232 APPS TRACKED · 227 CLAUSES ON FILE · 38 WITH NO CLAUSE TO QUOTE

Which marketplaces train AI on your data?

Of the 7 marketplaces on file, 3 are graded, and every one of them trains on your data by default. The other 4 have a policy that doesn't say either way. All 3 graded entries are D. SHEIN scores lowest for exposure and Vinted highest.

7 APPS TRACKED IN THIS CATEGORY · WORST FIRST

Do they train on your listings, your messages and what you bought?

A marketplace holds what a shop never sees: the photographs you took of your own things, the description you wrote, the messages you exchanged with a stranger to settle a price. And the record of everything you bought. These apps are graded here on one narrow question: does any of that train a model, and how hard is it to stop. Read together, the ones that say enough to grade share a shape. Training that runs unless you act, and a right to object that is, with one regional exception, exercised by writing to the company, not by a switch. The rest never use the word.

The ones that say it, and give you a right to object

eBay says it uses personal data to “train, test, validate, and align our own AI models as well as third-party AI models”, under legitimate interest, and extends the right to object to AI training by name. Accounts in the EEA, the UK and Switzerland get a switch in settings for AI development and training, read on a signed-in account, not archived, and set to Yes. Everyone else objects by request through the eBay Privacy Center. The mitigation is specific: “filtering, data masking, differential privacy techniques”, as eBay assesses them.

Vinted builds “internal machine learning models” from member data and adds a sentence most policies don’t: “we neither sell them nor make them otherwise available to third parties”. That’s a commitment about distribution, not about training. The models are built either way. The basis given is legitimate interests, which is what makes the right to object reach the clause. No setting governs it: the route is an email or the help-centre form, and nothing in the document turns model development off for your account.

SHEIN’s is narrower and better documented than most of the group. The scope is customer-service chat, used to “train our internal service-quality models”. The chats are de-identified first and the legal basis is stated. The objection is set out explicitly: “You have the right to object at any time to the use of your customer-service chat content”. Objecting is the remedy, through the Privacy Center, and the processing runs until you do. The same section says human reviewers may read the chats to validate the AI’s output.

The ones that never use the word

Depop’s policy never uses the word “train”. Machine learning appears once, as a tool for “detecting fraud, phishing, commercial spam”, not as anything built from your data. The document is precise about the listings, messages, photographs and location it holds, and about running recommendations on them. On whether any of it reaches a model it’s silent. It isn’t silent about the price of leaving the recommender: “you must close your Depop account and cease using our Service”. Its help centre adds that its recommendation systems “learn your interests quickly from the listings you view, like, add to bag, and buy”, which is the same shape: learning, without the word train.

Etsy publishes its policy as a PDF per region. The UK and US versions were read side by side. Neither contains “train”, “machine learning” or “artificial intelligence”. What the policy does describe is “automated processing techniques and/or manual (human) review” for safety, information used “to improve our Services”, and personalised recommendations and advertising. Advertising isn’t training. Whether listings, messages or purchase history train a model, it never raises, and a document that doesn’t raise the subject can’t be read either way.

Shopify explains its machine learning as what some laws call “automated decision-making”, used “to help us improve our services”, and commits either to keeping a human involved or to confining it to decisions without legal effect. App store ordering is the example given. That’s a statement about consequences, not about inputs. No form of “train” appears in the document. A merchant learns their data may drive a decision, and not whether it builds the thing making it.

Temu’s ranking and recommendation of goods is the whole of the shopping experience, and the policy is detailed about the behavioural data it collects to drive it. What it never does is use the words: no form of “train”, no “machine learning”, no “artificial intelligence”, no bare “AI”. The only “model” in it is your phone’s. Silence is a finding about the document, not an accusation.

Every quotation above is the company’s own words, read from a dated copy of its document kept on file. The check date and the copy are on each verdict, and every grade on this page is the one on the company’s own entry. UNCLEAR is a finding about the document, never an accusation about the company. A policy that comes to answer the question is re-read against it. How grades are set · Right of reply

Side by side

2 pairs of marketplaces people choose between, with both verdicts on one page.