Contract trap · Privacy policy
Content used for AI training
The policy or ToS grants the operator (and sometimes affiliates/third parties) the right to use messages, documents, images, calls, voice, code and usage data to 'train, improve or develop' machine-learning/AI models, usually opt-out only (email, hidden setting) or with no opt-out, and frequently introduced by a quiet terms update over previously collected data.
- Severity
- Serious
- How often it turns up
- Common
- Holds up?
- Depends where you are
- Clause phrases
- 22
What it looks like in a contract
Redline matches these phrases against your document verbatim. Drafters rarely invent new wording — they copy it, which is why the same sentences turn up across unrelated contracts.
In English-language contracts
- to train, tune and improve our machine learning and artificial intelligence models
- Service Generated Data
- we may use your content to develop new products and features
- generative AI
- for use with and training of our machine learning
- you grant us a license to use your content for machine learning
- you can opt out by emailing
- unless you opt out
- de-identified or aggregated data may be used to train
- including third-party AI models
In Russian-language contracts
- для обучения моделей машинного обучения
- для обучения моделей искусственного интеллекта
- для обучения нейросетей
- нейросетевых моделей
- для улучшения и развития Сервиса
- в целях совершенствования Сервиса и разработки новых продуктов
- Пользователь предоставляет право использовать Контент для обучения
- Пользователь соглашается на использование Контента для обучения
- анализ содержимого автоматизированными и ручными методами
- данные могут использоваться для обучения алгоритмов
- обезличенные данные могут использоваться
- отказаться можно, направив запрос
Check your own contract
Paste a clause, a page or the whole document. Nothing leaves your browser: the matching runs here, on this page, against the phrases above.
Why it bites
Confidential documents, faces, voices, client data and private chats become permanent model weights that cannot be deleted or 'un-trained'; may breach NDAs, professional secrecy and GDPR; opt-out is hidden, regional or by email and windows expire (Meta EU 27 May 2025).
Is it enforceable where you are
The same clause can be routine in one country and void in another. What follows is what the law says where you are — not advice on your particular contract.
In the EU and the UK, the GDPR governs the legal basis, the retention period and your right to erasure; in the US, state privacy laws (CCPA/CPRA and its successors) give an opt-out of sale and sharing.
United States
Lawful if disclosed prospectively; FTC (Feb 2024): retroactively changing terms to permit AI training may be unfair or deceptive; FTC orders have required deletion of models trained on unlawfully obtained data (Everalbum 2021, Rite Aid, Amazon Alexa); CCPA/CPRA opt-outs for some uses.
- Cited
- CCPA
- CPRA
- FTC
European Union
Needs a lawful basis; DPC forced X to suspend and delete EU data used for Grok (Aug-Sept 2024); Meta trains on EU public content under legitimate interest with a right to object (from 27 May 2025) — noyb sent a cease-and-desist and filed complaints challenging that basis (May 2025); LinkedIn EU training from 3 Nov 2025 with opt-out; new purpose incompatible with the original = GDPR Art 6(4) issue; AI Act GPAI copyright-transparency obligations apply to model providers.
- Cited
- GDPR Art 6(4)
United Kingdom
UK GDPR; ICO consultation series on generative AI (2024) requires a lawful basis and honouring objections; LinkedIn paused UK training in Sept 2024 after ICO engagement.
- Cited
- GDPR
- ICO
Russia
Обучение ИИ — новая цель обработки, требующая отдельного конкретного согласия (ст. 5 ч. 2, ст. 9 152-ФЗ); 233-ФЗ allows use of properly обезличенные data for AI without consent, so watch for «обезличенные» combined with «обучение моделей»; ст. 16 п. 4 ЗоЗПП — нельзя обусловливать услугу предоставлением ПД, не нужных для договора.
- Cited
- 152-ФЗ
- 233-ФЗ
- ст. 16 п. 4 ЗоЗПП
- ст. 5 ч. 2
- ст. 9
Where this has actually happened
Regulator actions, court rulings and the contracts they were fought over.
- Zoom ToS §10.4 (Aug 2023) — 'Service Generated Data' for AI training; reversed after backlash, no training on customer content without consent
- Adobe Terms of Use update (June 2024) and Slack privacy principles controversy (May 2024) — customer data used for ML by default, opt-out only by emailing
- LinkedIn — generative-AI training on by default from 18 Sept 2024; EU/EEA/CH training from 3 Nov 2025; Meta AI training on EU public content — objection deadline 27 May 2025
- DPC v. X (Twitter International) — High Court proceedings Aug 2024; X agreed to stop using and delete EU users' data collected 7 May-1 Aug 2024 for Grok
- X (Twitter) ToS effective 15 Nov 2024 — content licence 'for use with and training of our machine learning and artificial intelligence models'; WeTransfer ToS, 1 July 2025 — machine-learning licence removed 15 July 2025 after backlash
- FTC Technology Blog, Feb 2024 — 'quietly changing your terms of service could be unfair or deceptive'
What to do
In order, from the thing that takes a minute to the thing that takes a letter.
- Search the terms for 'train', 'machine learning', 'AI', 'Service Generated Data', 'improve our models'
- Opt out immediately and keep proof (email, screenshot)
- Use enterprise/API tiers or DPAs with explicit 'no training' commitments and never upload NDA material to consumer tiers
- EU/UK: object under GDPR Art 21 before any announced deadline and complain to the DPA
- RU: обучение ИИ — новая цель, требующая отдельного согласия (ст. 5 ч. 2, ст. 9 152-ФЗ).
Traps that travel with it
Drafters who use one of these usually use several.