Monitored company
Gremlin
clause.watch tracks 1 legal document published by Gremlin, re-reading each one every six hours. Below is what each document covers, in plain English.
Privacy
Privacy Policy Overview — Gremlin, Inc. (Version 1.3, updated November 17, 2021)
1. Data Collection and Use
Gremlin collects information you provide and information gathered automatically.
Information you provide
This may include:
- Name, email address, and password when registering
- Information submitted through mailing lists, surveys, inquiries, or customer support
- Communications with Gremlin; phone calls may be recorded with notice and permission
- Customer Data submitted through the software, which may include personally identifiable information and login or notification details
For business customers, the organization that contracts with Gremlin—such as an employer—controls the relevant Gremlin account and Customer Data. The Terms of Service, rather than this policy alone, govern that data.
Automatically collected information
Gremlin may collect:
- IP address, browser type, operating system, HTTP header information
- Referring website and usage data, such as page views, conversion rates, and time spent
- Software usage and experiment information, including experiment duration and whether an experiment succeeds or fails
- Cookie, web beacon, mobile identifier, Flash cookie, and similar tracking data
Gremlin uses this information to provide, secure, administer, analyze, and improve its Services; understand user behavior; measure marketing and advertising; prevent fraud; and personalize content or advertisements.
Gremlin may treat anonymized, aggregated, or de-identified information as “Non-Personal Information” and use or disclose it for any purpose, subject to applicable law. If combined with identifying information, it is treated as Personal Information.
2. User Rights
The policy gives EEA residents rights to:
- Access, correct, update, or request deletion of Personal Information
- Object to or restrict processing
- Request data portability
- Withdraw consent
- Opt out of marketing communications
- Complain to a data protection authority
Requests may be made using the “Contact Us” information, but the supplied document does not include an actual email address or other contact details. Gremlin may retain information needed for legal compliance, dispute resolution, or enforcement of agreements.
Users can generally control Cookies through browser settings. However, disabling them may impair certain features. Gremlin does not currently honor “Do Not Track” signals.
3. Third-Party Sharing and International Transfers
Gremlin states that it does not sell or trade Personal Information to third parties. However, it shares or permits access to information through:
- Advertising, marketing, and analytics partners, including Google Analytics
- Business service providers such as Salesforce
- Survey providers and other contractors
- Authentication providers, including SAML single sign-on providers
- Authorized personnel and contractors with a business need
Ad Partners may track activity across Gremlin and other websites or applications, combine data, deliver targeted advertising, and measure ad performance. Gremlin may combine partner-collected data with information it collects directly.
Gremlin and its Services are hosted outside the EEA, including in the United States. The policy warns that U.S. privacy protections and government-access rules may be less protective than those in a user’s home country.
4. AI/ML Training
The policy does not state that user data is used to train artificial intelligence or machine-learning models. It does permit broad use of aggregated, anonymized, or de-identified information and collection of analytics and usage data. Users seeking certainty about AI training should review the Terms of Service or obtain clarification from Gremlin, especially regarding Customer Data.
5. Key User Obligations and Restrictions
- Users under 13 may not use the Services or submit Personal Information.
- Users are responsible for deciding whether to provide information and for reviewing the privacy practices of linked third-party websites.
- By using the Services, users agree to the Privacy Policy.
- Continued use after policy changes constitutes acceptance.
- Customers should avoid submitting unnecessary sensitive information because Customer Data may be controlled by the contracting organization and processed in the U.S.
6. Liability and Disputes
This Privacy Policy contains limited dispute and liability terms. It states that Gremlin is not responsible or liable for third-party linked websites or their privacy practices. It also reserves information necessary to resolve disputes and enforce agreements.
The policy does not specify:
- A governing law or dispute forum
- Arbitration or court procedures
- Financial liability caps
- Remedies for privacy violations
- Detailed breach-notification obligations
Those provisions may appear in the separate Terms of Service. The security language describes SSL transmission and access controls, but does not guarantee that security will never be compromised.
7. Policy Changes
Gremlin may revise the Privacy Policy by posting changes on the same webpage and updating the modification date. No separate email or individualized notice is promised. Continued use after changes is treated as acceptance, so users must periodically check the policy.
Change history
2026-08-29 · Privacy
Summary
The supplied diff only states: “Removed approximately 739 words from the document.” It does not identify which clauses were deleted or provide the replacement text.
Key implications
- Unable to determine substantive changes: The deleted language could concern data rights, confidentiality, liability, security, intellectual property, termination, governing law, or other important terms.
- Potential AI-training changes cannot be assessed: The diff does not show whether provisions were added, removed, or modified regarding:
- Use of customer data to train, fine-tune, evaluate, or improve AI models;
- Whether customer data, prompts, outputs, or usage data may be used for those purposes;
- Whether training is permitted by default or only with customer consent;
- Opt-out or deletion rights;
- Use of data for model safety, analytics, or service improvement;
- Human review or access to customer data;
- Restrictions on using confidential or personal information;
- Ownership of model improvements or derived data; or
- Retention and deletion of training data.
Risk assessment
The removal of approximately 739 words may materially alter the agreement, but the direction and severity of the risk cannot be determined without the actual deleted and replacement language. If the deleted provisions limited the provider’s use of customer data, their removal could expand the provider’s rights to use that data—including for AI training—or eliminate customer protections. Conversely, the deletion could remove broad provider rights or improve customer protections.
Information needed
Please provide the actual redlined text, including:
1. The words or clauses marked as deleted;
2. Any replacement or newly added language; and
3. The surrounding section headings or clauses.
Without that text, no reliable legal comparison or conclusion about AI-training rights is possible.
2026-08-28 · Privacy
Summary of Important Changes
1. Expanded and More Specific Uses of Information
The revised policy replaces a broad statement allowing use and disclosure of Non-Personal Information “for any purpose” with a detailed list of permitted purposes, including:
- Responding to requests and customer-service inquiries.
- Creating and administering online accounts.
- Developing tools and features.
- Analyzing usage and improving website navigation, content, functionality, and services.
- System administration, security, fraud prevention, abuse prevention, and technical support.
- Business administration, billing, account management, advertising, recruitment, surveys, contests, and communications.
Although the list is more transparent, it is still broad and permits use of customer information for analytics, service improvement, advertising optimization, trend analysis, and general business purposes.
2. AI Training / Machine Learning
No express reference to training AI models, machine learning models, generative AI, foundation models, or using customer content as training data appears in the revised language.
However, the new permission to use information to:
- “analyze your usage,”
- “better understand our users,”
- improve services and functionality, and
- analyze trends,
could potentially support analytics or model development unless other provisions restrict that use. The policy does not state:
- Whether customer-submitted content or service data may be used to train AI models.
- Whether data is anonymized before model training.
- Whether prompts, outputs, logs, or account data are retained for AI purposes.
- Whether customers can opt out of AI training.
- Whether third-party AI providers receive customer data.
- Whether trained models will be treated as derived from customer data.
Risk: The absence of an explicit AI-training restriction leaves uncertainty and may permit arguments for secondary use of data for model development under the broad service-improvement language.
3. Sharing and Third-Party Providers
The revision adds clearer categories of third-party recipients, including cloud hosting, backups, email providers, analytics providers, and other service providers. It states sharing will be limited to what is necessary for those functions and subject to the policy and applicable law.
It also adds disclosure rights for:
- Corporate sales, mergers, reorganizations, or similar transactions.
- Legal process, government requests, national security, and law enforcement.
- Protecting rights, property, users, customers, and enforcing the Terms of Service.
The “do not sell or trade” statement is retained, but transfer or disclosure during a corporate transaction is expressly permitted.
4. International Transfers
The revised text more directly states that services and third-party business systems may be hosted outside the EEA, including in the United States. It warns that foreign privacy protections may differ from those in the customer’s home country.
5. Retention and Customer Rights
Retention is described as lasting while the customer uses the Services or has an account, and as necessary for legal, regulatory, billing, administrative, and dispute-related purposes.
The revised policy preserves rights to access, correction, deletion, restriction, portability, objection, and complaints, subject to applicable law. It also clarifies that withdrawal of consent does not affect prior processing or processing based on other lawful grounds.
6. Drafting Risk
The diff is highly repetitive and appears to splice together substantial sections of the policy. The final consolidated text should be checked carefully for inconsistencies, duplicated provisions, and unintended omissions—particularly concerning AI use, data retention, security commitments, and third-party processing.
2026-08-24 · Privacy
Summary of Important Changes
1. Broad use of “Non-Personal Information”
The revised policy introduces a broad definition of “Non-Personal Information”: information that does not identify a person as a specific natural person, including location, demographic information, ZIP codes, and information that has been anonymized, aggregated, or de-identified.
Gremlin may use and disclose Non-Personal Information for any purpose, despite other restrictions in the policy, unless applicable law requires otherwise.
Risk
- This is a significant expansion of permitted use and disclosure.
- The policy does not explain the technical or legal standard used to determine whether information is sufficiently anonymized or de-identified.
- Data that appears non-identifying could potentially be combined with other information and become identifiable.
The policy expressly states that if Non-Personal Information is combined with personal information, it will be treated and used as personal information. However, the broad “any purpose” authorization remains a material concern for data that Gremlin considers permanently de-identified.
2. AI-model training
The diff contains no express reference to artificial intelligence, machine learning, foundation models, model training, fine-tuning, or using customer data to develop AI systems.
However:
- The authorization to use and disclose Non-Personal Information “for any purpose” could potentially be interpreted to permit using properly anonymized or aggregated customer data to train or improve AI models.
- There is no express statement that customer data will not be used for AI training.
- There is no opt-out, consent requirement, deletion mechanism, model-output restriction, or limitation on retaining data incorporated into an AI model.
- The policy does not clarify whether customer-submitted content, prompts, logs, telemetry, or support data qualify as personal information or Non-Personal Information.
Recommended clarification: expressly state whether customer data may be used for AI training. If permitted, identify the data categories, purposes, providers, retention rules, safeguards, and opt-out rights. If not permitted, add a clear prohibition covering customer content and service data.
3. Data sharing and service providers
The revised text identifies Gremlin as the controller of information collected through its Services and describes third-party providers such as Salesforce and Google Analytics as processors for data they hold.
It also permits sharing with authorized personnel and contractors with a business need, subject to confidentiality and protective contractual terms.
Risk
The language is technically awkward and may create uncertainty about whether Gremlin or third-party providers control particular data sets.
4. International transfers
The policy now emphasizes that data may be hosted and processed in the United States and warns that U.S. protections may be less comprehensive than those in the user’s home country.
Risk
The policy does not identify a specific transfer mechanism, such as standard contractual clauses or another recognized safeguard.
5. Retention and individual rights
Retention is expanded to cover the period of service use, account ownership, fulfillment of policy purposes, and additional legal, tax, or regulatory requirements.
EEA rights are expanded or clarified to include access, correction, deletion, objection, restriction, portability, consent withdrawal, and complaints to a supervisory authority. Gremlin reserves the right to retain information it deems necessary for legal compliance, disputes, and enforcement.
2026-08-23 · Privacy
Summary of Important Changes
1. Customer-data use and AI-model training
- No express reference to artificial intelligence, machine learning, foundation models, model training, fine-tuning, or use of customer data as training data appears in the diff.
- The revised language nevertheless broadens or clarifies permitted uses of information, including:
- analyzing usage;
- improving the Services, including navigation, content, functionality, tools, and features;
- understanding users and usage trends;
- monitoring usage and other activities;
- addressing errors, security, and technical issues; and
- general business and customer-service purposes.
- These provisions could potentially support analytics or automated-system development, but they do not clearly authorize AI training. If AI training is intended, the policy should say so expressly and address whether customer content, prompts, outputs, account data, or telemetry may be used.
- The policy continues—or more clearly states—that Non-Personal Information may be used and disclosed for any purpose, notwithstanding the Privacy Policy, unless applicable law requires otherwise.
- Information that is anonymized, aggregated, or de-identified may be treated as Non-Personal Information. However, if it is combined with personal information, it is treated as personal information. The revised example expressly includes combining a ZIP code with a name.
- Risk: “Non-Personal Information” is defined broadly, and the “any purpose” authorization could create uncertainty about whether supposedly de-identified data may be used for commercial analytics, product development, or AI-related purposes. Re-identification, inadequate anonymization, or combining datasets could create regulatory and contractual exposure.
2. Expanded operational and business uses
The revised policy adds or emphasizes use for:
- account creation and administration;
- website management, contests, promotions, surveys, and other website features;
- advertising-campaign improvement;
- email and other communications;
- service delivery, maintenance, protection, billing, and account administration;
- security, fraud prevention, abuse investigation, and error correction.
These additions provide a more detailed legal basis for processing but may also expand the purposes beyond the prior, narrower wording.
3. Sharing with third parties
- The revised language identifies trusted providers such as cloud-hosting, backup, email, Google Analytics, and Salesforce-type providers.
- Sharing is described as limited to what is necessary to perform provider functions and subject to the Privacy Policy and applicable law.
- It adds disclosure rights for corporate transactions, legal process, government and national-security requests, investigations, protection of rights, and enforcement of the Terms of Service.
- The “we do not sell or trade” statement remains.
4. International transfers and retention
- The revised text states that Services and third-party business accounts may be hosted outside the EEA, including the United States.
- It reduces the prior comparative statement about U.S. privacy protections to a broader statement that protections may differ from the customer’s home country.
- Retention grounds are expanded to include account management, billing, legal, tax, regulatory, dispute-resolution, and agreement-enforcement needs, with possible additional retention periods.
5. Customer rights and marketing
- Rights to access, correct, delete, restrict, object, and obtain portability are retained or restated.
- Marketing opt-out rights are clarified, while operational, security, account, and service-related communications may not be opted out of.
- Withdrawal of consent does not affect prior processing or processing based on other lawful grounds.
2026-08-23 · Privacy
Executive Summary
The diff substantially rewrites and expands the privacy policy, particularly the treatment of Non-Personal Information, international transfers, data-controller/processor roles, retention, EEA rights, security, and third-party links. The apparent diff contains extensive duplication and concatenated text, so the final published version should be carefully checked for formatting and internal consistency.
AI Model Training
- No express authorization to use Customer Data to train AI models appears in the diff.
- However, the revised definition of “Non-Personal Information” is broad and includes information that has been “anonymized, aggregated or de-identified.”
- Gremlin may “use and disclose this information for any purpose,” notwithstanding the rest of the policy, unless applicable law requires otherwise.
- The policy also states that if Non-Personal Information is combined with personal information, it will be treated and used as personal information. This provides some protection against unrestricted use after re-identification or linkage.
- Risk: The broad “any purpose” language could arguably cover analytics, product development, automated systems, and potentially AI model training, even though training is not mentioned. It does not address:
- whether customer prompts, logs, content, or telemetry are used;
- whether data is used to train general-purpose or customer-specific models;
- opt-out or consent rights;
- retention of training data or model outputs;
- deletion from datasets or trained models; or
- restrictions on disclosure to AI vendors.
- Customers seeking assurance should request an explicit contractual statement that Customer Data is not used for AI training without consent, or a detailed AI data-use addendum.
Other Important Changes and Risks
Broader data-use/disclosure rights
- Non-Personal Information may be used or disclosed for any purpose.
- The policy expressly permits retention of such information in archives where Gremlin deems it necessary for legal obligations, disputes, or enforcing agreements.
- The revised language may reduce the practical effect of deletion requests for data classified as anonymized or de-identified.
International transfers
- The policy now expressly states that services and data may be hosted in the United States, including for users outside the EEA.
- It warns that U.S. protections may be less comprehensive than those in the user’s home country.
- This creates cross-border transfer and government-access risks for non-U.S. customers.
Third-party providers and roles
- Gremlin identifies itself as controller for information it collects through its services and third-party business accounts such as Salesforce.
- For data held by advertising or other third-party providers, Gremlin describes itself as a processor and says the data remains under that provider’s control.
- This allocation may limit Gremlin’s responsibility for third-party processing.
Retention and rights
- Retention may continue while the user uses the services or has an account, plus additional periods required for legal, tax, or regulatory reasons.
- EEA rights are expanded or clarified, including objection, restriction, portability, consent withdrawal, and complaints to a regulator.
- Gremlin reserves the right to retain information needed for legal compliance, disputes, or enforcement.
Security and third parties
- Security language is more detailed, including SSL, tracking technologies, fraud prevention, access controls, confidentiality obligations, and authorized contractors.
- Third-party website links are disclaimed more broadly; operators’ separate privacy policies govern their collection and use.
2026-08-22 · Privacy
Summary
The provided diff does not include the actual contractual language. It only states:
> “Added approximately 739 words to the document”
Because the added wording is not shown, it is not possible to determine what legal rights, obligations, or risks were introduced.
AI Training and Customer Data
No specific language is provided addressing whether:
- Customer data may be used to train, fine-tune, or improve AI models;
- Customer prompts, inputs, outputs, files, or personal information may be retained;
- Data may be shared with affiliates, contractors, or third-party AI providers;
- Customer data may be used in aggregated, de-identified, or anonymized form;
- Customers may opt out of AI training or require deletion of training data;
- Human reviewers may access customer data for model evaluation or safety purposes; or
- The provider gives any confidentiality, security, ownership, or non-use commitments concerning AI-related processing.
Accordingly, no conclusion can be reached about whether the changes expand or restrict the provider’s ability to use customer data for AI training.
Other Legal Risks
The actual additions are necessary to assess potential changes involving:
- Data ownership and licensing;
- Confidentiality and privacy;
- Data retention and deletion;
- Security obligations and breach liability;
- Subprocessors and international transfers;
- Intellectual-property rights in inputs and outputs;
- Warranties, indemnities, and liability limits;
- Suspension or termination rights; and
- Changes to fees or service obligations.
Required Information
Please provide the full redlined text, including the approximately 739 added words and any surrounding provisions. Without the actual language, the diff cannot be meaningfully analyzed.
2026-08-20 · Privacy
Summary of Important Changes and Risks
1. Broad new rights to use “Non-Personal Information”
The revised policy introduces a broad definition of “Non-Personal Information”: information that does not identify a person, including location, demographic, ZIP-code, anonymized, aggregated, or de-identified information.
Gremlin may now use and disclose Non-Personal Information for any purpose, despite other limits in the Privacy Policy, unless applicable law requires otherwise.
Risks
- “Non-Personal Information” is defined broadly and may include information derived from customer activity or usage.
- Anonymized or de-identified information can sometimes be re-identified, particularly when combined with other data.
- The policy does not limit disclosure to service provision, analytics, security, or product improvement.
2. Combining data can restore personal-information treatment
If Gremlin combines Non-Personal Information with Personal Information—for example, a ZIP code with a name—the combined data will be treated and used as Personal Information under the policy.
This is a helpful clarification, but it does not prevent Gremlin from using information that remains classified as Non-Personal Information for broad purposes.
3. AI-model training
The revised language does not expressly mention artificial intelligence, machine learning, model training, model fine-tuning, or generative AI.
However, the authorization to use and disclose Non-Personal Information “for any purpose” could potentially be interpreted to permit:
- Training or improving AI or machine-learning models;
- Creating derived datasets, embeddings, or statistical models;
- Sharing de-identified usage data with AI vendors or other service providers.
The policy does not expressly exclude customer content, prompts, outputs, telemetry, or usage data from AI training. It also does not state whether data used for training will be deleted, segregated, or prevented from appearing in model outputs. Customers seeking a no-training commitment should request an express contractual restriction.
4. Data transfers and U.S. processing
The revised policy expressly states that Gremlin’s services and data may be hosted or provided in the United States and outside the EEA. It warns that foreign privacy protections may be less comprehensive than those in the customer’s home country.
This increases transparency but highlights potential international-transfer, government-access, and compliance risks.
5. Controllers, processors, and vendors
The revision adds a “Data Controller and Data Processor” section. Gremlin is described as controlling information collected through its services, while it may act as a processor for data held by third-party providers such as Google Analytics or Salesforce.
The policy also permits use of authorized contractors with access to Personal Information, subject to confidentiality and protective-contract requirements.
6. Retention and legal exceptions
Retention is expanded to continue while the customer uses the services or has an account, plus additional periods required for legal, tax, or regulatory reasons. Gremlin also reserves the right to retain archived information needed for legal obligations, disputes, or contract enforcement.
7. Additional privacy rights
EEA users receive expanded rights, including objection, restriction, portability, consent withdrawal, and complaints to a data-protection authority. Marketing opt-out procedures are clarified. These changes generally benefit individuals but do not materially restrict broad Non-Personal Information use.
2026-08-19 · Privacy
Summary
The provided diff does not include the actual contractual language. It only states:
> “Added approximately 739 words to the document”
Accordingly, it is not possible to determine:
- What provisions were added or changed;
- Whether customer data may be used to train, fine-tune, evaluate, or improve AI models;
- Whether the provider may use customer data for product development, analytics, or other secondary purposes;
- Whether customer data is shared with affiliates, subprocessors, or third parties;
- Whether confidentiality, security, deletion, retention, or ownership rights have changed;
- Whether the customer has any opt-out, objection, or approval rights;
- Whether new indemnities, liability exclusions, or compliance obligations were added.
AI-Training Risk Assessment
No conclusion can be reached regarding AI-model training because the relevant added language is not included. The key terms to check for include:
- “Train,” “fine-tune,” “improve,” “develop,” or “enhance” models
- Use of customer inputs, outputs, prompts, content, or data
- Whether use is limited to aggregated, de-identified, or anonymized data
- Whether the provider may use data for general-purpose models or only for the customer’s account
- Whether data is retained after termination or deletion
- Whether the customer can opt out or must affirmatively consent
- Restrictions on using data to train models that may benefit other customers
- Provider commitments regarding confidentiality, security, and data deletion
Required Information
Please provide the full redline or the actual 739 words of added text, including the surrounding provisions if available. Without the substantive wording, any assessment of legal effect or risk would be speculative.
2026-08-18 · Privacy
Summary
Scope of the Diff
The diff states only that approximately 739 words were removed. It does not identify:
- Which clauses were deleted;
- Whether any provisions were added or replaced;
- The subject matter of the deleted language; or
- Whether the deletion affects data use, confidentiality, security, intellectual property, or AI training.
AI Training and Customer Data
No specific change concerning the use of customer data to train AI models can be determined from the information provided.
The deleted text could potentially have included provisions addressing:
- Whether customer data may be used to train, fine-tune, or improve AI models;
- Whether customer data is used for product development or service analytics;
- Whether data is anonymized, aggregated, or de-identified before use;
- Whether customer data is excluded from training by default or only upon opt-out;
- Whether human reviewers or service providers may access data;
- Ownership of inputs, outputs, and model improvements; or
- Retention and deletion of data used in model development.
Potential Legal Risks
Because the deleted language is not available, the principal risk is loss of important protections or restrictions, including:
1. Expanded data-use rights: A deleted limitation may have restricted the provider from using customer data for advertising, analytics, product improvement, or AI training.
2. Reduced confidentiality protection: Deleted language may have required customer data to remain confidential or limited access by employees, contractors, or subprocessors.
3. Unclear AI-training permissions: If provisions concerning model training were removed, the agreement may now be ambiguous about whether customer data can be used to train general-purpose or customer-specific models.
4. Loss of opt-out or consent rights: Deleted terms may have provided an opt-out mechanism, prior consent requirement, or contractual prohibition on training.
5. Intellectual-property and liability gaps: The deletion may affect ownership of data, outputs, trained-model improvements, indemnities, or responsibility for unauthorized data use.
Conclusion
The supplied diff is insufficient for a substantive legal comparison. It confirms only that material text was removed; it does not establish whether the change is favorable or unfavorable, or whether it changes AI-training rights.
To analyze the risks accurately, the deleted 739 words—or the complete before-and-after contract versions—are required.
2026-08-18 · Privacy
Structured Summary of Important Changes
1. Expanded permitted uses of customer information
The revised policy replaces a broad statement allowing use and disclosure of Non-Personal Information for any purpose with a longer list of specified purposes, including:
- Responding to customer requests and support needs.
- Creating and administering online accounts.
- Developing tools and features.
- Analyzing usage and improving website navigation, content, functionality, and services.
- System administration, security, fraud prevention, abuse investigations, and error correction.
- Business administration, advertising-campaign improvement, communications, recruitment, billing, and account management.
Risk: Although the purposes are more detailed, the policy still authorizes broad behavioral analytics and service-improvement uses. The definition of Non-Personal Information continues to include location, demographic, ZIP-code, anonymized, aggregated, or de-identified information. The policy also states that information may be treated as personal information where required by law, but otherwise preserves broad use rights.
2. AI model training
The diff does not expressly mention artificial intelligence, machine learning, foundation models, model training, fine-tuning, or use of customer data to train AI systems.
However, the new rights to “analyze your usage,” “develop and provide tools and features,” “improve our Services,” and “better understand our users” are broad enough that, depending on the definitions elsewhere in the policy, they could potentially be argued to cover data analysis for product development or machine-learning purposes.
Key risk: There is no explicit limitation stating that customer content will not be used to train AI models, nor any explanation of whether data is:
- Used for training or fine-tuning models;
- De-identified before training;
- Shared with AI vendors;
- Retained in model weights;
- Used to train general-purpose models rather than customer-specific tools; or
- Subject to an opt-out.
Customers requiring confidentiality should seek an express contractual restriction on AI training and secondary model-development uses.
3. Broader third-party disclosures
The revised policy describes sharing with trusted providers performing cloud hosting, backups, email, technical, and administrative functions. It also adds disclosure in connection with a corporate sale, merger, reorganization, dissolution, or similar transaction.
Risk: Personal information may be transferred, sold, or disclosed as part of a transaction. The policy promises providers at least the same level of privacy protection, but does not specify vendor names, retention limits, audit rights, or deletion obligations.
4. International transfers and government access
The policy now states that services and third-party providers may be hosted outside the EEA, including in the United States, and warns that foreign privacy protections may differ. It also expressly permits disclosures to public or government authorities, including for national-security and law-enforcement purposes.
Risk: EEA customers may face cross-border transfer and government-access concerns, with limited detail about transfer mechanisms or safeguards.
5. Retention and rights
Retention is reframed around account administration, billing, legal obligations, disputes, and regulatory requirements, with additional retention permitted where legally required. Privacy rights are restated, including access, correction, deletion, restriction, portability, and objection rights.
Risk: The policy does not provide precise deletion timelines and reserves the right to retain archived information.
Between 2022-12-03 and 2024-06-23 · Privacy
Summary
The provided diff does not include the actual amended contract language. It only states:
> “Added approximately 739 words to the document”
Because the additions, deletions, and replacements are not shown, it is not possible to identify:
- Changes to the parties’ rights or obligations
- New fees, liability, indemnity, or termination provisions
- Changes to confidentiality, security, or data-protection obligations
- Whether customer data may be used to train, fine-tune, evaluate, or improve AI models
- Whether such use requires consent, is automatic, or can be opted out of
- Whether customer data may be shared with affiliates, vendors, or model providers
- Ownership or licensing rights in customer data, outputs, prompts, or derived data
- Data retention, deletion, anonymization, or cross-border-transfer provisions
AI-Training Review
No conclusion can be reached regarding AI-model training because the actual added language is missing. The phrase “Added approximately 739 words” does not reveal whether the new provisions:
- Permit training on customer content or usage data
- Exclude customer content from training by default
- Allow use of de-identified, aggregated, or telemetry data
- Grant the provider a broad license to use customer data
- Apply different rules to consumer, business, or free-tier customers
- Permit human review or use by subcontractors
- Create an opt-out or deletion mechanism
Information Needed
Please provide the full redline, including the text represented by:
{additions}[deletions][]{replacements}
Once provided, the changes can be analyzed for legal effect, business risk, and specific AI-data-training implications.
Between 2020-10-30 and 2022-12-03 · Privacy
Key Changes and Risks
1. Expanded use and disclosure of “Non-Personal Information”
The revised policy replaces specific permitted uses—such as responding to requests, administering accounts, improving services, and security—with a broad statement that Gremlin may use and disclose Non-Personal Information for any purpose, unless applicable law requires otherwise.
“Non-Personal Information” now expressly includes information that has been anonymized, aggregated, or de-identified, as well as examples such as location, demographic information, and ZIP codes.
Risk: The “any purpose” language is substantially broader and may permit commercial uses, sharing with vendors, analytics providers, or other third parties that were not previously stated. The policy does not define the technical standard for anonymization or de-identification, creating uncertainty about re-identification risk.
2. Combining non-personal and personal information
The revised language states that if Non-Personal Information is combined with personal information—for example, combining a ZIP code with a name—it will be treated and used as personal information under the policy.
Risk: This is a helpful limitation, but the policy still gives Gremlin broad discretion to determine when information is sufficiently anonymized or de-identified before combination.
3. AI model training
The diff contains no express reference to artificial intelligence, machine learning, model training, model improvement, or use of customer data to train AI models.
However, the new authorization to use and disclose Non-Personal Information “for any purpose” could arguably be interpreted to include training or improving AI models if Gremlin classifies the data as anonymized, aggregated, or de-identified.
Customer risk: There is no clear commitment that customer data will not be used for AI training, no distinction between customer content and telemetry, no opt-out, no retention limit for training datasets, and no statement about whether third-party AI providers may receive such data. Customers seeking a contractual prohibition should request express language addressing these points.
4. New international-transfer disclosures
The revised policy expressly states that Gremlin and its service providers operate outside the EEA, including in the United States, and warns that foreign protections may be less comprehensive.
Risk: This provides more disclosure but does not identify specific transfer mechanisms, such as Standard Contractual Clauses, adequacy decisions, or supplementary safeguards.
5. Third-party processors and vendors
The policy adds clearer “Data Controller” and “Data Processor” descriptions and identifies services such as Salesforce and Google Analytics.
Risk: It states that third-party data remains under the provider’s control, potentially creating uncertainty over Gremlin’s responsibility and the allocation of compliance obligations.
6. Retention, rights, and security
Retention is broadened to include periods required for legal, tax, or regulatory reasons, and EU rights are expanded to include objection, restriction, portability, consent withdrawal, and complaints.
Security language is more specific, including SSL, authorized personnel, contractors, fraud prevention, and security technologies. These are positive clarifications, but they are policy commitments rather than detailed contractual security guarantees.
2021-11-17 · Privacy
The publisher records this document as revised on this date (“dated 11/17/2021”).
Between 2019-05-03 and 2020-10-30 · Privacy
Summary of Important Changes
1. Expanded purposes for using customer information
The revised policy replaces a broad statement allowing use and disclosure of Non-Personal Information “for any purpose” with a more detailed list of permitted uses, including:
- Responding to customer requests and support needs.
- Creating and administering online accounts.
- Developing, maintaining, and improving the Services.
- Analyzing usage, trends, and user behavior.
- Website navigation and content improvements.
- System administration, security, fraud prevention, abuse investigations, and technical issue resolution.
- General business administration, billing, recruitment, advertising, surveys, promotions, and communications.
Risk: Although the purposes are more specific in places, the policy still preserves a broad right to use and disclose information classified as Non-Personal Information “for any purpose,” unless applicable law requires otherwise.
2. AI-model training
The diff contains no express reference to artificial intelligence, machine learning, model training, model fine-tuning, or use of customer data to train AI systems.
However, the revised language may create indirect risk:
- The company may use “your Information to analyze your usage” and to “improve” Services, content, functionality, and user understanding.
- Non-Personal Information—including anonymized, aggregated, or de-identified information—may be used and disclosed “for any purpose.”
- If personal information is combined with Non-Personal Information, the combined data is treated as personal information under the policy.
- The policy does not state that customer content or usage data will be excluded from AI training, nor does it provide an AI-specific opt-out, deletion mechanism, retention limit, or restriction on third-party model providers.
Practical implication: The wording does not clearly authorize training AI models using identifiable customer data, but it may arguably cover training or improving models using aggregated, de-identified, or usage-derived data. Customers seeking protection should request an explicit prohibition or limitation on AI training and model development.
3. Broader third-party sharing
The revised policy adds sharing with trusted service providers performing functions such as:
- Cloud hosting and backups.
- Email and communications.
- Analytics and advertising support.
- Technical and administrative services.
It also permits disclosure in connection with corporate sales, mergers, reorganizations, legal demands, law enforcement, national security, fraud prevention, and enforcement of the Terms of Service.
Risk: The former statement that the company did not sell or trade personal information is retained, but the new language allows broader disclosures to vendors and transaction counterparties. Vendor use restrictions are described generally and do not expressly address AI providers or secondary model training.
4. International transfers and retention
The revised policy states that data may be hosted or processed outside the EEA, including in the United States, and that protections may differ from those in the customer’s home country.
Retention language is expanded to permit retention for account administration, billing, legal, tax, regulatory, dispute, and business purposes, including additional periods required by law.
5. Customer rights and marketing
The policy adds or restates rights to access, correct, delete, restrict, port, and object to processing, while clarifying that withdrawal of consent does not affect prior lawful processing or processing based on other legal grounds. Marketing opt-out rights are expressly provided.