a copy of the personal information in a portable and, to the extent technically feasible, readily usable format that allows you to transmit the data to another entity without hindrance.",
      "evidence_url": "https://www.kimi.ai/user/agreement/userPrivacy?version=v2",
      "notes": "No self-service export is documented; access is by emailing membership@moonshot.ai and portability is listed among US state-specific rights 'where required by law'. The policy merely 'recommends exporting or saving' content before account deletion without naming an export feature.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "kimi",
      "question": "deletion_timeline",
      "value": "partial",
      "quote": "No. After deletion, the system retains data only to the minimum extent required by applicable laws for storage and security purposes.",
      "evidence_url": "https://www.kimi.ai/help/others/account-deletion",
      "notes": "The help center answers 'Will manually deleted conversations still be retained?' with 'No', retaining only what applicable law requires (network logs such as timestamps and account identifiers, per the chat-issues article), which reads as deletion taking effect when the chat is deleted with a legal exception. For account deletion no period is given: after the request is 'approved' the content 'enter[s] the deletion workflow', and the Privacy Policy only promises to delete or anonymize on account deletion subject to legal obligations and disputes (voiceprints alone have a 3-year limit), so the commitment covers chats but not the account, which is PARTIAL under the revised rubric.",
      "confidence": "low",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "kimi",
      "question": "no_ads_use",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "Kimi discloses targeted advertising with third-party ad networks using 'personal information we maintain' and hashed account identifiers, but the documents never state whether conversation content is included in or excluded from ad personalisation.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "kimi",
      "question": "no_sale_sharing",
      "value": "partial",
      "quote": "We may work with third-party ad networks and advertising partners to deliver advertising and personalized content on our services, on other websites and services, and across other devices.",
      "evidence_url": "https://www.kimi.ai/user/agreement/userPrivacy?version=v2",
      "notes": "The US disclosures state that disclosure to Ad Networks and Advertising Partners 'qualifies as the sale of personal information or the sharing' for targeted advertising under certain laws, with opt-outs via a 'Do Not Sell or Share' footer link, Global Privacy Control, DAA/NAI tools and US state rights requests; no sale/share for users known to be under 16.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "kimi",
      "question": "human_review_limited",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "The Terms licence Content for 'safety and quality review of the Services' and the API help says content review 'does not store or expose your original data', but no document says whether humans read consumer conversations or in which cases.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "kimi",
      "question": "no_precise_location",
      "value": "partial",
      "quote": "many mobile devices allow you to change your device permissions to prevent our products and services from accessing certain types of information from your device (such as your contact lists or precise geolocation data)",
      "evidence_url": "https://www.kimi.ai/user/agreement/userPrivacy?version=v2",
      "notes": "The collection section describes only general geographic location derived from the IP address, but the choices section states that device permissions can be used to prevent Kimi's products from accessing 'precise geolocation data', and the advertising section lists 'location-identifying technologies' among data-collection methods; the US disclosures list a 'Geolocation data' category. Because precise collection is mentioned and is gated only by a declinable device permission, the revised rubric's YES branch (no precise or GPS collection mentioned anywhere) is not met and PARTIAL applies; the documents partly contradict each other, so confidence is medium.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "kimi",
      "question": "rights_channel",
      "value": "yes",
      "quote": "If you have any questions, suggestions, or concerns about this Privacy Policy or our data practices, or if you wish to exercise your rights regarding your personal information, you can contact us through the following methods:",
      "evidence_url": "https://www.kimi.ai/user/agreement/userPrivacy?version=v2",
      "notes": "A documented email channel for data subject rights requests (Cloudflare-obfuscated; decodes to membership@moonshot.ai, a general membership mailbox rather than a privacy-specific alias) plus in-product feedback and in-product account deletion are available to all users; identity verification may be requested. Additional rights are region-specific (US states).",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "qwen-chat",
      "question": "no_training_default",
      "value": "no",
      "quote": "To train and improve the accuracy, performance, and quality of our services (including our AI models)",
      "evidence_url": "https://g.alicdn.com/qwenweb/qwen-ai-fe/0.0.79/js/p_privacypolicy-index.js",
      "notes": "The Privacy Policy's purpose table lists this purpose against the data type \"De-identified User Content\" on a legitimate-interests basis, and the Terms (section on User Content, clause (e)) have the user consent to Qwen using and storing User Content that is not personal data to develop and improve its machine-learning and AI technologies. No opt-in, default-off state or plan/region exception is stated.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "qwen-chat",
      "question": "training_opt_out",
      "value": "no",
      "quote": "You hereby expressly authorise and consent to us: (i) using and storing User Content that is not personal data to develop and improve our machine-learning and artificial-intelligence technologies;",
      "evidence_url": "https://g.alicdn.com/qwenweb/qwen-ai-fe/0.0.79/js/p_termsservice-index.js",
      "notes": "The Terms have every user consent to training use of User Content and the Privacy Policy lists training of AI models on de-identified User Content as a legitimate-interest purpose, while neither document describes a setting, request route or training-specific objection to stop it; under the revised rubric a documented training default with no described way to stop it is NO, not UNKNOWN. The only related mechanism is a jurisdiction-dependent right to 'restrict or object to how we process your Personal Data' via the DPO email, which is not tied to training and would not obviously reach de-identified content, so it does not qualify for the PARTIAL branch.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "qwen-chat",
      "question": "uploads_excluded",
      "value": "no",
      "quote": "(e) we may process any User Content to improve our services and/or develop new products and services (including without limitation for our internal business purposes and/or for other customers). You hereby expressly authorise and consent to us: (i) using and storing User Content that is not personal data to develop and improve our machine-learning and artificial-intelligence technologies;",
      "evidence_url": "https://g.alicdn.com/qwenweb/qwen-ai-fe/0.0.79/js/p_termsservice-index.js",
      "notes": "The Terms define Prompts as submitted \"text, documents, images, videos, audio, or other materials\" and User Content as Prompts plus Outputs, so uploaded files and images fall under the same training clause as chat text; no upload-specific exclusion or opt-out is documented anywhere in the policy or terms.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "qwen-chat",
      "question": "business_no_training",
      "value": "yes",
      "quote": "Alibaba Cloud protects data privacy and will never use your data for model training.",
      "evidence_url": "https://www.alibabacloud.com/help/en/model-studio/what-is-model-studio",
      "notes": "Statement is an FAQ answer in the Alibaba Cloud Model Studio documentation, the API/business platform for Qwen models; it is documentation rather than contract language, and Qwen Chat itself documents no team or enterprise tier.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "qwen-chat",
      "question": "temporary_chat",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "No temporary, incognito or history-off mode is mentioned in the Qwen Privacy Policy or Terms of Service.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "qwen-chat",
      "question": "memory_controls",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "The Privacy Policy confirms a Memory feature \"which may retain certain details from your conversations to enable more personalised and consistent responses in future chats\" and refers to \"applicable personalisation settings\", but does not document whether memory can be viewed, deleted item by item or turned off.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "qwen-chat",
      "question": "user_deletion",
      "value": "partial",
      "quote": "You can exercise some of these rights through your Services account.",
      "evidence_url": "https://g.alicdn.com/qwenweb/qwen-ai-fe/0.0.79/js/p_privacypolicy-index.js",
      "notes": "Erasure is listed as a right the user \"may have\" depending on jurisdiction, exercisable partly in the account and otherwise by emailing the DPO (DPO_qwenlm-intl@service.alibaba.com); the retention section presupposes account deletion, but per-conversation deletion is not documented.",
      "confidence": "low",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "qwen-chat",
      "question": "data_export",
      "value": "partial",
      "quote": "(a)access your Personal Data and information relating to how it is processed;",
      "evidence_url": "https://g.alicdn.com/qwenweb/qwen-ai-fe/0.0.79/js/p_privacypolicy-index.js",
      "notes": "Access and data portability are both listed among the rights a user 'may have' depending on jurisdiction (items (a) and (d) of section IX), exercisable partly through the account and otherwise by request to the DPO email (DPO_qwenlm-intl@service.alibaba.com); no self-service export tool for conversations is documented, so data is available only on request, which is PARTIAL. The mobile-app policy variant is identical on this point.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "qwen-chat",
      "question": "deletion_timeline",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "Retention is described only as lasting \"where we have an ongoing legitimate need\", with possible retention after account deletion for legal, complaint or litigation reasons; no deletion period is stated for chats or accounts.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "qwen-chat",
      "question": "no_ads_use",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "The policy covers opt-in marketing emails and cookies but says nothing about whether conversation content is used to target or personalise advertising.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "qwen-chat",
      "question": "no_sale_sharing",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "There is no statement that personal data is not sold; disclosure recipients are affiliates, processors, analytics providers, transaction counterparties, authorities and \"any other person, with your consent\", with nothing said about third-party marketing either way.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "qwen-chat",
      "question": "human_review_limited",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "The policy states that rated (thumbs up/down) conversations are stored as feedback and the Terms reserve a right to review or remove User Content, but neither document says whether staff or contractors read conversations or under what limits.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "qwen-chat",
      "question": "no_precise_location",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "Automatically collected data listed (non-exhaustively, \"such as\") are IP address, time zone, country and device details; precise geolocation is neither claimed nor excluded, and the mobile-app policy variant is identical on this point.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "qwen-chat",
      "question": "rights_channel",
      "value": "yes",
      "quote": "We will respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection laws.",
      "evidence_url": "https://g.alicdn.com/qwenweb/qwen-ai-fe/0.0.79/js/p_privacypolicy-index.js",
      "notes": "A dedicated DPO email (DPO_qwenlm-intl@service.alibaba.com, mailto qwenlm-intl@service.alibaba.com) and postal address are given for all users, alongside in-account controls for some rights; the rights themselves are described as depending on the user's jurisdiction.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "duck-ai",
      "question": "no_training_default",
      "value": "yes",
      "quote": "your conversations are not used to train chat models by DuckDuckGo or the underlying model providers (for example, Open AI and Anthropic).",
      "evidence_url": "https://duckduckgo.com/duckduckgo-help-pages/duckai/ai-chat-privacy",
      "notes": "Applies to free and paid tiers by default; the one exception is a conversation the user explicitly shares with DuckDuckGo via feedback, which DuckDuckGo stores and reviews to improve its products. Provider agreements (Anthropic, OpenAI, Mistral, Azure, Tinfoil) prohibit training on Duck.ai data.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "duck-ai",
      "question": "training_opt_out",
      "value": "yes",
      "quote": "Never use your Duck.ai conversations to train their models",
      "evidence_url": "https://duckduckgo.com/duckduckgo-help-pages/duckai/ai-chat-privacy",
      "notes": "No opt-out is needed because conversations are never used for training by DuckDuckGo or, under contract, by any model provider; the only way a chat reaches DuckDuckGo for product improvement is the user's explicit feedback share.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "duck-ai",
      "question": "uploads_excluded",
      "value": "yes",
      "quote": "Uploaded images and files are not retained unless they are flagged as CSAM, in which case they are retained and reported to the relevant authorities.",
      "evidence_url": "https://duckduckgo.com/duckduckgo-help-pages/duckai/ai-chat-privacy",
      "notes": "Image and PDF uploads are covered by the same no-training provider agreements and are not retained; they are anonymously scanned for CSAM by a third-party moderation provider (and in some cases the model provider) before processing. For Tinfoil-hosted models a Trusted Execution Environment technically prevents reading or training on uploads.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "duck-ai",
      "question": "business_no_training",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "DuckDuckGo offers no business, team, enterprise or API tier for Duck.ai; only free use and the consumer DuckDuckGo Subscription (Plus/Pro) are documented, so the question does not apply.",
      "confidence": "high",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "duck-ai",
      "question": "temporary_chat",
      "value": "yes",
      "quote": "We never store your prompts or any information that could reveal the contents of your conversations (except when you explicitly choose to share a conversation with us when providing feedback).",
      "evidence_url": "https://duckduckgo.com/duckduckgo-help-pages/duckai/ai-chat-privacy",
      "notes": "There is no per-chat incognito mode; the only history-off option is a global Duck.ai setting that stops saving recent chats locally ('You can disable chat history at any time in Duck.ai settings'), which on its own would be PARTIAL. YES applies through the revised rubric's second branch: DuckDuckGo states it never stores prompts or conversation content on its servers (Sync & Backup and shared links are end-to-end encrypted so DuckDuckGo cannot read them), chats are never used for training, and provider agreements require deletion at most within 30 days; the one disclosed caveat is that Anthropic may retain chats where required by law or to combat malicious use, and OpenAI/Anthropic prompt caches hold chats in memory for up to 1 hour.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "duck-ai",
      "question": "memory_controls",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "None of the Duck.ai documents mention a memory or personalisation feature that carries information across conversations, and none states that Duck.ai does not remember anything between chats; the only stored chat state described is local recent-chat history and optional end-to-end-encrypted Sync & Backup, which are history rather than memory. The revised rubric says silence never means there is no memory feature and the 'never stores conversation content' convention is not extended to this question, so the cell is UNKNOWN; the previous YES was inferred from the never-store statement rather than from any statement about memory.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "duck-ai",
      "question": "user_deletion",
      "value": "yes",
      "quote": "No matter which version you choose, you can delete a chat by clicking the delete icon next to it or delete all chats by using the Fire Button within Duck.ai or within your browser.",
      "evidence_url": "https://duckduckgo.com/duckai/privacy-terms",
      "notes": "Individual, multi-select and delete-all chat deletion are self-service; Duck.ai has no user account to delete (the paid subscription uses a random ID and an optional email), and cancelling a subscription removes remaining personal information within 30 days.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "duck-ai",
      "question": "data_export",
      "value": "partial",
      "quote": "You may ask us what information we may hold about you, categories of any third parties to whom we disclose the information (if any), and the business or commercial purpose for obtaining and sharing your information (if shared).",
      "evidence_url": "https://duckduckgo.com/duckduckgo-help-pages/r-legal/privacy-rights",
      "notes": "No in-product export of chats is documented; chats live on the user's device or in end-to-end-encrypted Sync & Backup that DuckDuckGo cannot read, so access requests to privacy@duckduckgo.com cover only the limited personal information DuckDuckGo holds (for example a subscription email).",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "duck-ai",
      "question": "deletion_timeline",
      "value": "yes",
      "quote": "In addition, we have agreements in place with all model providers that further limit how they can use data from these anonymous requests, including not using Prompts and Outputs to develop or improve their models, as well as deleting all information received once it is no longer necessary to provide Outputs (at most within 30 days, with limited exceptions for safety and legal compliance).",
      "evidence_url": "https://duckduckgo.com/duckai/privacy-terms",
      "notes": "DuckDuckGo itself stores no readable chats, so local deletion is immediate; shared-chat links are deleted after 30 days and subscription personal data within 30 days of cancellation. Gap: no explicit propagation period is stated for deleting an encrypted Sync & Backup chat from servers (they auto-delete after 18 months without access).",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "duck-ai",
      "question": "no_ads_use",
      "value": "yes",
      "quote": "We don’t save or share your search, chat, or browsing history when you search on DuckDuckGo, chat on Duck.ai, or use our apps and extensions.",
      "evidence_url": "https://duckduckgo.com/privacy",
      "notes": "Duck.ai shows no ads; DuckDuckGo's revenue comes from search ads that are contextual to the results page (\"not based on you as a person\"), and since chats are never saved or tied to identifiers they cannot feed ad personalisation. The policy does not contain a sentence naming ads and chats together.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "duck-ai",
      "question": "no_sale_sharing",
      "value": "yes",
      "quote": "We have never sold any personal information. Period.",
      "evidence_url": "https://duckduckgo.com/privacy",
      "notes": "General Privacy Policy statement applies worldwide; model providers additionally agree never to share Duck.ai data with third parties for their own commercial purposes (subprocessors excepted).",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "duck-ai",
      "question": "human_review_limited",
      "value": "yes",
      "quote": "You can choose to share a conversation with us when providing feedback, in which case we store and review it to improve our products.",
      "evidence_url": "https://duckduckgo.com/duckduckgo-help-pages/duckai/ai-chat-privacy",
      "notes": "Human review is limited to conversations the user explicitly shares via feedback; DuckDuckGo otherwise never stores prompts. Caveats: uploads are scanned for CSAM by a moderation provider, and Anthropic may retain chats where required by law or to combat malicious use.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "duck-ai",
      "question": "no_precise_location",
      "value": "yes",
      "quote": "Duck.ai can privately share your city-level location with AI model providers to tailor responses without exposing your exact location or IP address.",
      "evidence_url": "https://duckduckgo.com/duckduckgo-help-pages/what-information-does-duckai-share-with-model-providers",
      "notes": "Only a GEO::IP-derived region (and, if the user enables the off-by-default \"Use Approximate Location\" setting, a guessed city) is used; the IP address and guessed location are discarded and never saved.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "duck-ai",
      "question": "rights_channel",
      "value": "yes",
      "quote": "While not all DuckDuckGo users have the legal rights described on this page, it is DuckDuckGo’s policy to honor these rights for our users as described regardless of where you live.",
      "evidence_url": "https://duckduckgo.com/duckduckgo-help-pages/r-legal/privacy-rights",
      "notes": "Requests go to privacy@duckduckgo.com (Privacy Manager), a toll-free US number or a mailing address; EU and UK GDPR representatives are also listed. For content about a person appearing in outputs, users are directed to the model provider.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "brave-leo",
      "question": "no_training_default",
      "value": "yes",
      "quote": "We may cache large prompts to improve performance but these are deleted within minutes. We do not use your conversations for model training.",
      "evidence_url": "https://brave.com/privacy/browser/",
      "notes": "Applies to free and Premium Leo with no setting needed. The only route by which conversation text reaches Brave is the voluntary thumbs-up/down feedback, which sends the full conversation to Brave for 'improving Leo's responses' and is deleted after 1 year. The policy does not address retention or training by the third-party model providers Leo calls (e.g. Anthropic, Meta, Mixtral) or by endpoints you configure via Bring Your Own Model.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "brave-leo",
      "question": "training_opt_out",
      "value": "yes",
      "quote": "No. Your conversations are not persisted for model training.",
      "evidence_url": "https://brave.com/leo/",
      "notes": "No opt-out is needed because conversations are never used for training; Brave does not retain prompts, responses or context server-side. Feedback that shares a conversation with Brave is opt-in per response (thumbs icons).",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "brave-leo",
      "question": "uploads_excluded",
      "value": "yes",
      "quote": "We don’t store or retain prompts, responses, context, or personal data on our servers. We may cache large prompts to improve performance but these are deleted within minutes. We do not use your conversations for model training.",
      "evidence_url": "https://brave.com/privacy/browser/",
      "notes": "Uploads are covered by the blanket no-retention/no-training statement for everything sent to Leo, and the data-processing table lists 'Summarizing/suggesting questions for websites, documents, or other uploaded content' with 'Query, website/document contents' retained only 'Ephemeral - discarded soon after chat is completed'. Applies to free and Premium Leo alike; documented upload types are PDFs, documents and page content. Uploads are not named in a separate training sentence, and the policy is silent on retention by third-party model providers (e.g. Anthropic) that Leo may call, hence medium confidence.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "brave-leo",
      "question": "business_no_training",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "Brave documents no business, team, enterprise or API tier for Leo; Leo Premium is a consumer subscription under the same policy. Brave's separate Search API product is not an AI-assistant offering and is not covered here.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "brave-leo",
      "question": "temporary_chat",
      "value": "yes",
      "quote": "Temporary chats don’t log in your history. Instantly delete chats when they’re closed.",
      "evidence_url": "https://brave.com/leo/",
      "notes": "Temporary chats are a documented Leo feature; server-side, the privacy policy states prompts/responses/context are not retained (cached large prompts deleted within minutes) and are never used for training, so nothing persists beyond the closed session. Chat history is also unavailable in Private Windows and Private Windows with Tor.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "brave-leo",
      "question": "memory_controls",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "Leo offers a user-authored customization ('Set preferences for Leo to remember across chats'), but the fetchable Brave documents do not describe whether these preferences can be viewed, deleted or switched off, and no automatic memory extraction from conversations is documented. The relevant help-center article is behind bot protection (HTTP 403).",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "brave-leo",
      "question": "user_deletion",
      "value": "yes",
      "quote": "You can disable conversation storage or clear saved chats by going to brave://settings/leo-ai",
      "evidence_url": "https://brave.com/privacy/browser/",
      "notes": "Chat history exists only locally on the device and the privacy policy documents a self-service way to clear saved chats or disable storage at brave://settings/leo-ai; the product page adds that history can be accessed and deleted from the Leo conversation list, though the step-by-step help-center article returns HTTP 403. Free Leo needs no account, so the rubric's no-account branch applies; Leo Premium requires a subscription account that the Terms of Use say can be terminated 'by following the instructions on the Service' at account.brave.com. Per-conversation deletion is not spelled out sentence by sentence in the fetchable documents, hence medium confidence.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "brave-leo",
      "question": "data_export",
      "value": "partial",
      "quote": "In certain circumstances you have the right to request and receive personal data in a structured, commonly used, machine readable format that makes it possible to reuse the data.",
      "evidence_url": "https://brave.com/privacy/browser/",
      "notes": "No self-service export of Leo conversations is documented; chats exist only on the user's device and Brave holds no conversation data server-side. Portability of whatever personal data Brave does hold (e.g. Premium account data) is available on request to privacy@brave.com.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "brave-leo",
      "question": "deletion_timeline",
      "value": "yes",
      "quote": "Ephemeral - discarded soon after chat is completed. If local storage is enabled, chat history will be stored locally on your device.",
      "evidence_url": "https://brave.com/privacy/browser/",
      "notes": "Leo queries and context are discarded server-side as soon as the chat completes, and cached large prompts are deleted within minutes, so there is nothing to purge on deletion; local history is under the user's control. The one longer retention is voluntary feedback submissions (full conversation text), deleted after 1 year.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "brave-leo",
      "question": "no_ads_use",
      "value": "yes",
      "quote": "We do not collect identifiers that can be linked to you (such as IP address). We don’t store or retain prompts, responses, context, or personal data on our servers.",
      "evidence_url": "https://brave.com/privacy/browser/",
      "notes": "Brave states it never stores Leo prompts, responses or context on its servers, which the revised rubric treats as an explicit statement that conversation content cannot be used for advertising; the same branch already decides temporary_chat, deletion_timeline and human_review_limited for this app. Brave Ads are matched on the device from browsing signals and the policy says Brave 'does not have access to your information, your browsing history, or any details that can be used to identify or profile you'. The Brave Ads section never mentions Leo chat content, so whether locally stored chat history is excluded from on-device ad matching is not stated; applies to free and Premium Leo.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "brave-leo",
      "question": "no_sale_sharing",
      "value": "yes",
      "quote": "We do not buy, sell, or share personal data about consumers.",
      "evidence_url": "https://brave.com/privacy/browser/",
      "notes": "Stated globally in the Browser Privacy Policy (not limited to California) and repeated in the CCPA notice ('Brave does not buy, sell, or otherwise trade in personal information'). Leo additionally does not collect linkable identifiers such as IP address.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "brave-leo",
      "question": "human_review_limited",
      "value": "yes",
      "quote": "We don’t store or retain prompts, responses, context, or personal data on our servers.",
      "evidence_url": "https://brave.com/privacy/browser/",
      "notes": "Because conversations are not retained, there is no stored content for staff to review; the only disclosed path to Brave staff is the user-initiated feedback (thumbs-up/down), which sends the full conversation text and optional details to Brave to improve Leo and is deleted after 1 year. The policy does not literally use the words 'human review'.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "brave-leo",
      "question": "no_precise_location",
      "value": "yes",
      "quote": "The website may store your location. Your location is not sent to us in this process.",
      "evidence_url": "https://brave.com/privacy/browser/",
      "notes": "Browser geolocation is only shared with a website after the user grants permission and is never sent to Brave; the Leo section adds that Brave does not collect identifiers that can be linked to you such as IP address. No location collection is listed for Leo in the data-processing table.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "brave-leo",
      "question": "rights_channel",
      "value": "yes",
      "quote": "To contact our data protection officer and privacy team with privacy related enquiries, or to exercise your data protection and privacy rights, email privacy@brave.com",
      "evidence_url": "https://brave.com/privacy/browser/",
      "notes": "A dedicated privacy address (privacy@brave.com) is offered to all users regardless of region, with access, erasure, rectification, restriction, objection and portability rights listed; the CCPA notice repeats the same address for California residents. The address is a mailto link, so the rendered text has a space before the closing full stop and the quote therefore ends at the address.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "lumo",
      "question": "no_training_default",
      "value": "yes",
      "quote": "Lumo doesn’t use your chats to train the AI models. We run the models on servers we control and never send your data to any third parties.",
      "evidence_url": "https://proton.me/support/lumo-privacy",
      "notes": "Applies to Guest, Free and Plus by default. The only exception is the optional in-app feedback button, which sends an anonymized copy of the prompt and response to Lumo's team 'to help us improve the model' (and, for the Apertus model, may be shared with Swiss AI, ETH Zurich and EPFL) only when the user explicitly submits it.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "lumo",
      "question": "training_opt_out",
      "value": "yes",
      "quote": "Lumo never keeps your data or uses it to train LLMs.",
      "evidence_url": "https://proton.me/support/lumo-privacy",
      "notes": "No opt-out is needed because chats are never used for training; saved history is zero-access encrypted so Proton cannot read it. Sharing a prompt/response with Proton happens only if the user presses the feedback button.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "lumo",
      "question": "uploads_excluded",
      "value": "yes",
      "quote": "Information you enter is never used to train AI models.",
      "evidence_url": "https://proton.me/support/lumo-getting-started",
      "notes": "Lumo's no-training statements are blanket ('Information you enter is never used to train AI models', 'Lumo never keeps your data or uses it to train LLMs'), and the same getting-started article documents file uploads ('Upload sensitive legal files and have Lumo summarize them'); the Lumo Privacy Policy adds that inputs and outputs are zero-access encrypted after processing. Applies to Guest, Free and Plus by default; the only exception is the optional feedback button, which sends an anonymised prompt and response only when the user submits it. Uploads are not singled out in a separate training sentence, hence medium confidence.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "lumo",
      "question": "business_no_training",
      "value": "yes",
      "quote": "Lumo never trains AI models on your chats, eliminating any risk of data breaches or your business data surfacing in someone else's response.",
      "evidence_url": "https://proton.me/business/lumo",
      "notes": "Lumo for Business (team plan with admin tools) is covered by the same no-logs, zero-access-encryption and no-training commitments by default; no API offering is documented. The HTML encodes the apostrophe as &#x27;.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "lumo",
      "question": "temporary_chat",
      "value": "yes",
      "quote": "Once the session ends, nothing is saved, synced, or stored anywhere, so you can chat with total privacy and confidence.",
      "evidence_url": "https://proton.me/lumo/security",
      "notes": "'Ghost Mode' is a per-chat toggle; the chat is discarded when closed and, per the no-training and no-logs statements, is not used for training and no server record is kept (query data is erased after the response is generated). Guest sessions without an account are likewise erased at the end of each session.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "lumo",
      "question": "memory_controls",
      "value": "yes",
      "quote": "You have full control over what Lumo remembers at all times, and memories are zero-access encrypted.",
      "evidence_url": "https://proton.me/support/lumo-memory",
      "notes": "Memory is off until the user selects 'Turn on memory' in Settings > Memory; saved memories are listed there and can be edited, deleted individually ('Delete memory'), cleared ('Clear auto-generated' / 'Clear all'), auto-updating can be switched off, and Memory can be turned off entirely, on web and mobile.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "lumo",
      "question": "user_deletion",
      "value": "yes",
      "quote": "Through your account interface, you can directly access, edit, delete, or export personal data processed by the Company in your use of the Services.",
      "evidence_url": "https://proton.me/lumo/privacy-policy",
      "notes": "Deletion is self-service in the account interface; account deletion is documented at account.proton.me (Settings > Account and password > Delete account) and removes all Proton services' data. A dedicated walkthrough for deleting a single Lumo chat was not found in the fetched pages, though saved chats are user-held zero-access-encrypted data; guest users have no stored history.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "lumo",
      "question": "data_export",
      "value": "yes",
      "quote": "Through your account interface, you can directly access, edit, delete, or export personal data processed by the Company in your use of the Services.",
      "evidence_url": "https://proton.me/lumo/privacy-policy",
      "notes": "Export is stated as a self-service function of the account interface; the fetched documents do not describe a Lumo-specific chat export format or whether it covers encrypted chat history, so the scope of the export is not detailed.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "lumo",
      "question": "deletion_timeline",
      "value": "partial",
      "quote": "After Lumo processes your query and generates a response, the data is erased.",
      "evidence_url": "https://proton.me/support/lumo-privacy",
      "notes": "Immediate erasure is stated only for processing data, Guest sessions and Ghost Mode chats; saved Free/Plus chat history is synced to Proton servers with zero-access encryption, and no period is stated for purging a deleted chat or a deleted account (the product page only says you can delete your account at any time). The rubric's never-stored branch does not apply because history is stored server-side even though Proton cannot read it; the support article states no metadata such as timestamps or IP addresses is kept.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "lumo",
      "question": "no_ads_use",
      "value": "yes",
      "quote": "The questions you ask Lumo — about your work, your health, or your ideas — aren’t accessible to us. So they can never be used to target ads, shape what you see online, or build a personal profile that third parties could exploit.",
      "evidence_url": "https://proton.me/lumo",
      "notes": "Lumo shows no ads and conversation content is zero-access encrypted so Proton cannot read it; Proton's general policy also states it does no targeted advertising or profiling. Proton may email account holders about Proton products, which is adjustable in account settings.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "lumo",
      "question": "no_sale_sharing",
      "value": "yes",
      "quote": "Many AI assistants share and sell your data with third parties or with other subsidiaries within their business. Lumo never shares your data.",
      "evidence_url": "https://proton.me/support/lumo-privacy",
      "notes": "Disclosure is limited to binding requests from competent authorities. Caveats: with the optional Web search feature a simplified version of the request (not the full query) is sent to selected search partner APIs; payment and support processors act on Proton's behalf.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-11",
      "quote_missing_since": "2026-09-18"
    },
    {
      "app": "lumo",
      "question": "human_review_limited",
      "value": "yes",
      "quote": "The information you provide and the responses generated by the Services are secured using zero-access encryption after having been processed by Lumo, which is intended to prevent access by the Company, its staff, or third parties.",
      "evidence_url": "https://proton.me/lumo/terms",
      "notes": "Staff cannot read stored conversations; the only disclosed human access is an anonymized prompt/response the user explicitly submits via the feedback button. Prompts are decrypted transiently on Proton-controlled GPU servers to generate the response.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "lumo",
      "question": "no_precise_location",
      "value": "yes",
      "quote": "Our applications do not access or track any location-based information from your device.",
      "evidence_url": "https://proton.me/lumo/privacy-policy",
      "notes": "Stated in the Lumo Privacy Policy and repeated in Proton's general policy; the support article adds that Lumo stores no metadata such as IP addresses. IP addresses may be processed transiently for anti-abuse under the general policy.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "lumo",
      "question": "rights_channel",
      "value": "yes",
      "quote": "Through your account interface, you can directly access, edit, delete, or export personal data processed by the Company in your use of the Services.",
      "evidence_url": "https://proton.me/lumo/privacy-policy",
      "notes": "In-product controls are available to all account holders regardless of region; suspended accounts exercise rights via the support team, and users may complain to the competent supervisory authority. Proton lists legal@proton.me as a legal contact.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "huggingchat",
      "question": "no_training_default",
      "value": "partial",
      "quote": "Hugging Face does not store any user data for training purposes.",
      "evidence_url": "https://raw.githubusercontent.com/huggingface/chat-ui/main/PRIVACY.md",
      "notes": "Hugging Face itself states it does not store any user data for training and does not store request bodies or responses when routing (also at huggingface.co/docs/inference-providers/security). However every HuggingChat message is routed to third-party Inference Providers (Cerebras, Groq, Together AI, etc.) and the same document says 'External providers are responsible for their own security and data handling', so provider-side training use is not excluded by Hugging Face's statement; no opt-in/opt-out setting is documented.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "huggingchat",
      "question": "training_opt_out",
      "value": "partial",
      "quote": "External providers are responsible for their own security and data handling. Please consult each provider’s respective security and privacy policies via the Inference Providers documentation linked above.",
      "evidence_url": "https://raw.githubusercontent.com/huggingface/chat-ui/main/PRIVACY.md",
      "notes": "No self-service training setting is documented. Hugging Face states it does not store user data for training, so no opt-out is needed for Hugging Face's own use, but conversations are forwarded to third-party inference providers whose training practices are governed by their own policies and for which Hugging Face documents no opt-out or provider-selection control for HuggingChat users.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "huggingchat",
      "question": "uploads_excluded",
      "value": "partial",
      "quote": "Hugging Face does not store any user data for training purposes.",
      "evidence_url": "https://raw.githubusercontent.com/huggingface/chat-ui/main/PRIVACY.md",
      "notes": "Hugging Face's blanket statement covers all user data, uploads included, for its own training; but every HuggingChat request is routed to third-party Inference Providers and the same document says 'External providers are responsible for their own security and data handling', with no documented exclusion or opt-out for provider-side use. Image uploads exist on vision models but are not mentioned in any privacy text. Scored the same way as no_training_default for the same provider gap; no plan or regional differences are documented.",
      "confidence": "low",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "huggingchat",
      "question": "business_no_training",
      "value": "partial",
      "quote": "Hugging Face does not store any user data for training purposes. We do not store the request body or response when routing requests through Hugging Face. Logs are kept for debugging purposes for up to 30 days, but no user data or tokens are stored.",
      "evidence_url": "https://huggingface.co/docs/inference-providers/security",
      "notes": "Covers the Inference Providers API (the same router HuggingChat uses). Hugging Face does not store API data for training, but the doc defers to 'the Data Security Policies of each provider' for how external providers handle the data, so exclusion is not guaranteed end-to-end. Enterprise Hub and dedicated Inference Endpoints are not addressed in the fetched documents.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "huggingchat",
      "question": "temporary_chat",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "No temporary, incognito or history-off mode is mentioned in the HuggingChat privacy text, the chat-ui docs, or the Hugging Face privacy policy; conversation history is stored by default and can be deleted manually.",
      "confidence": "high",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "huggingchat",
      "question": "memory_controls",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "The fetched vendor documents do not mention any cross-conversation memory feature or memory controls for HuggingChat.",
      "confidence": "medium",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "huggingchat",
      "question": "user_deletion",
      "value": "yes",
      "quote": "Conversation history: Stored so you can access past chats; you can delete any conversation at any time from the UI.",
      "evidence_url": "https://raw.githubusercontent.com/huggingface/chat-ui/main/PRIVACY.md",
      "notes": "Individual conversations are deletable from the HuggingChat UI; the Hugging Face privacy policy states 'You may decide to cancel your account and your content at any time by editing your profile', i.e. account deletion is self-service in HF account settings.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "huggingchat",
      "question": "data_export",
      "value": "partial",
      "quote": "You may be entitled under data protection laws to access and review Personal Information the Company holds related to you.",
      "evidence_url": "https://huggingface.co/privacy",
      "notes": "No self-service export of HuggingChat conversations is documented; access is offered as a data-protection request by email to privacy@huggingface.co and is framed as depending on applicable law ('may be entitled').",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "huggingchat",
      "question": "deletion_timeline",
      "value": "partial",
      "quote": "your information and Content of your own Repositories, whether public or private, within 90 days.",
      "evidence_url": "https://huggingface.co/terms-of-service",
      "notes": "The ToS commits only to 'commercially reasonable efforts' to delete account information and content within 90 days of account cancellation (longer than 30 days), and reserves retention for legal/regulatory compliance and backup processes; no period is stated for deleting an individual HuggingChat conversation. Quote is a fragment because the raw HTML splits the sentence with inline <strong> tags.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "huggingchat",
      "question": "no_ads_use",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "The documents do not address conversation content and advertising. The Hugging Face privacy policy does say it 'may disclose Anonymous Information (with or without compensation) to third parties, including advertisers and partners, for purposes including, but not limited to, targeting advertisements', but this refers to aggregated non-identifying usage data, not chat content.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "huggingchat",
      "question": "no_sale_sharing",
      "value": "partial",
      "quote": "The Company will not sell, rent or lease your Personal Information except as provided for by this Policy.",
      "evidence_url": "https://huggingface.co/privacy",
      "notes": "No-sale statement carries an 'except as provided for by this Policy' carve-out; the policy permits sharing with affiliates and processors and disclosure of Anonymous (aggregated) Information to advertisers and partners 'with or without compensation'. It also states HF does not authorise third-party collection of PII through advertising technologies without separate consent.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "huggingchat",
      "question": "human_review_limited",
      "value": "partial",
      "quote": "The Company also reserves the right to access this information with your consent, or without your consent only for the purposes of pursuing legitimate interests such as maintaining security on its Services or complying with any legal or regulatory obligations.",
      "evidence_url": "https://huggingface.co/privacy",
      "notes": "Applies to any private information/content on the Services (conversations are not named specifically). Access is limited to consent or 'legitimate interests such as' security and legal compliance, but 'such as' leaves the list open-ended; the HuggingChat text is silent on human review.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "huggingchat",
      "question": "no_precise_location",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "The Hugging Face privacy policy lists 'your session (date, location), your IP address' among automatically collected data without defining whether location is precise or approximate; no device-location permission is described. HuggingChat-specific text does not mention location.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "huggingchat",
      "question": "rights_channel",
      "value": "yes",
      "quote": "If you wish to request the erasure of all of your Personal Information that we process, you may do so by sending a written request to privacy@huggingface.co",
      "evidence_url": "https://huggingface.co/privacy",
      "notes": "The Hugging Face privacy policy names privacy@huggingface.co for access and erasure requests from any user, and the HuggingChat privacy text repeats the same address for 'any of your legal privacy rights'. On the policy page the address is an HTML-entity-encoded mailto link (rendered normally), and in the chat-ui PRIVACY.md it is wrapped in angle brackets that tag-stripping removes, which is why the quote moved to the policy page. The policy also names the CNIL as lead EU authority; the channel is not restricted by region.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "replika",
      "question": "no_training_default",
      "value": "no",
      "quote": "This includes collecting and immediately anonymizing user feedback, and small portions of Messages and Content data to train our proprietary safety algorithms, enhance chatbot performance, prevent inappropriate outputs, and ensure compliance with safety standards.",
      "evidence_url": "https://replika.com/legal/privacy",
      "notes": "By default (legitimate-interest basis, no opt-in) Replika uses anonymized 'small portions' of message and content data to train its proprietary safety algorithms and enhance chatbot performance; the policy says this anonymized data is used only internally and 'is not used to train third-party large language models', and the third-party LLM providers that generate replies are contractually barred from training on user data. The companion also 'learns from your interactions' as core functionality.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "replika",
      "question": "training_opt_out",
      "value": "partial",
      "quote": "your right to object to the processing of your personal data for the processing activities based on our legitimate interest and to request that we restrict our use of your personal data",
      "evidence_url": "https://replika.com/legal/privacy",
      "notes": "Training on anonymised 'small portions' of messages for safety algorithms and chatbot performance rests on legitimate interest, and the only documented way to stop it is the Section 7.D right to object to legitimate-interest processing, exercised by request to my@replika.com or the postal address with identity verification; no in-app training toggle exists and deleting the account is not an opt-out. This is the rubric's 'legal right to object' partial branch; which rights apply is stated to depend on location. Optional in-chat feedback prompts can simply be dismissed.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "replika",
      "question": "uploads_excluded",
      "value": "partial",
      "quote": "This includes the messages you send and receive through the Apps, such as facts you may provide about you or your life, and any photos, videos, and voice and text messages you provide.",
      "evidence_url": "https://replika.com/legal/privacy",
      "notes": "Photos, videos and voice messages fall under the 'Messages and content' category, which is the same category whose anonymized 'small portions' are used by default to train safety algorithms and enhance chatbot performance; the only opt-out is the same request-based right to object that applies to conversations. Face/head-tracking data is stated to stay on-device and never be stored.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "replika",
      "question": "business_no_training",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "Replika is a consumer product; no business, team, enterprise or API offering is documented in the Privacy Policy, Terms or help center.",
      "confidence": "high",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "replika",
      "question": "temporary_chat",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "No temporary, incognito or history-off mode is mentioned in any fetched Replika document; the help center only notes that chat history is displayable for the past four months for technical reasons while the companion retains what it learned.",
      "confidence": "high",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "replika",
      "question": "memory_controls",
      "value": "partial",
      "quote": "You can also check your Replika’s memory to see what facts they’ve learned about you, your pets, or the people in your life.",
      "evidence_url": "https://help.replika.com/api/v2/help_center/en-us/articles/360000874712.json",
      "notes": "The Memory tab (tap Replika's name > Memory) lets users view memories and 'Tap a memory to read it fully or remove it' or add memories manually, but no documented way exists to switch memory off, and the memory article says visible memories sit on top of 'a deeper system that draws on patterns from your overall conversation history' that is not exposed to the user.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "replika",
      "question": "user_deletion",
      "value": "partial",
      "quote": "Right now, there’s no way to delete your entire message history without deleting your account.",
      "evidence_url": "https://help.replika.com/api/v2/help_center/en-us/articles/4410750548493.json",
      "notes": "Account deletion is self-service (Settings > Account > Delete Account on mobile; Settings > My Profile > Delete Replika on web; the Privacy Policy confirms 'You can delete your account in your account settings'), but conversations/message history cannot be deleted separately; only individual Memory entries can be removed.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "replika",
      "question": "data_export",
      "value": "partial",
      "quote": "Where applicable, we will provide the information in a portable, machine-readable, readily usable format.",
      "evidence_url": "https://replika.com/legal/privacy",
      "notes": "Access to a copy of personal data is available only on request to Luka (email my@replika.com) with identity verification and 'Depending on your location'; no in-app export of conversations is documented.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "replika",
      "question": "deletion_timeline",
      "value": "partial",
      "quote": "we process your profile information, messages and content, interests and preferences for up to 60 days after termination of the contract;",
      "evidence_url": "https://replika.com/legal/privacy",
      "notes": "Messages and content are retained up to 60 days after account termination (longer than 30 days), while account information, financial records and automatically collected data are kept 'for a minimum period of 10 years' for legal retention; the Terms separately claim data is 'removed permanently' as soon as the account is deleted, so the documents are not consistent.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "replika",
      "question": "no_ads_use",
      "value": "yes",
      "quote": "We may also use information about your visit to our Website to promote our Services, but we will never use or disclose the content of your Replika conversations for marketing or advertising purposes.",
      "evidence_url": "https://replika.com/legal/privacy",
      "notes": "Advertising partners receive only Website-visit data (clicks, pages, IP, advertising ID, browser) and 'will never have access to your conversations with your Replika AI Companion or any photos or other content you submit through the Apps'; the statement is repeated in Sections 2.B and 3.D.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "replika",
      "question": "no_sale_sharing",
      "value": "partial",
      "quote": "Our disclosure of information to these partners may be considered a \"sale\" or \"sharing\" of personal information or \"targeted advertising\" under applicable laws.",
      "evidence_url": "https://replika.com/legal/privacy",
      "notes": "Website-visitor data (not app or conversation data) is shared with third-party advertising partners for interest-based advertising 'to you and others', with an opt-out via the cookie settings at replika.com/legal/cookies; Do Not Track is not honoured. The help center article 'Do you sell my personal information?' states 'We do not sell your personal information or share it with third parties for profit', which conflicts with the policy's own characterisation.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "replika",
      "question": "human_review_limited",
      "value": "yes",
      "quote": "No humans join your conversations, and your messages are never read or responded to by people on Replika’s behalf.",
      "evidence_url": "https://help.replika.com/api/v2/help_center/en-us/articles/115001070971.json",
      "notes": "Explicit no-human-reading statement in the official help center; the Privacy Policy itself does not describe human access but lists 'Messages and content' as processed for fraud prevention, legal claims and authority requests, and the help article 'Can I delete my conversations?' adds 'you're the only one who can access and manage your conversation history'.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "replika",
      "question": "no_precise_location",
      "value": "yes",
      "quote": "This includes your computer's or mobile device's operating system, manufacturer and model, browser, IP address, device and cookie identifiers, language settings, mobile device carrier, and general location information such as city, state, or geographic area.",
      "evidence_url": "https://replika.com/legal/privacy",
      "notes": "Only general location (city/state/area) is listed; the help article on app permissions mentions camera and microphone permissions but no location permission, and the Cookie Policy repeats the 'general location information' wording.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "replika",
      "question": "rights_channel",
      "value": "yes",
      "quote": "To exercise your rights or make a request, please contact us as provided in Section 11.A below. We may ask for specific information from you to help us confirm your identity.",
      "evidence_url": "https://replika.com/legal/privacy",
      "notes": "Channels for all users: email my@replika.com (privacy@replika.com is also named for sensitive-data deletion), postal address in San Francisco, in-app account deletion, and a help-center support form (help.replika.com/hc/en-us/requests/new, 'Privacy & Safety' category) for full erasure with a one-month response commitment; EU/UK users additionally get EDPO representative forms and a DPO address. Which rights apply is stated to depend on location.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "apple-intelligence",
      "question": "no_training_default",
      "value": "no",
      "quote": "Apple may retain and use this data for up to two years to develop and improve Siri, Dictation, Search, and limited other language processing functionality in Apple products and services. For example, transcripts may be used to fine-tune Siri, Search, Voice Control, Translate, and automatic speech recognition models.",
      "evidence_url": "https://www.apple.com/legal/privacy/data/en/ask-siri-dictation/",
      "notes": "Scored on the least protective component (convention 3), which is Siri: Apple stores transcripts of Siri and Dictation requests, keyed to a rotating device identifier rather than the Apple Account, and uses them by default for up to two years to develop and improve Siri and to fine-tune Siri, Search, Voice Control, Translate and speech-recognition models; audio is stored only with the separate opt-in Improve Siri and Dictation. Apple Intelligence itself is more protective: requests sent to Private Cloud Compute are not stored or accessible to Apple, and aggregated content trends are collected only if the user opts in to Device Analytics. Because a default consumer user of this product is exposed to Siri, the Siri default decides the cell.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "apple-intelligence",
      "question": "training_opt_out",
      "value": "no",
      "quote": "Apple may retain and use this data for up to two years to develop and improve Siri, Dictation, Search, and limited other language processing functionality in Apple products and services. For example, transcripts may be used to fine-tune Siri, Search, Voice Control, Translate, and automatic speech recognition models.",
      "evidence_url": "https://www.apple.com/legal/privacy/data/en/ask-siri-dictation/",
      "notes": "Siri request transcripts are used by default to develop Siri and to fine-tune models, and no setting is documented that stops that use short of turning Siri and Dictation off entirely: the Improve Siri and Dictation toggle governs only whether audio is stored and reviewed, and Share Device Analytics governs aggregated Apple Intelligence improvement data. Scored on the least protective component (Siri); Apple Intelligence requests sent to Private Cloud Compute are not retained and need no opt-out.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "apple-intelligence",
      "question": "uploads_excluded",
      "value": "partial",
      "quote": "The data sent to and returned by Private Cloud Compute is not stored or made accessible to Apple. The data is processed only to fulfill your request, after which point the results are returned securely to your device and are not retained by Private Cloud Compute.",
      "evidence_url": "https://www.apple.com/legal/privacy/data/en/intelligence-engine/",
      "notes": "The documents never name uploads. For content handled by Apple Intelligence (emails, documents and photos processed by Writing Tools, summaries or visual intelligence) Apple states it is processed on device or sent to Private Cloud Compute where it is not stored or made accessible to Apple, which excludes that content from training by inference rather than by an explicit training statement. The Siri component, which the same product includes and which does store request transcripts and related request data for model improvement, says nothing about content attached to requests, and the opt-in ChatGPT extension (off by default) lets OpenAI train on attachments when a ChatGPT account is signed in. Exclusion is therefore stated only for one component of the product.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-11",
      "quote_missing_since": "2026-09-18"
    },
    {
      "app": "apple-intelligence",
      "question": "business_no_training",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "The fetched documents do not address a business, enterprise or API offering of Apple Intelligence or Siri; Apple does not offer a hosted Apple Intelligence API for third-party customer data, so the question is largely not applicable.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "apple-intelligence",
      "question": "temporary_chat",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "No temporary, incognito or history-off mode is documented for Siri or Apple Intelligence. Siri request transcripts are stored on Apple servers by default under a rotating device identifier for up to two years and can only be deleted in bulk (Siri & Dictation History) or by disabling Siri; Apple Intelligence requests sent to Private Cloud Compute are not retained. The documents neither describe such a mode nor state that none exists, and a retention disclosure alone is not that statement, so the cell is unknown.",
      "confidence": "medium",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "apple-intelligence",
      "question": "memory_controls",
      "value": "partial",
      "quote": "If you turn off both Siri and Dictation, the transcripts of your Siri and Dictation requests that are stored on your device and used to personalize your experience will be deleted.",
      "evidence_url": "https://www.apple.com/legal/privacy/data/en/ask-siri-dictation/",
      "notes": "Siri's cross-request personalization (on-device history, app learning) can be deleted all at once via Settings > Siri > Siri & Dictation History > Delete Siri & Dictation History and switched off per app (Learn from this App) or by disabling Siri, but the documents do not describe viewing or deleting individual stored items.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "apple-intelligence",
      "question": "user_deletion",
      "value": "partial",
      "quote": "You can delete the transcripts of your Siri and Dictation requests that are stored on your device by going to Settings > Siri > Siri & Dictation History and tapping Delete Siri & Dictation History.",
      "evidence_url": "https://www.apple.com/legal/privacy/data/en/ask-siri-dictation/",
      "notes": "Account deletion is self-service: the Apple Data and Privacy page (privacy.apple.com, described in support article 102283) lets users delete their Apple Account and the data associated with it permanently, in over 240 countries and regions. Conversation deletion is bulk only: the documents describe deleting the whole Siri & Dictation History stored on the device, not individual requests, and the Siri transcripts held on Apple servers are keyed to a rotating device identifier with no user deletion path described. Apple Intelligence requests are not retained by Private Cloud Compute, so nothing needs deleting there.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "apple-intelligence",
      "question": "data_export",
      "value": "partial",
      "quote": "You can request a copy of the data that Apple stores which is associated with your Apple Account.",
      "evidence_url": "https://support.apple.com/en-us/HT208502",
      "notes": "Self-service 'Request a copy of your data' exists at privacy.apple.com (availability varies by country), but Siri and Apple Intelligence request data is not linked to the Apple Account and so is not part of that export; the on-device Apple Intelligence Report (Settings > Privacy & Security) can be exported as a file listing requests sent to Private Cloud Compute or ChatGPT.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "apple-intelligence",
      "question": "deletion_timeline",
      "value": "partial",
      "quote": "The data is processed only to fulfill your request, after which point the results are returned securely to your device and are not retained by Private Cloud Compute.",
      "evidence_url": "https://www.apple.com/legal/privacy/data/en/intelligence-engine/",
      "notes": "Apple Intelligence cloud requests are never retained (immediate), but for Siri the documents state only a retention ceiling (transcripts up to two years; reviewed samples longer) and give no purge period after the user deletes Siri & Dictation History or the Apple Account; the Privacy Policy only commits to 'the shortest possible period permissible under law'.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-11",
      "quote_missing_since": "2026-09-18"
    },
    {
      "app": "apple-intelligence",
      "question": "no_ads_use",
      "value": "yes",
      "quote": "This contextual data, as well as your Siri transcripts and related request data, are not used to build a marketing profile, and are never sold to anyone.",
      "evidence_url": "https://www.apple.com/legal/privacy/data/en/ask-siri-dictation/",
      "notes": "Apple runs an advertising platform in the App Store, News and Stocks, but Siri transcripts and request data are excluded from marketing profiles and Apple Intelligence request content is not stored by Apple at all; Personalized Ads can additionally be disabled in Settings > Privacy & Security > Apple Advertising.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "apple-intelligence",
      "question": "no_sale_sharing",
      "value": "yes",
      "quote": "Apple does not sell your personal data including as “sale” is defined in Nevada and California.",
      "evidence_url": "https://www.apple.com/legal/privacy/en-ww/",
      "notes": "The worldwide Privacy Policy also states 'Apple does not share personal data with third parties for their own marketing purposes'; sharing is limited to affiliates, service providers acting on Apple's instructions, partners, and disclosures at the user's direction or for legal reasons.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "apple-intelligence",
      "question": "human_review_limited",
      "value": "partial",
      "quote": "Apple may also review a subset of the transcripts of your interactions with Siri, and this small subset of interactions that has been reviewed may be kept beyond two years for the ongoing improvement of these products and services.",
      "evidence_url": "https://www.apple.com/legal/privacy/data/en/ask-siri-dictation/",
      "notes": "Human review is disclosed but its purpose is model/quality improvement rather than safety-only: a subset of Siri transcripts may be reviewed by default, and audio is reviewed by Apple employees only for users who opt in to Improve Siri and Dictation. Apple Intelligence requests processed by Private Cloud Compute are not accessible to Apple.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "apple-intelligence",
      "question": "no_precise_location",
      "value": "partial",
      "quote": "If you have Location Services turned on for Siri, the location of your device at the time you make a request will be sent to Apple to help Siri and Dictation improve the accuracy of its response to your requests.",
      "evidence_url": "https://www.apple.com/legal/privacy/data/en/ask-siri-dictation/",
      "notes": "Location is sent only when the user grants Location Services for Siri (Settings > Privacy & Security > Location Services > Siri, can be set to Never); Apple stores only the approximate location with the request, and otherwise approximates location from the IP address.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "apple-intelligence",
      "question": "rights_channel",
      "value": "yes",
      "quote": "This set of self-service tools is available to customers in over 240 countries and regions around the world and includes options to:",
      "evidence_url": "https://support.apple.com/en-us/102283",
      "notes": "The Apple Data and Privacy page (privacy.apple.com) offers access/copy, correction, transfer, deactivation and deletion tools globally, and the Privacy Policy directs remaining requests to the privacy inquiry form at apple.com/legal/privacy/contact; California residents can also call 1-800-275-2273.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "alexa-plus",
      "question": "no_training_default",
      "value": "no",
      "quote": "To do that, we use your Alexa requests to train our speech recognition and natural language understanding systems using machine learning.",
      "evidence_url": "https://www.amazon.com/b/?node=23608617011",
      "notes": "The Alexa Privacy Hub states that Alexa requests are used by default to train speech recognition and natural language understanding systems, and that voice recordings, transcripts and typed requests help Alexa learn preferences; saving is on by default. The pages predate Alexa+ branding but cover the same Alexa requests; no Alexa+-specific exclusion is documented.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "alexa-plus",
      "question": "training_opt_out",
      "value": "partial",
      "quote": "If you would rather not have your voice recordings used to develop new features or manually reviewed to improve Alexa, it’s easy to opt-out through Alexa Privacy Settings in the Alexa app",
      "evidence_url": "https://www.amazon.com/b/?node=23608617011",
      "notes": "A self-service control exists (Alexa app: More > Alexa Privacy > Manage Your Alexa Data), but it is scoped to voice recordings being used to develop new features or manually reviewed; typed Alexa+ chats and attachments are not addressed, and the training statement itself covers all Alexa requests, so the cell is partial.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "alexa-plus",
      "question": "uploads_excluded",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "Alexa+ accepts uploaded or emailed documents, photos and notes, and Amazon says shared attachments can be reviewed in the Alexa Privacy dashboard, but no fetchable Amazon document says whether attachments are excluded from or covered by the training opt-out.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "alexa-plus",
      "question": "business_no_training",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "Amazon offers Alexa Smart Properties / Alexa for Business, but their data-use terms live on help/developer pages that were not fetchable, and the consumer documents retrieved do not address them.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "alexa-plus",
      "question": "temporary_chat",
      "value": "partial",
      "quote": "If you update your settings to “Don’t save recordings” (Settings > Alexa Privacy > Manage Your Alexa Data > Choose how long to save recordings), all previously saved voice recordings will be deleted, and future voice recordings will not be saved.",
      "evidence_url": "https://www.amazon.com/b/?node=23608614011",
      "notes": "There is no per-chat incognito mode; the closest control is the account-level Don’t save recordings option among four retention choices (save until deleted, 18 months, 3 months, don’t save). Even then transcripts and typed requests are kept until the chat has been inactive for 30 days so the history can be reviewed, and the page does not say whether requests under this setting are excluded from training, which makes an account-level setting partial under the rubric.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "alexa-plus",
      "question": "memory_controls",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "Alexa+ explicitly remembers facts users tell it and context across conversations, and Amazon says interactions can be reviewed and managed in the Alexa Privacy dashboard, but no fetchable document describes viewing, deleting individual memories, or turning the memory feature off.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "alexa-plus",
      "question": "user_deletion",
      "value": "partial",
      "quote": "All of your voice recordings and transcripts are saved by default, but you can change how long they are saved or choose to delete them at any time.",
      "evidence_url": "https://www.amazon.com/b/?node=23608614011",
      "notes": "Individual recordings and transcripts can be deleted self-service online, in the Alexa app or on Echo Show devices (by day, device or profile), and a retention period can be set. Deleting the Amazon account itself is not described on the Alexa privacy pages and is a separate account-wide process, so only the conversation half is documented here.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "alexa-plus",
      "question": "data_export",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "The fetchable pages document e-mailing your smart-home device history and asking Alexa+ to send a conversation recap to the app or email, but Amazon's general 'Request Your Data' portal (amazon.com/hz/privacy-central/data-requests) redirects to sign-in and the Privacy Notice is blocked, so a self-service export of conversations/account data could not be verified.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "alexa-plus",
      "question": "deletion_timeline",
      "value": "partial",
      "quote": "So you can review your chat history, we will save the transcipts and any typed requests until the associated chat has been inactive for 30 days, after which those transcripts will automatically be deleted.",
      "evidence_url": "https://www.amazon.com/b/?node=23608614011",
      "notes": "A 30-day automatic deletion is stated for transcripts and typed requests of inactive chats, and manually deleted recordings and transcripts are said to be deleted from Amazon’s cloud, but no period is given for completing a manual deletion or an account deletion, and the Don’t save recordings setting can take up to 36 hours to apply. A period stated for one mechanism only is partial. The quote reproduces the page’s own spelling of transcripts.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "alexa-plus",
      "question": "no_ads_use",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "The Alexa Privacy Hub only points to 'Advertising Controls' for interest-based ads; Amazon's Interest-Based Ads notice and Privacy Notice (help nodes 201909150 / 468496), which would state whether Alexa interactions feed ad personalisation, return 403 to the crawler.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "alexa-plus",
      "question": "no_sale_sharing",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "The sale/marketing-sharing statement is in the Amazon Privacy Notice, which is not fetchable; the fetchable settings guide only states that by default Amazon does not share personal information with third-party skill developers unless the user grants permission.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "alexa-plus",
      "question": "human_review_limited",
      "value": "partial",
      "quote": "Training Alexa relies in part on supervised machine learning, also referred to as “manual” or “human” review. This is an industry-standard practice conducted by trained specialists to help Alexa understand the correct interpretation of a request and provide the appropriate response in the future.",
      "evidence_url": "https://www.amazon.com/b/?node=23608617011",
      "notes": "Human review of requests is disclosed as part of training and quality improvement, not limited to safety or support cases, with a self-service opt-out for voice recordings; that is the rubric’s partial branch (review for broader purposes with a documented limit).",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "alexa-plus",
      "question": "no_precise_location",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "Location handling is only touched on indirectly (e.g. a postcode shared with a weather skill, device address); the Privacy Notice and Alexa privacy FAQ that describe location collection were not fetchable.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "alexa-plus",
      "question": "rights_channel",
      "value": "partial",
      "quote": "For example, you can review and manage your Alexa+ interactions and available settings in the Alexa Privacy dashboard.",
      "evidence_url": "https://www.aboutamazon.com/news/devices/alexa-plus-international-launch",
      "notes": "An in-product Alexa Privacy dashboard (Alexa app > More > Alexa Privacy, or amazon.com/alexaprivacysettings) is documented for reviewing and deleting Alexa/Alexa+ interactions and attachments, but a general channel for access, portability or full-account deletion requests is only described in the unfetchable Privacy Notice/Request Your Data pages.",
      "confidence": "low",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "snapchat-my-ai",
      "question": "no_training_default",
      "value": "no",
      "quote": "For example, our algorithms and machine learning models take into account the conversations Snapchatters are having with My AI to improve the responses from My AI.",
      "evidence_url": "https://values.snap.com/privacy/privacy-policy",
      "notes": "My AI conversations are retained and used by default to improve Snap's products, models and My AI responses (Privacy Policy 'Develop & Improve Features, Algorithms & Machine Learning Models'; help article: messages 'may be used to improve Snap's products'). Underlying models are OpenAI GPT and Google Gemini; Snap's docs do not say whether those providers train on the content.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "snapchat-my-ai",
      "question": "training_opt_out",
      "value": "no",
      "quote": "For example, our algorithms and machine learning models take into account the conversations Snapchatters are having with My AI to improve the responses from My AI.",
      "evidence_url": "https://values.snap.com/privacy/privacy-policy",
      "notes": "My AI conversations are used by default to improve Snap's models and My AI responses, and no listed document describes a setting or channel that stops that use: the Delete My AI Data control only deletes stored data, which is not an opt-out, and the region-dependent right to object to processing is not tied to training in the Privacy Policy. Under the rubric, training on by default with no documented way to stop it is no. EEA and UK users can use a support-form objection route.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "snapchat-my-ai",
      "question": "uploads_excluded",
      "value": "no",
      "quote": "When you interact with My AI, we use the content you share and your location (if you have enabled location sharing with Snapchat) to improve Snap’s products, including enhancing My AI’s safety and security, and to personalize your experience, including ads.",
      "evidence_url": "https://values.snap.com/privacy/privacy-by-product",
      "notes": "Snaps (images/video) sent to My AI are treated the same as text: 'we retain the content you send to and receive from My AI (like Snaps and Chats)' and the Privacy Policy defines AI 'Inputs' as text, images, video, audio and precise location, all usable for improvement. No upload-specific opt-out exists.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "snapchat-my-ai",
      "question": "business_no_training",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "My AI is a consumer feature inside Snapchat; Snap publishes no business, team, enterprise or API offering of My AI, and the fetched documents do not address training on business-customer data for any AI assistant product.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "snapchat-my-ai",
      "question": "temporary_chat",
      "value": "no",
      "quote": "Unlike Snaps and Chats shared with friends, all content shared with My AI — in one-on-one conversations and when you @ mention My AI — is stored until you delete it.",
      "evidence_url": "https://help.snapchat.com/hc/en-us/articles/7012334940948",
      "notes": "No temporary, incognito or history-off mode is documented for My AI; the docs affirmatively state that all My AI content is retained until the user deletes it and may be used for improvement and ads. The only 'off' switch is a parent disabling My AI for a teen via Family Center.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "snapchat-my-ai",
      "question": "memory_controls",
      "value": "yes",
      "quote": "Snapchat stores your conversations with My AI, but My AI won’t remember your prior conversations with it over time. You can delete your My AI data at any time from Settings.",
      "evidence_url": "https://help.snapchat.com/hc/en-us/articles/18937378754324",
      "notes": "Snap states My AI has no cross-conversation memory, and stored history can be wiped via Settings > Privacy Controls > Delete My AI Data (iOS) / Account Actions (Android). Caveat: Snap separately uses My AI conversations to infer interests for personalization and ads at the account level (e.g. Lifestyle Categories), which is not a chatbot memory but is also not fully inspectable.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "snapchat-my-ai",
      "question": "user_deletion",
      "value": "yes",
      "quote": "This will deactivate an account for 30 days, during which time the account can still be reactivated . After 30 more days, the account will be permanently deleted.",
      "evidence_url": "https://help.snapchat.com/hc/en-us/articles/7012328360596",
      "notes": "Account deletion is self-service in-app (Settings > Account Actions > Delete Account) or via accounts.snapchat.com; the entire My AI conversation can be deleted anytime with 'Delete My AI Data', while individual My AI messages can only be long-pressed and deleted within 24 hours of sending.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "snapchat-my-ai",
      "question": "data_export",
      "value": "yes",
      "quote": "Download your data. You can make a request in our Download My Data tool to export a copy of your Snapchat information.",
      "evidence_url": "https://values.snap.com/privacy/privacy-policy",
      "notes": "Self-service 'Download My Data' at accounts.snapchat.com (also reachable from Settings > My Data) produces a zip; the help article lists categories such as Saved Chat History, Location and Search History but does not explicitly name My AI conversations, so their inclusion is not confirmed in the documents.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "snapchat-my-ai",
      "question": "deletion_timeline",
      "value": "partial",
      "quote": "It can take up to 30 days to delete the relevant My AI data from Snapchat servers.",
      "evidence_url": "https://help.snapchat.com/hc/en-us/articles/18937378754324",
      "notes": "My AI data deletion is committed within 30 days, but account deletion takes 30 days of deactivation plus 30 more days (60 total; 210 in India), the Privacy Policy says Snap 'cannot promise that deletion will take place by a specific time', and deleted-account data is kept for 'legal, security, and business needs', a broader exception than legal/safety holds.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "snapchat-my-ai",
      "question": "no_ads_use",
      "value": "no",
      "quote": "Our advertising partners receive your queries (if we determine there’s commercial intent) and additional context, including your age range (i.e., whether you are under 18 or not), country/language, operating system type (i.e., iOS/Android), and IP address to help provide appropriate and relevant ads for you.",
      "evidence_url": "https://values.snap.com/privacy/ads-privacy",
      "notes": "My AI conversations are used both to personalize ads across Snapchat ('personalize your experience, including ads') and to serve contextual 'sponsored' ads inside My AI, for which queries with commercial intent are sent to Snap's advertising partners. Ad-preference opt-outs (activity-based, audience-based) do not exclude My AI content; EU/UK/Norway/Switzerland users can additionally opt out of personalized content and ads.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "snapchat-my-ai",
      "question": "no_sale_sharing",
      "value": "no",
      "quote": "To provide My AI, we may share your information with our service providers and advertising partners.",
      "evidence_url": "https://values.snap.com/privacy/privacy-by-product",
      "notes": "The rubric's NO branch applies because conversation content is disclosed to advertising partners: Snap's Ads Privacy page says ads inside My AI are provided by Snap's advertising partners rather than by Snap, and that those partners receive the user's queries when commercial intent is detected, together with age range, country/language, operating system type and IP address. The U.S. State Privacy Notice states that Snap does not sell data or share it for cross-context behavioural advertising and frames ad-serving disclosures as going to service providers acting on Snap's behalf, but that notice applies only to residents of certain U.S. states and the global Privacy Policy contains no no-sale statement.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "snapchat-my-ai",
      "question": "human_review_limited",
      "value": "partial",
      "quote": "This includes improving the underlying machine learning models and algorithms that make our generative AI features work and may include both automated and manual (i.e., human) review or labeling of the content and any feedback you submit.",
      "evidence_url": "https://values.snap.com/privacy/privacy-by-product",
      "notes": "Human review of content submitted to generative AI features (including My AI) is disclosed for the broad purpose of improving quality and safety of models, not limited to safety, abuse or user-initiated cases; the narrower 'only review when flagged' commitment applies to private Chats with friends, which Snap explicitly says work differently from My AI.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "snapchat-my-ai",
      "question": "no_precise_location",
      "value": "partial",
      "quote": "Sharing of your precise location with Snapchat, such as GPS data, is disabled by default.",
      "evidence_url": "https://values.snap.com/privacy/privacy-by-product",
      "notes": "Precise (GPS) location is collected only if the user grants the device-level permission; once granted to Snapchat it is also available to My AI (even in Ghost Mode) for place recommendations and is listed as an AI 'Input'. The U.S. notice adds that geolocation may be used for personalized ads. Users can revoke the OS permission and clear cached location via 'Clear My AI Data'.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "snapchat-my-ai",
      "question": "rights_channel",
      "value": "yes",
      "quote": "You can access, update, and delete your information, decide who can contact you, and download your data from within the Snapchat app.",
      "evidence_url": "https://values.snap.com/privacy/privacy-policy",
      "notes": "In-product controls (Download My Data, Delete My AI Data, Delete Account) are available to all users regardless of region, plus a support request form linked from the Privacy Policy and the privacy@snap.com address given in the U.S. State Privacy Notice; a Data Protection Officer contact is also referenced.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "kagi-assistant",
      "question": "no_training_default",
      "value": "yes",
      "quote": "When you use the Assistant by Kagi, your data is never used to train AI models (not by us or by the LLM providers), and no account information is shared with the LLM providers.",
      "evidence_url": "https://help.kagi.com/kagi/ai/assistant.html",
      "notes": "Applies to all plans by default with no setting required; Kagi proxies requests to third-party model APIs and its LLMs & Privacy table lists 'Trains on User Data via API: No' for every provider. The Privacy Policy phrases the provider choice as 'whenever possible', a softer wording than the Assistant docs.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "kagi-assistant",
      "question": "training_opt_out",
      "value": "yes",
      "quote": "When you use the Assistant by Kagi, your data is never used to train AI models (not by us or by the LLM providers), and no account information is shared with the LLM providers.",
      "evidence_url": "https://help.kagi.com/kagi/ai/assistant.html",
      "notes": "No opt-out is needed because conversations are never used for training by Kagi or the providers; there is therefore no training toggle in the Assistant settings.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "kagi-assistant",
      "question": "uploads_excluded",
      "value": "yes",
      "quote": "When you use the Assistant by Kagi, your data is never used to train AI models (not by us or by the LLM providers), and no account information is shared with the LLM providers.",
      "evidence_url": "https://help.kagi.com/kagi/ai/assistant.html",
      "notes": "The Assistant page documents file uploads (documents, spreadsheets, images and audio up to 30 MB, retained in the thread context for follow-up messages) and, on the same page, states that the user's data is never used to train AI models by Kagi or by the LLM providers. Uploads are not named in that sentence, so coverage comes from the blanket 'your data' statement, which the rubric accepts for all plans by default. Kagi's LLMs & Privacy table lists 'Trains on User Data via API: No' for every provider, while the Privacy Policy's 'whenever possible' wording about provider choice is softer.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "kagi-assistant",
      "question": "business_no_training",
      "value": "partial",
      "quote": "When using third party AI model providers, we are using privacy-respecting services that do not save the data or use it for training, whenever possible.",
      "evidence_url": "https://kagi.com/privacy",
      "notes": "Kagi Team plans include the Assistant and inherit its unqualified no-training statement, but the Team plan docs carry no separate training clause, and for Kagi's API products (FastGPT, Summarizer, Enrichment) the only statement is the Privacy Policy's hedged 'whenever possible' wording covering all AI tools.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "kagi-assistant",
      "question": "temporary_chat",
      "value": "partial",
      "quote": "By default, threads are deleted after 24 hours of inactivity. This behavior can be adjusted in the settings .",
      "evidence_url": "https://help.kagi.com/kagi/ai/assistant.html",
      "notes": "The default 'temporary' Thread Saving mode expires threads 24 hours after the last message (permanent removal per the Privacy Policy) with immediate delete available and no training use, but threads remain visible in history during those 24 hours and Kagi's own LLMs & Privacy table discloses provider-side API retention of up to 30 days, with Anthropic keeping flagged prompts for 2 years.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "kagi-assistant",
      "question": "memory_controls",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "No memory feature is documented for Kagi Assistant: the only persistent cross-thread context is the user-written Custom Instructions field (not memory under this rubric), threads are the unit of storage and are deleted after 24 hours by default, and Kagi states that it does not build user profiles and that AI requests are not associated with the account. However, Kagi nowhere states that the Assistant does not remember anything across conversations, and the rubric treats silence about memory as unknown rather than as evidence that no memory exists; the previous quote concerned search queries and profiling in the rights addendum, not Assistant memory.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "kagi-assistant",
      "question": "user_deletion",
      "value": "yes",
      "quote": "Threads can be renamed, pinned, made permanent, shared, added to folders, exported, and deleted via the ⋮ button, which is displayed when you hover over the thread.",
      "evidence_url": "https://help.kagi.com/kagi/ai/assistant.html",
      "notes": "Individual threads are deleted via the thread menu or Ctrl/Cmd+Shift+Backspace; the account is deleted self-service in Account settings (Delete Account button, password confirmation), which also cancels any paid plan without refund.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "kagi-assistant",
      "question": "data_export",
      "value": "yes",
      "quote": "Export conversations as markdown or JSON",
      "evidence_url": "https://help.kagi.com/kagi/ai/assistant.html",
      "notes": "Conversation export is self-service per thread (Markdown or JSON via the thread menu); a full account-data portability copy (JSON/CSV of account details, subscription and preferences) is obtained by emailing privacy@kagi.com rather than in-product.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "kagi-assistant",
      "question": "deletion_timeline",
      "value": "yes",
      "quote": "By default and unless otherwise stated, Kagi Assistant automatically deletes conversation threads after one day. After this period, they are permanently removed. Users can also choose to delete a thread immediately via the Assistant UI.",
      "evidence_url": "https://kagi.com/privacy",
      "notes": "Threads are permanently removed after one day by default or immediately on manual deletion; account data is 'permanently removed within 30 days' except legally required records (tax/billing) and fraud/dispute needs. Residual server-side data: sampled load-balancer/VM logs 7 days and Sentry error samples 90 days, stated as not linked to an account; third-party model providers retain API data up to 30 days per Kagi's table.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "kagi-assistant",
      "question": "no_ads_use",
      "value": "yes",
      "quote": "Our business model eliminates any need to monetise your data, so we're ad-free, tracker-free, and collect only what's necessary for your account to function, with complete transparency about what we collect and why.",
      "evidence_url": "https://help.kagi.com/kagi/settings/privacy.html",
      "notes": "Kagi is a paid, ad-free subscription with no advertising product; the Privacy Rights Addendum adds 'We don't share your information for behavioral advertising', so conversation content cannot be used for ad targeting.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "kagi-assistant",
      "question": "no_sale_sharing",
      "value": "yes",
      "quote": "No. We don't sell your personal information. We don't share your information for behavioral advertising.",
      "evidence_url": "https://kagi.com/privacy/rights",
      "notes": "Stated for all users (the Addendum extends rights 'to all users, everywhere'); a California Shine-the-Light paragraph additionally states Kagi does not share personal information with third parties for their direct marketing. Third parties involved are processors only (payment processors, map providers, model API providers).",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "kagi-assistant",
      "question": "human_review_limited",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "Neither the Privacy Policy, the Rights Addendum nor the Assistant docs say whether Kagi staff or contractors can read Assistant conversations; the policy only states that debugging logs are not linked to an account and that billing-data access is restricted to authorized personnel.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "kagi-assistant",
      "question": "no_precise_location",
      "value": "partial",
      "quote": "If you have enabled precise location, it's stored solely on your device and serves to provide more accurate localized search results.",
      "evidence_url": "https://help.kagi.com/kagi/settings/privacy.html",
      "notes": "Precise location is an optional, user-enabled feature (Geolocation in Kagi Maps or 'Use Location for Searches'), stored client-side in the kagi_precise_location cookie and clearable from Privacy Settings; when enabled it is sent with searches and Assistant web searches. IP-based approximate location is not separately addressed.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "kagi-assistant",
      "question": "rights_channel",
      "value": "yes",
      "quote": "Whether you're in the EU (GDPR), UK, California (CCPA/CPRA), or one of the growing number of US states with privacy laws, you have rights over your data. We extend these rights to all users, everywhere, even where not legally required.",
      "evidence_url": "https://kagi.com/privacy/rights",
      "notes": "Dedicated address privacy@kagi.com for access, portability, restriction and objection requests (acknowledged in 48-72 hours, fulfilled within 30 days, up to 45 for complex cases), plus in-product controls at kagi.com/settings for correction and account deletion; authorized agents accepted and no fees charged.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "venice",
      "question": "no_training_default",
      "value": "yes",
      "quote": "Venice.ai agrees that it shall not use, and shall require that third-party large language model providers (“Third-Party LLM Providers”) do not use, any User Content to train any machine learning, deep learning, or statistical learning algorithms, LLMs, neural networks, or models.",
      "evidence_url": "https://venice.ai/legal/tos",
      "notes": "Terms of Service 10.2 applies to all users and all User Content (Inputs and Outputs) with no opt-in required; the Privacy Policy additionally states Venice does not have access to or store prompt/output content. In 'Anonymous' mode prompts are relayed to third-party frontier providers, which Venice contractually binds to the same no-training rule but whose own retention the product page says you should assume.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "venice",
      "question": "training_opt_out",
      "value": "yes",
      "quote": "We may record your actions (e.g., that you created a chat), but we will not have access to or store the content of your Prompts or Outputs.",
      "evidence_url": "https://venice.ai/legal/privacy-policy",
      "notes": "No opt-out is needed: conversations are never stored by Venice and Terms 10.2 prohibits training on User Content by Venice and its model providers. Only generated videos are temporarily held until download.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "venice",
      "question": "uploads_excluded",
      "value": "yes",
      "quote": "Venice.ai agrees that it shall not use, and shall require that third-party large language model providers (“Third-Party LLM Providers”) do not use, any User Content to train any machine learning, deep learning, or statistical learning algorithms, LLMs, neural networks, or models.",
      "evidence_url": "https://venice.ai/legal/tos",
      "notes": "Terms 10.2 is a blanket bar on training with 'any User Content', and Terms 10.1 defines User Content to include submitted messages, photos, video, audio, images, folders, data and text, so uploads are covered by default without any user action; the Privacy Policy adds that Venice does not have access to or store submitted documents, images or audio ('Prompts'). Likeness (face) uploads are processed by BytePlus solely for the requested generation, are not used for Venice's own business purposes, and are purged from temporary storage within 1 hour. Applies to all plans; in 'Anonymous' mode third-party providers see the content but are contractually bound by the same no-training clause.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "venice",
      "question": "business_no_training",
      "value": "yes",
      "quote": "Venice.ai agrees that it shall not use, and shall require that third-party large language model providers (“Third-Party LLM Providers”) do not use, any User Content to train any machine learning, deep learning, or statistical learning algorithms, LLMs, neural networks, or models.",
      "evidence_url": "https://venice.ai/legal/tos",
      "notes": "Venice documents no separate business or team tier; its business offering is the API, which the Terms define as part of the 'Service', so the Terms 10.2 no-training clause (binding Venice and its third-party LLM providers) applies to API customer data by default with no contract term or setting required. The API privacy docs add that Venice does not store or log prompt and response content for normal inference and keeps only operational metadata (model, token counts, timestamps, IP) for billing and abuse prevention.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "venice",
      "question": "temporary_chat",
      "value": "partial",
      "quote": "Venice proxies your request to leading frontier model providers. Your identity is obscured from the provider, but you should assume the provider is storing your content.",
      "evidence_url": "https://venice.ai/privacy",
      "notes": "No temporary or incognito mode is documented, but the Privacy Policy states Venice will not have access to or store prompt or output content and the privacy page says history stays on the device, which would satisfy the 'never stored on its servers' branch. Rated partial rather than yes because Venice itself discloses that in the default 'Anonymous' mode (frontier models such as GPT, Claude and Gemini, available on all plans) the third-party provider likely saves the prompt with no retention limit stated, which also contradicts the Privacy Policy's zero-data-retention statement about model providers; the stricter Private, TEE and E2EE modes (the latter two Pro-only) avoid this.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "venice",
      "question": "memory_controls",
      "value": "yes",
      "quote": "You can toggle Memory in the settings on Venice.",
      "evidence_url": "https://venice.ai/blog/venice-memoria-technical-overview",
      "notes": "Memoria stores memories only in the browser (IndexedDB), never on Venice servers; Chat Memory is toggled at Settings → Memory → Chat Memory, individual memories can be viewed, edited and deleted at Settings → Memory → Interactions, and sharing memories with third-party 'anonymized' models is off by default. Disabling memory does not delete existing memories; they must be deleted explicitly.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "venice",
      "question": "user_deletion",
      "value": "partial",
      "quote": "You may terminate your account and these Terms at any time by contacting customer service at",
      "evidence_url": "https://venice.ai/legal/tos",
      "notes": "The Terms describe account termination by contacting customer service (the quote stops before an obfuscated email address). The FAQ page says the account can be deleted from account settings, but that page is rendered by JavaScript and cannot be verified by the pipeline. Conversations exist only in the browser and the Privacy Policy logs \"if you deleted a conversation\" as a user action, so in-product conversation deletion is implied but not described. Documents disagree on account deletion, hence partial.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "venice",
      "question": "data_export",
      "value": "partial",
      "quote": "You may ask us to provide you with a copy of the personal data we maintain about you, including a machine-readable copy of the personal data that you have provided to us, and request information about its processing.",
      "evidence_url": "https://venice.ai/legal/privacy-policy",
      "notes": "Access/portability is a request-based right listed under 'Your European Privacy Rights', exercised by emailing Venice. Chats already live only on the user's device; the Pro-only Encrypted Backup (web app, max 5 backups, 90-day expiry) restores history into Venice rather than providing a readable export, and no general self-service export of account data is documented.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "venice",
      "question": "deletion_timeline",
      "value": "partial",
      "quote": "we may retain personal data for backups, archiving, prevention of fraud and abuse, analytics, satisfaction of legal obligations, or where we otherwise reasonably believe that we have a legitimate reason to do so, to the extent permitted by applicable law.",
      "evidence_url": "https://venice.ai/legal/privacy-policy",
      "notes": "Conversation content is never stored on Venice servers, so there is nothing to purge for chats; for account data no fixed deletion period is stated and the retention exceptions are broad (backups, analytics, 'legitimate reason'). Only likeness uploads have a stated window (deleted from temporary storage within 1 hour).",
      "confidence": "low",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "venice",
      "question": "no_ads_use",
      "value": "yes",
      "quote": "We do not collect or retain your Prompts or Outputs (other than as described in the Prompts and Outputs section above).",
      "evidence_url": "https://venice.ai/legal/privacy-policy",
      "notes": "There is no explicit advertising clause about conversations; the protection follows from Venice stating it has no access to prompt/output content, so it cannot be used for ad targeting. Venice does use other personal data (device identifiers, mobile advertising identifiers, usage information) 'For marketing and advertising purposes' and lets analytics and advertising partners set cookies.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "venice",
      "question": "no_sale_sharing",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "The Privacy Policy contains no 'do not sell' statement and no California/CCPA notice. It discloses sharing with affiliates 'for any of the purposes described', with analytics partners (Google Analytics) and says advertising partners may collect cross-site activity via cookies, but does not say whether data is sold or shared for third parties' own marketing.",
      "confidence": "medium",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "venice",
      "question": "human_review_limited",
      "value": "partial",
      "quote": "You acknowledge and agree that Venice.ai reserves the right to, and may from time to time, monitor any and all information transmitted or received through the Service for operational and other purposes.",
      "evidence_url": "https://venice.ai/legal/tos",
      "notes": "The Privacy Policy says Venice will not have access to or store prompt/output content (and E2EE mode makes this cryptographically enforced), but Terms 10.11 reserves a broad monitoring right 'for operational and other purposes' without listing specific cases, so the documents are inconsistent. In 'Anonymous' mode third-party model providers see prompts under their own policies.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "venice",
      "question": "no_precise_location",
      "value": "yes",
      "quote": "We may collect and infer your general location information, including, for example, by collecting and using your internet protocol (IP) address when you visit our website.",
      "evidence_url": "https://venice.ai/legal/privacy-policy",
      "notes": "Only general (IP-derived) location is described; device data listed (device identifiers, carrier, push tokens) does not include GPS/precise location and no location permission is documented for any feature.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "venice",
      "question": "rights_channel",
      "value": "partial",
      "quote": "You may exercise these rights by contacting us using the contact details as indicated in the “Contact Information” section below.",
      "evidence_url": "https://venice.ai/legal/privacy-policy",
      "notes": "The Privacy Policy names a dedicated privacy mailbox, DataPrivacy@venice.ai, in its Contact Information section for all users and for likeness-metadata access, correction, deletion and download requests, but the general access, portability, deletion and objection rights (and the sentence directing users to that mailbox to exercise them) are stated only 'if you are located in Europe'. No privacy portal, form or in-product rights request is documented and account termination goes through customer service, so the channel counts as documented for some jurisdictions only.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "manus",
      "question": "no_training_default",
      "value": "partial",
      "quote": "a perpetual and irrevocable license to use Your Content in an aggregated manner to improve the Services",
      "evidence_url": "https://files.manuscdn.com/webapp/_next/static/chunks/20ao8cskg9oth.js",
      "notes": "Neither the Privacy Policy nor the Terms says that user content is used to train models: Terms 5.3 grants a perpetual, irrevocable licence to use Your Content (inputs and outputs) 'in an aggregated manner to improve the Services' and create Usage Data, and the Privacy Policy lists 'Inputs, prompts and user-generated content' under service-improvement/analytics and R&D purposes by default, without saying whether that includes model training. Under the revised rubric a licence to improve the services that is silent on models is partial with low confidence, not no. Terms 5.4 additionally warns that third-party AI providers 'may retain certain rights to use or disclose Your Content'; no opt-in or opt-out is documented.",
      "confidence": "low",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "manus",
      "question": "training_opt_out",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "No setting, form or request path to stop use of conversations for service improvement or training is documented for individual users; the only documented choices concern marketing emails, targeted-advertising sharing and content deletion. Because the training default itself is only a service-improvement licence that does not mention models (see no_training_default), the cell stays unknown rather than no. European users have a legal right to object to legitimate-interest processing via privacy@manus.im, but the documents do not tie it to training.",
      "confidence": "medium",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "manus",
      "question": "uploads_excluded",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "Uploaded files, photos, audio and video are collected as 'Inputs, prompts and user-generated content' (plus sandbox files) and fall under the same Terms 5.3 licence to use Your Content in aggregated form to improve the Services, but the documents never say whether uploads or any content are used to train models, and there is no blanket no-training statement or upload-specific exclusion. Silence on training means unknown, consistent with the partial/low-confidence training default; a 'no' would attribute a practice the documents do not state.",
      "confidence": "medium",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "manus",
      "question": "business_no_training",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "For API customers, Space owners and Team plans Manus says it acts as a data processor on documented instructions and under a Data Processing Addendum, but no document states that API or Team data is excluded from training or service improvement. Processor language alone is not a training exclusion, so the cell is unknown rather than partial.",
      "confidence": "medium",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "manus",
      "question": "temporary_chat",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "No temporary, incognito or history-off chat mode is described in the Privacy Policy, Terms or help center. The only ephemeral component documented is the Browser Sandbox (auto-deleted 7 days after last activity on free plans, 14 days on paid), which is not a chat mode.",
      "confidence": "medium",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "manus",
      "question": "memory_controls",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "The documents do not describe a cross-conversation memory feature or any controls for viewing, deleting or disabling memory; the Privacy Policy only mentions personalisation to 'remember your selections and preferences'.",
      "confidence": "medium",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "manus",
      "question": "user_deletion",
      "value": "partial",
      "quote": "If you are an individual user, you can choose to delete certain content through your account. If you wish to request to close your account, please contact us.",
      "evidence_url": "https://files.manuscdn.com/webapp/_next/static/chunks/28lq3ui3tovcp.js",
      "notes": "Deletion of 'certain content' is self-service, but the Privacy Policy says account closure requires contacting Manus while Terms 7 says you may close your account 'on the user profile page', so the documents contradict each other; the help center confirms account deletion exists and that some personal information is retained afterwards for legal, accounting and fraud purposes.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "manus",
      "question": "data_export",
      "value": "partial",
      "quote": "Transfer a machine-readable copy of your personal information to you or a third party of your choice.",
      "evidence_url": "https://files.manuscdn.com/webapp/_next/static/chunks/28lq3ui3tovcp.js",
      "notes": "No self-service export of conversations or account data is documented for individual users; the only documented route is the 'Transfer' right to a machine-readable copy on request to privacy@manus.im, which sits under the Notice to European users. Terms 5.8 mentions tools that 'may' export Your Content to third-party services, and Team Owners can export members' session data, neither of which is a personal-data export for the individual.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "manus",
      "question": "deletion_timeline",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "No deletion period is stated for chats or accounts: the Privacy Policy retains data 'to fulfill the purposes' and for legal, accounting, reporting, legal-claim and fraud purposes, and the help center says data is 'securely deleted' once an unspecified retention period expires. The only fixed period is for Browser Sandbox data (7 days free / 14 days paid after last activity).",
      "confidence": "medium",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "manus",
      "question": "no_ads_use",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "Manus advertises its own product on other platforms and, with consent where required, processes 'certain online identifiers' to target ads, measure them and build audiences, with an 'Ads About Manus' toggle, a 'Your Privacy Choices' link and GPC support. The documents never say whether conversation content is or is not used for ad personalisation: the European legal-basis table lists only contact, device and online-activity data under 'Advertising' (not inputs/prompts), which suggests exclusion but is not a statement, so the cell stays unknown.",
      "confidence": "medium",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "manus",
      "question": "no_sale_sharing",
      "value": "partial",
      "quote": "We share information about you with our marketing and measurement vendors and service providers and partners to help us promote the Service to you on apps and websites, and to measure the effectiveness of those promotions.",
      "evidence_url": "https://files.manuscdn.com/webapp/_next/static/chunks/28lq3ui3tovcp.js",
      "notes": "Personal information (identifiers) is shared with marketing vendors for targeted advertising of Manus, which the California notice treats as CCPA 'sharing'; users can opt out via the 'Ads About Manus' setting, the 'Your Privacy Choices' footer link, GPC, or industry opt-outs. There is no explicit statement that personal data is never sold.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "manus",
      "question": "human_review_limited",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "The documents do not say whether Manus staff or contractors read conversations or task content; Terms 5.3 licenses content use to 'monitor your compliance with these Terms' without describing human review, and the only disclosed viewers of session content are Team Plan Owners/Administrators (not the vendor).",
      "confidence": "medium",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "manus",
      "question": "no_precise_location",
      "value": "yes",
      "quote": "radio/network information (e.g., WiFi, LTE, 3G), and general location information such as city, state or geographic area.",
      "evidence_url": "https://files.manuscdn.com/webapp/_next/static/chunks/28lq3ui3tovcp.js",
      "notes": "Automatic collection is limited to general location (city/state/area, IP-derived); no device location permission is described. Caveat: metadata of user-uploaded content may include 'location info', and the Terms ask users not to submit precise geolocation as sensitive information.",
      "confidence": "low",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "manus",
      "question": "rights_channel",
      "value": "partial",
      "quote": "You may submit requests by email to privacy@manus.im or our postal address above.",
      "evidence_url": "https://files.manuscdn.com/webapp/_next/static/chunks/28lq3ui3tovcp.js",
      "notes": "A dedicated privacy/DPO address (privacy@manus.im) is given for all users, but the enumerated access, deletion and portability rights and this request channel sit under the 'Notice to European users'; for everyone else the policy offers only account-settings edits, in-app content deletion and 'contact us' for account closure, plus the 'Ads About Manus' opt-out. Team Plan members must first ask their Team Owner (30-day fallback to Manus).",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "genspark",
      "question": "no_training_default",
      "value": "partial",
      "quote": "The rights you grant in this license are for the limited purpose of operating, promoting, and improving our Service, and to develop new ones.",
      "evidence_url": "https://www.genspark.ai/terms",
      "notes": "The consumer documents never say whether individual users' prompts are used to train Genspark models: the Terms licence over submitted content is 'for the limited purpose of operating, promoting, and improving our Service, and to develop new ones', and the Privacy Policy uses collected information (which includes prompts and outputs) 'to evaluate and improve our Service', without mentioning models, so the rubric's licence-to-improve branch gives partial with low confidence. The 'automatically opted out of model training' promise applies only to Team and Enterprise plans and cannot decide the consumer cell; the help center's Zero Data Retention statement concerns the third-party inference platforms hosting open-source models, not Genspark's own use.",
      "confidence": "low",
      "verified": true,
      "verified_at": "2026-09-11"
    },
    {
      "app": "genspark",
      "question": "training_opt_out",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "No consumer-facing training opt-out setting or request channel is documented. The team-plan comparison table lists \"Platform service improvement: Disabled by default; opt-out available\" for Team/Enterprise only; the privacy policy's Universal Opt-out Mechanism handling concerns sale/sharing and sensitive data, not training.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "genspark",
      "question": "uploads_excluded",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "The privacy policy says uploaded reference images and voice recordings are transmitted to third-party AI providers to fulfil the request and that virtual try-on photos are \"Used solely for virtual try-on visualization\", but it does not say whether uploads are used for Genspark's own training or covered by any opt-out; the Team/Enterprise \"prompts and content are never used to train\" statement does not apply to individual plans.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "genspark",
      "question": "business_no_training",
      "value": "yes",
      "quote": "No. Both Team and Enterprise accounts are automatically opted out of model training. Per Genspark's Data Processing Agreement (DPA), your prompts and content are never used to train Genspark models.",
      "evidence_url": "https://www.genspark.ai/helpcenter/team-enterprise-plans",
      "notes": "Applies to Team and Enterprise plans by default; subprocessors (OpenAI, Anthropic, Google) are said to be bound by no-training agreements with Zero Data Retention where applicable. Caveat: the same article says a DPA is \"not currently available\" on Team (only Enterprise), so the Team guarantee rests on the help-center statement rather than a signed DPA; Genspark documents no public API offering.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "genspark",
      "question": "temporary_chat",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "No temporary, incognito or history-off chat mode is described in the privacy policy, terms or help center; the Chrome extension article only says extension conversation history is kept for the current session, which is not a documented privacy mode.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "genspark",
      "question": "memory_controls",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "Genspark documents cross-conversation memory (SecondBrain, which \"auto-saves all your past Genspark activity\" and connected apps; Genspark Claw long-term memory shared across channels). The only documented control is that connected integrations \"can be disconnected at any time from the Home page\"; viewing, deleting individual memories or switching memory off entirely is not addressed.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "genspark",
      "question": "user_deletion",
      "value": "partial",
      "quote": "all your data will be permanently removed and cannot be recovered under any circumstances.",
      "evidence_url": "https://www.genspark.ai/helpcenter/account-management",
      "notes": "Account deletion is self-service (Settings > \"Delete User\", confirm in dialog and email) and covers \"All conversation history\". Deleting an individual conversation is not documented anywhere fetched (History view and AI Drive file trash exist, but no per-chat delete).",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "genspark",
      "question": "data_export",
      "value": "partial",
      "quote": "Residents of the EU, UK, Canada, and certain other countries have the right to receive or reasonably access the Personal Data that we process, request a portable copy of that information, and the ability to review, correct, delete, restrict, or object to the processing of such information.",
      "evidence_url": "https://www.genspark.ai/privacy",
      "notes": "No self-service export is documented; portable copies are available on request by email, framed as rights of residents of listed US states and of the EU/UK/Canada \"and certain other countries\". AI Drive lets users download individual files, but nothing covers conversations.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "genspark",
      "question": "deletion_timeline",
      "value": "partial",
      "quote": "If you close your account, we will delete your account data from our servers within 30 days.",
      "evidence_url": "https://www.genspark.ai/privacy",
      "notes": "30-day commitment is stated for account closure only; no period is given for deleting individual conversations. Retention section also allows keeping data \"for other legitimate business purposes, including to meet our legal, regulatory, auditing, fraud prevention, or other compliance obligations\", and the Team/Enterprise article states backups are retained 90 days post-deletion.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "genspark",
      "question": "no_ads_use",
      "value": "yes",
      "quote": "Please note that we do not sell or share your Personal Data, use it for targeted advertising, or process your sensitive Personal Data.",
      "evidence_url": "https://www.genspark.ai/privacy",
      "notes": "The policy states that Genspark does not sell or share Personal Data, which includes prompts, or use it for targeted advertising. The sentence sits in the section on rights for residents of certain US states but is worded as a universal practice, and no ads are documented in the product; Genspark may use account data for its own marketing, which does not count against this question. Confidence medium because the placement leaves room to read the statement as region-scoped.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "genspark",
      "question": "no_sale_sharing",
      "value": "yes",
      "quote": "We do not sell, trade, or otherwise share Personal Data with third parties, except as described in the following circumstances or as otherwise described in this policy.",
      "evidence_url": "https://www.genspark.ai/privacy",
      "notes": "Listed exceptions are service providers (hosting, Google Analytics, AI model providers, Stripe), business transfers, consent and legal requests; the US-state section adds \"we do not sell Personal Data\". The catch-all \"or as otherwise described in this policy\" is the only qualification.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "genspark",
      "question": "human_review_limited",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "Neither the privacy policy nor the terms say whether Genspark staff can read consumer conversations. Only the Team/Enterprise comparison table states \"Raw content access for analytics: Never accessed or analyzed\" and that admins cannot view members' content, which does not cover individual plans.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "genspark",
      "question": "no_precise_location",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "The privacy policy never mentions geolocation; its US-state category table (identifiers, network activity, commercial info, photos, call audio) omits any geolocation category, and the terms only say \"We may identify users' geographic locations through technical means to implement geoblocking\" without specifying precision. Silence is treated as unknown.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "genspark",
      "question": "rights_channel",
      "value": "partial",
      "quote": "and would like to make a request pursuant to any of the rights described in this section, you may do so by emailing us at",
      "evidence_url": "https://www.genspark.ai/privacy",
      "notes": "Rights requests go to an email address (Attn: Privacy Officer; the address is Cloudflare-obfuscated in the HTML so it cannot be quoted), framed for residents of 19 listed US states and for EU/UK/Canada residents; response within 10 business days, fulfilment within 45 days. No portal, form or in-product rights control is documented, and the channel is a generic contact address.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "z-ai",
      "question": "no_training_default",
      "value": "no",
      "quote": "For individual users, we reserve the right to process any User Content to improve our existing Services and/or to develop new products and services, including for our internal business operations and for the benefit of other customers.",
      "evidence_url": "https://docs.z.ai/legal-agreement/terms-of-use.md",
      "notes": "Terms IV.3(a) reserves the right to process any User Content of individual users to improve existing Services and develop new ones, and has users 'explicitly authorize and consent' to storage and use of User Content that does not constitute personal data 'for the purpose of developing and improving our machine learning and artificial intelligence technologies'; the Privacy Policy separately lists 'when we train and improve our models' as a legitimate-interest purpose for personal data. No opt-in is required and no setting is described, so consumer conversations are used by default. Enterprise and API customers are excluded unless they agree (see business_no_training).",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "z-ai",
      "question": "training_opt_out",
      "value": "partial",
      "quote": "the right to object to processing of your personal data, including profiling conducted on grounds of public or legitimate interest. In places where such a right applies, we will no longer process the personal data in case of such objection unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms",
      "evidence_url": "https://docs.z.ai/legal-agreement/privacy-policy.md",
      "notes": "No self-service training toggle is documented. The only route is a request by email (user_feedback@z.ai) under the objection right, which the policy limits to \"places where such a right applies\" and which the vendor may override for \"compelling legitimate grounds\"; the terms only say \"Contact us with any concerns about our use of User Content\". Whether this stops training on non-personal content is not stated.",
      "confidence": "low",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "z-ai",
      "question": "uploads_excluded",
      "value": "partial",
      "quote": "we may permit you to submit text, documents, or other materials to our Services for processing",
      "evidence_url": "https://docs.z.ai/legal-agreement/terms-of-use.md",
      "notes": "Uploaded documents and images fall within Prompts and User Content, and the same section IV consent to use User Content for developing and improving models applies to them with no upload-specific exclusion or self-service opt-out. The Privacy Policy gives a right to object to legitimate-interest processing that it ties to model improvement, available where such a right applies; a request-based opt-out tied to training makes the cell partial under the rubric, matching training_opt_out.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "z-ai",
      "question": "business_no_training",
      "value": "yes",
      "quote": "For enterprises and developers using API Services, we will not use your User Content for developing or improving Services unless you explicitly agree to such use.",
      "evidence_url": "https://docs.z.ai/legal-agreement/terms-of-use.md",
      "notes": "Applies to the API Services (the only business offering documented); the Data Processing Addendum adds that the company does \"not store any of the content the Customer or its End Users provide or generate\". Caveat: the parallel sentence in Additional Terms 3(b) is printed inside square brackets, suggesting draft text.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "z-ai",
      "question": "temporary_chat",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "Neither the privacy policy nor the terms mention a temporary, incognito or history-off mode for chat.z.ai.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "z-ai",
      "question": "memory_controls",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "The privacy policy and terms do not mention a cross-conversation memory feature or controls for it; the only docs page on \"memory\" (devpack/resources/memory-mechanism) is a tutorial about coding-agent memory files, not the consumer chat product.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "z-ai",
      "question": "user_deletion",
      "value": "partial",
      "quote": "You also are able to delete individual conversations, which will be removed immediately from your conversation history and automatically deleted from our back-end.",
      "evidence_url": "https://docs.z.ai/legal-agreement/privacy-policy.md",
      "notes": "Individual conversation deletion and full chat-history deletion \"via your settings\" are self-service. Account deletion is described in the terms as a request that the vendor will \"review and process\" and that takes effect \"Once approved\", so it is not clearly an in-product self-service control.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "z-ai",
      "question": "data_export",
      "value": "partial",
      "quote": "the right to request a copy of the personal data we process about you, subject to certain exceptions and conditions. In certain cases and subject to applicable law, you have the right to port your information.",
      "evidence_url": "https://docs.z.ai/legal-agreement/privacy-policy.md",
      "notes": "Access and portability are available only on request via the contact email, \"subject to certain exceptions\" and \"subject to applicable law\"; no self-service export of conversations is documented.",
      "confidence": "high",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "z-ai",
      "question": "deletion_timeline",
      "value": "partial",
      "quote": "You also are able to delete individual conversations, which will be removed immediately from your conversation history and automatically deleted from our back-end.",
      "evidence_url": "https://docs.z.ai/legal-agreement/privacy-policy.md",
      "notes": "Immediate removal is stated for individually deleted conversations (back-end deletion is \"automatic\" but no period is given); no timeline is stated for account deletion, and the retention section allows keeping data for legitimate business interests \"such as improving and developing our Services\" and for legal claims, which is broader than legal/safety holds.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "z-ai",
      "question": "no_ads_use",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "The documents do not say whether conversation content is used for advertising; the policy notes collection of \"device or advertising identifiers\" but describes no ad targeting and no exclusion of chat content from it.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "z-ai",
      "question": "no_sale_sharing",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "The sharing section lists affiliates, vendors/service providers (e.g., Google Analytics), business transfers, authorities and consent-based disclosures, but contains no statement that personal data is not sold or shared with third parties for their own marketing.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "z-ai",
      "question": "human_review_limited",
      "value": "unknown",
      "quote": "",
      "evidence_url": "",
      "notes": "Human review of conversations by staff or contractors is not mentioned in the privacy policy or terms.",
      "confidence": "low",
      "verified": false,
      "verified_at": ""
    },
    {
      "app": "z-ai",
      "question": "no_precise_location",
      "value": "yes",
      "quote": "IP address (including location information inferred from your IP address)",
      "evidence_url": "https://docs.z.ai/legal-agreement/privacy-policy.md",
      "notes": "The only location data described is inferred from IP address within Device and Network Information; no precise/GPS geolocation collection is listed. The policy does not explicitly state that precise location is never collected, so this rests on the enumerated data categories.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    },
    {
      "app": "z-ai",
      "question": "rights_channel",
      "value": "yes",
      "quote": "Please contact us by using the contact information provided in this Privacy Policy if you would like to exercise any of your rights. We will respond to your request consistent with applicable law and subject to proper verification.",
      "evidence_url": "https://docs.z.ai/legal-agreement/privacy-policy.md",
      "notes": "The Privacy Policy tells users to exercise any of their rights by contacting the address given in the policy, and its Contact section directs 'questions, comments and requests regarding this policy' to user_feedback@z.ai, a mailbox named for rights requests and offered to all users (it also handles complaints and copyright notices, which the revised rubric tolerates). The rights list is prefaced with a 'depending on where you live' hedge, which the rubric says does not demote when the channel itself is universal. In-product settings additionally cover deletion of individual conversations and chat history; there is no portal or form.",
      "confidence": "medium",
      "verified": true,
      "verified_at": "2026-09-18"
    }
  ],
  "apps": [
    {
      "id": "chatgpt",
      "name": "ChatGPT",
      "vendor": "OpenAI",
      "homepage": "https://chatgpt.com",
      "repo": null,
      "sources": [
        "https://openai.com/policies/privacy-policy/",
        "https://help.openai.com/en/articles/5722486-how-your-data-is-used-to-improve-model-performance",
        "https://help.openai.com/en/articles/8555545-file-uploads-faq",
        "https://help.openai.com/en/articles/8590148-memory-faq",
        "https://help.openai.com/en/articles/6378407-how-can-i-delete-my-account",
        "https://help.openai.com/en/articles/7260999-how-do-i-export-my-chatgpt-history-and-data",
        "https://help.openai.com/en/articles/20001047-ads-in-chatgpt",
        "https://openai.com/transparency-and-content-moderation/"
      ]
    },
    {
      "id": "claude",
      "name": "Claude",
      "vendor": "Anthropic",
      "homepage": "https://claude.ai",
      "repo": null,
      "sources": [
        "https://www.anthropic.com/legal/privacy",
        "https://privacy.claude.com/en/articles/7996868-is-my-data-used-for-model-training",
        "https://support.claude.com/en/articles/12260368-use-incognito-chats",
        "https://support.claude.com/en/articles/11817273-use-claude-s-chat-search-and-memory-to-build-on-previous-context",
        "https://privacy.claude.com/en/articles/10023660-deleting-claude-accounts",
        "https://privacy.claude.com/en/articles/9450526-export-your-claude-data",
        "https://privacy.claude.com/en/articles/10023555-how-do-you-use-personal-data-in-model-training",
        "https://privacy.claude.com/en/articles/10458704-how-does-anthropic-protect-the-personal-data-of-claude-users"
      ]
    },
    {
      "id": "gemini",
      "name": "Gemini",
      "vendor": "Google",
      "homepage": "https://gemini.google.com",
      "repo": null,
      "sources": [
        "https://support.google.com/gemini/answer/13594961",
        "https://policies.google.com/privacy",
        "https://policies.google.com/technologies/retention?hl=en-US",
        "https://support.google.com/gemini/answer/13278892?hl=en",
        "https://support.google.com/gemini/answer/13275745?hl=en",
        "https://support.google.com/gemini/answer/16598469?hl=en",
        "https://support.google.com/a/answer/15706919?hl=en",
        "https://ai.google.dev/gemini-api/terms"
      ]
    },
    {
      "id": "copilot",
      "name": "Microsoft Copilot",
      "vendor": "Microsoft",
      "homepage": "https://copilot.microsoft.com",
      "repo": null,
      "sources": [
        "https://privacy.microsoft.com/en-us/privacystatement",
        "https://support.microsoft.com/en-us/privacy/microsoft-copilot/privacy-controls",
        "https://support.microsoft.com/en-us/privacy/microsoft-copilot/activity-history",
        "https://support.microsoft.com/en-us/privacy/manage-your-copilot-activity-history-in-the-privacy-dashboard",
        "https://support.microsoft.com/en-us/microsoft-copilot/privacy-faq-for-microsoft-copilot",
        "https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy",
        "https://learn.microsoft.com/en-us/copilot/microsoft-365/enterprise-data-protection",
        "https://support.microsoft.com/en-us/account-billing/how-to-close-your-microsoft-account-c1b2d13f-4de6-6e1b-4a31-d9d668849979"
      ]
    },
    {
      "id": "perplexity",
      "name": "Perplexity",
      "vendor": "Perplexity AI, Inc.",
      "homepage": "https://www.perplexity.ai",
      "repo": null,
      "sources": [
        "https://www.perplexity.ai/hub/legal/privacy-notice",
        "https://www.perplexity.ai/help-center/en/articles/11564572-data-collection-at-perplexity",
        "https://www.perplexity.ai/help-center/en/articles/10968016-memory",
        "https://www.perplexity.ai/help-center/en/articles/11564562-self-serve-data-deletion",
        "https://www.perplexity.ai/help-center/en/articles/11564568-gdpr-compliance-at-perplexity",
        "https://www.perplexity.ai/help-center/en/articles/10354873-how-long-does-perplexity-retain-my-search-history-profile-data-and-personal-information",
        "https://www.perplexity.ai/help-center/en/articles/10354810-security-and-privacy-with-file-uploads",
        "https://www.perplexity.ai/hub/legal/enterprise-terms-of-service"
      ]
    },
    {
      "id": "grok",
      "name": "Grok",
      "vendor": "xAI (SpaceXAI LLC)",
      "homepage": "https://grok.com",
      "repo": null,
      "sources": [
        "https://x.ai/legal/privacy-policy",
        "https://x.ai/legal/faq",
        "https://x.ai/legal/terms-of-service",
        "https://x.ai/legal/terms-of-service-enterprise",
        "https://x.ai/legal/europe-privacy-policy-addendum",
        "https://x.ai/legal/ccpa"
      ]
    },
    {
      "id": "meta-ai",
      "name": "Meta AI",
      "vendor": "Meta Platforms, Inc.",
      "homepage": "https://www.meta.ai",
      "repo": null,
      "sources": [
        "https://mbasic.facebook.com/privacy/policy/printable/?locale=en_US",
        "https://mbasic.facebook.com/privacy/genai/?locale=en_US",
        "https://mbasic.facebook.com/legal/ai-terms?locale=en_US",
        "https://about.fb.com/news/2023/09/privacy-matters-metas-generative-ai-features/",
        "https://mbasic.facebook.com/legal/eu-ai-terms?locale=en_US"
      ]
    },
    {
      "id": "deepseek",
      "name": "DeepSeek",
      "vendor": "DeepSeek",
      "homepage": "https://chat.deepseek.com",
      "repo": null,
      "sources": [
        "https://cdn.deepseek.com/policies/en-US/deepseek-privacy-policy.html",
        "https://cdn.deepseek.com/policies/en-US/deepseek-terms-of-use.html",
        "https://cdn.deepseek.com/policies/en-US/deepseek-open-platform-terms-of-service.html",
        "https://cdn.deepseek.com/policies/en-US/model-algorithm-disclosure.html"
      ]
    },
    {
      "id": "le-chat",
      "name": "Vibe (Le Chat)",
      "vendor": "Mistral AI",
      "homepage": "https://chat.mistral.ai",
      "repo": null,
      "sources": [
        "https://legal.mistral.ai/terms/privacy-policy",
        "https://legal.mistral.ai/terms/row-consumer-terms",
        "https://legal.mistral.ai/terms/eu-consumers-terms-of-service",
        "https://legal.mistral.ai/terms/commercial-terms-of-service",
        "https://help.mistral.ai/en/articles/455207-can-i-opt-out-of-my-input-or-output-data-being-used-for-training",
        "https://help.mistral.ai/en/articles/347633-do-you-use-my-conversations-with-vibe-to-show-me-ads",
        "https://help.mistral.ai/en/articles/347615-do-you-sell-or-share-my-data-for-marketing",
        "https://help.mistral.ai/en/articles/347632-can-other-people-view-my-conversations"
      ]
    },
    {
      "id": "character-ai",
      "name": "Character.AI",
      "vendor": "Character Technologies, Inc.",
      "homepage": "https://character.ai",
      "repo": null,
      "sources": [
        "https://character.ai/_next/static/chunks/pages/privacy-645bfcb925495ab4.js",
        "https://character.ai/_next/static/chunks/pages/regional-d6d1e02db80cf5eb.js",
        "https://support.character.ai/api/v2/help_center/en-us/articles/42788047758747.json",
        "https://support.character.ai/api/v2/help_center/en-us/articles/30299431702555.json",
        "https://support.character.ai/api/v2/help_center/en-us/articles/15063461160475.json",
        "https://support.character.ai/api/v2/help_center/en-us/articles/47703013822875.json",
        "https://support.character.ai/api/v2/help_center/en-us/articles/15063996838299.json"
      ]
    },
    {
      "id": "poe",
      "name": "Poe",
      "vendor": "Quora, Inc.",
      "homepage": "https://poe.com",
      "repo": null,
      "sources": [
        "https://poe.com/pages/privacy",
        "https://poe.com/pages/privacy-center",
        "https://poe.com/pages/tos",
        "https://help.poe.com/api/v2/help_center/en-us/articles/19944206309524.json",
        "https://poe.com/api_terms"
      ]
    },
    {
      "id": "pi",
      "name": "Pi",
      "vendor": "Inflection AI, Inc.",
      "homepage": "https://pi.ai",
      "repo": null,
      "sources": [
        "https://inflection.ai/privacy-policy",
        "https://inflection.ai/terms-of-service",
        "https://inflection.ai/transparency-and-content-moderation",
        "https://inflection.ai/notice-on-model-training",
        "https://help.pi.ai/en/articles/15425697-pi-s-memory",
        "https://help.pi.ai/en/articles/12988158-export-and-share-chat-history-safely-with-limits-and-tips",
        "https://help.pi.ai/en/articles/13147175-how-do-i-delete-my-pi-account-and-all-my-data",
        "https://help.pi.ai/en/articles/13147185-how-is-my-data-used-and-how-can-i-control-my-privacy-and-tracking"
      ]
    },
    {
      "id": "you-com",
      "name": "You.com",
      "vendor": "SuSea, Inc. (d/b/a You.com)",
      "homepage": "https://you.com",
      "repo": null,
      "sources": [
        "https://you.com/privacy",
        "https://you.com/terms",
        "https://you.com/privacy-requests",
        "https://you.com/docs/administration/zero-data-retention",
        "https://45321510.fs1.hubspotusercontent-na1.net/hubfs/45321510/Legal/You.com%20MSA%20(Online)%20(December%202025).pdf",
        "https://45321510.fs1.hubspotusercontent-na1.net/hubfs/45321510/Legal/You.com%20Platform%20Data%20Security%20Overview%20(May%202025).pdf"
      ]
    },
    {
      "id": "kimi",
      "name": "Kimi",
      "vendor": "Moonshot AI",
      "homepage": "https://www.kimi.ai",
      "repo": null,
      "sources": [
        "https://www.kimi.ai/user/agreement/userPrivacy?version=v2",
        "https://www.kimi.ai/user/agreement/modelUse?version=v2",
        "https://www.kimi.ai/help/features/memory-space",
        "https://www.kimi.ai/help/others/account-deletion",
        "https://www.kimi.ai/help/others/chat-issues",
        "https://www.kimi.ai/help/kimi-api/api-data-security",
        "https://www.kimi.ai/help/kimi-business/kimi-business"
      ]
    },
    {
      "id": "qwen-chat",
      "name": "Qwen Chat",
      "vendor": "Alibaba Cloud",
      "homepage": "https://chat.qwen.ai",
      "repo": null,
      "sources": [
        "https://g.alicdn.com/qwenweb/qwen-ai-fe/0.0.79/js/p_privacypolicy-index.js",
        "https://g.alicdn.com/qwenweb/qwen-ai-fe/0.0.79/js/p_termsservice-index.js",
        "https://www.alibabacloud.com/help/en/model-studio/what-is-model-studio"
      ]
    },
    {
      "id": "duck-ai",
      "name": "Duck.ai",
      "vendor": "DuckDuckGo",
      "homepage": "https://duck.ai",
      "repo": null,
      "sources": [
        "https://duckduckgo.com/duckai/privacy-terms",
        "https://duckduckgo.com/privacy",
        "https://duckduckgo.com/duckduckgo-help-pages/duckai/ai-chat-privacy",
        "https://duckduckgo.com/duckduckgo-help-pages/duckai/recent-chats",
        "https://duckduckgo.com/duckduckgo-help-pages/what-information-does-duckai-share-with-model-providers",
        "https://duckduckgo.com/duckduckgo-help-pages/r-legal/privacy-rights",
        "https://duckduckgo.com/pro/privacy-terms/us"
      ]
    },
    {
      "id": "brave-leo",
      "name": "Brave Leo AI",
      "vendor": "Brave Software, Inc.",
      "homepage": "https://brave.com/leo/",
      "repo": null,
      "sources": [
        "https://brave.com/privacy/browser/",
        "https://brave.com/leo/",
        "https://brave.com/terms-of-use/",
        "https://brave.com/privacy/ccpa/"
      ]
    },
    {
      "id": "lumo",
      "name": "Lumo",
      "vendor": "Proton AG",
      "homepage": "https://lumo.proton.me",
      "repo": null,
      "sources": [
        "https://proton.me/lumo/privacy-policy",
        "https://proton.me/lumo/terms",
        "https://proton.me/support/lumo-privacy",
        "https://proton.me/support/lumo-memory",
        "https://proton.me/lumo/security",
        "https://proton.me/lumo",
        "https://proton.me/business/lumo",
        "https://proton.me/support/lumo-getting-started"
      ]
    },
    {
      "id": "huggingchat",
      "name": "HuggingChat",
      "vendor": "Hugging Face, Inc.",
      "homepage": "https://huggingface.co/chat",
      "repo": "https://github.com/huggingface/chat-ui",
      "sources": [
        "https://huggingface.co/privacy",
        "https://huggingface.co/terms-of-service",
        "https://raw.githubusercontent.com/huggingface/chat-ui/main/PRIVACY.md",
        "https://huggingface.co/docs/inference-providers/security"
      ]
    },
    {
      "id": "replika",
      "name": "Replika",
      "vendor": "Luka, Inc.",
      "homepage": "https://replika.com",
      "repo": null,
      "sources": [
        "https://replika.com/legal/privacy",
        "https://replika.com/legal/terms",
        "https://help.replika.com/api/v2/help_center/en-us/articles/360000874712.json",
        "https://help.replika.com/api/v2/help_center/en-us/articles/37208679176077.json",
        "https://help.replika.com/api/v2/help_center/en-us/articles/4410750548493.json",
        "https://help.replika.com/api/v2/help_center/en-us/articles/115001070971.json",
        "https://help.replika.com/api/v2/help_center/en-us/articles/360000885332.json",
        "https://help.replika.com/api/v2/help_center/en-us/articles/37171427757069.json"
      ]
    },
    {
      "id": "apple-intelligence",
      "name": "Apple Intelligence / Siri",
      "vendor": "Apple",
      "homepage": "https://www.apple.com/apple-intelligence/",
      "repo": null,
      "sources": [
        "https://www.apple.com/legal/privacy/data/en/intelligence-engine/",
        "https://www.apple.com/legal/privacy/data/en/ask-siri-dictation/",
        "https://www.apple.com/legal/privacy/en-ww/",
        "https://www.apple.com/legal/privacy/data/en/improve-siri-dictation/",
        "https://www.apple.com/legal/privacy/data/en/chatgpt-extension/",
        "https://support.apple.com/en-us/HT208502",
        "https://support.apple.com/en-us/102283"
      ]
    },
    {
      "id": "alexa-plus",
      "name": "Alexa+",
      "vendor": "Amazon",
      "homepage": "https://www.amazon.com/alexaplus",
      "repo": null,
      "sources": [
        "https://www.amazon.com/Alexa-Privacy-Hub/b?ie=UTF8&node=19149155011",
        "https://www.amazon.com/b/?node=23608617011",
        "https://www.amazon.com/b/?node=23608614011",
        "https://www.aboutamazon.com/news/devices/alexa-plus-international-launch",
        "https://www.aboutamazon.com/news/devices/new-alexa-generative-artificial-intelligence",
        "https://www.aboutamazon.com/news/devices/alexa-plus-available-free-prime-members-us"
      ]
    },
    {
      "id": "snapchat-my-ai",
      "name": "Snapchat My AI",
      "vendor": "Snap Inc.",
      "homepage": "https://www.snapchat.com",
      "repo": null,
      "sources": [
        "https://values.snap.com/privacy/privacy-policy",
        "https://values.snap.com/privacy/privacy-by-product",
        "https://values.snap.com/privacy/privacy-policy/us-state-privacy-notice",
        "https://values.snap.com/privacy/ads-privacy",
        "https://help.snapchat.com/hc/en-us/articles/13889139811860",
        "https://help.snapchat.com/hc/en-us/articles/18937378754324",
        "https://help.snapchat.com/hc/en-us/articles/7012334940948",
        "https://help.snapchat.com/hc/en-us/articles/7012328360596"
      ]
    },
    {
      "id": "kagi-assistant",
      "name": "Kagi Assistant",
      "vendor": "Kagi Inc.",
      "homepage": "https://kagi.com/assistant",
      "repo": null,
      "sources": [
        "https://kagi.com/privacy",
        "https://kagi.com/privacy/rights",
        "https://help.kagi.com/kagi/ai/assistant.html",
        "https://help.kagi.com/kagi/ai/llms-privacy.html",
        "https://help.kagi.com/kagi/settings/privacy.html",
        "https://help.kagi.com/kagi/settings/delete-account.html",
        "https://help.kagi.com/kagi/plans/team-plan.html"
      ]
    },
    {
      "id": "venice",
      "name": "Venice",
      "vendor": "Venice.ai, Inc.",
      "homepage": "https://venice.ai",
      "repo": null,
      "sources": [
        "https://venice.ai/legal/privacy-policy",
        "https://venice.ai/legal/tos",
        "https://venice.ai/privacy",
        "https://docs.venice.ai/overview/privacy",
        "https://venice.ai/faqs",
        "https://venice.ai/blog/venice-memoria-technical-overview",
        "https://venice.ai/blog/venice-launches-end-to-end-encrypted-ai"
      ]
    },
    {
      "id": "manus",
      "name": "Manus",
      "vendor": "Butterfly Effect Pte. Ltd.",
      "homepage": "https://manus.im",
      "repo": null,
      "sources": [
        "https://files.manuscdn.com/webapp/_next/static/chunks/28lq3ui3tovcp.js",
        "https://files.manuscdn.com/webapp/_next/static/chunks/20ao8cskg9oth.js",
        "https://help.manus.im/en/articles/11711823-will-my-personal-data-be-deleted-after-i-delete-my-account",
        "https://help.manus.im/en/articles/11711929-who-can-see-my-tasks",
        "https://help.manus.im/en/articles/13125514-do-i-own-the-assets-websites-images-videos-slides-generated-via-manus"
      ]
    },
    {
      "id": "genspark",
      "name": "Genspark",
      "vendor": "MainFunc Inc.",
      "homepage": "https://www.genspark.ai",
      "repo": null,
      "sources": [
        "https://www.genspark.ai/privacy",
        "https://www.genspark.ai/terms",
        "https://www.genspark.ai/helpcenter/team-enterprise-plans",
        "https://www.genspark.ai/helpcenter/account-management",
        "https://www.genspark.ai/helpcenter/secondbrain",
        "https://www.genspark.ai/helpcenter/troubleshooting-guide",
        "https://www.genspark.ai/business"
      ]
    },
    {
      "id": "z-ai",
      "name": "Z.ai",
      "vendor": "Zhipu AI (Z.ai)",
      "homepage": "https://chat.z.ai",
      "repo": null,
      "sources": [
        "https://docs.z.ai/legal-agreement/privacy-policy.md",
        "https://docs.z.ai/legal-agreement/terms-of-use.md",
        "https://docs.z.ai/legal-agreement/privacy-policy",
        "https://docs.z.ai/legal-agreement/terms-of-use",
        "https://chat.z.ai/legal-agreement/privacy-policy"
      ]
    }
  ],
  "questions": [
    {
      "id": "no_training_default",
      "group": "training",
      "name": "Chats excluded from training by default",
      "question": "Are a consumer user's conversations excluded from training or improving the vendor's models by default, without the user changing a setting?",
      "rubric": "YES if the documents state that conversations of consumer users are not used to train or improve models unless the user opts in, or that the vendor never stores or has no access to conversation content. PARTIAL if exclusion applies only to some plans (for example paid consumer tiers), some regions or some data types; if training is on by default for some users and off for others; if the vendor itself does not train but says third-party model providers it routes to may; or if the documents grant a licence to use conversation content to improve the services without saying whether that includes models (say so in the notes, confidence low). NO if consumer conversations are used by default to train or improve models, including internal classifiers or safety models. UNKNOWN if the consumer documents do not say; statements about business or API plans do not count."
    },
    {
      "id": "training_opt_out",
      "group": "training",
      "name": "Training opt-out for individuals",
      "question": "Can an individual consumer user stop their conversations from being used for training?",
      "rubric": "YES if a documented self-service setting exists (a setting that stops training on new conversations from that point on still counts; note whether earlier conversations are covered), or if conversations are never used for training so no opt-out is needed (say so in the notes). PARTIAL if the opt-out requires contacting the vendor or submitting a form; applies only in some regions; disables other features (for example chat history) as a side effect; is available only by choosing certain models, bots or paid plans; or exists only as a legal right to object that the documents tie to training. NO if the documents state training cannot be avoided, or if training is on by default and the documents describe no way to stop it; deleting stored data is not an opt-out. UNKNOWN if the training default itself is unknown and no opt-out is mentioned."
    },
    {
      "id": "uploads_excluded",
      "group": "training",
      "name": "Uploaded files excluded from training",
      "question": "Are files, images and documents the user uploads excluded from training by default?",
      "rubric": "YES if uploads are excluded from training by default, either named explicitly or covered by a blanket statement that no user content or data is used for training. PARTIAL if uploads are used for training by default but a documented opt-out that the documents tie to training (self-service or by request) covers them; if only some upload types are covered; or if the sibling question no_training_default is partial because the documents grant a licence to improve the services without saying whether that includes models. NO if uploads are used for training with no opt-out. UNKNOWN if uploads are not mentioned and no blanket statement exists, or if the product does not accept uploads (say so in the notes)."
    },
    {
      "id": "business_no_training",
      "group": "training",
      "name": "Business and API data not used for training",
      "question": "For the vendor's business, team, enterprise or API offerings, is customer data excluded from training by default?",
      "rubric": "YES if the documents (contract terms or official help pages) state that business, enterprise, team or API customer data is not used for training by default. PARTIAL if only some of these offerings are covered, exclusion requires a contract term or setting, or the vendor itself does not train but third-party model providers used by the offering may. NO if such data is used by default, or the documents list API or developer data as a training source without an exclusion. UNKNOWN if the vendor has no such offering or the documents do not address it (say which in the notes)."
    },
    {
      "id": "temporary_chat",
      "group": "control",
      "name": "Temporary or incognito chat",
      "question": "Is there a documented temporary, incognito or history-off mode whose conversations are not saved to history and not used for training?",
      "rubric": "YES if such a mode exists on the main web and mobile apps and its conversations are neither kept in history nor used for training, with any safety-retention period of 30 days or less; also YES if the vendor states that conversation content is never stored on its servers, so every chat already meets the condition (say so in the notes). PARTIAL if the mode exists but conversations may still be used for training, are retained longer than 30 days by the vendor or by model providers the vendor discloses, or the mode is limited to some plans; or if the only history-off option is an account-level setting rather than a per-chat mode. NO if the documents state that no such mode exists, or make a product-level statement that everything shared with the assistant is stored until the user deletes it; a retention-period disclosure alone is not such a statement. UNKNOWN if not addressed."
    },
    {
      "id": "memory_controls",
      "group": "control",
      "name": "Memory can be inspected and switched off",
      "question": "If the app keeps memory about the user across conversations, can the user view, delete and turn off that memory?",
      "rubric": "YES if the vendor states that the product does not remember anything across conversations, or if automatically generated memory can be viewed, deleted (item by item, or by editing and clearing a viewable memory summary) and turned off entirely. User-typed preference or custom-instruction fields are not memory for this question. PARTIAL if only some of view, delete and turn-off are documented; if memory can only be cleared all at once or only by deleting the source chats; if controls exist only on some platforms; or if a documented part of the memory cannot be inspected. NO if memory is kept and cannot be turned off or deleted. UNKNOWN if memory is not mentioned (silence never means there is no memory feature), or if a memory feature is documented but none of its controls are (say so in the notes)."
    },
    {
      "id": "user_deletion",
      "group": "control",
      "name": "Self-service deletion of chats and account",
      "question": "Can the user delete individual conversations and their whole account themselves, inside the product?",
      "rubric": "YES if both individual conversation deletion (message-level deletion counts for single-thread apps) and account deletion are self-service; for products without accounts, YES if conversation deletion is self-service (say so in the notes). PARTIAL if only one of the two is self-service, if either requires a request to the vendor, or if conversation content can only be removed by deleting the account. NO if neither is possible. UNKNOWN if not addressed."
    },
    {
      "id": "data_export",
      "group": "control",
      "name": "Self-service data export",
      "question": "Can the user export their conversations and account data themselves?",
      "rubric": "YES if a self-service export of conversations exists in the product, or conversations are stored only on the user's device and the documents describe how to copy or export them. PARTIAL if data is provided only on request (a data-access request), or the export excludes conversations. NO if no export or access is offered. UNKNOWN if not addressed."
    },
    {
      "id": "deletion_timeline",
      "group": "retention",
      "name": "Deleted chats purged within 30 days",
      "question": "When a user deletes a conversation or account, do the documents commit to removing it from the vendor's systems within 30 days, apart from legal or safety holds?",
      "rubric": "YES if a period of 30 days or less is stated, or deletion is described as immediate (for example 'deleted when the conversation is deleted'), or the vendor states that conversation content is never stored on its servers; exceptions must be limited to legal, security or safety obligations. PARTIAL if a longer fixed period is stated (a reactivation grace period counts as part of the period); if the period is stated only for some data (account but not chats, one mode only, inputs but not outputs); if the exceptions are broad (backups without a purge period, 'legitimate business purposes', or keeping de-identified copies for training); or if the documents contradict each other. NO if the documents state that deleted data is retained indefinitely or that deletion only hides the data. UNKNOWN if no period is stated."
    },
    {
      "id": "no_ads_use",
      "group": "sharing",
      "name": "Chats not used for advertising",
      "question": "Do the documents state that conversation content is not used to target or personalise advertising?",
      "rubric": "YES if the documents state that conversation content is not used for advertising; or the product shows no ads and the documents limit the use of conversation content to providing the service (no marketing use); or the vendor states it never stores or has no access to conversation content. Use of cookies, identifiers or account data (not conversation content) for the vendor's own marketing does not count against this question. PARTIAL if ads exist and conversation content is excluded only with exceptions, only in some regions, or only for some plans. NO if conversation content is used to select or personalise advertising. UNKNOWN if not addressed."
    },
    {
      "id": "no_sale_sharing",
      "group": "sharing",
      "name": "No sale or sharing for third-party marketing",
      "question": "Do the documents state that the vendor does not sell personal data or share it with third parties for their own marketing?",
      "rubric": "YES if the documents state that the vendor does not sell personal data and does not share it for third-party marketing, including under the 'sell' and 'share' definitions of US state privacy laws; sharing with processors acting on the vendor's behalf does not count against this, and a statement scoped to those legal definitions but offered to all users counts as YES. PARTIAL if the vendor discloses that it sells or shares (under those definitions) through advertising cookies or partners, even for its own advertising, and offers an opt-out; or if the statement is limited to some jurisdictions (for example a California-only notice). NO if personal data is sold or shared for third-party marketing without an opt-out, or conversation content is disclosed to advertising partners. UNKNOWN if not addressed."
    },
    {
      "id": "human_review_limited",
      "group": "sharing",
      "name": "Human review disclosed and limited",
      "question": "Do the documents disclose whether vendor staff or contractors can read conversations, and limit that to specific cases?",
      "rubric": "YES if the documents state that conversations are not read by humans, or that human access happens only in specific cases such as safety, abuse, legal requests, support requests initiated by the user, content the user reported or feedback the user submitted; or if the vendor states it never stores or has no access to conversation content. PARTIAL if human access is also disclosed for broader purposes such as quality, service improvement or model training, or the limits are vague; review of feedback the user chose to submit does not demote even when the vendor uses it to improve the product. A generic reserved right in the terms to review or remove content is not a disclosure of human access and leaves the cell unknown. NO if the documents state conversations are routinely reviewed by humans without stated limits. UNKNOWN if human access is not mentioned."
    },
    {
      "id": "no_precise_location",
      "group": "collection",
      "name": "No precise location collection",
      "question": "Do the documents state that precise geolocation is not collected, or collected only with explicit permission for a specific feature?",
      "rubric": "YES if the documents state that precise location is not collected, or describe the location data collected as only approximate (derived from IP address, city or region level) with no precise or GPS collection mentioned anywhere in the documents. PARTIAL if precise location is collected only with the user's explicit device permission, which can be declined, whatever it is then used for. NO if precise location is collected as part of normal use without a permission gate. UNKNOWN if location is not mentioned, or is mentioned without saying whether it is precise or approximate."
    },
    {
      "id": "rights_channel",
      "group": "collection",
      "name": "Documented channel for data rights",
      "question": "Do the documents give a concrete way to exercise data rights such as access, deletion or portability, available to all users?",
      "rubric": "YES if a privacy portal, form, in-product control or designated address (a privacy address, or a mailbox the documents name for rights requests, even if it is also used for support) is documented for exercising rights and offered to all users; a 'depending on where you live you may have rights' hedge does not demote when the channel itself is offered to everyone. PARTIAL if a channel is documented only for some jurisdictions (for example EU or California residents), if only a generic contact address not designated for rights requests is given, or if in-product controls cover only some rights and no channel exists for the rest. NO if the documents state that such requests are not accepted. UNKNOWN if not addressed."
    }
  ]
}
