clause.watch Contracts Recent changes Start monitoring

Monitored company

appcues

clause.watch tracks 3 legal documents published by appcues, re-reading each one every six hours. Below is what each document covers, in plain English.

Privacy Policy

18,093 characters · Read the original

Privacy Policy Overview

Last updated: May 2026. This summary explains the practical effects of the policy. It is not a substitute for the full policy or any agreement with Appcues.

1. Data Collection & Usage

Appcues processes four main categories of information:

  • End-user PII: Information that can identify an individual, including:
  • Profile information submitted through the customer’s use of Appcues.identify()
  • Browser and environment information
  • Current page URL and title
  • Application interaction data, such as clickstream or usage activity, when linked to an identified user
  • End-user Appcues Data: Aggregate or unidentified information about interactions with Appcues experiences, such as whether a flow or tooltip was displayed or used. Survey and form responses may become PII if they identify a person.
  • Customer PII: Names, email addresses, account information, authorized team-member details, and information about customer use of Appcues. Appcues does not store payment-card information; it uses a PCI-compliant payment processor.
  • Customer Aggregate Data: Non-PII statistics, such as active-user counts and the number of experiences shown or published.

Appcues uses this information to provide, personalize, secure, and analyze its services; display analytics; support customers; manage business relationships; and conduct direct marketing and sales support for existing customers.

2. User Rights

Depending on applicable law, users may have rights to:

  • Access, correct, amend, or delete their PII
  • Restrict or object to certain uses or disclosures
  • Request information about categories or specific items of PII
  • Opt out of materially different uses or sharing
  • Receive responses within legally required timeframes, generally without charge

Requests may be sent to support@appcues.com, with account or user details where applicable.

Important limitation: If Appcues processes data on behalf of your employer, application provider, or another customer, that organization generally controls the data. Appcues may refer your request to that organization, so users may need to exercise rights directly with the customer.

3. Third-Party Sharing

Appcues says it does not sell PII and does not share PII for third parties’ direct marketing or cross-context behavioral advertising.

It may disclose data to:

  • Service providers supporting the Appcues platform or business
  • Optional third-party integrations enabled by the customer
  • Other providers at the customer’s direction
  • Payment processors
  • Authorities when legally required or for fraud, safety, illegal activity, or terms enforcement
  • A successor company in a merger, acquisition, or similar ownership transfer

Customer-configured integrations can result in data leaving Appcues and being sent to another provider. Users should review their organization’s settings and privacy notices.

4. AI/ML Training

The policy does not state that user data is used to train artificial-intelligence or machine-learning models, nor does it expressly prohibit such use. It describes analytics, service delivery, business operations, and customer-directed sharing, but provides no specific AI-training commitment. Users seeking certainty should request clarification from Appcues or their organization.

5. Key Obligations and Risks

Customers—not only Appcues—have responsibility for privacy configuration under the Shared Responsibility Model. Customers enabling clickstream or application-interaction collection must:

  • Review what their application exposes
  • Configure collection limits appropriately
  • Comply with privacy laws and contractual duties to their own users
  • Control whether browser history and interaction data are collected

Users should understand that URLs, page titles, form responses, and interaction data could contain sensitive information if the customer configures the product improperly.

Some non-identified data that could later become identifiable may be retained for up to two years. Deletion may also leave information in archival backups until deleted in the ordinary course of business. Legal or contractual requirements may delay deletion.

6. Liability & Disputes

This privacy policy does not provide a detailed general limitation-of-liability clause. It does state that Appcues may disclose information to comply with lawful government requests, including law-enforcement or national-security demands.

For individuals in the EEA, UK, or Switzerland whose complaints remain unresolved, Appcues commits to a U.S.-based alternative dispute-resolution process. Under specified conditions, binding arbitration may be available after other procedures are exhausted.

7. Changes

Appcues may change the policy at any time. Changes become effective immediately when posted on its services or website. Continued use after posting indicates acceptance. The policy does not promise individual notice, email notice, or an advance notice period.

Terms of Service

17,939 characters · Read the original

Appcues Terms of Service: User-Focused Overview

*This summary is based only on the Terms of Service provided. It is not legal advice. The document refers to a separate Privacy Policy, but that policy was not included, so important data-handling details cannot be confirmed.*

1. Data Collection and Usage

The Terms expressly require or contemplate collection of:

  • A valid email address and other registration information.
  • Account credentials and payment/card information for paid accounts.
  • “Electronic data and information” submitted by or for you to the Services.
  • Content created or uploaded in your Appcues account.
  • Usage information relevant to subscription limits, such as Monthly Active Users and Page Views.

The Terms state that personally identifiable information is governed by Appcues’ Privacy Policy, but they do not explain:

  • What specific personal data is collected;
  • The purposes and legal bases for processing;
  • How long data is retained;
  • Where data is stored or transferred;
  • Security safeguards;
  • Whether tracking technologies or analytics are used.

Appcues says it may access or remove content that violates the Terms or is otherwise objectionable, and may cooperate with law enforcement. It also may retain residual information in backups or archives after cancellation or termination.

The statement “We are GDPR Compliant!” is not accompanied by details about GDPR roles, processing agreements, transfer mechanisms, or specific user rights.

2. User Rights

The Terms provide that you retain ownership of content submitted or created exclusively in your account. Appcues receives only the limited rights needed to provide the Services.

However, the Terms do not describe specific privacy rights such as:

  • Access, correction, deletion, or portability;
  • Objection or restriction of processing;
  • Withdrawal of consent;
  • Complaint procedures;
  • How to submit data-rights requests.

Those rights, if available, must be determined from the separate Privacy Policy or applicable law.

You may cancel your account, but cancellation generally takes effect at the end of the current service period. Cancellation or termination may permanently delete account content, and Appcues warns that it may not be recoverable.

3. Third-Party Sharing

The confidentiality provisions generally restrict disclosure of confidential information to third parties, but permit access by:

  • Employees and contractors who need the information and are bound by confidentiality obligations;
  • Legal counsel and accountants;
  • Authorities where disclosure is legally compelled.

The Terms also contemplate third-party partners or suppliers in the liability provisions, suggesting that vendors may support the Services. They do not identify those vendors or explain their data access.

Appcues may cooperate with law enforcement and may investigate or prosecute violations. The Privacy Policy should be reviewed for service providers, advertising/analytics partners, international transfers, and other disclosures.

4. AI/ML Training

The Terms do not state whether customer content, personal data, usage data, or communications are used to train artificial-intelligence or machine-learning models.

Accordingly, users should not assume either that data is excluded or that it is used. This should be confirmed in writing or in the Privacy Policy, particularly if the account contains confidential, regulated, or customer data.

5. Key User Obligations and Restrictions

Users must:

  • Be human and provide accurate registration information;
  • Protect account credentials;
  • Pay fees and keep payment details current;
  • Use the Services only for authorized internal business purposes;
  • Comply with laws, copyright rules, and the Acceptable Use Policy;
  • Stay within product, user, page-view, and other subscription limits.

Prohibited conduct includes reselling or sublicensing the Services, uploading unlawful or infringing material, violating privacy rights, transmitting malicious code, disrupting the Services, bypassing usage limits, copying or mirroring the platform, reverse engineering, and building a competing product.

Exceeding usage limits may trigger automatic charges or require an upgrade.

6. Liability and Disputes

The Services are provided “as is” and “as available,” with broad disclaimers of warranties, including fitness, merchantability, and non-infringement.

Neither party is generally liable for lost profits or indirect, incidental, consequential, special, or exemplary damages. Total liability is capped at the fees paid or payable during the preceding 12 months. Payment obligations are not capped.

The parties have reciprocal indemnification obligations for certain intellectual-property and legal claims, but those obligations are subject to notice and control-of-defense requirements and are the exclusive remedy for covered claims.

Disputes are governed by Delaware law, regardless of the user’s location. The Terms do not specify a required court, arbitration process, or venue.

7. Changes and Termination

Appcues may change the Terms at any time, potentially with or without advance notice. It says it will make reasonable efforts to email users about material changes, as determined by Appcues. Continued use constitutes acceptance.

Appcues may modify, suspend, discontinue, or reprice Services. It may suspend or terminate accounts for violations, and may terminate inactive free accounts after 60 days. Paid cancellations generally cannot be made mid-term and are nonrefundable.

Website Terms of Use

5,496 characters · Read the original

Website Terms of Use: Key Points and Risks

Document: Appcues, Inc. Website Terms of Use

Last updated: June 29, 2023

> Important limitation: These Terms incorporate Appcues’ separate Privacy Policy, but that policy is not included here. As a result, the Terms alone do not provide a complete description of data practices or GDPR rights. The opening statement “We are GDPR Compliant!” is not a substitute for reviewing the Privacy Policy or assessing the company’s actual compliance.

1. Data Collection & Usage

The Terms state that users must provide:

  • A valid email address when registering
  • Any other information Appcues requires during registration
  • Account and password information
  • Any other personally identifiable information submitted through the Site

The Terms say that personally identifiable information is governed by the Privacy Policy, but they do not explain:

  • What categories of data are collected
  • Why data is collected or how long it is retained
  • Whether cookies, analytics, advertising technologies, or tracking tools are used
  • Whether data is transferred internationally
  • How account or usage data is secured

Users should review the Privacy Policy before creating an account or submitting information.

2. User Rights

No specific privacy rights are described in these Terms. The Terms do not explain how users can:

  • Access, correct, delete, or export their data
  • Withdraw consent or object to processing
  • Restrict processing
  • Opt out of marketing communications
  • Complain to a data protection authority
  • Request information about automated decision-making

Any such rights would need to be determined from the Privacy Policy and applicable law, including potentially the GDPR or other local privacy laws. The Terms also do not provide a specific privacy-request contact process.

3. Third-Party Sharing

The Terms do not explain whether Appcues shares personal data with:

  • Service providers and contractors
  • Affiliates or corporate parents/subsidiaries
  • Analytics, hosting, security, or payment providers
  • Advertising or marketing partners
  • Government authorities

Appcues reserves the right to cooperate with law enforcement when investigating Terms violations. The liability clause also refers to “third-party partners or suppliers,” but this does not itself authorize or describe data sharing. The Privacy Policy should be consulted for details.

4. AI/ML Training

The Terms contain no statement addressing whether user information, account content, Site activity, or submitted materials are used to train artificial intelligence or machine-learning models.

Users should not assume either that data is used or that it is excluded. Anyone concerned about AI training should look for a separate AI/data-use policy or obtain written clarification from Appcues.

5. Key User Obligations and Restrictions

Users must:

  • Be human and at least 13 years old
  • Provide accurate registration information, including a valid email
  • Protect account credentials and passwords
  • Use the Site lawfully and only for authorized purposes
  • Comply with applicable laws, including copyright law
  • Maintain no more than one free account per person or legal entity

Users may not use bots or automated registration methods, copy or reuse the Site’s code or visual design without written permission, or engage in conduct violating the Terms.

Appcues may investigate violations, remove content, suspend or cancel accounts, and bar access without notice. It has no duty to prescreen or monitor activity, but may do so at its discretion.

6. Liability and Disputes

Liability limits

The Site is provided “as is” and “as available,” without warranties such as merchantability, fitness for a particular purpose, or non-infringement.

Appcues disclaims liability for lost profits and special, indirect, incidental, consequential, or exemplary damages. Its total liability for claims relating to the Terms or Site is capped at $50, even if it was warned that damages were possible.

These limitations may be restricted by applicable law, but they create substantial risk for users.

Indemnification

Users must defend and reimburse Appcues and related parties for third-party claims, including reasonable attorneys’ fees, arising from the user’s Site use or Terms violations. This obligation could expose users to significant costs.

Governing law

Delaware law governs, regardless of the user’s location. The Terms do not specify a court location, arbitration requirement, or formal dispute-resolution procedure.

7. Changes to the Terms and Site

Appcues may modify or discontinue the Site, temporarily or permanently, with or without notice.

It may change the Terms at any time, effective with or without prior notice. Appcues says it will use reasonable efforts to email users about material changes, as determined by Appcues. Continued use after changes means acceptance. Users who disagree must stop using the Site immediately.

Change history

2026-09-06 · Privacy Policy

grew 3.5% · Observed by clause.watch

Key Changes and Risks

1. Policy date and contact information

  • The policy is now labeled “Privacy Policy — Last updated: May 2026.”
  • The contact section is expanded to invite questions about:
  • The privacy policy;
  • Collection and use of personal information; and
  • Exercising rights under the policy and applicable law.
  • The support email address remains support@appcues.com.

Risk/impact: The updated date may trigger contractual or notice requirements under applicable privacy laws or customer agreements. The revised contact language could be helpful for rights requests but does not itself create specific response obligations or procedures.

2. Security and privacy framework substantially reframed

The previous introductory language described four general categories of information and stated that Appcues generally handled data consistently regardless of type, product, business, or customer direction.

The replacement emphasizes:

  • Encryption at rest and in transit;
  • Customer control, including through identity verification, over the amount of personally identifiable information handled by Appcues;
  • A shared responsibility model for security and privacy; and
  • The Appcues Trust Center and implementation of measures identified there.

Risk/impact: This is more principles-based and may provide less detail about the specific categories of data collected and how each category is treated. References to the Trust Center and “measures identified there” may incorporate external materials that can change over time. Customers should confirm whether the Trust Center creates binding commitments or merely describes current practices.

3. Third-party service-provider disclosure clarified and expanded

The policy continues to state that Appcues does not sell data to third parties. However, it now expressly states that Appcues may provide data to third parties:

  • For use within or in support of the Appcues product or business;
  • At the customer’s direction; and
  • For purposes including providing analytics graphs in the Appcues Studio application and managing related operations.

The prior language appears to have been incomplete or less specific.

Risk/impact: The revised wording confirms a broad ability to disclose customer or end-user data to service providers and other third parties supporting Appcues or acting at the customer’s direction. It does not identify the categories of providers, data involved, geographic locations, or specific contractual safeguards.

4. Retention and deletion language

The policy states that data may be deleted or aggregated in the ordinary course of business. It also expressly directs deletion requests to support@appcues.com.

Risk/impact: “Ordinary course of business” is not a fixed retention period and may leave customers uncertain about when deletion occurs. The policy does not appear to promise deletion within a specific timeframe or address backups, legal holds, or downstream service providers.

5. AI-model training

  • No express change concerning AI or machine-learning model training appears in the supplied diff.
  • The revised third-party and analytics language does not expressly authorize or prohibit using customer or end-user data to train, fine-tune, evaluate, or improve AI models.
  • Accordingly, the diff does not establish a customer opt-out, consent requirement, data-use limitation, or prohibition on AI training.

Recommended follow-up: Customers should request a clear written commitment stating whether their data, prompts, outputs, telemetry, or end-user data may be used for AI training or model improvement, including by third-party providers.

2026-09-06 · Terms of Service

shrank 6.4% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-09-06 · Privacy Policy

shrank 3.4% · Observed by clause.watch

Summary

The supplied diff does not contain the actual contractual language that was added, deleted, or replaced. It only states:

> “Added approximately 86 words to the document”

Accordingly, it is not possible to determine what legal terms changed or whether the changes create new risks.

AI Training and Customer Data

No language is provided addressing:

  • Whether customer data may be used to train, fine-tune, or improve AI models
  • Whether prompts, inputs, outputs, account information, or usage data may be retained
  • Whether data is used for generalized model training or only for the customer’s specific account or model
  • Whether the customer can opt out of AI training or data-use practices
  • Whether data is anonymized, aggregated, or de-identified before use
  • Whether human reviewers or third-party providers may access customer data
  • Whether customer data is deleted after a specified period
  • Ownership or licensing rights in customer inputs, outputs, or derived model improvements

Risk Assessment

The available material does not support a meaningful legal-risk analysis. In particular, it cannot establish whether the new language:

  • Expands the provider’s rights to use customer content
  • Grants a broad or perpetual license to customer data
  • Permits use of confidential or personal information for AI training
  • Weakens confidentiality, security, or deletion obligations
  • Transfers data to affiliates or third-party AI providers
  • Limits the customer’s ability to object to or control data use

Needed Information

Please provide the full redline using the stated notation—for example:

  • Additions: {new language}
  • Deletions: [deleted language]
  • Replacements: [old language]{new language}

The actual 86 added words, together with the surrounding provisions, are necessary to identify the changes and assess their effect on customer data and AI-model training.

2026-09-05 · Terms of Service

grew 6.8% · Observed by clause.watch

Structured Summary of Important Changes

1. Account and Registration Requirements

  • The agreement now expressly requires accounts to be registered by a human; accounts created by bots or automated methods are prohibited.
  • Customers must provide a valid email address and any other information Appcues requests during registration.
  • Customers are responsible for account and password security.
  • Appcues disclaims liability for losses arising from a customer’s failure to meet those security obligations.
  • Personally identifiable information submitted by the customer is now expressly made subject to Appcues’s Privacy Policy.
  • A person or legal entity may maintain only one account.

Risk: The security disclaimer may shift more account-compromise risk to the customer. The incorporated Privacy Policy may contain additional data-use rights or obligations that are not stated in the Terms and may be changeable separately.

2. Expanded Usage Restrictions

The revised terms add or clarify that customers may not:

  • Use the Services for illegal or unauthorized purposes.
  • Violate applicable laws, including copyright laws.
  • Use the Services for more than one product unless the Order Form permits it.
  • Resell, sublicense, lease, distribute, or provide the Services as part of a service bureau or outsourcing offering.
  • Store or transmit unlawful, infringing, defamatory, malicious, or privacy-violating material.
  • Attempt unauthorized access or interfere with the Services.
  • Circumvent contractual usage limits.
  • Copy, mirror, frame, or reproduce the Services except for limited internal or documented uses.
  • Access the Services to build a competitive product or service.

The email Services must comply with the Acceptable Use Policy (“AUP”), available at a linked Appcues webpage.

Risk: These restrictions are broad and may permit suspension or termination for a wide range of conduct. Incorporation of an external AUP creates a risk that important obligations can be changed or expanded outside the main Terms.

3. New AI-Specific Terms

  • The revision introduces “Appcues AI Features.”
  • Any use of the AI Features must comply with a separate AI Acceptable Use Policy at appcues.com/ai-aup.
  • The AI terms appear to impose usage restrictions but do not expressly state:
  • Whether customer data or prompts may be used to train Appcues’s or third-party AI models;
  • Whether data is retained, anonymized, or shared with AI subprocessors;
  • Whether customer inputs or AI outputs are used for service improvement;
  • Who owns or controls AI-generated outputs; or
  • Whether Appcues provides confidentiality or guarantees accuracy for AI outputs.

AI-training risk: The diff does not create an express customer-data training authorization, but it also does not prohibit training or clearly limit Appcues’s use of customer data for model development. The Privacy Policy and AI AUP should be reviewed for those rights. Customers should seek an explicit contractual statement that their data, prompts, outputs, and personal information will not be used to train general-purpose or third-party models without consent.

4. License and Intellectual Property

  • The customer receives a limited, non-exclusive, non-transferable, non-sublicensable right to use the Services during the subscription term for internal business purposes.
  • Appcues and its licensors retain all rights in the Services and related intellectual property.

Overall impact: The revised language is more detailed and restrictive, with stronger customer compliance obligations and greater reliance on external policies.

2026-09-05 · Privacy Policy

grew 3.5% · Observed by clause.watch

Summary of Important Changes

1. Broader description of data handling

The revised language replaces a general statement that Appcues does not sell data and only shares certain data with third parties with a more detailed description of data categories and security/privacy practices. It now refers to:

  • All customer and end-user data;
  • The amount of personally identifiable information (PII) handled;
  • Customer control through identity verification;
  • A “Shared Responsibility Model” for security and privacy;
  • Appcues’ Trust Center and related implementation measures; and
  • At-rest and in-transit encryption.

Risk: The revised language is more operational and security-focused, but it does not necessarily restrict Appcues’ substantive rights to use or disclose data. References to the Trust Center or security measures may also incorporate external documents that could change over time.

2. Expanded third-party/service-provider use

The policy continues to state that Appcues does not sell data. However, the revised language more clearly permits providing data to third parties:

> “for use within or in support of the Appcues product or business or at the direction of our customers”

Examples include providing analytics graphs in the Appcues Studio application and managing related services.

Risk: This is a potentially broad authorization. It may cover vendors, analytics providers, contractors, and other service providers, and may permit disclosures made at the customer’s direction. The excerpt does not specify:

  • The categories of third parties;
  • Whether third parties may use data for their own purposes;
  • Retention and deletion requirements;
  • International transfers; or
  • Whether customers must affirmatively authorize particular disclosures.

3. Data deletion and aggregation

The revised text states that certain information is deleted or aggregated in the ordinary course of business and adds that deletion requests may be sent to support@appcues.com.

Risk: “In the ordinary course of business” is not a defined retention period and may allow Appcues discretion over when deletion or aggregation occurs. Aggregated data may remain available for analytics, reporting, or other business purposes, depending on whether it is truly de-identified.

4. AI-model training

The provided diff contains no express reference to artificial intelligence, machine learning, model training, model improvement, prompts, outputs, or using customer data to train AI models.

Accordingly, the change does not expressly add or remove a contractual right to train AI models. However, the broader authorization to provide data to third parties for use in or support of the Appcues business could create uncertainty if Appcues or a service provider uses AI tools in delivering those services.

Recommended clarification: The policy or agreement should expressly state whether customer data, end-user data, prompts, outputs, or derived data may be used to train or improve general-purpose or Appcues-specific AI models, and whether customers can opt out.

2026-09-05 · Privacy Policy

shrank 3.4% · Observed by clause.watch

Summary

The provided diff does not include the actual added language. It only states:

> “Added approximately 86 words to the document”

Without the text of those additions, it is not possible to reliably identify:

  • Changes to customer data rights or permitted uses
  • Whether customer data may be used to train, fine-tune, or evaluate AI models
  • Whether data is anonymized, aggregated, or otherwise de-identified before such use
  • Any opt-in, opt-out, consent, or objection rights
  • New data-sharing or disclosure permissions
  • Changes to confidentiality, security, retention, or deletion obligations
  • Allocation of intellectual-property rights in model outputs or training materials
  • Any new risks involving sensitive, personal, or regulated data

AI-Training Risk Assessment

No conclusion can be reached regarding AI-model training because the relevant added wording is not included in the diff. In particular, the available description does not establish whether the contract:

  • Expressly authorizes training AI models using customer data;
  • Restricts training to aggregated or de-identified data;
  • Prohibits use of customer data for model training;
  • Allows use of prompts, inputs, outputs, telemetry, or usage data for training;
  • Gives the customer notice or control over such use; or
  • Permits retention of data after the customer relationship ends.

Information Needed

Please provide the actual 86-word addition, using the stated notation for additions, deletions, and replacements. Once provided, the language can be assessed for its legal effect, including any new rights granted to the provider and any material risks to the customer.

2026-09-04 · Privacy Policy

grew 3.5% · Observed by clause.watch

Summary

The supplied diff does not include the actual amended contract language. It only states:

> “Added approximately 86 words to the document”

Accordingly, the specific legal changes and risks cannot be reliably analyzed.

AI Training and Customer Data

The diff provides no language indicating whether:

  • Customer data may be used to train, fine-tune, or improve AI models;
  • Customer prompts, outputs, files, or other content may be retained or reviewed;
  • Data may be shared with affiliates, service providers, or third-party AI vendors;
  • Customer data may be aggregated, anonymized, or de-identified for model development;
  • The customer can opt out of AI training or require deletion of training data; or
  • The provider gives any confidentiality, security, ownership, or non-use commitments concerning customer data.

Therefore, no conclusion can be reached about whether the amendment expands or restricts AI-training rights.

Other Legal Risks

Because the added 86 words are not provided, it is also impossible to assess potential changes involving:

  • Liability, indemnification, or warranty obligations;
  • Data protection and security;
  • Intellectual-property ownership or licenses;
  • Confidentiality;
  • Termination and data deletion;
  • Subcontractors or international data transfers; or
  • Changes to governing law, dispute resolution, or fees.

Information Needed

Please provide the actual 86-word addition, including any surrounding text if the addition modifies an existing sentence. The comparison should show the language using the stated notation:

  • {added text}
  • [deleted text]
  • [old text]{new text}

Without the operative wording, any substantive interpretation would be speculative.

2026-09-04 · Terms of Service

shrank 6.4% · Observed by clause.watch

Diff Analysis

Key Limitation

The supplied diff contains only the notation:

> “Added approximately 186 words to the document”

It does not include the actual added, deleted, or replaced contractual language. As a result, it is not possible to reliably identify:

  • Changes to customer data rights or ownership
  • New permissions to collect, access, disclose, retain, or monetize data
  • Whether customer data may be used to train, fine-tune, evaluate, or improve AI models
  • Whether prompts, inputs, outputs, personal information, or confidential information are included in any training authorization
  • Opt-out, deletion, confidentiality, security, or data-retention provisions
  • Changes to liability, indemnification, compliance, or audit rights

AI-Training Risk Assessment

No conclusion can be reached about AI-model training because the relevant contractual text is missing. In particular, the diff does not reveal whether the new language:

  • Grants the provider a license to use customer content for model training or product improvement
  • Allows use of data in aggregated, de-identified, or anonymized form
  • Permits sharing with affiliates, vendors, or third-party AI providers
  • Makes training use automatic unless the customer opts out
  • Applies training rights to personal data, confidential information, regulated data, or uploaded content
  • Allows trained models or derived outputs to be retained after termination or deletion
  • Limits the customer’s ability to prohibit training or require deletion

Information Needed

Please provide the actual diff, including the approximately 186 added words and any deleted or replacement language. The analysis should preserve the markup format, for example:

  • Additions: {new language}
  • Deletions: [deleted language]
  • Replacements: [old language]{new language}

Once provided, the changes can be assessed for legal effect, business risk, and specifically whether customer data may be used to train or improve AI models.

2026-09-03 · Terms of Service

grew 6.8% · Observed by clause.watch

Summary

The provided diff does not include the actual amended contract language. It only states:

> “Added approximately 186 words to the document”

Accordingly, it is not possible to identify:

  • The specific legal or commercial changes;
  • New customer obligations or provider rights;
  • Changes to liability, confidentiality, security, ownership, termination, or dispute provisions;
  • Whether customer data may be used to train, fine-tune, evaluate, or improve AI models;
  • Whether such use requires consent, is automatic, or can be opted out of;
  • Whether data may be anonymized, aggregated, retained, disclosed to affiliates or vendors, or transferred across jurisdictions; or
  • Whether the provider claims ownership of model outputs, derived data, embeddings, prompts, or other materials generated from customer data.

AI-Training Issues to Check

The added language should be reviewed specifically for terms such as:

  • “train,” “fine-tune,” “improve,” “develop,” or “evaluate” models;
  • “service improvement” or similarly broad purposes;
  • “customer content,” “inputs,” “outputs,” “usage data,” or “derived data”;
  • Consent that is automatic unless the customer opts out;
  • Rights that continue after termination;
  • Use of data in de-identified or aggregated form;
  • Sharing with subprocessors, affiliates, or third-party model providers;
  • Restrictions or disclaimers concerning confidential, personal, regulated, or sensitive data; and
  • Whether the provider gives any deletion, audit, security, or indemnification commitments.

Information Needed

Please provide the actual 186 added words, with any deletions and replacements shown using the stated notation. Without the text itself, no reliable legal-risk analysis can be performed.

2026-09-03 · Privacy Policy

shrank 3.4% · Observed by clause.watch

Summary of Important Changes

1. New or Expanded Privacy and Security Overview

The revised policy replaces the former introductory description of information categories and sensitivity levels with a broader overview covering:

  • At-rest and in-transit encryption;
  • All customer and end-user data;
  • Customer control through identity verification;
  • The amount of personally identifiable information (PII) handled by Appcues;
  • A shared-responsibility model for security and privacy; and
  • The Appcues Trust Center and implementation of related security measures.

Risk/impact: These additions describe security practices and governance at a high level, but they do not appear to create detailed, enforceable security commitments. Customers may need to review the Trust Center and contractual security terms for specific controls, certifications, audit rights, or breach obligations.

2. Third-Party Data Sharing Language Reorganized

The prior language stated that Appcues does not sell data to third parties and may provide data to third-party services for use within or in support of the Appcues product or business, or at the customer’s direction.

The revised text appears to preserve this concept but restructures it and begins adding examples, including providing analytics graphs in the Appcues Studio application and managing related functions. The supplied diff is repetitive and appears incomplete, so it is not possible to determine the full list of examples or whether any substantive categories of recipients were added.

Risk/impact: The policy continues to permit disclosure to service providers and other third parties for product, business, support, analytics, or customer-directed purposes. Customers should confirm whether these providers may process PII, the applicable data-processing terms, and whether onward transfers or international transfers are addressed elsewhere.

3. Data Deletion Request Language

The revised text includes a statement that data is deleted or aggregated in the ordinary course of business and identifies support@appcues.com as the contact for data-deletion requests.

Risk/impact: “Ordinary course of business” is not a precise retention period and may leave Appcues discretion over timing. The policy does not, in this diff, specify exceptions, backup retention, legal holds, or a guaranteed deletion deadline.

4. Contact Information and Rights Requests

The contact section is rewritten to invite questions about the policy, collection and use of personal information, and exercise of privacy rights under the policy and applicable law. It directs users to support@appcues.com and retains Appcues’ mailing address.

5. AI Training

No express change concerning the use of customer or end-user data to train, fine-tune, evaluate, or improve AI models is shown in the supplied diff. The revised references to analytics and third-party services do not expressly authorize AI training, but the incomplete formatting means the full policy should be reviewed to confirm whether separate AI-use language appears elsewhere.

2026-09-03 · Terms of Service

shrank 6.4% · Observed by clause.watch

Key Changes and Legal Risks

1. Account registration and security obligations

The revised terms add detailed account requirements:

  • Accounts must be registered by a human; automated or “bot” accounts are prohibited.
  • Customers must provide a valid email address and other information Appcues may require.
  • Customers are responsible for account and password security.
  • Appcues disclaims liability for losses resulting from the customer’s failure to comply with the security obligation.
  • Personally identifiable information submitted by the customer is expressly made subject to Appcues’s Privacy Policy.
  • Customers may not maintain more than one account or use the Services for illegal or unauthorized purposes.

Risk: The security disclaimer may shift losses arising from compromised credentials to the customer, even where the circumstances may be disputed. The Privacy Policy is incorporated by reference, so its terms should be reviewed separately.

2. Revised and expanded usage restrictions

The prior license language and intellectual-property reservation are reorganized into a new “Right to Access and Use the Service” section. The customer receives a limited, non-exclusive, non-transferable, non-sublicensable right to use the Services:

  • During the applicable subscription term;
  • Solely for internal business purposes; and
  • Subject to the Terms and applicable Order Form.

The restrictions now expressly prohibit, among other things:

  • Providing the Services to anyone other than the customer or authorized users;
  • Reselling, sublicensing, leasing, or using the Services in a service-bureau or outsourcing arrangement;
  • Storing or transmitting unlawful, infringing, defamatory, malicious, or privacy-violating content;
  • Unauthorized access, interference, circumvention of usage limits, copying, framing, mirroring, or creation of a competing product or service.

The revised language also limits use to one product unless the Order Form states otherwise.

Risk: These restrictions may narrow permitted use, particularly for affiliates, contractors, customers, multi-product deployments, and managed-service arrangements. Violations may create termination or indemnity exposure, depending on other provisions.

3. Email and AI-specific acceptable-use policies

Use of Appcues email Services must comply with the general Acceptable Use Policy (“AUP”). A new provision states that use of Appcues AI Features must comply with a separate AI AUP at appcues.com/ai-aup.

Risk: The AI AUP is incorporated by reference but is not included in the supplied text. Appcues may be able to update that online policy, potentially changing permitted uses without a negotiated amendment.

4. AI model training and customer data

The diff does not expressly state that customer data will—or will not—be used to train AI models. It adds regulation of AI Feature use through the AI AUP, but no clear provisions address:

  • Whether customer inputs, outputs, or usage data are used for model training;
  • Whether data is shared with third-party AI providers;
  • Opt-out rights;
  • Ownership or confidentiality of AI inputs and outputs; or
  • Retention and deletion of AI-related data.

Key concern: The absence of an express “no training” commitment leaves the data-use position unclear. Customers should obtain written clarification and review the Privacy Policy, AI AUP, and any Data Processing Agreement before submitting confidential or personal data to AI Features.

2026-09-02 · Terms of Service

grew 6.8% · Observed by clause.watch

Summary of Important Changes

1. New account and registration obligations

The revised terms add requirements that:

  • Accounts must be registered by a human; bot or automated registrations are prohibited.
  • Customers must provide a valid email address and other information Appcues may require.
  • One person or legal entity may not maintain more than one account.
  • Customers are responsible for account and password security.
  • Appcues disclaims liability for losses resulting from the customer’s failure to meet its security obligations.
  • Personally identifiable information submitted by the customer is expressly made subject to Appcues’ Privacy Policy.

Risk: The customer’s security responsibilities are expanded, while Appcues’ liability for account compromise or resulting losses is expressly limited. The Privacy Policy becomes important because it may contain additional data-use terms outside the Terms of Service.

2. Broader and reorganized usage restrictions

The prior usage restrictions are replaced or substantially reorganized. The revised language prohibits, among other things:

  • Illegal or unauthorized use.
  • Use for anyone other than the customer or its authorized users.
  • Resale, sublicensing, leasing, distribution, or use in a service bureau or outsourcing offering.
  • Storage or transmission of unlawful, infringing, libelous, tortious, or privacy-violating material.
  • Malicious code, interference with service integrity or performance, unauthorized access, circumvention of usage limits, copying, framing, mirroring, or reverse-use to build a competitive product or service.
  • Use of more than one product unless authorized in an Order Form.

Risk: The revised restrictions are generally more detailed and may give Appcues broader grounds to suspend or terminate access for alleged misuse. Some terms—such as “competitive product or service” and “unauthorized purpose”—could be interpreted broadly.

3. New AI-specific terms

The revision adds a provision stating that use of Appcues AI Features must comply with the Acceptable Use Policy, with a separate AI policy URL:

https://www.appcues.com/ai-aup

The AI Features are therefore subject to an external policy incorporated by reference.

AI training and customer-data use

The provided diff does not expressly state:

  • Whether customer data, prompts, inputs, outputs, or usage information may be used to train Appcues’ or third-party AI models.
  • Whether customer data is excluded from model training.
  • Whether data is anonymized, aggregated, retained, or shared with AI providers.
  • Whether the customer must opt in or may opt out of training.
  • Who owns AI inputs and outputs.

Risk: The Terms add AI functionality and incorporate a separate AI policy, but do not provide a clear contractual restriction or authorization regarding AI-model training. The AI AUP and Privacy Policy should be reviewed for any data-training, retention, subprocessors, or third-party-model provisions.

4. Revised access grant and intellectual-property language

The access license is restated as a limited, non-exclusive, non-transferable, non-sublicensable right to use the Services during the subscription term for internal business purposes. Appcues and its licensors expressly reserve all rights in the Services and related intellectual property.

Risk: The customer receives no broader rights to use, reproduce, commercialize, or provide access to the Services beyond the stated license.

2026-09-02 · Terms of Service

shrank 6.4% · Observed by clause.watch

Summary

The provided diff does not include the actual amended language. It only states:

> “Added approximately 186 words to the document”

Accordingly, the legal and commercial impact of the changes cannot be reliably assessed.

AI Training and Data-Use Changes

No conclusions can be drawn about whether the customer’s data may be used to:

  • Train, fine-tune, or improve artificial-intelligence or machine-learning models;
  • Create or improve generalized models used for other customers;
  • Generate embeddings, profiles, analytics, or derivative data;
  • Retain prompts, outputs, files, or other customer content for model-development purposes;
  • Permit human review or annotation of customer data;
  • Share data with affiliates, subprocessors, or third-party AI providers; or
  • Use de-identified, aggregated, or pseudonymized data for training or product improvement.

The actual added wording is required to determine whether any such rights were introduced or expanded.

Potential Risks Requiring Review

The missing text should be checked for:

1. Broad data-use rights — language permitting use of customer content for “improvement,” “research,” “analytics,” or “business purposes.”

2. Ambiguous AI permissions — references to “machine learning,” “models,” “automated systems,” or “service improvement” without clear limits.

3. Ownership and license scope — perpetual, irrevocable, worldwide, transferable, sublicensable, or royalty-free licenses to customer data.

4. De-identification claims — whether data is genuinely anonymized or merely pseudonymized, and whether re-identification is prohibited.

5. Retention and deletion — whether data remains in training datasets or model weights after contract termination or deletion requests.

6. Confidentiality and security — whether customer data may be accessed by personnel or third-party AI providers.

7. Regulatory compliance — implications for personal data, confidential information, trade secrets, regulated data, and sector-specific requirements.

Conclusion

No substantive change can be identified from the supplied diff, including any change concerning AI-model training. The complete 186-word addition, together with the surrounding original language if necessary, should be provided for a meaningful legal analysis.

2026-09-01 · Privacy Policy

grew 3.5% · Observed by clause.watch

Summary of Important Changes

1. Major restructuring and updated date

  • The policy is now labeled “Privacy Policy — Last updated: May 2026.”
  • The opening “Overview” has been substantially rewritten and appears to replace the former description of how Appcues categorizes information.
  • The diff is fragmented and repetitive, so the exact final wording should be confirmed against the clean policy.

2. Security and privacy framework expanded

The revised overview expressly references:

  • At-rest and in-transit encryption for customer and end-user data;
  • Customer control through Identity Verification;
  • A formal Shared Responsibility Model for Security and Privacy;
  • The Appcues Trust Center; and
  • Implementation of the security and privacy measures described there.

These additions provide more detail about Appcues’s security program, but they may also frame security responsibilities as shared with the customer. Customers should review the referenced Trust Center and determine what controls remain their responsibility.

3. Third-party disclosures clarified or broadened

The prior language stated that Appcues does not sell data to third parties, while allowing disclosures to third-party services in specific cases. The revised language continues to state that data is not sold, but describes third-party use as being:

  • Within or in support of the Appcues product or business;
  • At the direction of customers; and
  • For examples such as providing analytics graphs in the Appcues Studio application and managing related services.

This may clarify operational disclosures, but it also confirms that customer or end-user data can be shared with service providers for a range of product, business, analytics, or customer-directed purposes. The final text should be reviewed for any additional examples or service-provider terms.

4. Data retention and deletion

The revised text appears to state that data is deleted or aggregated in the ordinary course of business. It also retains or adds a process for deletion requests through support@appcues.com.

“Ordinary course of business” is not a specific retention period and may leave Appcues discretion over how long data is retained. Customers needing defined deletion timelines should seek contractual commitments, particularly in a Data Processing Addendum.

5. AI-model training

  • No express provision concerning artificial intelligence, machine learning, model training, model improvement, or use of customer data to train AI models appears in the supplied diff.
  • The expanded references to analytics and third-party services do not, by themselves, authorize AI training, but the excerpt may be incomplete or poorly formatted.
  • Customers should verify the clean policy and related terms for an express statement that customer content, personal data, prompts, outputs, or end-user data will not be used to train or improve general-purpose AI models without consent.

6. Contact information

The contact section is reformatted and now expressly invites questions, privacy-rights requests, and requests concerning collection and use of personal information through support@appcues.com.

2026-08-31 · Privacy Policy

shrank 3.4% · Observed by clause.watch

Summary

The provided diff does not include the actual amended contractual language. It only states:

> “Added approximately 86 words to the document”

Accordingly, it is not possible to determine:

  • What provisions were added, deleted, or replaced;
  • Whether the changes affect the parties’ rights or obligations;
  • Whether liability, confidentiality, security, intellectual property, or termination terms changed; or
  • Whether the customer’s data may be used to train, fine-tune, evaluate, or otherwise improve AI models.

AI Training and Customer Data

No substantive language concerning AI model training or customer-data usage is included in the supplied diff. Therefore, no conclusion can be reached about whether the revised agreement:

  • Permits or prohibits training models on customer data;
  • Applies restrictions only to personal or confidential data, rather than all customer data;
  • Allows use of aggregated, de-identified, anonymized, or derived data;
  • Requires customer consent or provides an opt-out;
  • Allows use by the provider’s affiliates, contractors, or third-party AI vendors;
  • Grants the provider rights to retain data after termination; or
  • Requires deletion, segregation, security controls, or audit rights.

Risk Assessment

The only identifiable fact is that approximately 86 words were added. The legal significance and risk level cannot be assessed without the wording of those additions and any related deletions or replacements.

Please provide the actual redline text, including the words inside {}, [], and []{}.

2026-08-31 · Terms of Service

grew 6.8% · Observed by clause.watch

Key Changes and Risks

1. AI features are now expressly covered
  • The revised terms add a specific provision stating that use of “Appcues AI Features” must comply with the Acceptable Use Policy (AUP).
  • The AI AUP is located at a separate URL: https://www.appcues.com/ai-aup.
  • This creates additional obligations for customers and incorporates an external policy that may be changed separately from the Terms of Service.

Risk: The diff does not specify what the AI Features do, what data they process, where processing occurs, or whether customer data is retained, shared with AI vendors, or used to train models. Customers must review the AI AUP and related privacy documentation to determine those terms.

2. No express customer-data training authorization appears in the diff
  • The changes do not expressly state that Appcues may use customer data, prompts, inputs, outputs, or other customer content to train, fine-tune, improve, or evaluate AI models.
  • They also do not expressly prohibit such use.
  • The revised language states that personally identifiable information submitted by the customer is subject to Appcues’ Privacy Policy.

Risk: Any permission to use data for AI training may exist in the Privacy Policy, AI AUP, Data Processing Addendum, or another linked document rather than in these Terms. The incorporation of the Privacy Policy means customers should verify whether it permits:

  • model training or improvement using customer content;
  • use of aggregated, de-identified, or pseudonymized data;
  • disclosure to third-party AI providers;
  • retention of prompts, outputs, or uploaded material; and
  • opt-out rights or contractual deletion commitments.
3. Security responsibility shifts more clearly to the customer
  • The revised terms require customers to maintain the security of their account and password.
  • Appcues disclaims liability for loss or damage resulting from the customer’s failure to comply with that obligation.

Risk: This may reduce Appcues’ responsibility for account compromise caused by weak credentials, unauthorized users, or customer-side security failures. The terms do not, in this diff, provide corresponding security standards or breach-notification commitments for Appcues.

4. Expanded account and usage restrictions

The revision adds or clarifies that:

  • automated or “bot” accounts are prohibited;
  • customers must provide a valid email address and requested registration information;
  • one person or legal entity may not maintain more than one account;
  • Services may not be used for illegal or unauthorized purposes;
  • use is limited to one product unless the Order Form permits otherwise;
  • use must comply with the general AUP and, for AI Features, the AI AUP; and
  • customers may not use the Services for third parties, resell them, circumvent usage limits, copy them, or build a competing product.

Risk: Violations may justify suspension or termination, and the external AUPs may create broad, evolving restrictions beyond the main contract.

5. Revised license language

The document restores or reorganizes Appcues’ limited, non-exclusive, non-transferable, non-sublicensable license for internal business use during the subscription term, while preserving Appcues’ ownership of the Services and related intellectual property.

Risk: Customer rights remain narrow, and third-party or external-use scenarios may require express Order Form authorization.

2026-08-30 · Privacy Policy

grew 3.5% · Observed by clause.watch

Executive Summary

The diff substantially reorganizes the opening sections of the Privacy Policy and adds security-governance concepts. However, the markup is fragmented and repetitive, so some changes cannot be confirmed with certainty from the excerpt alone.

Important Changes

1. Security and privacy framework expanded

The revised language adds or emphasizes:

  • At-rest and in-transit encryption;
  • Customer control through “Identity Verification”;
  • A “Shared Responsibility Model” for security and privacy;
  • The Appcues Trust Center; and
  • Implementation of security measures identified there.

Risk/impact: These statements may create clearer security commitments or customer expectations. The policy should clarify whether the Trust Center contains binding contractual commitments, and whether the security measures are mandatory, illustrative, or subject to change.

2. Data classification language reorganized

The prior discussion classified information into four general groups based on sensitivity. The new text appears to replace or supplement that framework with references to:

  • All customer and end-user data;
  • The amount of personally identifiable information handled by Appcues; and
  • Different levels of sensitivity in context.

Risk/impact: The revised wording may broaden the policy’s coverage and could make the categories less precise. Customers may have less visibility into exactly which data types receive which protections.

3. Third-party disclosures

The policy continues to state that Appcues does not sell data to third parties. It also continues permitting disclosure of data to third-party services:

> “for use within or in support of the Appcues product or business or at the direction of our customers”

Examples include providing analytics graphs in the Appcues Studio application.

Risk/impact: This is a broad authorization. It may permit data sharing with service providers, analytics vendors, or other subcontractors whenever connected to Appcues’ business or customer instructions. The excerpt does not identify categories of vendors, permitted data, retention limits, or objection/notice rights.

4. Retention and deletion

The excerpt references data being deleted or aggregated in the ordinary course of business and provides that deletion requests may be sent to support@appcues.com.

Risk/impact: “Ordinary course of business” is vague and does not establish a specific retention period. Customers should confirm whether deletion applies to backups, subprocessors, derived data, and aggregated or de-identified information.

5. Contact information and effective date

The policy is labeled “Last updated: May 2026.” The contact section is reformatted and adds a direct statement inviting privacy questions and rights requests through support@appcues.com.

AI Model Training

No express language in the provided diff authorizes or prohibits using customer or end-user data to train, fine-tune, evaluate, or improve AI models. The third-party-service language is broad enough to warrant clarification, particularly if AI vendors are used, but it is not itself an explicit AI-training grant.

Customers should request a clear statement addressing:

  • Whether customer data or prompts may train general-purpose models;
  • Whether data is used only for customer-specific features;
  • Opt-out or consent rights;
  • Human review and model-improvement use; and
  • Deletion of training data and derived model artifacts.

2026-08-30 · Terms of Service

shrank 6.4% · Observed by clause.watch

Summary

The supplied diff does not include the actual added or deleted contractual language. It only states:

> “Added approximately 186 words to the document”

Accordingly, it is not possible to determine what legal rights, obligations, or risks changed.

AI Training and Customer Data

No conclusions can be drawn about whether the changes:

  • Permit the provider to use customer data to train, fine-tune, or improve AI models;
  • Allow use of customer prompts, inputs, outputs, files, or personal information for training;
  • Restrict training to aggregated, anonymized, or de-identified data;
  • Require customer consent or provide an opt-out;
  • Permit subcontractors or third-party model providers to use the data;
  • Establish retention, deletion, or confidentiality protections for training data; or
  • Address ownership of data, model outputs, or models trained using customer data.

Risk Assessment

The added language should be reviewed for provisions that:

1. Expand the provider’s permitted use of customer data beyond delivering the services;

2. Treat customer data or usage data as a “service improvement” resource;

3. Permit model training without an affirmative customer opt-in;

4. Allow retention of data after termination;

5. Permit disclosure to affiliates, vendors, or AI providers;

6. Limit the provider’s liability for unauthorized use or data breaches; or

7. Conflict with confidentiality, data-protection, or sector-specific obligations.

Information Needed

Please provide the actual 186 words, with additions shown in {...} and deletions shown in [...]. Without the underlying text, no reliable legal comparison or identification of AI-training-related changes can be performed.

2026-08-29 · Privacy Policy

shrank 3.4% · Observed by clause.watch

Summary

The diff states only that approximately 86 words were added, but it does not include the actual added language.

Key Legal Changes

  • Cannot determine: The specific rights, obligations, restrictions, or liabilities created by the additions.
  • Cannot assess: Whether the changes affect confidentiality, intellectual property, data ownership, security, indemnities, termination, or regulatory compliance.
  • No reliable interpretation possible: Word count alone is insufficient to identify the legal effect of the amendment.

AI Training and Customer Data

The provided diff does not reveal whether customer data may be used to train AI models. It is therefore not possible to determine whether the new language:

  • Allows the provider to use customer data, prompts, outputs, or usage data to train or improve AI models;
  • Applies training rights to identifiable, confidential, or personal information;
  • Permits sharing of customer data with affiliates, vendors, or third-party model providers;
  • Provides an opt-out or requires the customer’s consent;
  • Requires anonymization, de-identification, aggregation, or deletion;
  • Gives the customer ownership or control over model inputs, outputs, or derived data; or
  • Creates obligations under privacy or data-protection laws.

Risk Assessment

No substantive risk assessment can be completed without the actual 86 added words. The added text should be provided, ideally with the surrounding provisions, so the changes can be reviewed for:

1. Permission to use customer data for AI training or product improvement;

2. Expansion of the provider’s license or data-use rights;

3. Disclosure to subprocessors or third-party AI providers;

4. Retention, deletion, and confidentiality protections; and

5. Any customer opt-out, approval, or audit rights.

2026-08-28 · Privacy Policy

grew 3.5% · Observed by clause.watch

Summary of Important Changes

1. Expanded security and privacy framework

The policy replaces a general reference to “kinds” of information collected with specific privacy and security concepts, including:

  • Encryption at rest and in transit
  • Coverage of all customer and end-user data
  • Customer control through identity verification
  • A shared responsibility model for security and privacy
  • The Appcues Trust Center and related implementation measures

Risk/impact: These additions provide more detail but may also make Appcues’ security commitments more specific and potentially more enforceable. The policy appears to incorporate or rely on information in the Trust Center, which should be reviewed separately because it may contain additional commitments or limitations.

2. Revised data-classification language

The prior language described four general groups of information based on sensitivity. The replacement instead emphasizes the amount of personally identifiable information handled by Appcues and the contextual measures used to protect it.

Risk/impact: The revised wording may reduce clarity about the specific categories of data collected and their sensitivity. It does not appear to provide a new, detailed description of the information itself.

3. Third-party data sharing language clarified and expanded

The policy continues to state that Appcues does not sell data to third parties. However, it now expressly states that Appcues may provide data to third-party services:

  • For use within or in support of the Appcues product or business
  • At the direction of customers
  • For purposes such as providing analytics graphs in the Appcues Studio application

Risk/impact: This confirms a broader operational sharing permission than a simple “we never sell data” statement might suggest. The term “third-party services” is not defined in the supplied diff, and the language does not identify specific providers, data categories, retention periods, or whether providers may use data for their own purposes. Customer-directed sharing may also place greater responsibility on the customer for obtaining appropriate notices and consents.

4. Data deletion and aggregation

The policy retains language stating that data is deleted or aggregated in the ordinary course of business. It also identifies support@appcues.com as the address for deletion requests.

Risk/impact: “Ordinary course of business” is vague and does not establish a definite deletion timetable. The diff does not add a clear commitment to delete backups, identify exceptions, or provide a formal deletion certification process.

5. Contact information and rights requests

The contact section is rewritten to invite questions about the policy, collection and use of personal information, and exercise of rights under the policy and applicable law. It provides the support email and Appcues’ mailing address.

6. AI-model training

No express provision concerning AI training is visible in the supplied diff. The changes do not clearly authorize or prohibit using customer data, end-user data, prompts, analytics, or other information to train, fine-tune, evaluate, or improve AI models.

Key risk: The expanded third-party-services language could potentially cover AI or analytics vendors unless restricted elsewhere in the policy or contract. The underlying agreement, data-processing addendum, product terms, and Trust Center should be checked for a separate AI-training provision.

2026-08-28 · Terms of Service

grew 6.8% · Observed by clause.watch

Summary

The provided diff does not include the actual added contractual language. It only states:

> “Added approximately 186 words to the document”

Accordingly, it is not possible to identify:

  • Changes to the parties’ rights or obligations;
  • New limitations of liability, warranties, indemnities, or termination rights;
  • Changes to confidentiality, security, privacy, or data-retention terms;
  • Whether customer data may be used to train, fine-tune, evaluate, or improve AI models;
  • Whether data may be shared with affiliates, service providers, or third parties;
  • Whether customer consent is required before AI-model training;
  • Any opt-out, deletion, anonymization, or data-use restrictions; or
  • Whether the new language applies retroactively to previously supplied data.

AI Training and Data-Use Review

No AI-related change can be assessed because the specific additions are not included. The relevant text should be reviewed for terms such as:

  • “train,” “fine-tune,” “develop,” “improve,” or “evaluate” models;
  • “customer data,” “inputs,” “outputs,” “content,” or “usage data”;
  • Rights to use data in “de-identified,” “aggregated,” or “anonymized” form;
  • Perpetual, irrevocable, worldwide, royalty-free, or sublicensable licenses;
  • Sharing data with subprocessors, affiliates, or third-party model providers;
  • Customer opt-out or consent mechanisms; and
  • Obligations to delete or return data after termination.

Needed Information

Please provide the full diff, including the approximately 186 added words and any surrounding deleted or replacement language. Without the actual wording, a legal risk analysis would be speculative.

2026-08-28 · Privacy Policy

shrank 3.4% · Observed by clause.watch

Summary

The supplied diff does not include the actual amended contractual language. It only states:

> “Added approximately 86 words to the document”

Accordingly, it is not possible to determine:

  • What provisions were added or changed;
  • Whether the customer’s data may be used to train, fine-tune, evaluate, or improve AI models;
  • Whether any customer consent or opt-out rights were introduced or removed;
  • Whether data may be shared with affiliates, vendors, or model providers;
  • Whether confidential information, personal data, prompts, outputs, or usage data are covered;
  • Whether the provider obtains ownership or broad usage rights;
  • Whether retention, deletion, security, or regulatory obligations changed; or
  • Whether the customer faces new indemnity, liability, or compliance risks.

AI Training and Data-Use Risk

No substantive AI-training language appears in the supplied material. Therefore, no conclusion can be reached about whether the amendment:

  • Permits training on customer content by default;
  • Limits training to aggregated or de-identified data;
  • Allows human review or model evaluation using customer data;
  • Applies different rules to consumer and enterprise accounts; or
  • Provides an opt-out, deletion mechanism, or contractual restriction.

Required Information

Please provide the complete redline text, including the approximately 86 added words and any surrounding provisions. The additions should be marked with {}, deletions with [], and replacements with []{} as described.

2026-08-28 · Terms of Service

shrank 6.4% · Observed by clause.watch

Structured Summary of Important Changes

1. Account eligibility and registration requirements

  • The revised terms require each account holder to be a human; accounts registered by bots or automated methods are prohibited.
  • Customers must provide a valid email address and any other information Appcues requests during registration.
  • One person or legal entity may not maintain more than one account.
  • Services may not be used for illegal or unauthorized purposes.

Risk: Appcues gains broader discretion to request registration information and potentially restrict or terminate accounts that do not meet these requirements. The terms do not specify how long registration information will be retained or how it will be used beyond a general reference to the Privacy Policy.

2. Customer security obligations and liability

  • The customer is expressly responsible for maintaining the security of its account and password.
  • Appcues disclaims liability for losses resulting from the customer’s failure to meet that obligation.

Risk: This may shift significant breach-related risk to the customer, potentially including unauthorized use resulting from compromised credentials. The excerpt does not provide a corresponding Appcues security standard or security-related remedy.

3. Privacy Policy incorporation

  • Personally identifiable information submitted by the customer is now stated to be subject to Appcues’s Privacy Policy.

Risk: Important data-use terms may now be located outside the contract and may be changeable separately. The Privacy Policy should be reviewed for processing purposes, subprocessors, international transfers, retention, deletion, and customer rights.

4. AI features and AI-model training

  • New language states that use of Appcues AI Features must comply with the Acceptable Use Policy, specifically an AI-related policy at https://www.appcues.com/ai-aup.
  • The AI language appears to regulate how customers may use the features, but the excerpt contains no express provision stating whether customer data, prompts, inputs, outputs, or usage information may be used to train, fine-tune, evaluate, or improve Appcues’s or third-party AI models.
  • There is also no express commitment that customer data will be excluded from model training, deleted after processing, segregated from other customers, or subject to a particular retention period.

Risk: The absence of an explicit training restriction or prohibition creates uncertainty. The AI AUP and Privacy Policy may contain the operative data-use terms and should be reviewed before submitting confidential, personal, regulated, or proprietary information. Customers should seek a written “no training/no model improvement” commitment if required.

5. Service-use restrictions and external policies

  • The revised restrictions prohibit unlawful use, infringement, malicious code, interference, unauthorized access, circumvention of usage limits, copying, mirroring, and competitive-product development.
  • Email Services must comply with the general AUP; AI Features must comply with the separate AI AUP.
  • The prior detailed restrictions are reorganized and, in several places, replaced by broader consolidated language.

Risk: Incorporation of online AUPs creates potential uncertainty regarding future policy changes and gives Appcues additional grounds to suspend or terminate access. Confirm whether policies can be changed unilaterally and whether customers receive notice.

6. License wording

  • The limited, non-exclusive, non-transferable, non-sublicensable right to use the Services is retained but relocated and clarified as applying during the subscription term and for internal business purposes only.

Risk: The internal-use limitation may restrict affiliates, contractors, service providers, or customer-facing deployments unless expressly covered by the Order Form.

2026-08-27 · Privacy Policy

grew 3.5% · Observed by clause.watch

Summary of Important Changes

1. Privacy policy update and contact information

  • The policy is now identified as “Privacy Policy — Last updated: May 2026.”
  • The contact section has been substantially revised:
  • The prior contact-information heading and address formatting appear to have been replaced or reorganized.
  • Customers may now contact Appcues regarding:
  • Questions about the policy;
  • Collection and use of personal information; and
  • Exercise of privacy rights under the policy and applicable law.
  • The policy expressly provides the email address support@appcues.com for these purposes.

Risk/impact: This is generally helpful, but the updated “last updated” date may trigger contractual notice, consent, or change-management requirements. Customers should confirm whether the policy is incorporated into their agreement and whether amendments require advance notice or consent.

2. Security and privacy overview restructured

The prior discussion of information categories and general handling practices has been replaced with an overview emphasizing:

  • At-rest and in-transit encryption;
  • Coverage of all customer and end-user data;
  • Customer control over the amount of personally identifiable information handled by Appcues, including through “Identity Verification”;
  • A shared-responsibility model for security and privacy; and
  • The Appcues Trust Center and implementation of measures described there.

Risk/impact: The revised language is more security-focused but may be less specific about the categories of information collected and the baseline protections Appcues contractually promises. References to the Trust Center may shift important details into external materials that could change over time.

3. Third-party service disclosures

The policy continues to state that Appcues does not sell data to third parties. It also clarifies that data may be provided to third-party services:

  • For use within or in support of the Appcues product or business;
  • At the direction of customers; and
  • For examples such as providing analytics graphs in the Appcues Studio application and managing related functions.

Risk/impact: The wording may broaden or clarify the permitted sharing/use of customer or end-user data for service providers and business operations. The provision does not identify specific vendors, data categories, retention limits, or restrictions on vendors’ independent use.

4. Retention and deletion

The revised text refers to data being deleted or aggregated in the ordinary course of business and states that deletion requests may be sent to support@appcues.com.

Risk/impact: “Ordinary course of business” is potentially flexible and does not establish a definite retention period or deletion deadline.

5. AI-model training

No express change concerning AI training was identified in the supplied diff. The diff does not add or remove language expressly permitting or prohibiting use of customer or end-user data to train, fine-tune, evaluate, or improve AI models. However, the broader references to use for Appcues’s “product or business” and sharing with third-party services could create ambiguity if AI-related processing is performed under those purposes. Customers seeking to prohibit training should request an express contractual restriction.

2026-08-27 · Privacy Policy

shrank 3.4% · Observed by clause.watch

Summary

The diff only states that approximately 86 words were added, but it does not provide the actual added language.

Changes Identified
  • No substantive contractual changes can be analyzed from the information provided.
  • No specific additions, deletions, or replacements are shown.
  • The legal effect of the added text is therefore unknown.
Customer Data and AI Training
  • The diff does not reveal whether customer data may be:
  • Used to train, fine-tune, or improve AI models;
  • Shared with affiliates, vendors, or third-party AI providers;
  • De-identified, aggregated, or retained for model development;
  • Used for human review, automated profiling, or other secondary purposes;
  • Excluded from training by default or only excluded through an opt-out process.
  • Any new AI-training permission could create material risks involving confidentiality, intellectual property, privacy compliance, data retention, and use of customer content beyond the contracted services.
Further Information Needed

Please provide the actual 86-word addition, including the surrounding clause if possible. Without the text, it is not possible to determine whether the amendment creates new rights to use customer data, changes consent or opt-out requirements, or shifts liability and compliance obligations.

2026-08-26 · Terms of Service

grew 6.8% · Observed by clause.watch

Summary of Important Changes

1. Account and Registration Requirements

  • The customer must be a human; accounts created by bots or automated methods are prohibited.
  • Customers must provide a valid email address and any other information Appcues requests during registration.
  • One person or legal entity may not maintain more than one account.
  • Customers are responsible for account and password security.
  • Appcues disclaims liability for losses caused by the customer’s failure to meet these security obligations.
  • Personally identifiable information submitted by the customer is expressly made subject to Appcues’ Privacy Policy.

Risk: The Privacy Policy becomes important to understanding how personal data is handled, but its terms are not included here and may be changeable separately.

2. Broader and More Detailed Use Restrictions

The revised language adds or clarifies restrictions against:

  • Illegal or unauthorized use.
  • Violating applicable laws, including copyright law.
  • Use beyond one product unless authorized in the Order Form.
  • Reselling, sublicensing, leasing, distributing, or providing the Services to third parties.
  • Storing or transmitting unlawful, infringing, libelous, tortious, or privacy-violating material.
  • Transmitting malicious code or disrupting the Services.
  • Unauthorized access, circumvention of usage limits, copying, framing, mirroring, or accessing the Services to build a competing product or service.

Risk: These restrictions may give Appcues broad grounds to suspend or terminate access, particularly because “unauthorized” use and circumvention may be interpreted broadly.

3. Acceptable Use Policies

  • Email Services must comply with the Acceptable Use Policy (AUP), located at an external Appcues URL.
  • New language provides that use of Appcues AI Features must comply with a separate AI AUP at https://www.appcues.com/ai-aup.

Risk: The AI AUP is incorporated by reference but is not provided in the diff. Customers should review it and confirm whether Appcues may amend it unilaterally. Violations could affect access to AI Features or the broader Services.

4. AI Features and Training of AI Models

  • The diff adds references to “Appcues AI Features.”
  • The AI Features are subject to the separate AI AUP.
  • No express provision in the provided diff states whether customer data, prompts, inputs, outputs, usage information, or other content may be used to train, fine-tune, evaluate, or improve AI models.
  • There is also no clear commitment that customer data will be excluded from model training, deleted after processing, segregated, or protected from use by third-party AI providers.

Key risk: The absence of an express “no training on customer data” restriction leaves this issue unresolved. The Privacy Policy, AI AUP, Data Processing Addendum, or other incorporated terms may contain important permissions or limitations. These documents should be reviewed before using confidential, personal, or proprietary information with the AI Features.

5. Intellectual Property and License Structure

  • The revised structure restates that Appcues and its licensors retain all rights, title, and interest in the Services and related intellectual property.
  • Customer rights are limited, non-exclusive, non-transferable, non-sublicensable, and solely for internal business purposes during the subscription term.

Risk: The terms do not, in this excerpt, clarify ownership or permitted use of AI-generated outputs or whether outputs may be used commercially after termination.

2026-08-25 · Privacy Policy

grew 3.5% · Observed by clause.watch

Key Changes

1. Broader and more detailed description of security/privacy framework

The policy replaces a general statement that Appcues handles data differently based on “sensitivity in context” with references to:

  • At-rest and in-transit encryption;
  • Customer control, through identity verification, over the amount of personally identifiable information handled;
  • A “Shared Responsibility Model” for security and privacy; and
  • The Appcues Trust Center and related implementation measures.

Risk/impact: These additions may provide useful context, but they are largely high-level descriptions rather than binding security commitments. The “Shared Responsibility Model” may also emphasize that customers—not Appcues alone—are responsible for certain security and privacy controls. Customers should review the Trust Center and any incorporated security documentation to determine whether specific obligations, standards, or remedies apply.

2. Third-party use and disclosures are clarified and potentially broadened

The prior language stated that Appcues does not sell data and, in specific cases, provides data to third-party services “for use within or in support of the Appcues product or business or at the direction of our customers.”

The revised text retains the no-sale statement but more clearly authorizes third-party use for purposes including:

  • Supporting the Appcues product or business;
  • Acting at the customer’s direction; and
  • Providing analytics graphs in the Appcues Studio application.

Risk/impact: This confirms that customer and end-user data may be disclosed to service providers and potentially used across Appcues’s broader business operations, not solely for a narrowly defined customer service. The policy excerpt does not identify the vendors, limit their use, address international transfers, or explain whether they may retain data. Those issues should be checked in the subprocessors list and the customer’s data-processing agreement.

3. Deletion language and contact process

The revised text expressly states that data may be deleted or aggregated in the ordinary course of business and adds that deletion requests may be sent to support@appcues.com. The contact section is also rewritten to invite questions and requests concerning privacy rights and applicable law.

Risk/impact: “Ordinary course of business” is vague and may permit retention or aggregation for an unspecified period. The excerpt does not provide a firm deletion deadline, define “aggregated,” or explain whether backups and third-party copies are covered.

4. AI-model training

No express provision concerning artificial intelligence, machine-learning model training, model improvement, prompts, embeddings, or use of customer data to train models appears in the supplied diff.

Important limitation: The absence of a training provision does not establish that customer data will not be used for AI training. The revised third-party/business-use language could create uncertainty if AI vendors or analytics providers are involved. Customers should obtain written confirmation that customer and end-user data—including telemetry, analytics, support content, and derived data—is not used to train or improve general-purpose or provider-owned AI models unless expressly authorized.

5. Administrative updates

The policy is dated May 2026, and the contact information section is reformatted and expanded.

2026-08-24 · Privacy Policy

shrank 3.4% · Observed by clause.watch

Summary

The provided diff only states that approximately 86 words were added, but does not include the actual added language or identify where it appears in the agreement.

AI Training and Customer Data

  • No conclusions can be drawn about whether the customer’s data may be:
  • Used to train, fine-tune, or improve AI models;
  • Used to develop products or services;
  • Shared with model providers or other third parties;
  • Anonymized, aggregated, or retained for training purposes; or
  • Excluded from training by default or only upon customer request.

Other Legal Risks

The substantive effect of the amendment cannot be assessed without the wording of the 86 added words. In particular, the missing text could change:

  • Data ownership or licensing rights;
  • The provider’s rights to access, retain, or process customer content;
  • Confidentiality obligations;
  • Use of subprocessors or third-party AI providers;
  • Security and breach obligations;
  • Liability, indemnification, or compliance responsibilities; or
  • The customer’s ability to opt out or terminate.

Information Needed

Please provide the actual 86-word addition, including any surrounding text showing where it was inserted. The original and revised clauses would be especially helpful if the addition modifies an existing provision.

2026-08-24 · Terms of Service

shrank 6.4% · Observed by clause.watch

Summary

The provided diff does not include the actual amended contract language. It only states:

> “Added approximately 186 words to the document”

Accordingly, it is not possible to identify the legal changes, new risks, or whether the customer’s data may be used to train AI models.

AI Training and Data Use

No substantive language addressing any of the following was provided:

  • Whether customer data may be used to train, fine-tune, test, or improve AI models
  • Whether prompts, inputs, outputs, personal information, or confidential information are retained
  • Whether data may be shared with affiliates, vendors, or model providers
  • Whether customer data is used for service improvement or product development
  • Whether the customer can opt out of AI training or data-use practices
  • Whether data is anonymized, aggregated, or de-identified before use
  • Ownership of inputs, outputs, or trained-model derivatives
  • Deletion, retention, security, or audit obligations relating to AI processing

Other Contract Risks

No assessment can be made of changes concerning:

  • Liability, indemnification, or disclaimers
  • Confidentiality and privacy obligations
  • Intellectual-property ownership or licenses
  • Data-security requirements
  • Service levels or termination rights
  • Governing law or dispute resolution
  • Subcontractors or international data transfers

Information Needed

Please provide the actual 186-word addition and identify any deleted or replaced text using the stated notation. Without the underlying wording, the legal impact of the amendment cannot be reliably analyzed.

2026-08-24 · Privacy Policy

grew 3.5% · Observed by clause.watch

Executive Summary

The diff appears to reorganize and substantially expand the introductory privacy and security provisions, but the formatting is heavily duplicated and fragmented. The clearest changes concern security controls, customer responsibility, third-party service providers, deletion/aggregation language, and contact information.

Important Changes

1. New or expanded security and privacy framework

The revised text adds or emphasizes:

  • At-rest and in-transit encryption.
  • Customer control, through “Identity Verification,” over the amount of personally identifiable information handled by Appcues.
  • An express “Shared Responsibility Model for Security and Privacy.”
  • The Appcues Trust Center and implementation of measures identified there.

Risk/impact: These statements may create reliance on security controls or customer responsibilities described outside the policy, particularly in the Trust Center. The policy should clearly identify whether Trust Center materials are contractual, incorporated by reference, or merely informational.

2. Third-party disclosures are described more broadly and specifically

The revised language states that Appcues may provide data to third-party services:

  • For use within or in support of the Appcues product or business;
  • At the direction of customers; and
  • For examples such as providing analytics graphs in the Appcues Studio application and managing related services.

The policy continues to state that Appcues does not “sell” data to third parties, but this does not prohibit disclosures to service providers, contractors, or other processors.

Risk/impact: “Use within or in support of the Appcues product or business” is broad and could permit service-provider processing beyond strictly necessary customer instructions. Customers should confirm whether vendors may retain, combine, analyze, or independently use the data, and whether a current subprocessors list and objection rights apply.

3. Customer data used to train AI models

No express AI-training authorization or prohibition is visible in the supplied diff. The revised text does not clearly say whether customer data, end-user data, prompts, outputs, telemetry, or other content may be used to train, fine-tune, evaluate, or improve artificial-intelligence or machine-learning models.

The broad third-party/service-provider wording could potentially encompass AI vendors, depending on the rest of the policy or related agreements, but it does not expressly resolve that issue.

Recommended clarification: Add an explicit statement addressing whether customer data may be used for AI training or model improvement, whether data is de-identified or aggregated first, whether customer opt-out/consent is available, retention limits, and whether AI providers may use the data for their own purposes.

4. Deletion and aggregation language

The diff retains or introduces language stating that data is deleted or aggregated in the ordinary course of business. It also identifies support@appcues.com for deletion requests.

Risk/impact: “Ordinary course of business” is vague and may not establish a definite deletion period. The policy should specify retention schedules, backup handling, legal-retention exceptions, and whether aggregated or de-identified data may be retained indefinitely.

5. Contact and rights language

The revised contact section expressly invites questions about the policy, collection and use of personal information, and exercising rights under the policy and applicable law. It provides support@appcues.com and Appcues’ mailing address.

Risk/impact: This is helpful, but the policy should identify the specific privacy rights available, applicable response timelines, and any regional privacy representatives or appeal procedures.

Watch this company's contracts

We re-read these documents every six hours and email you when the wording changes.

Start monitoring free