We show them the clause before you read it.
Every verdict here rests on a sentence the company published itself. Before publishing, and again when a grade changes, we write to the company with the quotation and the archived copy it came from, and invite a correction. What comes back is printed word for word. What doesn't come back is printed too.
Answering can lower a grade. When a company tells us something true that its own documents don't say, the entry records what is true, and sometimes what is true is worse than what we'd been able to infer. That has happened here, including to Recraft and Zendesk, both of which answered a direct question candidly and ended up graded lower than before they replied.
We don't soften a grade to reward candour. A grade describes what a reader is exposed to, not how a company has behaved towards us, and crediting companies that reply would make this site a measure of its own correspondence. What we can do is not spring it on anyone: say it here, say it in a line of the letter itself, and correct the entry the same day if an answer turns out to have been read wrongly.
Answered once, and asked again
A reply usually ends the exchange. Sometimes it opens a question the reply didn't settle, or the entry changed enough that the company should see it again. These are those, with the question still outstanding printed as we put it. They're listed because a question nobody is counting the days on isn't really a question, and because 8 of the entries on this site rest on answers we're still owed.
Whether the support desk was right that Free users cannot opt out. If they can, we have undertaken in writing to return this entry to D the same day.
Whether Hub content — models, datasets and Spaces — is used for training, and whether Hugging Face will publish the commitment at Hub scope rather than only for Inference Providers.
Will the Enterprise exclusion, the retroactive reach of the opt-out and the Zero Data Retention bar on subprocessors be published in the policy, and is a settings-based opt-out planned?
Whether MyFitnessPal will put "we have not and are not using your personal information to train any proprietary models" in the privacy policy, and whether "proprietary models" is meant to exclude third-party providers.
Whether the email opt-out route for website users will be published, and which way the extension's training control ships for a new account-holder.
Whether inputs to "Synthesia's own AI powered experiences", which the October revision of the privacy policy maps to enhancing "our models' capabilities and safety", train Synthesia's models.
Whether Uizard will comment on section 8.14 of its terms, now the letter has gone to security@uizard.io, the address its support desk named twice.
Whether Ellipsus publishes anything saying it can't read the writing it holds, which would make it an A. Its reply of 7 October says works are encrypted at rest and in flight.
Nobody to write to
Every other company on this page was sent the clause it was graded on. These weren't, and not by choice: we went looking for somewhere to send it and their own published policies name nowhere that could take the question. That's worth recording instead of leaving a blank space, because a company graded on a document it publishes, offering no route to challenge that grading, has told you something. We publish what we searched so you can check the claim. We don't publish the mailboxes.
GitHub's privacy policy publishes no email address. We re-read the live page on 25 August 2026 and found none there either. Contact is routed through web forms, which give no address to reply to and leave no record either side can quote. We could not write to GitHub, and this entry says so rather than leaving the space blank.
Google's privacy policy publishes no email address for an enquiry of this kind. Three addresses appear across its captured policies and each is scoped to something else: withdrawing from a contract, inquiries under Japan's personal information law, and a data-access route listed beside a Korean phone number. Google routes privacy contact through web forms, which have no reply address and no record. We could not write to Google, and this entry says so rather than leaving the space blank.
LinkedIn's data protection officer is reachable only through a web form. The address its policy once gave, dpo@linkedin.com, now answers every message with a notice that it is no longer active or monitored. We wrote to it on 21 August 2026 and the notice came straight back, so this entry records that LinkedIn could not be written to, rather than that it was asked and stayed silent.
Microsoft's privacy policy publishes no email address. We re-read the live page on 25 August 2026 and found none there either. Contact is routed through web forms, which give no address to reply to and leave no record either side can quote. We could not write to Microsoft, and this entry says so rather than leaving the space blank.
PayPal's privacy statement publishes two email addresses and neither can take a question about its training clause. One belongs to a regulator, the Nevada Attorney General's consumer protection bureau, and writing there would read as filing a complaint rather than asking for a correction. The other is the privacy mailbox for PayPal's South Korea entity, listed with a Seoul address and a Korean phone number. We could not write to PayPal about the policy graded here.
TikTok's privacy policy publishes no email address. We re-read the live page on 25 August 2026 and found none there either. Contact is routed through web forms, which give no address to reply to and leave no record either side can quote. We could not write to TikTok, and this entry says so rather than leaving the space blank.
X's privacy policy contains no email address at all. The only address we could find anywhere on the site is a copyright mailbox, which would not reach anyone able to answer a question about the training clause. We could not write to X, and this entry says so rather than leaving the space blank.
Lloyds Banking Group's privacy policy publishes no email address. We re-read the live page on 25 August 2026 and found none there either. Contact is routed through web forms, which give no address to reply to and leave no record either side can quote. We could not write to Lloyds Banking Group, and this entry says so rather than leaving the space blank.
Miro's privacy policy publishes no email address. We re-read the live page on 25 August 2026 and found none there either. Contact is routed through web forms, which give no address to reply to and leave no record either side can quote. We could not write to Miro, and this entry says so rather than leaving the space blank.
Wispr Flow's privacy policy publishes no email address. We re-read the live page on 25 August 2026 and found none there either. We could not write to Wispr Flow, and this entry says so rather than leaving the space blank.
Uber's captured privacy notice publishes no email address, and Uber routes privacy contact through in-app and web forms. We could not write to Uber, and this entry says so rather than leaving the space blank.
eBay's User Privacy Notice publishes no email address. Contact is routed through the eBay Privacy Center, and the data protection officers are named on a further page behind it — which gives no address to reply to and leaves no record either side can quote. We could not write to eBay, and this entry says so rather than leaving the space blank.
Hotels.com's privacy statement publishes no email address. Expedia, Inc. is named as the party responsible for the data, and contact is routed through web forms — which give no address to reply to and leave no record either side can quote. We could not write to Hotels.com, and this entry says so rather than leaving the space blank.
Midjourney's privacy policy names privacy@midjourney.com, and that mailbox answers every message with a notice that it is not monitored and no one will respond. The only other route it offers is a data-deletion form. We wrote to the address on 11 September 2026 and the notice came back the same minute, so this entry records that Midjourney could not be written to rather than that it was asked.
Google publishes no email address for an enquiry of this kind on the Gemini privacy hub or in its privacy policy; contact is routed through web forms, which have no reply address and no record. We could not write to Google about this entry, and it says so rather than leaving the space blank.
Microsoft's privacy statement publishes no email address. Contact is routed through web forms, which give no address to reply to and leave no record either side can quote. We could not write to Microsoft about this entry, and it says so rather than leaving the space blank.
What they said
6 of these replies corrected us: the company pointed at an opt-out that was in its published policy all along and that this site had missed. Those are marked “corrected us”, not filed as something the company changed, because nothing on their side did. Replies that identified themselves as machine-generated are marked too. The substance was checked either way, but “Warp said so” shouldn't be read as a person at Warp saying so.
“Thank you for reaching out and reviewing Bitwarden! Correct, Bitwarden cannot access Vault data.”
“It is not accurate to state that “Chegg trains its own and third-party data AI models on what students submit.” While the policy language that you quoted is accurate, it is not complete. Chegg’s policy has always been that it does not use content submitted by users Chegg knows to be under 18 to train or improve any artificial intelligence model, and Chegg does not disclose content from such users to third parties for their own purposes. [...] we have since made that clear, even though this protection was always a part of Chegg’s practices.”
“Descript does not use any user data for AI model training unless the user has explicitly opted in via the "Share data with Descript" setting. [...] For Enterprise drives, data sharing is disabled by default and cannot be enabled. No user data is shared with sub-processors (such as OpenAI) for the purpose of training their AI models.”source ↗
“To clarify, D-ID does not use your resources or personal information to train, fine-tune, or improve our AI/ML models, or for any other purpose unrelated to providing our services. As mentioned previously, the resources you upload to your D-ID account, including images, videos, audio, and other user-provided content, are used to provide the services you request and are not accessible to others.”source ↗
“Based on the current policy language you quoted, your reading is supported in part: Duolingo may generate, record, and store audio recordings or transcripts of text and audio submitted when using Video Call or other AI-enabled features ... Users may also choose not to share their audio with Duolingo for product improvement purposes within the app Settings ... One important distinction is that the available opt-outs in the published materials are not limited to Google Analytics. [This reply was generated by AI.]”
“This is explicitly stated in bold just before the section of our Privacy Policy that you elected not to include: "We will never use your writing to train AI models." [...] There is no opt-in because there is no model in Ellipsus to train. Period. [7 October 2026:] You cannot opt into training. There is no training to opt into. [...] Additionally, works are encrypted at rest and in flight, so again: the only way a model could ever see the writing [...] is if a human being (e.g. yourself) manually puts it into some other model somewhere [...]”
“I have actually now added this line into our privacy policy. You can see this in the section "3rd Party AI connections".”source ↗
“The Team and Business controls are in our Terms of Use. Section 4.5 (AI Model Training) ... Section 4.7 covers our analytics licence and states that it "DOES NOT include using Your Content to train AI Models unless permitted under Section 4.5." ... By plan: Free, Plus, Pro and Ultra: training is on by default. Users can opt out themselves at any time in the application settings under "data control". No cost and no support request is needed. Team, Business and Enterprise: excluded from training automatically. The setting is locked and cannot be switched on.”
“I lead Legal at Glean Technologies Inc. Glean Technologies Inc. does not train on customer/user data, this is clearly stated in our security documents, which are confidential.”source ↗
“Enterprise Accounts: Customer data on Enterprise plans is strictly excluded from AI model training. Non-Enterprise Accounts: Data on non-Enterprise plans may be used to improve general AI models, but users can opt out at any time by contacting privacy@heygen.com. This opt-out applies retroactively to previously processed data. Third-Party Subprocessors & Vendors: All third-party AI vendors and subprocessors integrated with HeyGen operate under Zero Data Retention (ZDR) policies and are prohibited from training models on customer data.”
“Hugging Face does not store any user data for training purposes. Please refer to our Privacy Policy: https://huggingface.co/privacy or Security & Compliance: https://huggingface.co/docs/inference-providers/en/security for further information.”source ↗
“Regarding whether Krea uses customer data to train AI models, Krea states it does not. For Business and Enterprise plans, Krea commits that Inputs and Outputs are not used to train its AI models. [...] If you were looking specifically at the general Terms of Use and Privacy Policy, those pages do not spell this out. The training policy is published in the Business Terms and the Enterprise page above.”
“Thank you for your question. MyFitnessPal uses tools like artificial intelligence and machine learning systems to enhance and personalize our Service. However, we have not and are not using your personal information to train any proprietary models at this time. For more information, please see the How We Use Personal Information section in our Privacy Policy.”
“For services for individuals, such as ChatGPT and Codex, OpenAI may use content to train our models. Users can opt out of model training by either: Turning off “Improve the model for everyone” under Settings → Data Controls in ChatGPT; or Selecting “Do not train on my content” through our privacy portal. [...] After opting out, new conversations will not be used to train our models. [...] For our business offerings, including ChatGPT Business, ChatGPT Enterprise, and the API Platform, OpenAI does not train on inputs or outputs by default.”
“So yes: my earlier phrasing of "AI Data Usage toggle" was not the best label for the published control. The current help-center wording uses "AI Data Retention" [...] On the retention point, your reading matches the published guidance. I do not have a separate route to name for removing training data that was already collected before the opt-out. The available control applies going forward.”source ↗
“While the excerpt of the Learneo Privacy Policy (applicable to Quillbot) included in your inquiry is accurate and applicable, we would like to help clarify your “finding” statement. [...] For extensions users on versions 4.37.0 or above, we offer two data controls to opt out of [...] allowing Quillbot to use text inputs to train the models that power our AI tools. Users of any of our website-based tools can submit a request to object or opt-out of the use of text inputs or training purposes by email to privacy@quillbot.com. [...] Quillbot does not train on any text inputs from Team Plan users.”
“Recraft uses user-generated content—such as images created or uploaded, and text entered in prompts or chat mode—to improve its AI models by default. However, there is an opt-out control available: On the Pro plan, users can opt out of model training by turning off the "Help improve Recraft" toggle in their Profile settings. [...] Training opt-out is not available on the Free plan. For Team plans, opt-out is applied by default. API inputs and outputs are never used for model training.”
“Synthesia does not develop large language models or general purpose AI models. [...] We pre-train these AI components on performances by paid actors we commission, on performances that are publicly available, and on performances we license. We do not pre-train them on customer data. [...] Beyond that consented fine-tuning step, Synthesia does not use any other customer data, including the inputs to the product or the videos produced with it, to pre-train its AI models.”
“We’re not able to provide commentary or interpretation regarding Udio’s Terms of Service or privacy policies through the Support team. The published terms and policies are the appropriate source for information about how content and data may be used. [Asked for a legal or privacy contact:] We don’t have a legal or privacy contact that Support can provide for this type of inquiry. We appreciate you reaching out, but we’re not able to offer additional commentary beyond our published Terms of Service and privacy policies.”
“Currently, such cases fall outside of our scope of support. Please be assured that all security reports are treated with the utmost seriousness and are promptly forwarded to our dedicated security team. They can be contacted at security@uizard.io.”
“Warp has Zero Data Retention (ZDR) agreements with LLM providers like Anthropic, OpenAI, and Google, meaning they don't retain or train on any customer AI data. For data collected by Warp, you can opt out of telemetry and data collection anytime by going to Settings > Privacy and toggling off "Help improve Warp" and "Send crash reports." On Business and Enterprise plans, data collection is off by default. [This reply was generated by AI.]”
“We may use your content and interactions with Grok (e.g., prompts, searches, and other materials you submit) along with Grok's responses to train our models. ... You control whether your data is used for training Grok. ... When using Private Chat, where available, your content and interactions are not used for model training. Similarly, we do not use content from our business and enterprise customers to improve our models.”
“We do not have that opt-out information published on a page at the moment [...] Currently, opt-outs are supported for paid accounts only. Opt-outs are respected for customers who sign up for Free Trials or Proof of Concepts (PoCs) of specific features or functionality through their paid accounts. [Asked whether a standalone free trial, not taken out under a paid account, has any route to opt out:] You are correct, the answer is no.”
Asked, reply not yet due
These were written to within the last 14 days. They're listed because the invitation is on the record from the day it's sent, but not under the heading below, because a company can't be said to have declined to comment before it's had a chance to comment.
Asked, and did not answer
Each of these was sent the clause it was graded on and the archived copy behind it, and invited to correct anything wrong. None has replied. Read it as declining to comment, not as agreement.
If you work for a company on this site and something here is wrong, you don't need to wait to be asked. Send the paragraph and we'll publish the correction beside the clause: how to file one. We'd rather be corrected than be quoted approvingly.