clause.watch Contracts Recent changes Start monitoring

Monitored company

Contentstack

clause.watch tracks 2 legal documents published by Contentstack, re-reading each one every six hours. Below is what each document covers, in plain English.

Privacy

43,319 characters · Read the original

Contentstack Privacy Policy — User Overview

Last updated: June 30, 2026

Scope: Contentstack Inc., Lytics, Inc., their websites, and SaaS services. By using the Sites or Services, users are deemed to consent to the policy.

> This is a practical summary, not legal advice. Customer contracts, Master Agreements, Data Processing Addenda, Cookie Policy, and other linked terms may add important obligations or protections.

1. Data Collection and Use

Information collected

Depending on how you interact with Contentstack, it may collect:

  • Identity and contact data: name, email, physical address, username, password, employer, job title, and social-media details when authorized through a social platform.
  • Payment and billing data: credit-card, purchase-order, or bank information.
  • Account and usage data: login history, upload dates and times, software usage, comments, tags, and Customer Content.
  • Technical and tracking data: IP address, browser and device type, device identifiers, language preference, referring site, pages visited, clicks, geographic region, cookies, web beacons, pixel tags, and similar technologies.
  • Support and communications data: support conversations, survey feedback, and marketing interactions.
  • Information from third parties: potential-customer contact details and business insights from providers such as G2, ZoomInfo, and TechTarget.
Main purposes

Contentstack uses data to:

  • Provide, administer, secure, and improve the Services;
  • Manage accounts, billing, customer support, and referrals;
  • Track usage and diagnose technical problems;
  • Detect fraud, abuse, contract violations, and security threats;
  • Conduct analytics, create aggregated statistics, and improve marketing;
  • Send service notices, product updates, and direct marketing;
  • Measure advertising campaigns and support behavioral advertising.

Contentstack may link IP addresses, cookies, and email addresses to identify accounts and track usage. It states that aggregated data is de-identified, but tracking data may include information—such as IP addresses—that is unique to a user.

2. User Rights

Depending on location and applicable law, users may:

  • Access or review their personal data;
  • Correct inaccurate information;
  • Delete personal data or withdraw consent;
  • Object to processing, particularly legitimate-interest processing or direct marketing;
  • Restrict processing;
  • Request data portability;
  • Opt out of targeted advertising, certain “sales,” or significant-effect profiling under California law;
  • Obtain certain disclosures about categories, sources, purposes, and recipients of data.

Requests may be sent to privacy@contentstack.com. End Users of a Contentstack Customer’s service generally must direct rights requests to that Customer, because the Customer is the data controller.

Deletion may terminate access to the Services. Contentstack may retain information for legal, contractual, security, fraud-prevention, or dispute-related reasons. Customer and End User Content is generally deleted within 180 days after account termination, subject to stated exceptions.

3. Third-Party Sharing

Contentstack may share data with:

  • Account owners and teammates, including an employer, which may receive a user’s email, password, usage history, and relevant logs;
  • Affiliates and service providers for hosting, maintenance, communications, analytics, support, billing, identity verification, and marketing;
  • Named providers including Intercom, Google Forms, Hotjar, Marketo, Mixpanel, Outreach, Salesforce, Twilio/Authy, Typeform, Zendesk, Channeltivity, and DocuSign;
  • Advertising networks and social-media platforms for measurement and targeted advertising;
  • Referral recipients and business contacts;
  • Authorities when legally required;
  • Buyers or successors in a merger, acquisition, restructuring, asset sale, or bankruptcy.

Some processing occurs in the United States and other countries. Contentstack references Data Processing Addenda, Standard Contractual Clauses, Binding Corporate Rules, and the Data Privacy Framework, but third-party policies also apply.

4. AI/ML Training

The policy does not expressly state whether Customer Content, End User data, or other personal information is used to train artificial-intelligence or machine-learning models. It permits broad uses for improving Services, analytics, and marketing, but does not provide a specific AI-training restriction or opt-out in this text. Users should review the separate Artificial Intelligence Addendum and applicable Customer agreement.

5. Key User Obligations and Restrictions

  • Users under 16 may not use the Sites or Services.
  • Users should manage passwords, cookies, and account security settings responsibly.
  • Disabling cookies may substantially impair functionality.
  • Users should not submit another person’s data without appropriate authority or consent.
  • Group users should understand that employers/account owners may receive usage and account information.
  • Third-party websites, integrations, and social platforms are governed by their own privacy policies.
  • The policy does not honor browser “Do Not Track” signals.

6. Liability and Disputes

The policy states that Contentstack uses reasonable administrative, technical, and physical safeguards, including encryption, access controls, and two-factor authentication, but does not guarantee absolute security.

It provides no detailed general liability cap, indemnity, governing-law clause, arbitration provision, or dispute procedure. Those terms are likely in the Master Agreement or other applicable contract. For unresolved Data Privacy Framework complaints, users may pursue regulator-assisted processes and, in certain circumstances, binding arbitration. Contentstack may disclose data in response to U.S. national-security or law-enforcement requests.

7. Changes

Contentstack may change the policy at its discretion and encourages users to check it regularly. For material changes, it says it will provide advance notice by email, login notice, or both. Continued use after a change constitutes acceptance.

Terms

37,252 characters · Read the original

Contentstack Terms: Key User Implications

*This overview summarizes the provided Terms of Service, effective August 2022. It is not a substitute for reviewing the separate Privacy Policy, Use Policy, or any applicable master agreement.*

1. Data Collection & Usage

The Terms do not provide a detailed privacy notice identifying all personal data collected, retention periods, cookies, analytics, or security practices. They refer to Contentstack’s separate Privacy Policy and affiliate privacy policies, which are incorporated into the Agreement.

The service may process data that users upload or store, including:

  • Applications, code, executable files, and other technical data
  • Text, links, files, software, and other user-submitted “Content”
  • Account and login-related information
  • Payment and billing information for paid subscriptions
  • Data submitted by application users or customers

You are responsible for the legality and content of data placed in the service. The Terms specifically restrict storing or processing certain regulated data, including financial or health data subject to laws such as GLBA, HIPAA, HITECH, or COPPA. Special-category personal data concerning individuals in the EU or Canada is prohibited unless applicable legal exceptions apply and Contentstack is notified beforehand.

Contentstack receives a broad license to use submitted Content worldwide, royalty-free and non-exclusively, solely to display, distribute, and promote your application. Deleted Content may remain temporarily available through caches or references.

2. User Rights

The Terms do not grant comprehensive data-subject rights such as access, correction, portability, objection, or guaranteed deletion. Users may:

  • Cancel paid services through the account dashboard
  • Delete Content, subject to caching and delayed removal
  • Request users be added to or removed from an account
  • Request removal of an application from Contentstack’s public showcase

Upon termination, you are responsible for extracting or preserving your data. Access to account Content is forfeited after termination, and trial Content may be deleted without notice.

For copyright removals, users may submit a DMCA counter-notice, including consent to California federal-court jurisdiction and acceptance of service of process.

3. Third-Party Sharing

The Terms allow Contentstack to display links to your application and your company name/logo for marketing purposes without notice or compensation, unless you request exclusion.

Content may also be accessible through:

  • Contentstack suppliers, licensors, affiliates, and service infrastructure
  • Third-party applications, websites, or integrations you choose to use
  • Public showcases or application displays

Contentstack disclaims responsibility for third-party privacy practices, security, content, and data handling. Users should review third-party terms independently.

4. AI/ML Training

The Terms contain no express statement that user data or Content is used to train artificial-intelligence or machine-learning models. They also do not expressly prohibit such use beyond the license limitation for submitted Content. The separate Privacy Policy, Data Processing Agreement, or later policies should be reviewed for clarification.

5. Key Obligations and Restrictions

Users must:

  • Secure their accounts and promptly report unauthorized access
  • Accept responsibility for all account activity and uploaded Content
  • Obtain necessary intellectual-property and privacy permissions
  • Comply with applicable laws and third-party terms
  • Use the service only for themselves, their employer, affiliates, and authorized users
  • Pay fees and applicable taxes

Prohibited conduct includes resale or sublicensing, unlawful or infringing content, malware, phishing, unauthorized access, service disruption, copying, framing or mirroring, reverse engineering, competitive benchmarking, and sharing passwords. Contentstack may throttle usage or suspend access for excessive resource use, suspected violations, or security concerns.

Subscriptions automatically renew unless canceled before the billing period ends. Cancellations generally take effect at the end of the paid period, and refunds are generally unavailable following violations or termination.

6. Liability and Disputes

The service is provided “as is,” without warranties of uninterrupted operation, accuracy, fitness, merchantability, or non-infringement.

Contentstack generally excludes liability for consequential, incidental, special, substitute-service, interruption, and data-loss damages. Its maximum liability is generally limited to fees paid during the preceding 12 months, except where prohibited by law. Users must indemnify Contentstack for claims arising from their use or breach.

California law governs. Most disputes must proceed through JAMS mediation/arbitration in San Francisco, in English. The prevailing party may recover costs and attorneys’ fees, and jury-trial rights are waived to the maximum extent permitted. Intellectual-property and injunctive-relief claims are exceptions.

7. Changes to the Terms

Contentstack may modify or replace the Terms. Notice may be provided by email or when users access or log in to the service. Continued use after changes are posted constitutes acceptance. Users should monitor account email and login notices, particularly because changes may affect fees, usage limits, data handling, and termination rights.

Change history

2026-09-06 · Privacy

grew 5.1% · Observed by clause.watch

Key Changes and Risks

1. Major restructuring of the Privacy Policy

The existing introductory language has been substantially replaced with a broader legal-resource/navigation structure. The revised material:

  • Replaces references to “Contentstack Inc. and its subsidiary Lytics” operating particular websites and providing services to businesses with links to multiple agreements, policies, and regional documents.
  • Expands the apparent scope to include employees, contractors, candidates, marketplace users, developers, community users, partners, and other categories.
  • Adds or references documents including:
  • Master Agreements and Partner Agreements
  • Data Processing Agreements for the US/Canada and EMEA/UK
  • Security Addendum
  • Data Transfer Risk Assessment
  • Artificial Intelligence Addendum
  • Terms of Service and external-facing services policies

Risk: It is unclear which linked document governs a particular user, service, geography, or data type. The policy may incorporate or direct users to terms that are not included in the text, creating uncertainty about contractual precedence and applicable obligations.

2. Revised user classifications

The former classifications of “Visitors,” “Customers,” “Referral Partners,” and “End Users” are retained in substantially revised form. The revised language:

  • Defines visitors as people visiting the site without logging in.
  • Defines customers more broadly to include people or entities requesting information or using services through a free trial or paid software.
  • Retains a category for referral partners.
  • Clarifies that customer end-user data is controlled by the customer, who acts as data controller and instructs Contentstack on processing.

Risk: The new wording is broader and may cover additional users and interactions, including customer employees and contractors. Customers remain responsible for the legality of collecting and providing end-user data, while Contentstack’s role varies depending on the processing activity.

3. Controller/processor role changes

The revised text distinguishes between:

  • Contentstack acting as a processor for customer-controlled end-user data; and
  • Contentstack acting as a controller for sales, customer-service, billing, visitor, customer, and referral-partner interactions.

The prior language more expressly stated that customer end-user data would be governed by the Master Agreement and SaaS schedules. The new wording relies more heavily on separate Data Processing Addenda and other written agreements.

Risk: Customers should confirm that the applicable DPA, Master Agreement, and Privacy Policy are consistent, especially regarding permitted purposes, international transfers, retention, deletion, subprocessors, and liability.

4. Geographic and regulatory scope

The revised wording expressly addresses the EEA, UK, Switzerland, and California, including GDPR and the California Consumer Privacy Act. It refers to DPAs, EU Standard Contractual Clauses, and other applicable transfer mechanisms.

Risk: The policy appears to make protection dependent on execution of a DPA or other written agreement in some cases. Customers should not assume that the Privacy Policy alone provides all required statutory or contractual protections.

5. AI training and model-use changes

The diff does not add express language stating that customer data, end-user data, prompts, content, or service outputs may be used to train AI models. It does, however, add a reference/link to an “Artificial Intelligence Addendum.”

Important risk: The actual AI data-use terms may now be located in that separate addendum rather than the Privacy Policy. The diff does not establish whether customer data is:

  • Used to train, fine-tune, evaluate, or improve models;
  • Shared with third-party AI providers;
  • De-identified before use;
  • Excluded from model training by default or only on opt-out; or
  • Retained in AI-provider logs.

The Artificial Intelligence Addendum should therefore be reviewed before accepting the revised policy or using AI features.

2026-09-04 · Privacy

shrank 4.8% · Observed by clause.watch

Summary

The provided diff does not include the actual amended legal language. It only states:

> “Added approximately 196 words to the document”

Accordingly, it is not possible to identify:

  • Which provisions were added, deleted, or replaced;
  • Any changes to the parties’ rights or obligations;
  • New legal, commercial, privacy, or compliance risks; or
  • Whether customer data may be used to train, fine-tune, evaluate, or otherwise improve AI models.

AI Training and Data Use

No substantive language concerning AI models, machine learning, training data, model improvement, data retention, data anonymization, or use of customer content is included in the supplied diff.

The addition could nevertheless be significant if it addresses any of the following:

  • Permission to use customer data or content to train or improve AI models;
  • Use of customer data for third-party or general-purpose models;
  • Whether consent is required or use is automatic unless the customer opts out;
  • Ownership of inputs, outputs, derived data, embeddings, or model improvements;
  • De-identification standards and whether re-identification is prohibited;
  • Data retention after termination;
  • Disclosure of data to affiliates, service providers, or model providers; or
  • Restrictions on confidential, personal, regulated, or proprietary information.

Conclusion

A substantive comparison cannot be performed from the information provided. The approximately 196 added words, including any bracketed additions, deletions, or replacements, are needed to assess the legal impact and identify AI-related data-use risks.

2026-09-03 · Terms

grew 12.7% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-09-03 · Privacy

grew 5.1% · Observed by clause.watch

Summary

The provided diff does not include the actual contractual language. It only states that approximately 196 words were added.

AI Training and Customer Data
  • No language is provided showing whether customer data may be:
  • Used to train, fine-tune, or improve AI models;
  • Used to develop products, services, or algorithms;
  • Combined with other customers’ data;
  • De-identified, anonymized, or retained for model-training purposes;
  • Subject to an opt-out, consent requirement, or customer approval;
  • Used by service providers or subcontractors for AI-related purposes.

Accordingly, it is not possible to determine whether the changes create new rights to use customer data for AI training or impose new restrictions on such use.

Other Legal Risks

The actual additions are also necessary to assess potential changes involving:

  • Data ownership and licensing rights;
  • Confidentiality and permitted disclosures;
  • Data retention and deletion;
  • Security obligations and breach liability;
  • Intellectual-property ownership;
  • Warranties, indemnities, and limitations of liability;
  • Regulatory compliance; and
  • Termination or post-termination data handling.
Conclusion

No substantive legal change can be identified from the information supplied. Please provide the text of the 196 added words, together with any surrounding provisions if necessary to understand the amendments.

2026-09-03 · Terms

shrank 11.3% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-30 · Privacy

shrank 4.8% · Observed by clause.watch

Summary of Important Changes

1. Major restructuring and scope changes

  • The privacy policy has been substantially reformatted and reorganized, with extensive navigation links added to related documents, including:
  • Master Agreement and partner agreements
  • Data Processing Addenda
  • Security Addendum
  • Data Transfer Risk Assessment
  • Terms of Service
  • Artificial Intelligence Addendum
  • Marketplace, Community, and developer terms
  • The policy now expressly covers Contentstack’s employees and contractors, in addition to website visitors and service users.
  • References to Contentstack’s corporate structure and websites have been simplified or removed.

2. Changes to user categories and roles

  • The former categories of “Visitors,” “Customers,” “Referral Partners,” and “End Users” are retained but rewritten and expanded.
  • “Customers” now expressly include people using the Services:
  • During a free trial; or
  • Through purchasing the Software.
  • “Referral Partners” are more clearly addressed as individuals or entities referring prospective business customers.
  • The policy clarifies that, for End User data submitted through the Services, the Customer remains the data controller and Contentstack processes the data on the Customer’s instructions.
  • However, Contentstack now expressly states that it is the data controller for its own sales, customer-service, billing, and interactions with Visitors, Customers, and Referral Partners. This separates Contentstack’s independent business uses from its processor role.

3. International and California privacy framework

  • The policy more clearly addresses customers and data subjects in the EEA, United Kingdom, Switzerland, and California.
  • Cross-border and regulated processing is now tied to execution of a Data Processing Addendum or other written agreement incorporating applicable contractual clauses.
  • The language appears more streamlined, but customers should confirm which DPA, transfer mechanism, and regional terms actually apply to their account.

4. AI-model training and data use

  • The diff adds navigation to an Artificial Intelligence Addendum, but it does not expressly add language in the shown substantive text authorizing Contentstack to use Customer Content or End User data to train, fine-tune, or improve AI models.
  • The former language stated that Contentstack would not sell, disclose, or use End User personal data or content for third parties without controller authorization. That concept appears substantially retained, although rewritten.
  • The new AI Addendum may contain separate rules or permissions. Because it is now prominently linked, customers should review whether it is incorporated into the contract, applies automatically, permits model training, or distinguishes between:
  • Customer Content;
  • prompts and outputs;
  • de-identified or aggregated data; and
  • service-improvement data.
  • Risk: The privacy policy alone does not resolve whether AI-related processing is permitted. Any broader training rights may exist in the AI Addendum, Terms of Service, or Master Agreement.

5. Practical concerns

  • The extensive replacement text creates a risk of ambiguity or inconsistent cross-references.
  • Customers should identify the controlling agreement and obtain written confirmation that their data will not be used for AI training unless expressly authorized.

2026-08-29 · Terms

grew 12.7% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-28 · Privacy

grew 5.1% · Observed by clause.watch

Summary

The supplied diff does not include the actual contractual language. It only states:

> “Added approximately 196 words to the document”

Accordingly, it is not possible to identify the legal changes, new obligations, allocation of risk, or changes concerning use of customer data to train AI models.

AI Training and Customer Data

No substantive language is provided regarding:

  • Whether customer data may be used to train, fine-tune, or improve AI models;
  • Whether customer data is used for product development or service analytics;
  • Whether data is aggregated, anonymized, or de-identified before such use;
  • Whether the customer can opt out of AI training;
  • Whether customer prompts, inputs, outputs, or usage data are retained;
  • Whether data may be shared with affiliates, vendors, or model providers;
  • Ownership or licensing rights in customer data, outputs, or model improvements; or
  • Security, confidentiality, deletion, or retention obligations applicable to AI-related data use.

Risk Assessment

No meaningful risk assessment can be completed without the added and deleted contractual text. The statement that approximately 196 words were added does not reveal whether those additions:

  • Expand the provider’s license to use customer data;
  • Permit secondary use of confidential information;
  • Create broad rights to train or improve models;
  • Limit the provider’s liability for AI-related data use;
  • Reduce customer control over deletion or opt-out rights; or
  • Impose new customer representations, warranties, or indemnities.

Information Needed

Please provide the full redline or the actual text of the additions, deletions, and replacements. Once supplied, the changes can be analyzed for:

1. Customer-data ownership and permitted uses;

2. AI training and model-improvement rights;

3. Confidentiality and privacy implications;

4. Retention, deletion, and security requirements;

5. Customer opt-out or consent rights;

6. Liability, indemnity, and warranty changes; and

7. Material changes to the customer’s commercial or legal risk.

2026-08-28 · Terms

shrank 11.3% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-28 · Terms

grew 12.7% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-27 · Privacy

shrank 4.8% · Observed by clause.watch

Summary of Important Changes

1. Major restructuring and expanded scope

  • The document changes from a relatively focused privacy policy for Contentstack’s websites and SaaS services to a broader legal/privacy portal containing links to:
  • Master and partner agreements
  • Data Processing Agreements (US/Canada and EMEA/UK)
  • Security addenda
  • Data-transfer assessments
  • Artificial Intelligence Addendum
  • Terms of service and marketplace terms
  • Employee, contractor, candidate, and subprocessors privacy notices
  • The policy now expressly covers employees and contractors, in addition to business users and website visitors.

Risk: Important data-use terms may now be located in separate linked documents. Customers should confirm which documents are incorporated into their contract and which version controls in the event of inconsistency.

2. Revised user classifications

The policy continues to distinguish among:

  • Visitors
  • Customers, including free-trial users and purchasers
  • Referral Partners

However, the definition of “Customer” is broadened to include persons acting for themselves or an entity who request information or use the services. Referral Partners are also described more specifically as persons referring business entities.

Risk: Broader definitions may bring additional people and activities within the policy’s scope, potentially expanding the categories of personal data Contentstack may collect and use.

3. Revised controller/processor roles

  • The prior language generally stated that the customer controlled End User data and that Contentstack processed it under the customer’s instructions.
  • The revised language states that Contentstack is the data controller for:
  • Sales
  • Customer-service management
  • Billing
  • Interactions with visitors, customers, and referral partners
  • Customers remain the controllers of End User data submitted through the SaaS services, while Contentstack acts as processor for that data.
  • The policy applies to End User data supplied by customer employees and contractors.

Risk: The division between Contentstack’s controller activities and processor activities is more explicit but may be broader. Data used for account administration, support, sales, or billing may be subject to Contentstack’s independent purposes rather than solely customer instructions.

4. Data protection documentation and international transfers

  • The revised text relies more heavily on separate DPAs, EU/UK Standard Contractual Clauses, and international data-transfer addenda.
  • The policy references coverage for the EEA, UK, Switzerland, and California.
  • Contact information for privacy requests is consolidated around privacy@contentstack.com.
  • References to the EU-U.S., UK, and Swiss-U.S. Data Privacy Frameworks are retained or clarified.

5. AI-model training and AI data use

  • The diff adds a link or reference to an “Artificial Intelligence Addendum.”
  • The supplied changes do not show substantive language stating whether customer data, End User data, prompts, outputs, or content may be used to train, fine-tune, evaluate, or improve AI models.
  • Accordingly, the key AI-training terms cannot be determined from this diff.

Recommended action: Review the separate Artificial Intelligence Addendum and applicable Terms of Service. Confirm whether customer content is excluded from model training by default, whether consent or an opt-out is required, how de-identified or aggregated data is treated, and whether third-party AI providers may retain or train on submitted data.

2026-08-27 · Terms

shrank 11.3% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-26 · Terms

grew 12.7% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-26 · Privacy

grew 5.1% · Observed by clause.watch

Summary

The supplied diff does not include the actual added or revised legal language. It only states:

> “Added approximately 196 words to the document”

Accordingly, it is not possible to identify the substantive legal changes, risks, or any provisions concerning the use of customer data to train AI models.

AI Training and Customer Data

No conclusions can be drawn about whether the changes:

  • Permit or restrict using customer data to train, fine-tune, or improve AI models;
  • Allow use of customer content for product development, analytics, or benchmarking;
  • Require customer consent or provide an opt-out right;
  • Apply de-identification, aggregation, retention, or deletion limits;
  • Permit sharing data with AI providers, subprocessors, or affiliates;
  • Grant the provider ownership or broad usage rights over customer data; or
  • Address confidentiality, security, or regulatory compliance risks.

Information Needed

Please provide the actual redlined text, using the stated notation:

  • Additions: {new language}
  • Deletions: [deleted language]
  • Replacements: [old language]{new language}

Once provided, the analysis can identify the key changes, explain their practical effect, and flag any new risks—particularly rights to use customer data for AI training.

2026-08-25 · Terms

shrank 11.3% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-24 · Privacy

shrank 4.8% · Observed by clause.watch

Structured Summary of Important Changes

1. Major restructuring and scope changes

  • The document appears to have been substantially reorganized from a standalone privacy-policy page into a broader legal/privacy resource structure.
  • References to Contentstack’s websites, SaaS software, and business customers have been replaced or supplemented with references to:
  • Employees and contractors;
  • Marketplace users and applications;
  • Community users;
  • Developers;
  • Candidates and potential contractors; and
  • Other Contentstack legal documents.
  • The policy now expressly covers information submitted to or collected through both the Sites and Services.

Risk: The extensive restructuring makes it difficult to determine which terms are operative and whether links to other documents incorporate additional privacy or data-use obligations.

2. Expanded categories of users and data subjects

The prior policy distinguished generally among Visitors, Customers, Referral Partners, and End Users. The revised language retains or clarifies those categories and adds broader coverage for:

  • Employees and contractors;
  • Customers’ employees and contractors;
  • Marketplace participants;
  • Community users; and
  • Users of customer services whose information is processed through Contentstack.

Risk: The expanded scope may bring more individuals and more types of personal data under the policy without clearly explaining the precise collection, retention, or use rules for each category.

3. Controller and processor roles

  • The revised language more clearly states that Contentstack acts as a data controller for its own sales, customer-service, billing, visitor, customer, and referral-partner activities.
  • For End User data submitted through a customer’s use of the Services, the policy states that the Customer is the data controller, while Contentstack processes the data on the Customer’s instructions.
  • The revised text references Data Processing Addenda, EU Standard Contractual Clauses, and other written agreements for EEA, UK, Swiss, and California-related data.

Risk: The division of responsibilities is clearer in principle, but the policy does not fully specify which document controls in a conflict or how obligations apply where Contentstack uses customer data for its own purposes.

4. AI model training and artificial-intelligence use

  • The diff adds a link or reference to an “Artificial Intelligence Addendum.”
  • It also adds references to Contentstack’s AI-related products or features, including an AI assistant/companion.
  • However, the supplied diff does not expressly state:
  • Whether Customer Data or End User Data may be used to train, fine-tune, evaluate, or improve AI models;
  • Whether data is shared with third-party model providers;
  • Whether customer data is excluded from model training by default;
  • Whether opt-out or deletion rights exist; or
  • Whether prompts, outputs, feedback, telemetry, or usage data are retained for AI improvement.

Risk: The new AI-document reference may shift important data-use terms outside the Privacy Policy. Customers should obtain and review the Artificial Intelligence Addendum and confirm expressly whether their data, prompts, content, or End User information can be used for model training or product improvement.

5. Other notable changes

  • Contact and privacy-rights language has been updated, including a dedicated privacy email address.
  • International-transfer language and Data Privacy Framework references have been updated.
  • The prior statement that End User data would not be sold, disclosed, or used for third parties without authorization appears to be retained in substance, but its placement and surrounding wording have changed.

Overall assessment: The revision broadens the policy’s scope, formalizes controller/processor roles, and introduces AI-related documentation, but leaves the most important AI-training permissions unclear.

2026-08-24 · Privacy

grew 5.1% · Observed by clause.watch

Summary

The diff does not include the actual added language. It only states that approximately 196 words were added. As a result, it is not possible to determine:

  • What contractual obligations or rights changed;
  • Whether liability, confidentiality, security, payment, termination, or governing-law provisions were affected;
  • Whether the customer’s data may be used for artificial intelligence or machine-learning purposes;
  • Whether customer data may be used to train, fine-tune, evaluate, or improve AI models;
  • Whether such use is subject to customer consent, opt-out rights, anonymization, aggregation, or other limitations; or
  • Whether the provider may disclose customer data to AI vendors or other subprocessors.

AI-Training Risk Assessment

No conclusion can be reached regarding AI-model training because the added wording is not provided. The relevant language should be reviewed for terms such as:

  • “train,” “fine-tune,” “develop,” “improve,” or “enhance” models;
  • “artificial intelligence,” “machine learning,” “generative AI,” or “models”;
  • “service data,” “customer data,” “content,” “inputs,” or “outputs”;
  • rights to use data in “de-identified,” “aggregated,” or “匿名ized” form;
  • perpetual, irrevocable, worldwide, royalty-free, or sublicensable licenses;
  • use by affiliates, contractors, subprocessors, or third-party AI providers; and
  • opt-out, deletion, retention, or data-isolation provisions.

Required Information

Please provide the actual 196-word addition, including any deleted or replaced text. Without the operative wording, a substantive legal comparison and risk analysis cannot be performed.

2026-08-23 · Terms

grew 12.7% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-22 · Terms

shrank 11.3% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-22 · Privacy

shrank 4.8% · Observed by clause.watch

Key Changes and Risks

1. Significant restructuring and scope changes

  • The policy is substantially rewritten rather than merely updated.
  • References to Lytics, Inc. are removed from the opening description.
  • The policy now covers a broader set of users and activities, including:
  • Employees and contractors
  • Customers using free trials or purchased software
  • Referral Partners
  • Visitors and End Users
  • Sales, customer-service, billing, and other website interactions
  • Numerous links to other agreements and policies are added, including the Master Agreement, Data Processing Addenda, Security Addendum, Marketplace terms, and an Artificial Intelligence Addendum.

Risk: The policy’s relationship to the linked agreements is not explained. Customers may need to review those documents to determine which terms control, particularly for data processing, AI functionality, and marketplace services.

2. Changed controller/processor framework

  • The prior language stated that Contentstack acted as a data controller only for sales, customer-service, and billing operations, while customers controlled End User data and instructed Contentstack how to process it.
  • The revised language more clearly states that:
  • Customers are the data controllers for End User data submitted through the Services.
  • Contentstack acts as a processor for that data.
  • Contentstack is a controller for its own sales, customer-service, billing, Visitor, Customer, and Referral Partner interactions.

Risk: The revised wording may expand or clarify Contentstack’s independent controller role for account, marketing, support, and commercial data. The boundaries between controller and processor activities should be confirmed in the applicable DPA and Master Agreement.

3. End User data provisions

  • The prior policy expressly stated that Contentstack would not sell, disclose, or use End User personal data or content with third parties without controller authorization, except as expressly stated.
  • That express restriction appears to be removed or displaced by the revised text.
  • The revised policy instead relies more heavily on the Master Agreement, DPA, and other written agreements.

Risk: Removing the standalone restriction may create uncertainty about permitted disclosures, service-provider use, analytics, product improvement, and other secondary uses. Customers should verify whether equivalent protections remain contractually binding elsewhere.

4. AI-model training

  • The diff adds a link/reference to an “Artificial Intelligence Addendum.”
  • However, the revised privacy-policy language shown does not expressly state:
  • Whether Customer Data or End User data may be used to train, fine-tune, or improve AI models;
  • Whether prompts, outputs, or feedback are retained;
  • Whether data is used for Contentstack’s general-purpose models;
  • Whether customers can opt out; or
  • Whether AI providers or subprocessors may train on the data.

Risk: The AI Addendum may contain important training rights not visible in this diff. Customers should obtain and review it before accepting the revised policy, especially to confirm that Customer Data is excluded from model training unless expressly authorized.

5. Other observations

  • The prior detailed classification of Visitors, Customers, and Referral Partners is retained but reorganized.
  • Contact information and international-transfer references are updated or consolidated.
  • The change appears to preserve GDPR/UK/Swiss/California compliance concepts but shifts detail to separate addenda and agreements.

2026-08-22 · Privacy

grew 5.1% · Observed by clause.watch

Summary

The provided diff does not include the actual amended contract language. It only states:

> “Added approximately 196 words to the document”

Without the text of the additions, deletions, or replacements, it is not possible to determine:

  • What contractual provisions changed;
  • Whether the customer’s data may be used to train, fine-tune, or improve AI models;
  • Whether any such use is limited to de-identified, aggregated, or anonymized data;
  • Whether the customer can opt out of AI training or model-improvement activities;
  • Whether the provider obtains ownership or broad usage rights in customer data or outputs;
  • Whether data may be shared with affiliates, subprocessors, or third-party AI providers;
  • Whether confidentiality, security, retention, deletion, or intellectual-property protections were modified; or
  • Whether the customer assumes additional legal, regulatory, or indemnity risk.

Information Needed

Please provide the complete diff, including:

  • Additions shown in {braces};
  • Deletions shown in [brackets]; and
  • Replacements shown as []{}.

In particular, include any language referring to:

  • “training,” “train,” “fine-tuning,” or “improving” models;
  • “machine learning,” “artificial intelligence,” or “AI”;
  • customer data, prompts, inputs, outputs, usage data, or telemetry;
  • de-identification, anonymization, aggregation, or benchmarking;
  • service providers, subprocessors, or third-party model providers; and
  • ownership, licenses, confidentiality, security, retention, or deletion.

Once the actual text is provided, the changes can be analyzed for business impact, legal risks, and any new rights to use customer data for AI model development.

2026-08-21 · Terms

grew 12.7% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-21 · Privacy

shrank 4.8% · Observed by clause.watch

Structured Summary of Important Changes

1. Major restructuring and scope changes

  • The privacy policy has been substantially reorganized and appears integrated into a broader legal-document portal.
  • References to Contentstack’s websites and SaaS services for businesses remain, but the policy now also expressly covers:
  • Employees and contractors;
  • Candidates and potential contractors;
  • Marketplace users and developers;
  • Community users; and
  • Customers using Contentstack services.
  • The policy now includes or links to additional documents, including an Artificial Intelligence Addendum, Data Processing Addenda, EU Standard Contractual Clauses, and other service-specific terms.

Risk: The new cross-references may incorporate additional terms that are not included in this diff. Customers should review whether those documents impose separate rights to use data, including for AI purposes.

2. Revised user classifications and controller roles

The policy replaces the prior user categories and definitions with revised classifications for:

  • Visitors;
  • Customers, including free-trial and paid users; and
  • Referral Partners.

The policy more clearly distinguishes:

  • Contentstack acting as a controller for sales, customer-service, billing, and interactions with Visitors, Customers, and Referral Partners; and
  • The Customer acting as the data controller for End User data submitted through the Services, with Contentstack processing that data on the Customer’s instructions.

Risk: The expanded controller language may give Contentstack independent responsibility—and potentially broader independent-use rights—for account, sales, billing, and relationship-management data, even where a customer expects all data to be processed solely as a processor.

3. End User data protections

The prior language stated that Contentstack would not sell, disclose, or use End User personal data or content with third parties without controller authorization, subject to the Master Agreement and related schedules.

The revised language retains the basic concept that:

  • Customer-controlled End User data remains under the Customer’s control; and
  • Contentstack will not sell, disclose, or use it with third parties without authorization.

The revised text also clarifies that the policy may apply to End User data supplied by Customer employees and contractors.

Risk: The precise meaning of “authorization” is not defined here. It may be supplied by the Master Agreement, DPA, or AI Addendum, potentially allowing uses that are not apparent from the Privacy Policy alone.

4. AI training and model use

  • The diff adds a prominent reference/link to an Artificial Intelligence Addendum.
  • However, this diff does not expressly state whether Customer data, End User data, prompts, outputs, telemetry, or content may be used to train, fine-tune, evaluate, or improve AI models.
  • No clear opt-out, deletion right, retention limit, or prohibition on using Customer data for model training appears in the changed language.

Key risk: AI-related data-use rights may have been moved to the separate AI Addendum. The AI Addendum should be reviewed for any authorization to use Customer or End User data for training or service improvement, including by third-party AI providers.

2026-08-20 · Privacy

grew 5.1% · Observed by clause.watch

Summary

The supplied diff does not include the actual added or revised contract language. It only states:

> “Added approximately 196 words to the document”

As a result, it is not possible to reliably identify:

  • New contractual obligations or rights
  • Changes to liability, indemnity, confidentiality, or termination provisions
  • Changes affecting customer data ownership or permitted uses
  • Whether customer data may be used to train, fine-tune, evaluate, or improve AI models
  • Any opt-out, consent, anonymization, retention, or deletion requirements
  • Whether data may be shared with affiliates, subprocessors, or third-party model providers

AI-Training Risk Assessment

No conclusion can be drawn from the provided information about whether the agreement now permits or restricts the use of customer data for AI training. The added language should be reviewed specifically for terms such as:

  • “train,” “fine-tune,” “improve,” “develop,” or “evaluate” models
  • “customer data,” “input,” “output,” “content,” or “usage data”
  • Aggregated, de-identified, anonymized, or derived data
  • Service improvement or product development
  • Consent, opt-out, or default permission mechanisms
  • Data retention and deletion after termination
  • Disclosure to subprocessors or third-party AI providers

Information Needed

Please provide the actual diff, including the approximately 196 added words and any surrounding deleted or replacement language. Without the text itself, a legal risk analysis would be speculative.

2026-08-20 · Terms

shrank 11.3% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-19 · Privacy

shrank 4.8% · Observed by clause.watch

Summary of Important Changes

1. Scope and structure of the policy

  • The document has been substantially restructured and appears to replace much of the former privacy-policy introduction and user-classification language.
  • The policy now refers to a broader collection of legal documents, including:
  • Master Agreements and partner agreements
  • Data Processing Agreements and security addenda
  • An Artificial Intelligence Addendum
  • Terms of Service, marketplace terms, and other policies
  • The scope now expressly covers Contentstack’s sales, customer-service, billing, visitors, customers, and referral partners, rather than focusing primarily on website visitors, SaaS users, and customer end users.

2. Controller/processor roles

  • The revised language more clearly distinguishes:
  • Contentstack as a data controller for its own sales, customer-service, billing, website, and related business operations; and
  • Customers as the data controllers for end-user data submitted through the Services, with Contentstack processing that data on the customer’s instructions.
  • The former statement that customer end-user information would be governed by the Master Agreement and SaaS schedules has been replaced with broader language stating that customer end-user data is controlled by the customer and governed by the applicable contractual privacy terms.
  • The policy expressly addresses individuals and entities connected with the EEA, UK, Switzerland, and California, including references to DPAs, Standard Contractual Clauses, and the California Consumer Protection Act.

3. End-user data disclosures

  • The prior language stated that Contentstack would not sell, disclose, or use end-user personal data or content with third parties without controller authorization, except as expressly stated in the policy.
  • That language remains substantially represented in the revised text, but the new version is less direct and is embedded within a longer description of customer-controller relationships and contractual documents.
  • Customers should confirm that the referenced Master Agreement, DPA, and other linked documents contain adequate restrictions on subprocessors, secondary use, retention, deletion, and confidentiality.

4. AI-model training and artificial intelligence

  • The diff does not clearly add an express authorization for Contentstack to use customer data, end-user data, prompts, outputs, or content to train, fine-tune, or improve AI models.
  • However, the revised navigation expressly adds an “Artificial Intelligence Addendum.” This is legally important because AI-related permissions may now be located in that separate document rather than in the Privacy Policy.
  • The diff also adds or highlights AI-related site functionality, including an “AI Assistant” and “AI responses may contain mistakes” disclaimer. This suggests expanded AI functionality but does not itself establish training rights.
  • Risk: The Privacy Policy’s cross-reference to an AI Addendum may incorporate additional terms that are not visible in this diff. Customers should review whether that addendum:
  • permits training on customer or end-user data;
  • distinguishes service delivery from model training or product improvement;
  • applies by default or only upon opt-in;
  • permits human review or third-party AI providers;
  • covers prompts, outputs, metadata, and telemetry; and
  • provides deletion, opt-out, confidentiality, and non-retention commitments.

5. Drafting and operational concerns

  • The diff appears to contain substantial duplicated, reordered, or navigation text, creating uncertainty about the operative wording.
  • The former consent-by-use language appears to be revised or displaced, while the policy still states that using the Sites or Services indicates consent. The legal effect should be verified against applicable-law requirements and the contractual hierarchy.

2026-08-19 · Terms

grew 12.7% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-19 · Terms

shrank 11.3% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-18 · Terms

grew 12.7% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-18 · Privacy

shrank 1.6% · Observed by clause.watch

No

Watch this company's contracts

We re-read these documents every six hours and email you when the wording changes.

Start monitoring free