232 APPS TRACKED · 227 CLAUSES ON FILE · 38 WITH NO CLAUSE TO QUOTE
READ SIDEWAYS

Nobody writes “we won’t say”. They write something else instead.

Every other page here answers one question about one company. This one asks a question about the companies. Of the 232 policies read so far, 39 discuss AI training in terms specific enough to quote and still leave you unable to tell whether you're being trained on. That isn't what silence looks like. It's what drafting looks like, and it comes in a small number of recognisable shapes.

155
graded A–F
91
train by default (D–F)
64
off by default (A–C)
39
quote a clause, resolve nothing

The promise is about somebody else

9 VERDICTS

Each of these companies wrote a real, unambiguous commitment that nobody will train on your data — and then scoped it to a third party, one data source, or one moment in the pipeline. Read quickly, it sounds like an answer. Read closely, the vendor's own general use is still unstated. Dashlane scopes by geography rather than by data: “We do not collect, use, or sell personal data for the purpose of training large language models” is the fourth item in a lettered run of US state disclosures — under-18s, then Nevada, then Connecticut, then retention — and it is the Connecticut entry. Connecticut law requires that disclosure, which explains why it is there and not why it appears nowhere else. Clue scopes by silence rather than by words: its AI features are opt-in on explicit consent and it states plainly that no data reaches Anthropic, then says it operates a foundation model “trained by Clue” without ever saying what on. Starling’s AI notice says “no external AI models are trained using Starling data”, and that what it stores about your use of its AI features goes to improve them. Outside models are ruled out. Its own aren’t mentioned. Flo’s Privacy Portal FAQ asks whether your data trains Flo’s AI, and answers that it “is not used to train third party AI models”. Of Flo’s own models it says nothing. In 2021 its CTO spoke of training models “on Flo's large user population”, and no later document repeats or withdraws that.

Zendesk
graded E · read the verdict
“If Customer uses Generative AI Services, Service Data will not be used by any LLM Provider for any purpose other than to provide and secure the AI Services.”
Khan Academy
unclear · read the verdict
“To provide further privacy assurances, our service agreements with the providers of artificial intelligence models used to power our AI-Enabled Features do not permit the providers to use Input data to train their models.”
Nightfall AI
unclear · read the verdict
“Google Workspace APIs accessed through our services are not used for developing, improving, or training our generalized artificial intelligence ("AI") or machine learning ("ML") models.”
Outreach
unclear · read the verdict
“Google Workspace Data is not used to develop, improve, or train AI and/or ML models.”
D-ID
unclear · read the verdict
“While in the storage, awaiting processing or deletion, the Applicative Data is not accessed for any purpose, including not accessed for model training.”
Clue
unclear · read the verdict
“Through AWS Bedrock Clue operates its own Foundation Model of the LLM, which is a basic version of the LLM trained by Clue for Clue's AI features.”
Beautiful.ai
unclear · read the verdict
“Data processed by our AI models will not be used to train public LLM models.”
Starling Bank
unclear · read the verdict
“No external company will keep access to any Starling data, and no external AI models are trained using Starling data.”
Flo
unclear · read the verdict
“"The data science department specifically relies on Amazon SageMaker for ML, leveraging powerful GPU-based machines offered by AWS to train models on Flo's large user population," says Bugaev.”

Answered, but not in public

1 VERDICT

Asked directly, Zendesk answered directly: it trains Service Data into its native features, and customers can opt out at any time by contacting their Account Manager. Both halves were new, and neither is in anything Zendesk publishes — "Account Manager" appears zero times in the addendum and zero times in the privacy notice. The grade rests on an email rather than on anything a customer could look up, which is precisely the position a reader who never writes a letter is left in. Glean stood here until 20 August 2026, when its commitment turned out to be published on its own trust centre, one click from the front page. Being told an answer is confidential is not evidence that it is.

Answered, and being re-graded

2 VERDICTS

These companies answer the question somewhere this site didn't read at first. Replit did it somewhere its privacy policy doesn't: a blog post, which says public Repls are used for AI training. Manus did it in the policy itself, in a revision of 28 September 2026: de-identified data may be used "to develop and improve our models", and the opt-out depends on where you live. Each entry quotes the sentence now and carries no grade yet, because this site writes to a company before it publishes an adverse finding about it. Replit is being written to at the address in its privacy policy, which this site missed until 10 October 2026. Manus was written to again on 2 October 2026 about the new wording. Each moves once the letter has gone and the reply, or the silence, is on record.

The switch is named. Its position is not.

8 VERDICTS

Eight companies name the setting that controls training — some of them precisely, down to the menu it sits in — and not one says which way it ships. ElevenLabs gives you the "Data use" menu under "Terms and Privacy"; Cursor names "Privacy Mode"; Strava names "Product Improvements" and says it is on web and mobile; Wispr Flow renamed its switch to "Improve the model for everyone". Canva is the sharpest case: it states defaults five times in its privacy policy, every one about who can see a design, and never about whether training is on. Read the privacy policies and you learn exactly how to turn it off, and never whether you need to. That gap is the whole difference between a C and a D on this site — C is for training that is on by default where the product tells you so, and these eight made it unavailable. The information is not withheld from you by accident; the sentence that would settle it is one line long and none of them has written it.

Figma
graded D · read the verdict
“For Starter and Professional, content training is set to 'on' by default - admins can opt out”
Canva
graded D · read the verdict
“and to train our algorithms, models and AI products and services using machine learning to develop, improve and provide our Service. You can manage the use of your data for training AI to improve our Service in the privacy controls page under your privacy settings ⁠ (opens in a new tab or window) .”
Cursor
graded D · read the verdict
“If you choose to turn off "Privacy Mode": we may use and store codebase data, prompts, editor actions, code snippets, and other code data and actions to improve our AI features and train our models.”
Wispr Flow
graded D · read the verdict
“It lets you choose whether Wispr may use your Dictation data-audio, transcripts, and edits-to evaluate, train, or improve AI models.”
Strava
graded D · read the verdict
“We use information to enhance the quality, reliability, and/or accuracy of our AI Features by creating, developing, training, testing, improving, and maintaining AI and ML models run by Strava or our service providers. We use aggregated, de-identified information for AI Features where possible for their purpose.”
ElevenLabs
graded D · read the verdict
“Opt-out of Processing Your Data for Training: You may opt out of our use of your Personal Data for training at any time by navigating to the 'Data use' menu in the 'Terms and Privacy' section of your ElevenLabs account.”
Grammarly
graded D · read the verdict
“You can decide whether Superhuman can use your user content to train our AI models by adjusting the available training control(s) in your account settings.”
Recraft
graded E · read the verdict
“We may use such information to train Recraft's own proprietary AI models, but you may disallow such use of your information by opting out in your account profile settings.”

“Improve our services”, and nothing narrower

9 VERDICTS

A purpose broad enough to cover training without ever naming it. These are the clauses where a company had the opportunity to write “we do not train on your content”, or “we do”, and instead wrote something that survives either reading. Commonwealth Bank is the variant worth noticing: it says recordings are reviewed “to improve AI-generated summaries of calls”, which describes improving an AI feature while leaving open whether the recordings are training data. MyFitnessPal is the same shape with the tooling named rather than the feature: personal information used “to improve and enhance our Services, including through the use of various technologies (e.g., business intelligence tools, machine learning systems, and artificial intelligence)”. It tells you what is being run over your food and exercise logs, and still not whether those logs are in a training set. Blink is the affiliate variant: video and audio from cameras in homes, collected “to provide and continually improve the products and services of Blink and its affiliates” — the affiliate being Amazon — with no narrower purpose stated anywhere.

Discord
unclear · read the verdict
“We may also use content posted in larger spaces to help us develop, improve, and power our services, including features that help you catch up on conversations and safety features that identify harmful content on the services and support the enforcement of our Terms of Service and Community Guidelines .”
Commonwealth Bank
graded F · read the verdict
“Sometimes we use your information, for example your transaction information, to train, develop, and in deployed artificial intelligence models for purposes such as:”
MyFitnessPal
unclear · read the verdict
“We use your personal information to improve and enhance our Services, including through the use of various technologies (e.g., business intelligence tools, machine learning systems, and artificial intelligence)”
Blink
unclear · read the verdict
“We collect your personal information in order to provide and continually improve the products and services of Blink and its affiliates.”
Expedia
unclear · read the verdict
“Feature generation To better understand our travellers and improve how our services work for you. To enrich other applications such as embeddings”
N26
unclear · read the verdict
“Personalization, insights, and product optimization: supporting the analysis of customer interactions, transaction data, and product usage data to provide insights, recommendations, or personalized information within the N26 App and to improve our products and services.”
Netflix
unclear · read the verdict
“We take feedback from every visit to the Netflix service (for example, what titles you start watching, if you finish those titles, and how you rate those titles, such as thumbs up) and continually update our algorithms with those signals to improve the accuracy of their prediction of what you're most likely to watch.”
Wise
unclear · read the verdict
“We use information from your interactions and other data sources to refine the accuracy and improve the output of the Wise Assistant.”
Hypotenuse AI
unclear · read the verdict
“Notwithstanding anything to the contrary, we shall have the right to collect and analyze data and other information relating to the provision, use and performance of various aspects of the Services and related systems and technologies (including, without limitation, information concerning Content and data derived therefrom)”

Training named, then qualified

5 VERDICTS

Training is stated outright — and then made conditional on something the same document does not resolve: terms that depend on your plan, or a feature description that stops short of saying what happens generally. Eufy’s qualification is scope: the one training clause in Anker’s group policy covers “public materials only” — community-forum posts — while the cameras the brand actually sells go unmentioned by it. Oura’s qualification is the object. The heading says Large Language Model Training; the sentence under it says personal data may be used to develop, test, improve and support “Oura’s own AI, machine learning, and large language model-powered features”, and the one after rules out selling it to train somebody else’s. Features, not models, and the word train used of its own systems nowhere — from a ring that holds heart rate, sleep stages and body temperature. It sat under the heading above until 12 September 2026, on a reading that had described only the second sentence.

The answer is in another document

1 VERDICT

The only “AI” in SimpliSafe’s privacy policy is the title of a different document: an “AI Addendum” governing “Shared Video Content”, which the policy names and does not contain. That is materially different from silence — the question has been answered somewhere, in writing — but the somewhere is not the policy in front of the reader, and until the addendum is captured and read, the answer might as well not exist. It is the obvious next fetch, and this entry will be re-read against it.

One word, two meanings, no definition

1 VERDICT

“Training” is an ordinary English word before it is a technical one, and a policy that uses it without saying which sense it means leaves the reader to guess. These are not evasions of the kind elsewhere on this page — there is no AI language anywhere near them — which is exactly why they cannot be resolved by reading further. Samsung is the case that matters most: recordings of a customer’s voice and face, used “for training and quality control purposes”, in a document that never uses the words “artificial intelligence” or “machine learning” once. Read as staff review it is unremarkable and probably correct. Read the other way it is the whole question. The document does not choose, so neither do we.

Mentioned only in passing

12 VERDICTS

AI appears, but as a product surface, a definition, or a bare confirmation that the company uses it — never as a use of your data. Nothing here can be read as permission to train, and nothing rules it out, which is why these stay unresolved rather than being graded on inference. Depop is the narrowest: “machine learning” appears exactly once in its policy, attached to catching fraud and spam, and the word “train” not at all — a marketplace holding listings, messages and photographs, describing the one use of ML that is about removing users rather than learning from them. Reddit is the loudest silence: its policy names OpenAI’s ChatGPT and mentions licensing fees for bulk access to content, and still never uses the word “train” — the one company here whose AI arrangements are a matter of public record. Six more joined in August 2026 and they share a shape worth naming: each is specific about what its AI *does* and silent about what built it. Pipedrive names the material — “Pipedrive communications with Clients and Users”. Workday runs AI over the content of its calls and meetings. Opera says its assistant is “powered by OpenAI and Google”, so it can tell you where your words go and not what happens to them there. Shopify is the most carefully drafted: machine learning glossed as automated decision-making, with a human kept in the loop — a promise about consequences that leaves inputs untouched. None of the six uses any form of the word “train”. Three more joined them, and each holds something people would not hand over lightly. Bumble names OpenAI as the provider behind its icebreakers and states a 30-day retention period — mechanism disclosed, purpose not. Headspace defines AI, separates the behind-the-scenes uses from the ones you opt into, and lists “machine learning algorithms” among the things your personal information powers; powering a model and training one are different claims, and only the first is made. Gong records sales calls and optimises AI on them under legitimate interest, which is what training accomplishes without being the word for it. Four more, and the last is the one to read. Sourcegraph logs “prompt titles, prompt categories, query-derived metadata” from its AI features and never says what the models learn from — granularity about the metadata that makes the silence about the inputs hard to read as oversight. Hinge and Tinder carry identical Match Group wording naming machine learning as a means of developing features, never as something data feeds. And Flo sends “Personal data relating to cycle dates, goals, symptoms” to a named sub-processor its own policy calls a “Machine Learning Development Platform”, without once using the word “train”: reproductive health data arriving somewhere models are built, and no sentence saying whether it builds them.

Unity
unclear · read the verdict
“We may use third-party services that utilize artificial intelligence or other advanced technologies to help us operate our business and support internal functions.”
NordVPN
unclear · read the verdict
“To provide this service, we connect to your bank using a third-party platform, retrieve your transaction history, and use an automated analysis, which may include machine learning, to derive statistical patterns that represent typical account activity.”
Depop
unclear · read the verdict
“In some cases to protect our Service, this detection and enforcement takes place automatically using machine learning tools (such as in the case of detecting fraud, phishing, commercial spam or users that may have previously been removed from our Service).”
Reddit
unclear · read the verdict
“That content and information may also be available in search results on internet search engines like Google or in responses provided by an AI chatbot like OpenAI's ChatGPT as well as reshared by others without permission or where Reddit has no control.”
DBS Bank
unclear · read the verdict
“Personal data can be collected from various sources (including through interfaces powered by artificial intelligence ("AI")) and processed by us.”
The Guardian
unclear · read the verdict
“The Guardian may use generative AI functionalities in our software and systems, including in our use of personal data.”
Shopify
unclear · read the verdict
“Our use of Machine Learning One of the ways in which we are able to help merchants using Shopify is by using techniques like "machine learning" (some laws, including certain EEA and UK laws, may refer to this as "automated decision-making") to help us improve our services.”
DuckDuckGo
graded B · read the verdict
“In addition, we have agreements in place with all model providers that further limit how they can use data from these anonymous requests, including not using Prompts and Outputs to develop or improve their models”
Bumble
unclear · read the verdict
“AI tool providers to assist with message prompts - product features - OpenAI (it only retains inputs and prompts for 30 days)”
Headspace
unclear · read the verdict
“To power machine learning algorithms that support our Platform”
Gong
unclear · read the verdict
“improving our products, offerings and the overall performance of our Services, including through the utilization and optimization of Artificial Intelligence and Machine Learning capabilities”
Tinder
unclear · read the verdict
“Developing and improving new features and services, including through machine learning and other technologies, and testing them out”

The simplest way not to answer

38 VERDICTS

Everything above is a document that speaks and still leaves you guessing. This is the larger group: 38 policies that never raise the subject at all. No clause is quoted on those verdicts because there was nothing to quote, only a record of what was searched for and not found.

Sorted by how often it happens, the order is the interesting part. The companies that build this technology answer the question most of the time: 25 of 25 AI assistants say something. The companies holding your salary mostly don't. 9 of 19 banks and payment firms say nothing. Every incumbent bank checked was silent until Lloyds Banking Group turned out to say “to train systems that learn from data” in its group notice, and one counter-example is worth more than the tidier sentence it replaced. Read the rate as an observation about19 companies, not about banking, which is a bigger claim than19 documents can carry.

finance
9/19 silent
storage
3/7 silent
health
2/5 silent
gaming
2/5 silent
travel
2/6 silent
home-security
2/7 silent
marketplace
2/7 silent
platforms
2/8 silent
privacy-tools
3/13 silent
comms
2/9 silent
media
1/6 silent
work
4/28 silent
education
1/7 silent
fitness
1/10 silent
dev
1/15 silent
design
1/23 silent
ai-assistants
0/25 silent
social
0/10 silent
productivity
0/19 silent

Categories with fewer than five verdicts are left out, since a handful of documents can't support a rate. Every silent verdict is listed under unclear, with the terms searched for on each one.

The pattern we looked for and did not find

A site built on the phrase “privacy paywall” should be honest about how often it's actually caught one. Across 232 verdicts, 5 tiers met the test of an opt-out you can only reach by paying, and 8 companies gave a better training default to a plan an ordinary user can't buy. They are Anthropic, Figma, Jasper, Lovable, Miro, OpenAI, Uizard, Zapier. But a few examples aren't a trend, and this page won't call it one until the evidence says so.

A6 verdicts
B50 verdicts
C8 verdicts
D54 verdicts
E4 verdicts
F33 verdicts

Every quotation above is word for word from an archived capture, checked against it when this page was built, and links to the verdict that cites it. If a company changes one of these sentences, it turns up in the change record. The companies whose policies say nothing at all about training are listed under unclear. The hedging vocabulary itself is collected under weasel words.