Monitored company
FullStory
clause.watch tracks 3 legal documents published by FullStory, re-reading each one every six hours. Below is what each document covers, in plain English.
Partner Terms and Conditions
Partner Terms and Conditions: Key Points and Risks
> Scope: This agreement governs a business partner’s participation in Fullstory’s partner programs and use of the Partner Portal. It is not primarily an end-user privacy policy. Data handling is also governed by Fullstory’s Privacy Policy, Cookie Policy, Acceptable Use Policy, Service Terms, and any applicable Program Addendum.
1. Data Collection and Usage
The agreement may involve collection or access to:
- Partner profile information: Information the Partner submits or publishes in the Partner Portal. It must be truthful and accurate.
- Lead and prospect information: Identifying and business information about prospective or actual Fullstory customers, such as the Lead’s identity and likely purchase scope.
- Personal Data: Any information relating to an identified or identifiable person that is protected by applicable privacy laws.
- Account, tax, and payment information: Information required to enroll for Referral Fees.
- Login and portal activity: The Partner is responsible for activities conducted through its credentials, although the agreement does not provide detailed portal-logging disclosures.
Fullstory may use, reproduce, display, and disclose a Partner’s profile to third parties for business and program-related purposes. Prospect Information may be used only to provide services contemplated by the agreement and for related customer insights, service or feature announcements, and reporting.
Partners must not submit Sensitive Data—such as financial, health, government-identification, children’s, or special-category data—in Lead Registrations or otherwise share it with Fullstory under this agreement.
2. User/Partner Rights Regarding Data
The MPPA does not provide a detailed set of access, correction, deletion, portability, or objection rights. Those rights depend primarily on:
- Applicable data-protection laws;
- Fullstory’s Privacy Policy; and
- Any separate data-processing agreement or Service Terms that applies.
A Partner may request return or destruction of the other party’s Confidential Information. However, the recipient may retain information in ordinary-course backups, where legally required, or where reasonably needed to demonstrate compliance. Retained information remains protected by confidentiality obligations.
The Partner is responsible for giving individuals legally required privacy notices and obtaining any required consents before sharing their Personal Data with Fullstory.
3. Third-Party Sharing
The agreement permits disclosure of information to:
- Affiliates, employees, agents, contractors, and service providers with a need to know and confidentiality obligations;
- Third parties for business and program-related display of the Partner’s profile;
- Government authorities where disclosure is legally required; and
- Third-party websites or platforms linked through the Partner Portal.
Prospect Information may not be sold or otherwise shared with third parties, and may not be used to market the Partner’s own products or services unless Fullstory gives written authorization.
The agreement does not list specific vendors or explain international transfers; those details may appear in Fullstory’s separate privacy, security, or subprocessor materials.
4. AI/ML Training
The MPPA contains no express statement that Partner Data, Personal Data, Profile Information, or Prospect Information will be used to train artificial-intelligence or machine-learning models. It also contains no express prohibition on such use. Users should review the incorporated Privacy Policy, Service Terms, and any Data Processing Agreement for the controlling position.
Partners should avoid placing Customer Data or Sensitive Data in the Demo Account; Customer Data is expressly prohibited there.
5. Key Obligations and Restrictions
Partners must:
- Follow applicable privacy, anti-bribery, sanctions, export-control, and other laws.
- Maintain required licenses, permits, notices, and consents.
- Protect portal credentials and promptly report compromise.
- Complete Fullstory-required training or certifications.
- Refer Leads through approved channels and provide reasonable sales assistance.
- Use Fullstory materials and trademarks only as authorized and under branding rules.
- Act professionally and avoid deceptive, misleading, disparaging, spam, or unauthorized claims.
- Not sell, sublicense, distribute, or contract for the Services unless separately authorized.
- Not represent itself as Fullstory’s agent or bind Fullstory.
- Keep Confidential Information confidential and return or destroy it when requested.
- Not subcontract or outsource its contractual obligations without authorization.
Referral Fees may be lost if required account, tax, or payment information is not supplied within 180 days after the payment due date. Referral Fees are paid only after Fullstory receives customer payment, and the default aggregate cap is $75,000 per referred customer.
6. Liability and Disputes
The Services, program materials, benefits, and content are provided “as is” and “as available,” with broad warranty disclaimers.
Fullstory’s aggregate liability is generally capped at US$500, and neither party is liable for indirect, consequential, punitive, special, exemplary, lost-profit, business-interruption, goodwill, or data-loss damages. The cap does not apply to Fullstory’s gross negligence, willful misconduct, or fraudulent misrepresentation.
The Partner must indemnify Fullstory for claims involving, among other things, the Partner’s legal violations, misuse of Prospect Information, breach of conduct rules, gross negligence, willful misconduct, or fraud. Fullstory provides narrower indemnity protections, mainly for its misconduct and certain intellectual-property claims.
Delaware law governs, and disputes must generally be brought exclusively in state or federal courts located in Delaware. This may increase the cost and inconvenience of litigation for Partners elsewhere.
7. Changes and Termination
Fullstory may modify the MPPA and Program Addenda by posting revised versions on the Partner Site or Portal. Changes generally take effect on the first day of the following calendar month. For fixed Program Authorizations of 12 months or longer, changes generally apply upon renewal.
If a Partner objects, its exclusive remedy is to terminate the agreement or decline/cancel renewal. Fullstory may also change benefits, tiers, programs, the Portal, or participation rights, often in its sole discretion, with commercially reasonable or reasonable notice. Either party may generally terminate on 30 days’ written notice.
Privacy Policy
Fullstory Privacy Policy: User-Focused Overview
Effective date: May 19, 2025
This policy covers Fullstory’s website, SaaS analytics services, communications, and related interactions. If you visit a third-party website using Fullstory, that website’s privacy policy generally applies to data collected there.
1. Data Collection and Use
Information collected
Depending on your relationship with Fullstory, it may collect:
- Identity and contact data: name, email, address, telephone number, username, account credentials, and subscription details.
- Device and technical data: IP address, browser, operating system, mobile-network information, device identifiers, and approximate location/ISP.
- Browsing and session data: pages viewed, links clicked, referring URLs, time spent, mouse movements, clicks, scrolling, and non-sensitive text entered.
- Transaction data: payment details, billing records, payment history, and order information.
- Communications and content: emails, chat messages, support requests, surveys, social-media posts, blog comments, and customer stories.
- Employment information: education, employment history, and job-application materials.
For visitors to customer websites, Fullstory records session activity through cookies and local storage, including actions and text entered. Fullstory says it does not attempt to identify the same person across unrelated websites.
Purposes
Uses include providing and supporting the Services, processing transactions, improving products, measuring website performance, security and fraud prevention, legal compliance, marketing and targeted advertising, recruiting, and creating aggregated or de-identified analytics.
Important risk: Fullstory’s functionality can capture detailed behavioral sessions. Customers are expected to notify their own website or app visitors and are prohibited from submitting sensitive data, but the policy places substantial responsibility on customers to configure and use the service appropriately.
2. User Rights and Choices
Depending on location, users may have rights to:
- Access or obtain a copy of personal information
- Correct inaccurate information
- Delete information, subject to exceptions
- Restrict or object to processing
- Receive portable, machine-readable data
- Withdraw consent
- Opt out of marketing, targeted advertising, “selling” or “sharing” of data
- Avoid discriminatory treatment for exercising rights
Requests can be submitted to privacy@fullstory.com or 1-833-385-5786. Fullstory may verify identity and may deny or limit requests where legally permitted.
California residents can use the “Do Not Sell or Share My Personal Information” link. The policy states that Fullstory may sell or share certain visitor data for advertising and analytics purposes, but says it does not sell or share customer or customer-user data collected through the Services.
Users can opt out of Fullstory session capture across participating websites by setting an opt-out cookie. This choice depends on the cookie remaining present.
3. Third-Party Sharing
Fullstory may share information with:
- Hosting, IT, payment, billing, support, marketing, accounting, auditing, and other service providers
- Analytics providers
- Advertising and marketing partners, including for interest-based advertising
- Affiliates
- Social-media platforms when users interact with social features
- Buyers or successors in a merger, acquisition, financing, or asset sale
- Government authorities or others when legally required or necessary for security, fraud prevention, emergencies, or enforcement
Some recipients and personnel may be located outside your country. Fullstory says recipients should use information only for authorized purposes, but an acquisition could result in different privacy practices.
4. AI/ML Training
The policy does not expressly say that identifiable customer or user session data is used to train general-purpose AI models.
However, Fullstory may use or share aggregated or de-identified information for research, analysis, modeling, marketing, and service improvement. The policy does not define in detail how de-identification is performed or whether re-identification is possible.
For Subtext, session data is transformed into semantic representations and supplied to users’ coding agents or AI development tools. This may include screenshots, page structure, actions, network data, and console errors. Those AI tools’ use and retention are governed by their own terms, creating additional third-party data risks.
5. Key Obligations and Restrictions
Customers must:
- Give notice to their website or app visitors about Fullstory use
- Avoid providing sensitive data through the Services
- Follow Fullstory’s Acceptable Use Policy
- Not use Fullstory to build cross-site user profiles for selling or exchanging demographic lists
Users should avoid entering confidential or sensitive information into websites using Fullstory unless they understand the site’s controls and privacy notice.
6. Liability, Security, and Disputes
Fullstory describes “reasonable” physical, technical, and organizational safeguards but provides no guarantee of security. It disclaims responsibility for unauthorized access by attackers and Internet-related risks.
This Privacy Policy does not itself provide detailed damages caps, indemnities, warranties, or governing-law terms; those may appear in the Customer Terms, Service Agreement, or other contractual documents.
For EEA, UK, and Swiss data transferred under the Data Privacy Framework, complaints may proceed to Fullstory, then BBB National Programs, and ultimately potentially binding arbitration under the Framework.
7. Policy Changes
Fullstory may revise the policy. The effective date will change, and material changes may receive more prominent notice, including email for certain services. Users are encouraged to review the policy periodically; continued use may indicate acceptance of the updated practices.
Terms and Conditions
Overview of Key Terms and Risks
> Scope note: This is a business-to-business Master Services Agreement (MSA), not the complete privacy notice. Important privacy details—such as specific retention periods, data-subject procedures, subprocessors, and international-transfer mechanisms—are contained in the separate Data Processing Addendum (DPA), Privacy Policy, Security Documentation, and other linked policies.
1. Data Collection and Usage
- Customer Data includes electronic data submitted by or on behalf of the customer or its users through the services. This may include website, application, digital-property, and session-related information.
- Personal Data is broadly defined to include names, addresses, email addresses, telephone numbers, and sensitive information.
- The customer controls what data is collected through its application configuration and is solely responsible for configuring the service and ensuring lawful collection.
- The customer grants Fullstory, its affiliates, and applicable contractors a worldwide, royalty-free, limited-term license to host, copy, transmit, display, process, and use Customer Data as reasonably necessary to:
- Provide the services;
- Monitor, develop, and improve the services and professional services.
- Fullstory states that it acquires no ownership of Customer Data. However, it owns Usage Data—de-identified or aggregated operational information—and may use it to operate and improve its business.
Sensitive data risk
Customers must configure the service to prevent collection of sensitive data, including payment-card data, government identifiers, health information, and GDPR special-category data. If sensitive data is inadvertently collected, the customer must notify Fullstory and identify it so Fullstory can delete it. The agreement does not promise automatic detection or deletion.
2. User Rights
The MSA does not directly give individual users a detailed set of privacy rights. Rights such as access, correction, deletion, objection, portability, and restriction are primarily addressed in the separate DPA and applicable privacy laws.
The customer generally acts as the data controller and is responsible for:
- Having a lawful basis and obtaining required consents;
- Honoring privacy notices and user requests;
- Ensuring its data collection does not violate law or its own policies.
The customer may request earlier deletion of Customer Data after termination and may request a certificate of deletion.
3. Third-Party Sharing
- Fullstory may share or provide access to Customer Data to its affiliates and contractors as reasonably necessary to provide the services.
- Customers may enable third-party integrations. Doing so authorizes the third-party provider to access Customer Data needed for the integration.
- Fullstory disclaims responsibility for a third party’s use, disclosure, modification, or deletion of data.
- Third-party integration providers are expressly not treated as Fullstory subprocessors under the DPA, which may affect contractual protections.
- Fullstory may disclose confidential information where legally compelled, generally subject to notice where legally permitted.
4. AI/ML Training
The agreement does not expressly state that Customer Data will or will not be used to train generative AI or machine-learning models.
The license permits Fullstory to use Customer Data to “monitor, develop, and improve” its services. This language could potentially encompass analytics, algorithms, or machine-learning improvements, although it does not clearly authorize training general-purpose models. Customers should seek clarification or a contractual opt-out if AI training is a concern.
Usage Data may be retained, used, and disclosed if de-identified or aggregated so it does not identify the customer or users.
5. Key Customer Obligations
Customers must:
- Secure their own networks, equipment, credentials, and systems;
- Comply with the agreement, documentation, Acceptable Use Policy, and all applicable laws;
- Obtain rights, permissions, and consents for all Customer Data;
- Prevent sensitive-data collection;
- Avoid unlawful, infringing, deceptive, harmful, obscene, threatening, or malicious content;
- Not reverse engineer, copy, modify, or use the service to build a competing product;
- Promptly report violations;
- Export desired data before termination.
Fullstory may immediately suspend services where misuse threatens service security, integrity, or availability.
6. Liability and Disputes
- Most indirect, consequential, special, lost-profit, business-interruption, goodwill, and data-loss damages are excluded.
- Liability is generally capped at the greater of fees paid or payable in the prior 12 months or $1,000.
- The cap does not apply to certain matters, including payment obligations, customer breaches of usage restrictions, indemnification obligations, fraud, gross negligence, or willful misconduct.
- Services are generally provided “as is,” with limited warranties. Free trials have no warranty and essentially no liability protection.
- Non-EEA customers: Delaware law and exclusive courts in Wilmington, Delaware.
- EEA customers: England and Wales law and exclusive courts in London.
7. Changes, Renewal, and Termination
- The MSA itself generally requires a written, signed modification.
- Linked documentation, security materials, support policies, and the DPA may be updated periodically; the agreement does not provide a detailed general user-notification process.
- Subscriptions automatically renew annually unless written non-renewal notice is given at least 60 days before term end.
- Fees are generally non-refundable, and identical renewal services increase by 7%.
- After termination, session replay data may remain accessible for up to 30 days; Fullstory may delete Customer Data within six months, subject to legal-retention requirements.
Change history
2026-09-05 · Terms and Conditions
Summary
The diff states only that approximately 59 words were added, but it does not include the actual added language. As a result, the legal and commercial impact cannot be reliably assessed.
AI Training and Customer Data
- No specific language is provided addressing whether customer data may be:
- Used to train, fine-tune, or improve AI or machine-learning models;
- Used to develop products, services, or algorithms;
- Combined with other customers’ data;
- De-identified, anonymized, or aggregated for model training;
- Retained after termination for training or research purposes; or
- Shared with affiliates, contractors, or third-party AI providers.
- It is therefore not possible to determine whether the amendment:
- Expands or restricts the provider’s rights to use customer data;
- Changes whether customer content is used for model training by default or only with consent;
- Creates an opt-out or opt-in mechanism;
- Limits training to de-identified or aggregated data;
- Imposes confidentiality, security, retention, or deletion obligations; or
- Allocates responsibility for intellectual-property, privacy, or regulatory risks arising from AI training.
Other Potential Legal Risks
Because the added words are not shown, the following issues also cannot be evaluated:
- Changes to ownership or licensing of customer data, outputs, or derivative materials;
- Expanded rights to use data for analytics, benchmarking, or service improvement;
- New disclosures to subprocessors or third parties;
- Changes to confidentiality, data protection, or security obligations;
- New warranties, indemnities, limitations of liability, or compliance duties; and
- Whether the amendment applies retroactively to previously collected data.
Conclusion
The diff is insufficient for substantive legal analysis. The actual 59-word addition should be provided, ideally together with the surrounding original language, because the meaning may depend on definitions, exceptions, and related provisions elsewhere in the agreement.
2026-09-04 · Terms and Conditions
Structured Summary of Important Changes
1. Agreement structure and incorporated documents
- The document is renamed/reorganized from a “Master Services Agreement” presentation to a broader “Master Services Agreement” incorporating exhibits, policies, and addenda.
- The revised language expressly incorporates or references numerous documents, including:
- Acceptable Use Policy
- Customer DPA
- Security Addendum
- Subprocessor List
- International Data Transfers terms
- Privacy Policy and California Privacy Notice
- Reseller and partner terms
- Compliance and security documentation
- Support Policy
- Risk: These external documents may contain material obligations and may be updated separately. The customer should confirm which documents apply to its use case and whether the agreement limits unilateral changes to incorporated policies.
2. Contract formation and acceptance
- The agreement becomes binding upon the earliest of:
1. Customer signing an Order Form;
2. Customer or a User accessing or using the services; or
3. A User clicking an “I Accept,” “Sign Up,” or similar button.
- The language is clarified to cover individuals acting for an entity and confirms that the entity—not the individual—is the Customer.
- Risk: Use of the service or acceptance by a User can bind the organization even without a separately signed agreement. Customers should control administrator and User access.
3. Data protection and security
- The definition of the DPA now points to Fullstory’s online standard DPA, which may be updated where required by law.
- The agreement continues to define Customer Data broadly as electronic data submitted by or on behalf of Customer.
- Customers remain responsible for complying with applicable law and for not submitting Sensitive Data unless permitted.
- Fullstory’s obligation regarding improperly submitted Sensitive Data appears limited to deleting it after receiving sufficient information to locate it.
- Risk: The agreement does not appear to provide a broad deletion, remediation, or notification commitment for Sensitive Data submitted contrary to the agreement. The online DPA and Subprocessor List should be reviewed carefully.
4. AI-model training and use of Customer Data
- No express new provision authorizing Fullstory to use Customer Data to train artificial-intelligence or machine-learning models appears in the supplied diff.
- The revised text preserves the Customer Data ownership framework and states that Feedback does not include Customer Data. Fullstory may use Feedback without obligation to Customer, but that does not expressly authorize use of Customer Data for AI training.
- Important uncertainty: Because the diff incorporates external policies, documentation, and addenda, AI-related permissions could appear outside the quoted MSA—particularly in the DPA, Privacy Policy, Acceptable Use Policy, product terms, or documentation.
- Customers should obtain written confirmation that Customer Data, Personal Data, prompts, session content, and derived analytics will not be used to train or improve general-purpose or third-party AI models unless expressly authorized.
5. Support and service terms
- The Support Policy is now linked directly to a Fullstory help-center URL.
- Fullstory may update the Support Policy, but revisions may not materially diminish its responsibilities during the applicable Term.
- Risk: The online policy remains an incorporated, changeable document; customers should preserve a copy applicable on the contract date.
6. Historical version reference
- The agreement now identifies prior MSA versions as 2023 and 2020, replacing the prior generic “Previous MSA versions” wording. This appears mainly administrative but may affect interpretation of superseded terms.
2026-08-31 · Terms and Conditions
Structured Summary of Important Changes
1. Agreement Structure and Incorporated Documents
- The agreement is renamed/reframed as a “Master Services Agreement” rather than a “Master Services Agreement” preceded by the former customer terms language.
- The revised definition expressly incorporates a broad range of documents, including:
- Customer DPA
- Delivery and provider addenda
- Onboarding and service-provider materials
- Sub-processor list
- Free/International Use terms
- Data Transfer materials
- Security and compliance documentation
- Customer terms and other referenced policies
- Risk: Documents merely “referenced herein” may become contractually relevant even if the customer does not sign them separately. The customer should confirm which documents apply, their order of precedence, and whether Fullstory may update them unilaterally.
2. Contract Formation and Binding Effect
- The agreement becomes binding upon the earliest of:
1. Customer signing an Order Form;
2. Customer or its users accessing or using the services; or
3. Clicking an “I Accept,” “Sign Up,” or similar control.
- The language now more clearly applies where an individual acts for an entity and requires that person to represent the entity.
- Risk: Use of the service—even before procurement or legal review is complete—may bind the customer to the full agreement and incorporated online terms.
3. Customer and Affiliate Responsibility
- The revised language clarifies that “Customer” includes the entity represented by the person accepting the agreement.
- Customer affiliates may use the services, but Customer remains jointly and severally liable for affiliate compliance and payment obligations.
- Risk: The customer may be liable for breaches by affiliates, contractors, and other users, including users outside the original business unit.
4. Data and Privacy Terms
- The agreement retains or clarifies definitions of Customer Data, Personal Data, Sensitive Data, and the DPA.
- Fullstory’s DPA is incorporated by reference and may be updated where required by applicable law.
- Customer remains responsible for the legality of its data collection and use, including obtaining necessary permissions and avoiding prohibited Sensitive Data.
- Fullstory’s obligation regarding improperly submitted Sensitive Data is limited to deleting the data within its control after receiving sufficient locating information.
- Risk: Customers should verify the DPA’s data-use, retention, deletion, subprocessors, international-transfer, and audit provisions because those terms may control over the MSA.
5. AI Model Training
- No express new language authorizing or prohibiting use of Customer Data to train AI models appears in the supplied diff.
- The changes do not identify “AI,” “machine learning,” “model training,” “training data,” or similar concepts.
- Nevertheless, the broad incorporation of policies, documentation, addenda, and referenced data-transfer materials creates a potential indirect risk if any incorporated document contains AI-training rights or is later updated to do so.
- The customer should obtain written confirmation that Customer Data, Personal Data, prompts, outputs, and usage telemetry will not be used to train or improve general-purpose or third-party AI models without the customer’s express consent.
6. Other Notable Changes
- Support Policy is now linked to a specific online URL and may be updated, subject to a non-material-diminution limitation.
- Free Trial Services are expressly provided at Customer’s risk and may carry additional requirements.
- The prior MSA version reference is changed to “2023/2020,” which may create uncertainty about which historical version applies.
2026-08-30 · Terms and Conditions
Summary
The provided diff does not include the actual contractual language that was added, deleted, or replaced. It only states:
> “Added approximately 59 words to the document”
Accordingly, no substantive legal changes can be identified.
AI Training and Customer Data
- No language addressing the use of customer data to train, fine-tune, evaluate, or improve AI models is included.
- It is therefore impossible to determine whether the revised document:
- Permits or prohibits AI training using customer data;
- Requires customer consent;
- Allows use of data in aggregated, de-identified, or identifiable form;
- Grants the provider ownership or license rights in customer data or model outputs;
- Applies data-retention, deletion, confidentiality, or security limits; or
- Allows human review or sharing with affiliates and third-party AI providers.
Legal Risk Assessment
No new risks can be assessed from the material provided. The full text of the additions, deletions, and replacements is required to evaluate:
- Changes to customer rights and provider permissions;
- Ownership and intellectual-property effects;
- Confidentiality and privacy obligations;
- Data protection and regulatory compliance;
- Liability, indemnity, and warranty exposure; and
- Whether AI-training rights survive termination or apply to previously collected data.
Please provide the marked-up contractual language itself, including the text inside {}, [], and []{}.
2026-08-30 · Terms and Conditions
Summary
The provided diff does not include the actual contractual language. It only states:
> “Added approximately 59 words to the document”
As a result, it is not possible to determine:
- What legal provisions were added or changed.
- Whether the changes expand or restrict either party’s rights.
- Whether liability, confidentiality, data protection, intellectual property, termination, or audit rights are affected.
- Whether the customer’s data may be used to train, fine-tune, evaluate, or improve AI models.
- Whether customer data may be shared with affiliates, subprocessors, or third-party AI providers.
- Whether the customer has an opt-out, deletion, or data-use control.
AI-Training and Data-Use Assessment
No language addressing AI model training or related data use is included in the supplied diff. Therefore, no conclusion can be drawn about whether the revised terms:
- Permit training on customer content or personal data;
- Allow use of aggregated, de-identified, or anonymized data;
- Apply training rights to inputs, outputs, prompts, metadata, or usage data;
- Allow retention of data for model improvement;
- Permit disclosure to third-party model providers; or
- Require consent, provide an opt-out, or impose deletion obligations.
Information Needed
Please provide the actual 59 added words and, if applicable, the surrounding deleted or replacement language. The analysis should compare the full before-and-after wording, because the legal effect may depend on definitions, exceptions, and related provisions elsewhere in the agreement.
2026-08-27 · Terms and Conditions
Structured Summary of Important Changes
1. Agreement structure and incorporated documents
- The agreement is now presented as a Master Services Agreement and expressly includes “any exhibits, policies, or addenda attached hereto or referenced herein.”
- The revised text appears to incorporate or link to numerous external documents, including:
- Acceptable Use Policy
- Customer DPA
- Delivery and onboarding materials
- Provider Addendum
- Subprocessor List
- International Data Transfers terms
- Security and compliance documentation
- Privacy Policy and California privacy notice
- Reseller and technology-partner addenda
- Pass-through terms
Risk: The customer may be bound by terms located outside the main agreement, including terms that may be updated separately. The hierarchy among these documents is not stated in the excerpt. The customer should confirm which documents apply, whether they are part of the signed contract, and which document controls in case of conflict.
2. Data-processing terms
- “Customer Data,” “Personal Data,” “Sensitive Data,” and the “DPA” are now expressly defined or cross-referenced.
- The DPA is identified as Fullstory’s standard DPA, available online, and may be updated by Fullstory if required by applicable law.
- The agreement states that, where Fullstory processes Personal Data on the customer’s behalf, the DPA applies.
Risk: The customer’s data-protection rights and Fullstory’s obligations may depend substantially on an external DPA. The update language should be reviewed to determine whether changes are limited to legally required amendments or could materially affect the customer’s rights.
3. Customer responsibility for data
- Customer Data includes information submitted by or on behalf of the customer.
- The customer remains responsible for:
- The legality of its data and use of the services;
- The means by which it obtained Customer Data; and
- Avoiding submission of Sensitive Data unless permitted.
- If Sensitive Data is discovered, Fullstory’s stated obligation is to delete it from its control after receiving sufficient information to locate it.
Risk: The customer may bear significant compliance responsibility for data collected through its websites, applications, or other digital properties, including consent, notice, and lawful-basis obligations.
4. AI-model training and use of Customer Data
- No express provision in the supplied diff authorizes or prohibits Fullstory from using Customer Data to train AI or machine-learning models.
- No visible change grants Fullstory ownership of Customer Data or expressly permits use of Customer Data for product training, model training, analytics, or service improvement.
- The ownership section continues to state that Customer Data belongs to the customer, while Fullstory owns its services and related intellectual property.
- The Feedback provision allows Fullstory to use feedback without restriction, but expressly indicates that Feedback does not include Customer Data.
Important residual risk: The absence of an express AI-training restriction does not necessarily eliminate risk. AI-related permissions may appear in the DPA, Privacy Policy, Acceptable Use Policy, product terms, or other incorporated documents. Those documents should be reviewed for terms allowing use of customer content, telemetry, de-identified data, aggregated data, prompts, outputs, or usage data to train or improve models.
5. Other changes
- The agreement may become binding through signature, use of the services, or clicking an acceptance button.
- The customer is responsible for affiliate compliance and may be jointly and severally liable for affiliates.
- The prior MSA versions are identified as 2023 and 2020, suggesting a version update or replacement.
2026-08-26 · Privacy Policy
2026-08-24 · Privacy Policy
2026-05-20 · Terms and Conditions
The publisher records this document as revised on this date (“Last Updated: May 20, 2026”).
2025-05-19 · Privacy Policy
The publisher records this document as revised on this date (“Effective Date: May 19, 2025”).
Between 2023-08-04 and 2024-01-06 · Privacy Policy
Between 2023-05-05 and 2023-09-24 · Partner Terms and Conditions
Between 2022-05-06 and 2023-08-04 · Privacy Policy
Between 2022-02-04 and 2022-11-26 · Partner Terms and Conditions
Between 2020-12-17 and 2021-10-09 · Privacy Policy