clause.watch Contracts Recent changes Start monitoring

Monitored company

Cognito Forms

clause.watch tracks 2 legal documents published by Cognito Forms, re-reading each one every six hours. Below is what each document covers, in plain English.

Privacy Policy

36,833 characters · Read the original

Cognito Forms Privacy Policy — User Overview

*Based on the policy modified May 29, 2026. This is a practical summary, not legal advice.*

1. Data Collection & Usage

Account and billing information

Cognito Forms collects information you provide, including:

  • First and last name
  • Email address and password
  • Organization name
  • Profile image, job title, and department
  • IP address
  • Billing contact and address
  • Business type, business name, tax identifier, and payment-card details for paid plans

Cognito states that it does not directly capture, process, store, or transmit credit-card information; Stripe handles subscription payment-card processing.

Usage and technical data

Cognito records information about use of the service, such as IP address, date and time, browser, application activity, internal user and organization identifiers, errors, and server requests. It uses this information to:

  • Operate, secure, and administer the service
  • Prevent fraud, abuse, spam, and unauthorized access
  • Provide support and communications
  • Analyze, audit, research, and improve products and services
  • Personalize the service

Cookies are required to log in. Cognito says it does not place cookies or Google Analytics tracking on public or embedded forms, and does not track your customers when they submit those forms. However, paid organizations may independently connect their own analytics account to track form usage.

Your form data

The forms, entries, and uploaded files you create are described as belonging to you. Cognito nevertheless processes and may share that data as necessary to provide the service, deliver emails, support integrations, comply with law, or investigate abuse.

2. User Rights and Controls

Users may generally:

  • Access, download, update, or remove account information
  • Change their name, email, and password through account settings
  • Opt out of marketing emails using the unsubscribe link
  • Delete their account

Deleting an account also deletes organizations where the user is the sole owner, including forms and entries. Those materials become inaccessible and unrecoverable. Some historical support records may remain, and deleted information may remain in secure backups for up to 30 days. Information may also be retained for legal, dispute-resolution, security, or contractual purposes.

For information collected through someone else’s form, the relevant form owner—not Cognito—is primarily responsible for access, correction, or deletion requests.

European users may have additional GDPR rights, but organizations collecting EEA personal data must sign Cognito’s Data Processing Addendum. The policy also references U.S. state privacy laws and the EU-U.S., UK, and Swiss-U.S. Data Privacy Frameworks.

3. Third-Party Sharing

Cognito says it does not sell or mine personal data. It shares information with service providers only to operate, secure, support, improve, or enable features, including:

  • Microsoft Azure for hosting, with data geo-replicated in U.S. data centers
  • Stripe, PayPal, and Square for payment functions
  • MailChimp, Mandrill, Postmark, and Mailgun for email delivery
  • Zendesk and Pendo for support and in-app communications
  • Google Analytics, Google Maps, Application Insights, VWO, and People Data Labs
  • Optional integrations such as Zapier, Power Automate, Make, Google Drive, and OneDrive

Optional integrations can transmit form entries and files to other cloud services. Users must review and accept those providers’ separate terms and privacy policies.

Cognito may also disclose data to authorities, fraud-prevention organizations, or other parties when legally required, to enforce rights, investigate Terms of Service violations, or protect safety.

4. AI/ML Training

The policy does not expressly state that Cognito uses customer data to train general-purpose AI models.

It states that:

  • AI may process account information, form designs, organization details, prompts, and usage information to generate content, provide support, and improve service reliability.
  • Form-entry data will not be processed by AI without explicit consent.
  • If consent is given, entry data is used only to provide the requested functionality.
  • AI providers may process data only as service providers and may not retain or use it for their own purposes.
  • Limited human review may occur for support, quality assurance, and debugging.

Users should verify how “explicit consent” is obtained for particular AI features.

5. Key User Obligations

Users must:

  • Provide accurate account and billing information
  • Keep login credentials confidential
  • Promptly report suspected account compromise
  • Obtain appropriate consent before collecting personal information through forms
  • Comply with Cognito’s Terms of Service and applicable privacy laws
  • Understand that deleting an account may permanently destroy organizational data

6. Liability and Disputes

This policy itself provides no detailed warranty disclaimer, damages cap, or general liability limitation; those provisions are likely in the separate Terms of Service.

Privacy concerns should first be sent to privacy@cognitoforms.com. For unresolved EU/UK/Swiss Data Privacy Framework complaints, users may contact JAMS at no cost and, in certain circumstances, invoke binding arbitration under the Framework. U.S. data is stored and processed in the United States.

Cognito promises notice “as soon as possible” after a material security breach affecting users or organizations, but the policy does not specify a fixed notification deadline.

7. Policy Changes

Cognito may revise the policy by posting an updated version. Non-material changes generally take effect when posted. For material changes to data practices, it promises at least 15 days’ advance notice by email or another reasonable method, unless law or contractual terms require otherwise. The modification date identifies the latest version.

Terms of Service

30,479 characters · Read the original

Cognito Forms Terms of Service: Key User Takeaways

*This summary is based only on the Terms provided. The separate Privacy Policy, Acceptable Use Policy, Cookie Policy, Data Processing Addendum, and feature-specific terms may contain important additional details.*

1. Data Collection and Usage

What data is involved

The Terms indicate that Cognito Forms may handle:

  • Account information, including your name, email address, username, password-related information, and billing/payment details.
  • Forms, entries, uploaded files, templates, profile information, and other content you submit.
  • Personal information collected from people who complete your forms.
  • Usage, account, and service-related information, although the specific categories and retention practices are primarily left to the Privacy Policy.

You own your forms and entries, and Cognito says it claims no intellectual-property ownership over your uploaded content. However, you are responsible for ensuring you have the right to collect and use that content.

How Cognito may use content

Cognito may:

  • Provide, operate, maintain, and support the Service.
  • Review, copy, and internally distribute content from forms and accounts to investigate abuse, detect scams or problematic accounts, enforce the Terms, protect users, and troubleshoot or reproduce technical issues.
  • Create internal “Tools,” including algorithms and programs, for fraud detection and account enforcement.
  • Disclose information as described in its Privacy Policy or when legally required.

The Terms do not provide a full data-retention schedule. Closing an account generally results in permanent deletion of the account, forms, entries, and associated data, although residual backup copies may temporarily remain and cannot be recovered.

2. User Rights

  • You may close your account at any time.
  • You retain ownership of your forms, entries, and uploaded materials.
  • Account deletion is generally permanent and does not guarantee refunds or credits.
  • If you share forms, entries, templates, or other content, you authorize others to view and share that content as enabled by your use of the Service.
  • The Terms do not expressly describe rights to access, correct, export, restrict, or object to processing. Those rights may be addressed in the Privacy Policy or a Data Processing Addendum.
  • Users in the EEA, UK, or Switzerland collecting personal information must sign Cognito’s Data Processing Addendum to comply with GDPR-related requirements.

3. Third-Party Sharing

The Terms incorporate the Privacy Policy, which presumably governs detailed disclosures. Cognito may share or disclose information:

  • With service providers or other third parties needed to operate the Service.
  • To investigate abuse, enforce the Terms, protect users, or comply with law.
  • In response to subpoenas or legal demands; Cognito may charge you for its costs in responding.
  • Through payment processors such as Stripe, PayPal, or Square. Credit-card information generally must not be stored in Cognito Forms except through supported payment-processing integrations.

You are responsible for obtaining appropriate consent from people whose information you collect and for explaining your data practices in your own privacy policy.

4. AI/ML Training

The Terms do not expressly state that customer data is used to train general-purpose AI or machine-learning models.

However, Cognito expressly reserves the right to review and use form/account content to create internal algorithms and programs for fraud detection, abuse prevention, enforcement, and customer support. This could involve automated analysis or machine-learning techniques. The Terms do not clearly distinguish between “AI training,” service-improvement analytics, and security tools. Review the Privacy Policy or obtain clarification if this distinction matters to you.

5. Key User Obligations and Restrictions

You must:

  • Be at least 18 or the applicable age of majority and have authority to bind yourself or your organization.
  • Keep account credentials confidential and report unauthorized access immediately. You bear losses from stolen or hacked passwords.
  • Comply with applicable privacy, data-protection, sector-specific, and consumer-protection laws.
  • Obtain consent and required authorizations for information collected through your forms.
  • Own or have permission to use uploaded content.
  • Use the Service lawfully and only for creating, collecting, and managing forms and entries.

You may not reverse engineer, resell, disrupt, overload, bypass security, host unrelated files, or use the Service for unlawful, fraudulent, malicious, abusive, or prohibited purposes. Cognito may throttle, suspend, terminate, or delete accounts, sometimes without advance notice.

Important commercial risks include automatic subscription renewal, automatic conversion of trials to paid monthly plans, mostly non-refundable fees, usage overages, annual commitments, and possible deletion of inactive free accounts after six months without login.

6. Liability and Disputes

  • The Service is provided “as is,” with broad disclaimers of warranties, including security, reliability, availability, and fitness for purpose.
  • Cognito excludes indirect, special, punitive, and consequential damages to the fullest extent permitted by law.
  • Its total liability for claims in a month is capped at the amount you paid for the Service during the preceding month.
  • You must indemnify Cognito for certain claims arising from your misuse, breaches, or data-collection activities.
  • If Cognito successfully sues for misuse or breach, you may owe reasonable attorney fees.
  • South Carolina law governs disputes. The Terms do not specify arbitration or an exclusive court location.
  • Force-majeure provisions broadly excuse outages or failures caused by events outside Cognito’s control.

7. Changes and Notices

  • Non-material changes generally take effect when posted.
  • Material privacy or data-processing changes require at least 15 days’ advance notice.
  • Material billing, pricing, subscription, renewal, or payment changes affecting existing paid subscriptions require at least 30 days’ advance notice.
  • Notice may be provided by email, website posting, or another reasonable method. Users are responsible for monitoring the provided email address and website.

Change history

2026-09-05 · Privacy Policy

shrank 2.6% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-09-03 · Privacy Policy

grew 2.6% · Observed by clause.watch

Summary of Important Changes

1. Customer-support data is now shared with Zendesk

The revised language substantially changes the description of Cognito Forms’ customer-support practices:

  • Cognito Forms now expressly states that it provides “direct one-on-one support” and uses Zendesk to provide email, chat, and social-media support.
  • Information provided through chat sessions, email, Facebook, Twitter, or similar channels may be shared with Zendesk.
  • Zendesk may use that information to create and track support requests and facilitate communications needed to answer questions or resolve issues.
  • The revised wording says only the “minimum information necessary” is shared, but it does not define what information qualifies as necessary or impose a specific deletion period.
  • The policy refers customers to the Zendesk Privacy Policy, potentially making Zendesk’s separate data practices relevant.

Risk: Customers may disclose sensitive information in support interactions without realizing it will be transferred to a third-party service provider. The “minimum information necessary” limitation is helpful but subjective and does not expressly address sensitive personal information, international transfers, retention, or subcontractors.

2. New use of Pendo for analytics and communications

The policy now identifies Pendo as an “analytics, communication and development-planning platform.” Related additions indicate Pendo may be used for:

  • User sessions;
  • Onboarding;
  • In-app messaging; and
  • Activity-related emails.

Risk: This suggests expanded monitoring of user behavior and product activity, potentially linked to identifiable accounts. The excerpt does not specify what activity data is collected, whether it is shared with Pendo, how long it is retained, or whether users can opt out. The relationship between Pendo’s data use and Cognito Forms’ own product-development activities is also not fully explained.

3. No express AI-training provision identified

The provided diff does not add language expressly stating that customer data, form submissions, support content, usage data, or personal information may be used to train, fine-tune, evaluate, or improve artificial-intelligence models.

It also does not add an express prohibition against using customer data for AI training.

Implication: Based solely on this diff, there is no clear new contractual authorization for AI-model training. However, the broader descriptions of analytics, product development, support communications, and third-party processing may leave ambiguity about whether certain data could later be used for automated systems or AI-related development under other policy language.

4. Privacy inquiries and account deletion

  • Customers are given a specific privacy contact: privacy@cognitoforms.com.
  • The policy states that deleted information may remain in backups.
  • Account deletion is clarified as deleting both the user account and all associated organizations.

Risk: Deleting an account may have broader consequences than a user expects because all organizations are included, while backup retention means deletion may not be immediate or complete.

5. Other changes

The remaining edits are primarily grammatical, formatting, terminology, or contact-information updates. No material change to AI use, marketing consent, security obligations, or breach-notification standards is apparent from the excerpt.

2026-09-03 · Privacy Policy

shrank 2.6% · Observed by clause.watch

Summary

The supplied diff does not include the actual amended contract language. It only states:

> “Added approximately 149 words to the document”

As a result, it is not possible to determine:

  • What contractual provisions were added or changed.
  • Whether customer data may be used to train, fine-tune, evaluate, or improve AI models.
  • Whether data use is limited to providing the services or extended to product development, analytics, or model training.
  • Whether the customer’s confidential information, personal data, prompts, outputs, or usage metadata may be retained or disclosed.
  • Whether the provider may use data in aggregated, de-identified, or identifiable form.
  • Whether the customer can opt out of AI training or request deletion.
  • Any changes to security, confidentiality, intellectual-property ownership, indemnities, or regulatory obligations.
Risk assessment

No substantive legal risk can be assessed from the information provided. The statement that approximately 149 words were added does not identify the wording, scope, or effect of those additions.

Information needed

Please provide the actual diff, including the added language in {braces} and any deletions or replacements. Particular attention should be given to terms such as:

  • “train,” “fine-tune,” “improve,” “develop,” or “evaluate” models;
  • “customer data,” “content,” “inputs,” “outputs,” or “usage data”;
  • “aggregated,” “de-identified,” or “anonymized” data;
  • retention, deletion, confidentiality, and opt-out rights; and
  • ownership or licensing of data and AI-generated outputs.

2026-09-02 · Terms of Service

shrank 4.9% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-09-01 · Terms of Service

grew 5.1% · Observed by clause.watch

Summary

The supplied diff states only: “Added approximately 247 words to the document.” It does not include the actual added language or identify which provisions changed.

Key Legal Changes

  • Cannot be determined from the information provided. The content of the 247 new words is necessary to assess changes to:
  • Customer obligations or rights
  • Provider permissions and restrictions
  • Liability, indemnification, warranties, or disclaimers
  • Confidentiality and data-security obligations
  • Termination or dispute-resolution provisions
  • Governing law or other commercial terms

AI Training and Customer Data

  • No identifiable change can be confirmed. The supplied text does not show whether customer data may be:
  • Used to train, fine-tune, evaluate, or improve artificial-intelligence or machine-learning models
  • Shared with model providers or other third parties
  • Aggregated, anonymized, or de-identified for model development
  • Retained after termination for training or related purposes
  • Excluded from training unless the customer opts in or opts out

Risk Assessment

Because the actual additions are missing, it is not possible to determine whether the amendment creates new risks, including:

  • Broader rights to use customer content or personal data
  • Use of data for AI training without separate consent
  • Unclear ownership of inputs, outputs, or trained-model results
  • Reduced confidentiality or security protections
  • Indefinite data retention
  • Lack of an opt-out mechanism or contractual deletion requirement

Please provide the actual 247-word addition, including any surrounding deleted or replaced language, for a reliable legal comparison.

2026-09-01 · Terms of Service

shrank 4.9% · Observed by clause.watch

Summary of Important Changes

1. AI and Model Training

  • No express authorization to train AI models was added. The revised language does not specifically say that Cognito Forms may use customer data, form submissions, or account content to train, fine-tune, or improve generative AI or machine-learning models.
  • The Terms do refer to Cognito using Content from Forms and accounts to create “Tools” that help identify problem accounts. This appears to concern fraud, abuse, or account-monitoring algorithms, rather than general AI-model training.
  • The revised data-protection language requires customers to obtain consent for their customers’ data to be accessed, used, or disclosed by Cognito Forms “for providing the tools.” This could permit data use for those tools, but the scope is not clearly defined and could create uncertainty about whether machine-learning systems are included.
  • Customers must explain in a written privacy policy how they plan to use collected data and must obtain any authorizations needed to enable Cognito Forms to provide the Services. Customers should seek clarification on:
  • Whether submissions are used to train or improve models;
  • Whether data is anonymized or aggregated;
  • Whether third-party AI providers receive the data; and
  • Whether customers can opt out.

2. Expanded Customer Data-Compliance Obligations

  • The former, more specific requirements—such as signing a Data Processing Addendum for EEA, UK, or Swiss data and complying with California law—are replaced with broader obligations to comply with all applicable privacy and data-protection laws.
  • Customers are expressly responsible for:
  • Appropriate use and protection of sensitive information and identifiers;
  • Obtaining and maintaining explicit customer consent;
  • Obtaining authorizations required for Cognito Forms to provide its tools and Services; and
  • Disclosing intended data uses in a written privacy policy.
  • This shifts more compliance responsibility and regulatory risk to the customer.

3. Indemnity and Liability Risk

  • The revised language adds or substantially expands the customer’s obligation to defend, indemnify, and hold Cognito Forms harmless from claims, suits, or proceedings arising from acts or omissions concerning data collected through the customer’s forms.
  • The indemnity may cover losses and attorney fees resulting from third-party claims, including claims involving unauthorized data use or disclosure.
  • Cognito’s liability remains broadly limited, including exclusion of indirect, punitive, special, consequential, and similar damages, with total liability capped at fees paid for the preceding month.

4. Other Material Changes

  • Free Individual Accounts may be permanently deleted after six months without login, including associated data.
  • Material privacy or data-processing changes receive at least 15 days’ notice; material billing or subscription changes receive 30 days’ notice.
  • Subpoena-related costs may be charged to the customer, including employee time and deposition expenses.
  • Security-breach notice language remains, but customers must promptly notify affected individuals where required.

2026-08-31 · Terms of Service

grew 5.1% · Observed by clause.watch

Summary of Important Changes

AI and Data Training

  • No express authorization to train AI models was added. The diff does not state that Cognito Forms may use customer data to train generative AI, machine-learning, or other artificial-intelligence models.
  • The existing provision allowing Cognito Forms to distribute Content from Forms and accounts to create algorithms and programs (“Tools”) to identify problem accounts appears substantively unchanged. This still permits some use of customer content for fraud, abuse, or account-monitoring tools, but it is not expressly described as AI training.
  • The revised data-compliance language requires customers to obtain consent and authorizations allowing Cognito Forms to use collected data “for providing the tools.” This broadens and clarifies the customer’s responsibility to obtain permission for Cognito’s tool-related data use, but does not define the tools, the data involved, retention, model training, or whether data is de-identified.

Major Privacy and Compliance Changes

  • The prior regional requirements were removed:
  • Previously, customers collecting data from individuals in the EEA, UK, or Switzerland had to sign Cognito’s Data Processing Addendum (DPA) for GDPR compliance.
  • Previously, California-related language specifically referenced the CCPA and recommended signing the DPA.
  • The replacement imposes broader, jurisdiction-neutral obligations on customers to:
  • Comply with all applicable data-protection and privacy laws.
  • Protect sensitive information and personal identifiers.
  • Obtain and maintain explicit customer consent for access, use, or disclosure of data and for Cognito’s provision of tools.
  • Disclose in a written privacy policy how the customer plans to use collected data.
  • Obtain all authorizations necessary for Cognito Forms to provide the Services.
  • Risk: Removing the express DPA requirement may make the contract less clear regarding Cognito’s processor obligations, international transfers, security commitments, subprocessors, data-subject rights, and breach responsibilities. Customers handling regulated data should confirm whether a DPA remains available or necessary.

Increased Customer Liability

  • The revised language makes the customer solely responsible for acts or omissions concerning data collected through its forms.
  • Customers must defend, indemnify, and hold Cognito harmless from claims, suits, or proceedings arising from collected data or noncompliance with the revised policy.
  • Risk: This may shift substantially more privacy, consent, and regulatory exposure to the customer, potentially including third-party claims involving Cognito’s handling of data based on customer instructions.

Other Material Changes

  • Liability and warranty provisions were reorganized, but the core limits remain: Cognito disclaims warranties and consequential damages, and total liability is capped at fees paid for the prior month.
  • Cognito retains the ability to delete inactive free Individual Accounts and associated data after six months without login.
  • Customers may be charged for subpoena-related costs, including employee time spent retrieving records, preparing documents, and participating in depositions.
  • The Terms were modified on May 29, 2026.

2026-08-26 · Privacy Policy

grew 2.6% · Observed by clause.watch

Summary of Important Changes

AI Model Training

  • No express change addresses AI training. The revised text does not state whether Cognito Forms, Zendesk, Pendo, Google, or other service providers may use customer data to train, fine-tune, evaluate, or improve artificial-intelligence models.
  • The new language says information shared with Zendesk is used to create and track support requests and to facilitate communications needed to resolve issues. This is narrower than the prior reference to Zendesk’s handling of information, but it does not expressly prohibit secondary uses, including AI training.
  • Because Zendesk and other vendors’ privacy practices are incorporated by reference, customers may need to review those external policies to determine whether submitted support information can be used for model training or product improvement.
  • Risk: Customers may reasonably expect that “only uses this information to support the request” limits use to that purpose, but the provision does not clearly address vendor retention, de-identification, human review, automated processing, or AI training. A specific contractual prohibition or opt-out mechanism would provide greater certainty.

Customer Support and Data Sharing

  • The policy now provides a substantially more detailed description of Cognito’s support operations:
  • Cognito provides direct, one-on-one customer support.
  • Zendesk is used for email, chat, and social-media support.
  • Customer information is shared with Zendesk to create and track requests and support resolution.
  • The policy states that Cognito shares only the “minimum information necessary” to create support requests.
  • Pendo has been added as an analytics, communication, and development-planning platform. Its stated uses include:
  • Chat sessions;
  • User onboarding;
  • In-app messaging; and
  • Activity-related emails.
  • Risk: The policy identifies additional processing and external platforms but does not specify precisely what data is sent to Pendo or Zendesk, how long it is retained, whether data is combined across services, or whether vendors use it for their own purposes.

Rights, Deletion, and Complaints

  • The policy now expressly directs users with privacy or data-use concerns to privacy@cognitoforms.com, promising prompt attention.
  • The existing account-deletion language is clarified typographically but still states that deleting an account also deletes all associated organizations. Deleted information may remain in backups.
  • The policy adds or restates a commitment to security and breach notification, but the notification standard remains tied to an unauthorized intrusion that materially affects the customer or organization.

Other Changes

  • Most remaining edits are grammatical, typographical, or stylistic, including standardized quotation marks, apostrophes, and punctuation.
  • The policy states that changes to data-processing or privacy practices will generally receive at least 15 days’ advance notice, unless a different notice period applies.
  • The revision is marked May 29, 2026.

2026-08-26 · Terms of Service

shrank 4.9% · Observed by clause.watch

Summary

The provided diff does not include the actual amended contract language. It only states:

> “Added approximately 247 words to the document”

Accordingly, it is not possible to determine:

  • What contractual provisions were added or changed;
  • Whether customer data may be used to train, fine-tune, evaluate, or improve AI models;
  • Whether such use is mandatory or optional;
  • Whether customer consent is required;
  • Whether data is anonymized, aggregated, de-identified, or retained in identifiable form;
  • Whether the customer can opt out or revoke permission;
  • Whether data may be shared with affiliates, vendors, or third-party AI providers;
  • What security, confidentiality, deletion, or retention obligations apply; or
  • Whether the customer receives any ownership, control, or intellectual-property protections.

AI Training Risk Assessment

No conclusion can be reached regarding AI-model training because the relevant additions are not included in the diff. In particular, the text should be reviewed for terms such as:

  • “train,” “fine-tune,” “improve,” “develop,” or “evaluate” models;
  • “inputs,” “outputs,” “customer content,” or “usage data”;
  • “anonymized,” “aggregated,” or “de-identified” data;
  • rights granted to use data “for any purpose” or “commercial purposes”;
  • indefinite retention or post-termination use;
  • use by service providers or other customers; and
  • opt-out, consent, deletion, confidentiality, and security mechanisms.

Required Information

Please provide the actual redlined language, including the text shown within {}, [], and []{}. Without the substantive wording, any legal-risk analysis would be speculative.

2026-08-25 · Terms of Service

grew 5.1% · Observed by clause.watch

Summary of Important Changes

1. Customer data use and AI-related processing

  • The revised terms substantially change the customer’s privacy and data-compliance obligations. Customers must:
  • Comply with all applicable data-protection and privacy laws.
  • Properly use and protect sensitive information and personal identifiers.
  • Obtain and maintain explicit consent from individuals for the customer’s access, use, or disclosure of their data to Cognito Forms.
  • Obtain any authorizations needed for Cognito Forms to provide the Services.
  • Explain in a written privacy policy how the customer plans to use data collected through its forms.
  • Permit Cognito Forms to perform the actions described in the terms, including providing “tools.”
  • The prior language specifically required a Data Processing Addendum for personal information from the EEA, United Kingdom, or Switzerland and referenced GDPR and California requirements. The revised language removes that specific DPA requirement and replaces it with broader customer obligations. This may reduce procedural clarity and could leave customers uncertain about when a DPA is legally necessary.
  • The terms continue to allow Cognito Forms to use and distribute Content from Forms and accounts to create algorithms and programs (“Tools”) to identify problem accounts. The revised wording concerning customer authorization and use of “any” collected data may broaden the basis for this processing.
  • AI-training risk: The diff does not expressly state that customer data will be used to train generative AI or machine-learning models, nor does it expressly prohibit such use. However, the broad references to using customer data to create algorithms and “Tools,” together with the new consent and authorization language, could be interpreted as permitting algorithmic or AI-related processing. Customers should seek clarification on:
  • Whether form submissions, attachments, prompts, or metadata may be used for model training.
  • Whether data is anonymized or de-identified.
  • Whether third-party AI providers receive the data.
  • Whether customers can opt out or request deletion from training datasets.

2. Increased customer liability and indemnification

  • Customers now assume responsibility for losses resulting from acts or omissions concerning data collected through their Forms and must defend and indemnify Cognito Forms for related claims.
  • The indemnity language is broad and may cover third-party claims, attorney fees, and claims arising from misuse of the Service or compromised passwords.
  • The customer’s liability exposure may be significant, particularly for privacy, consent, or data-security violations.

3. Liability and warranty provisions

  • The revised terms retain broad warranty disclaimers and exclusions for indirect, punitive, special, and consequential damages.
  • Cognito Forms’ total liability remains capped at the amount paid for the Service in the prior month.
  • The revised language expressly disclaims warranties concerning security, reliability, timeliness, and performance, increasing customer risk for outages or data-related harm.

4. Other operational changes

  • Cognito may delete free Individual Accounts and associated data after six months of inactivity.
  • Material privacy or data-processing changes generally receive at least 15 days’ notice; billing or subscription changes receive at least 30 days’ notice.
  • Cognito may charge customers for subpoena-response costs, including employee time and document-retrieval expenses.

2026-08-25 · Terms of Service

shrank 4.9% · Observed by clause.watch

Summary

The provided diff does not include the actual added or changed contractual language. It only states:

> “Added approximately 247 words to the document”

Accordingly, it is not possible to determine:

  • What legal provisions were added or modified;
  • Whether liability, confidentiality, security, intellectual property, or termination rights changed;
  • Whether customer data may be used to train, fine-tune, evaluate, or improve AI models;
  • Whether data is shared with affiliates, vendors, or model providers;
  • Whether the customer can opt out of AI training or request deletion of training data; or
  • Whether the provider obtains rights to use customer content beyond providing the contracted services.

AI-Training Assessment

No specific AI-training language appears in the supplied diff. Therefore, no conclusion can be reached about whether the contract:

  • Uses customer data or inputs to train general-purpose or customer-specific models;
  • Uses data in de-identified, aggregated, or pseudonymized form;
  • Retains prompts, outputs, or uploaded materials for model improvement;
  • Allows human review of customer data;
  • Shares data with third-party AI providers; or
  • Limits use of customer data to providing the services.

Required Information

Please provide the actual 247 words added to the agreement, together with any surrounding deleted or replaced language. The full redline is preferable because the legal effect may depend on how the new language interacts with existing provisions concerning confidentiality, data ownership, permitted use, security, retention, and intellectual property.

2026-08-25 · Privacy Policy

shrank 2.6% · Observed by clause.watch

Summary

The diff only states that approximately 149 words were added; it does not include the actual added language or identify where it appears in the agreement.

Key Legal Changes
  • Cannot be determined from the information provided.
  • No substantive contractual terms are visible for review, including changes to:
  • Data ownership or licensing
  • Confidentiality
  • Privacy and security obligations
  • Intellectual property rights
  • Liability or indemnification
  • Termination rights
  • Use of customer content
AI Model Training
  • No conclusion can be reached regarding AI training.
  • The provided diff does not show whether customer data may be:
  • Used to train, fine-tune, or improve AI models
  • Reviewed by humans for model development
  • Combined with other customers’ data
  • Retained after termination
  • Used on an opt-in, opt-out, or mandatory basis
  • Subject to anonymization, de-identification, or other safeguards
Risk Assessment

The added language should be reviewed before assessing legal impact. Particular attention should be given to wording such as:

  • “improve,” “develop,” or “train” models or services
  • “anonymized,” “aggregated,” or “de-identified” data
  • Broad licenses to customer content or usage data
  • Rights that survive termination
  • Permission to share data with affiliates, vendors, or other customers
  • Any statement that customer data will not be used for training, especially if subject to exceptions

Conclusion: The actual 149 added words are required to identify the important legal changes and any new AI-training risks.

2026-08-24 · Terms of Service

grew 5.1% · Observed by clause.watch

Summary of Important Changes

1. Customer Data, Privacy, and AI/Algorithm Use

  • No express new authorization to train generative AI models appears in the diff. The revised language does not specifically say that Cognito may use Customer Content or form submissions to train, fine-tune, or improve artificial-intelligence models.
  • The Terms continue to permit Cognito to use and distribute Content from Forms and accounts to create algorithms and programs (“Tools”) that help identify problem accounts. This is broad enough to potentially include machine-learning or AI-based systems, but it does not clearly define:
  • whether customer data is used for model training;
  • whether data is de-identified or aggregated;
  • whether inputs or outputs are retained;
  • whether third-party AI providers receive the data; or
  • whether customers can opt out.
  • The revised privacy obligations now require customers to:
  • comply with applicable data-protection and privacy laws;
  • appropriately use and protect sensitive information and personal identifiers;
  • obtain and maintain explicit consent from their customers for access, use, or disclosure of the data to Cognito Forms; and
  • obtain any other authorizations needed for Cognito to provide the Services and Tools.
  • Customers must disclose in a written privacy policy how they plan to use the data collected. This shifts more compliance responsibility to the customer and may require updated notices, consent language, and contracts with form respondents.
  • The prior, more specific references to signing a Data Processing Addendum for EEA, UK, and Swiss data, and complying with the GDPR and California privacy law, are replaced with broader obligations. This may make the Terms less prescriptive, but it does not eliminate the customer’s legal obligations.

2. Data Liability and Indemnification

  • The revised Terms substantially expand customer responsibility for data collected through Forms. Customers assume responsibility for losses arising from acts or omissions relating to collected data and must comply with the revised privacy policy.
  • The customer must defend, indemnify, and hold Cognito harmless from claims, suits, or proceedings brought by form users relating to the customer’s data practices.
  • This creates potentially significant exposure if consent, disclosure, security, or AI-related data-use requirements are not properly handled.

3. Liability Cap and Disclaimers

  • The liability limitation is reorganized but remains broad: Cognito disclaims liability for indirect, punitive, special, and consequential damages, including service interruptions.
  • Cognito’s total liability remains capped at the amount paid for the Service in the preceding month.
  • Warranty disclaimers expressly include security, reliability, timeliness, and performance.

4. Other Notable Changes

  • Free Individual Accounts may be permanently deleted after six months without login.
  • Material privacy changes require at least 15 days’ notice; material billing or subscription changes require 30 days’ notice.
  • Credit-card processing language is clarified: Cognito says its systems do not process, store, or transmit card information when supported third-party processors such as Stripe, PayPal, or Square are used.
  • Subpoena-related costs may be charged to the customer, including employee time and deposition expenses.
  • The Terms state they were modified on May 29, 2026.

2026-08-21 · Terms of Service

shrank 4.9% · Observed by clause.watch

Summary

The diff does not include the actual amended contractual language. It only states:

> “Added approximately 247 words to the document”

Accordingly, it is not possible to identify the legal effect of the changes, including:

  • New or expanded rights to use customer data;
  • Whether customer data may be used to train, fine-tune, evaluate, or improve AI models;
  • Whether data may be shared with affiliates, service providers, or third parties;
  • Any new customer consent, opt-out, or deletion rights;
  • Changes to confidentiality, ownership, security, or retention obligations;
  • New warranties, indemnities, limitations of liability, or compliance duties.

AI-Training Review

No language addressing AI model training or related data use appears in the provided diff. The statement that approximately 247 words were added is insufficient to determine whether the additions:

  • Authorize training on customer content or personal data;
  • Permit use of data in aggregated, de-identified, or identifiable form;
  • Allow retention of prompts, outputs, or uploaded materials for model improvement;
  • Make training use automatic or subject to customer opt-out;
  • Permit human review or disclosure of data for training purposes; or
  • Restrict use of customer data to providing the contracted services.

Required Information

Please provide the actual added and deleted text, using the stated notation:

  • {added text}
  • [deleted text]
  • []{replacement text}

Without the substantive wording, no reliable legal risk assessment can be performed.

2026-08-20 · Privacy Policy

grew 2.6% · Observed by clause.watch

Summary

The diff does not include the actual added language. It only states that approximately 149 words were added.

Analysis

Because the new text is not provided, it is not possible to determine:

  • What legal obligations or rights were added.
  • Whether liability, indemnity, confidentiality, security, termination, or payment terms changed.
  • Whether the customer’s data may be used to train, fine-tune, evaluate, or improve AI models.
  • Whether data may be shared with affiliates, vendors, or third-party AI providers.
  • Whether the customer can opt out of AI training or object to such use.
  • Whether the provider must de-identify, aggregate, or delete data.
  • Whether customer data or outputs may be used for model development after termination.
  • Whether the provider claims ownership or broad usage rights over customer data, prompts, inputs, or outputs.

AI-Training Risk Assessment

No conclusion can be reached regarding AI-model training because the operative added language is missing. The added text should be reviewed specifically for terms such as:

  • “train,” “fine-tune,” “improve,” “develop,” or “optimize” models;
  • “inputs,” “content,” “customer data,” or “usage data”;
  • “de-identified,” “aggregated,” or “anonymized” information;
  • rights granted to use data “during and after” the agreement;
  • opt-out, consent, deletion, or retention provisions; and
  • disclosures to subprocessors or third-party model providers.

Required Information

Please provide the actual 149-word addition, including any deletion and replacement markup. Without the substantive diff, a reliable legal-risk analysis cannot be performed.

2026-08-19 · Terms of Service

grew 5.1% · Observed by clause.watch

Key Changes and Risks

1. Customer Data and AI/Algorithm Use

  • The revised terms replace a narrow requirement to sign a Data Processing Addendum (DPA) for certain European, UK, Swiss, and California data with broader obligations on the customer to:
  • Comply with all applicable privacy and data-protection laws;
  • Protect sensitive information and personal identifiers;
  • Obtain and maintain explicit consent for customers’ access to, use, or disclosure of the data;
  • Obtain authorizations needed for Cognito Forms to provide its services and “tools”; and
  • Explain in a written privacy policy how the customer plans to use any data collected.
  • The revised language appears to expand the customer’s responsibility for authorizing Cognito Forms’ use of collected data “for providing the tools.” However, it does not expressly state:
  • Whether customer data will be used to train, fine-tune, or evaluate AI models;
  • Whether data will be de-identified or aggregated before such use;
  • Whether customer data or outputs will be shared with third-party AI providers;
  • Whether customers can opt out; or
  • How long data used for model development will be retained.
  • The existing provision allowing Cognito Forms to use Forms and account content to create algorithms and programs that identify problem accounts remains important. Although described as account-security tools rather than AI training, the wording is broad and could potentially encompass machine-learning or automated-analysis systems.
  • Risk: Customers may be required to obtain broad consent for Cognito Forms’ data-related processing without receiving a clear contractual limitation on AI or model-training uses. The Privacy Policy and any Additional Terms should be reviewed for the operative rules.

2. Increased Customer Liability and Indemnity

  • The customer now assumes responsibility for losses arising from acts or omissions concerning data collected through its forms and must comply with Cognito Forms’ data policy.
  • The customer must defend and indemnify Cognito Forms for claims, suits, or proceedings connected with a user’s actions involving collected data.
  • The customer also indemnifies Cognito Forms for third-party claims arising from the customer’s use or misuse of the service, including conduct by someone using its password.
  • These obligations may expose customers to substantial costs, particularly for privacy, consent, or data-use claims.

3. Reduced Provider Liability Protections

  • The liability disclaimer remains broad and expressly excludes indirect, punitive, special, consequential, and similar damages, including service interruptions.
  • Total liability is capped at the amount paid for the service in the preceding month.
  • Security, reliability, performance, and fitness warranties are disclaimed.
  • The revised structure places much more data-compliance responsibility on the customer while preserving strong limitations on Cognito Forms’ exposure.

4. Other Material Changes

  • Free Individual Accounts inactive for six months or more may be permanently deleted, including associated data.
  • Material privacy or data-processing changes generally receive at least 15 days’ notice; billing or subscription changes receive 30 days’ notice.
  • Cognito Forms may charge costs for responding to subpoenas, including employee time and deposition participation.
  • The revision is dated May 29, 2026.

2026-08-19 · Terms of Service

shrank 4.9% · Observed by clause.watch

Summary

The provided diff does not include the actual contract language. It only states that approximately 247 words were added. As a result, it is not possible to determine:

  • What contractual terms changed;
  • Whether customer data may be used to train, fine-tune, evaluate, or improve AI models;
  • Whether the customer’s data may be shared with affiliates, vendors, or other third parties;
  • Whether data will be anonymized, aggregated, or de-identified before use;
  • Whether the customer can opt out of AI training or other secondary uses;
  • Whether ownership or licensing rights in customer data, outputs, or model improvements changed;
  • Whether confidentiality, security, retention, deletion, or compliance obligations were modified; or
  • Whether the provider received broader rights to use customer content beyond providing the contracted services.

AI Training and Data-Use Risk

No conclusion can be reached regarding AI-model training because the added wording is not included. The fact that 247 words were added does not itself show whether the changes expand or restrict data use.

The added text should be reviewed specifically for language allowing the provider to:

1. Use customer content to train, fine-tune, improve, or develop artificial-intelligence or machine-learning models;

2. Use data for product development, analytics, benchmarking, or service improvement;

3. Retain data after termination or deletion requests;

4. Combine customer data with data from other customers;

5. permit human review or third-party processing; or

6. claim a broad, perpetual, irrevocable, worldwide, royalty-free license.

Information Needed

Please provide the full redlined text, including the 247 added words and any deleted or replaced language. Without the actual wording, a reliable legal-risk analysis is not possible.

2026-08-19 · Privacy Policy

shrank 2.6% · Observed by clause.watch

Key Changes and Legal Risks

1. No Express AI-Training Authorization

  • The diff does not add language authorizing Cognito Forms, Zendesk, Pendo, Google, Mailgun, or any other provider to use customer data to train, fine-tune, evaluate, or improve AI models.
  • It also does not expressly prohibit such use.
  • Accordingly, the revised language appears silent on AI training. Any AI-related use may still be governed by the linked vendor privacy policies, data-processing terms, or separate service agreements.
  • Risk: Customers may not have clear contractual assurance that form submissions, support communications, usage data, or other personal information will be excluded from AI training. This should be clarified, particularly for sensitive form data.

2. Expanded and Reframed Customer Support Disclosures

The policy replaces the former detailed description of Zendesk with a broader description stating that Cognito:

  • Provides direct, one-on-one customer support;
  • Uses Zendesk for customer communications and support;
  • Shares information with Zendesk when customers use chat, email, or social-media channels;
  • Uses Zendesk to create and track requests and support resolution; and
  • Sends the “minimum information necessary” to create support requests.
Important implications
  • The new language expressly covers chat sessions, email, Facebook, Twitter, and other social-media interactions.
  • It adds or clarifies that Zendesk is used to create and track requests, not merely facilitate communication.
  • “Minimum information necessary” is helpful but undefined. The policy does not specify what information may be transmitted, how long Zendesk retains it, or whether Zendesk may use it for its own analytics, service improvement, or AI purposes.
  • The former wording apparently stated that Zendesk “only uses” the information for support. The revised wording says Zendesk uses the information to support the request-resolution process, which may be less precise or narrower in its restriction.

3. Addition of Pendo

  • Pendo is newly identified as an analytics, communication, and development-planning platform.
  • The policy states that Pendo is used for user onboarding, in-app messaging, and activity-related emails.

Risk: This may permit collection and sharing of product-usage or behavioral data with Pendo. The policy does not clearly define the data collected, retention period, opt-out rights, or restrictions on Pendo’s independent use.

4. Rights, Deletion, and Contact Updates

  • The account-deletion instruction is clarified: deleting an account deletes both the user account and all associated organizations.
  • A dedicated privacy/data-use contact email is added: privacy@cognitoforms.com.
  • The policy adds or updates the modification date to May 29, 2026.
  • Deleted information may still remain in backups, with no new specific deletion timeframe stated.

5. Minor Drafting Changes

  • Various punctuation, apostrophe, and wording corrections were made.
  • Marketing-email opt-out language appears substantively unchanged.

Between 2024-11-28 and 2025-07-31 · Privacy Policy

grew 2.0% · Reconstructed from Internet Archive captures

The wording changed. No written summary was produced for this revision.

Between 2023-10-04 and 2024-06-23 · Privacy Policy

grew 5.1% · Reconstructed from Internet Archive captures

The wording changed. No written summary was produced for this revision.

Watch this company's contracts

We re-read these documents every six hours and email you when the wording changes.

Start monitoring free