Monitored company
MURAL
clause.watch tracks 2 legal documents published by MURAL (mural.co), re-reading each one every six hours. Below is what each document covers, in plain English.
California Privacy
California Privacy Notice — User-Focused Overview
Scope and status: This notice applies only to California residents and is marked outdated, with a last-updated date of March 6, 2023. The current Privacy Statement and Terms may contain additional or different terms.
1. Data Collection and Use
The notice identifies these categories of personal information:
- Contact information: Such as identifying or communication details.
- Billing and payment information
- Product usage information: How users interact with the service.
- Device information: Including online identifiers, device identifiers, IP addresses, and similar technical data.
- Profile information
- Company information
- Site usage information
- Campaign information
- Certification information
- Inference data: Interests and preferences derived from other information.
The stated purposes include:
- Providing and administering the services
- Account management
- Security and performance monitoring
- Analytics and product development
- Marketing, outreach, and online advertising
- Legal and regulatory compliance
Important practical point: The notice permits use of data for broad operational, analytics, product-development, marketing, and advertising purposes. It does not provide detailed retention periods in this document; it refers users to a separate “Retention of Your Information” section.
2. User Rights
California residents may request, subject to legal exceptions:
- Access: Information about personal information held about them and/or a copy
- Correction: Updating inaccurate or outdated information
- Deletion: Deletion of certain personal information
- Restriction: Limiting certain uses or disclosures
- Opt out of sale or sharing: Particularly for targeted advertising or analytics
- Limit sensitive personal information use: The notice states that sensitive information is not used or disclosed for purposes requiring this opt-out right
To exercise rights, users are directed to the Privacy Statement’s rights section. Sale/sharing requests may be made through:
- The “Your Privacy Choices” link on the relevant site
- privacy@mural.co
- A legally recognized browser signal, such as Global Privacy Control, which the company says it recognizes
The company states it does not currently respond to ordinary Do Not Track (DNT) signals. DNT is different from legally recognized opt-out preference signals.
3. Third-Party Sharing
Personal information may be disclosed to:
- Other users and customers
- Integrations
- Service providers
- Affiliates
- Joint marketing partners
- Online advertising and analytics providers
- Entities involved in legal matters or business transactions
- Parties receiving information with user consent
The listed subprocessors include providers such as Adobe, AWS, Chorus, Databricks, CoreSignal, Fivetran, Mailchimp/Mandrill, Microsoft Azure, MongoDB, Salesforce, Segment, Amplitude, and New Relic, generally located in the United States.
The notice says the company does not disclose personal information to third parties for their own direct marketing under California’s “Shine the Light” law.
4. Sale, Sharing, and AI/ML Training
The company states that it may “sell” or “share” certain categories—particularly:
- Contact information
- Device information
- Company information
- Site usage information
- Campaign information
- Inference data
These disclosures are primarily to online advertising and analytics providers and may involve cookies, pixels, IP addresses, device identifiers, and usage information.
AI/ML training: This notice does not state whether user data is used to train artificial-intelligence or machine-learning models. It also does not expressly prohibit such use. Users should review the current Privacy Statement, service terms, and any AI-specific terms or data-processing agreement.
5. Key User Obligations and Restrictions
This document contains no meaningful user conduct rules, licensing terms, or account obligations. Those are likely located in separate Terms of Service.
Users should nevertheless understand that:
- Opt-outs may need to be made separately for cookies/pixels and other disclosures.
- Opting out may not stop all operational, security, legal, or service-related processing.
- Deletion and access rights are subject to statutory exceptions.
- The notice is outdated, so its descriptions may not reflect current practices.
6. Liability and Disputes
This privacy notice does not address:
- Liability limits
- Warranties or disclaimers
- Indemnification
- Arbitration
- Class-action waivers
- Governing law
- Dispute procedures
- Remedies for privacy violations
Those provisions must be reviewed in the applicable Terms of Service and any contract with the company.
7. Changes
This excerpt does not explain how policy changes are communicated. It only identifies a last-updated date and links users to a newer version. Users should check the current Privacy Statement and any account or email notices for the company’s change-notification procedure.
Main risk: Because this is an outdated, abbreviated California notice, it should not be treated as a complete statement of current data practices or contractual rights.
Terms of Service
Mural Services Agreement: Key User Implications
> Document-status warning: The text says it is an outdated January 29, 2026 version, while also stating an effective date of July 1, 2026. Users should verify the current agreement and Data Processing Addendum (DPA) at Mural’s terms page before relying on this version.
1. Data Collection & Usage
What data is involved
The agreement covers:
- Customer Content: Files, documents, objects, information, and materials created, uploaded, or stored in Mural.
- Personal Data: Defined primarily in the separate DPA, which is incorporated into the agreement. The text does not provide a complete list of personal data collected.
- Account and usage information: Mural may process information about how customers and users use the Services.
- Integration data: If users activate an integration, Mural and the integration provider may access relevant Content, usage data, and other information needed for interoperability.
- Feedback and research data: Feedback may be used by Mural without compensation. Voluntary product research may involve participation in testing, focus groups, workshops, or beta programs.
How Mural may use it
Mural receives a broad but purpose-limited license to host, use, transmit, display, perform, copy, distribute, and modify Customer Content to provide the Services. This license ends when the Content is no longer stored or the agreement terminates.
Mural may also process Personal Data and usage information to:
- Operate, support, secure, analyze, and improve the Services
- Develop new features and related products or services
- Meet technical requirements, such as adapting Content for devices
Users should not place highly sensitive information in Mural. The agreement specifically prohibits storing or processing GDPR Article 9 special-category data, Social Security numbers, tax IDs, driver’s-license numbers, and similar government identifiers. Mural also states that the Services are not HIPAA- or FERPA-compliant.
2. User Rights
- Ownership: Customers retain ownership of their Content; Mural does not acquire ownership merely because Content is uploaded.
- Limited control: Mural may use Content under the service-provision license described above.
- Confidentiality: Customer Content is treated as Customer Confidential Information, subject to exceptions and authorized sharing.
- Access after termination: Access ends immediately when the subscription ends. Mural may delete Content under its standard retention policies and has no continuing obligation to provide access. Users should export important Content before cancellation.
- Privacy rights: Specific rights—such as access, deletion, correction, portability, or objection—are not stated in this agreement and must be reviewed in the DPA and applicable privacy policy.
3. Third-Party Sharing
Mural may sublicense or disclose Content to contracted third parties only as needed to provide the Services. Listed subprocessors include AWS, Microsoft Azure, MongoDB, Salesforce, Twilio/Segment, Amplitude, New Relic, Databricks, Mailchimp/Mandrill, Fivetran, Adobe, Chorus, and Coresignal.
Users can activate integrations, but doing so may send Content and usage information to the integration provider. Mural disclaims responsibility for third-party security breaches, availability, compatibility, or practices. Review each integration’s privacy terms before enabling it.
4. AI/ML Training
The agreement does not expressly state that Customer Content is used to train general-purpose AI models. However, Mural may process Personal Data and usage information to analyze, improve, and develop Services and related products. The wording is broad enough that users should seek clarification—particularly regarding whether Content, prompts, outputs, or usage data are used for machine-learning development, and whether enterprise customers can opt out.
5. Key Obligations and Restrictions
Customers are responsible for:
- All Content and account activity, including unauthorized activity
- Authorized Users’ conduct and login confidentiality
- Their own hardware, networks, and security
- Compliance with applicable laws and export controls
Users may not reverse engineer, copy, modify, commercially exploit, disrupt, bypass security, or use Mural to build a competing service. Fees are generally non-refundable; subscriptions automatically renew unless canceled. Downgrades generally take effect at renewal without a refund or credit.
6. Liability & Disputes
- California law governs.
- Exclusive venue is state or federal court in San Jose/Northern District of California.
- Consequential, punitive, special, and similar damages are excluded.
- Most liability is capped at fees paid in the preceding 12 months.
- The cap does not apply to specified areas, including confidentiality breaches, indemnification, certain use restrictions, and unpaid fees.
- Services are provided largely “as is” and “as available,” with limited warranty remedies.
- Each party has specified indemnity obligations for certain third-party claims.
7. Changes and Notification
Mural may modify the agreement, Plans, and fees. Material changes become effective when published or on a date stated in a notice. Continued use of the Services constitutes acceptance. The agreement does not guarantee individualized notice for every change, so users should monitor Mural’s terms and renewal communications.
Change history
2026-09-06 · California Privacy
Summary
Scope of the Diff
- The diff states that approximately 803 words were added.
- However, the actual added language is not included in the material provided.
- Because there are no specific clauses to review, the legal effect of the changes cannot be reliably determined.
AI Training and Customer Data
- No information is provided showing whether customer data may be:
- Used to train, fine-tune, or improve artificial intelligence or machine-learning models;
- Combined with other customers’ data for model development;
- Anonymized, de-identified, or retained for training purposes;
- Shared with third-party AI providers;
- Used to generate or evaluate prompts, outputs, embeddings, or other model-related materials; or
- Excluded from training by default or only excluded if the customer opts out.
- Accordingly, no conclusion can be reached about whether the changes expand or restrict the provider’s rights to use customer data for AI training.
Other Potentially Important Issues
The missing language may affect, among other things:
- Data ownership and license rights: whether the provider receives broader rights to copy, modify, analyze, or create derivative works from customer data.
- Confidentiality: whether customer information may be used for product improvement or disclosed to vendors.
- Retention and deletion: whether data is retained after termination or deletion requests.
- Security and privacy: whether new processing activities create additional compliance or breach risks.
- Third-party processing: whether data may be sent to cloud, analytics, or AI subcontractors.
- Liability and indemnity: whether the customer assumes responsibility for data used in model development or AI outputs.
- Opt-out rights: whether customers can prohibit training use, and whether an opt-out applies prospectively or retroactively.
Required for a Complete Review
Please provide the actual 803 words added to the agreement, including any surrounding unchanged language. The specific wording is necessary to identify new rights, restrictions, obligations, and risks—particularly those concerning the use of customer data to train or improve AI models.
2026-09-04 · California Privacy
Executive Summary
The update mainly revises the California privacy disclosures, expands the listed subprocessors, and adds a detailed personal-information disclosure table. The diff does not expressly state that customer data will be used to train AI models, nor does it add an explicit AI-training permission or prohibition. However, several broadened purposes and third-party categories could potentially encompass machine-learning or AI-related analytics unless limited elsewhere in the agreement.
Important Changes and Risks
1. Expanded subprocessors and data recipients
The subprocessor list now identifies or clarifies providers including:
- Adobe Marketing Automation
- Amazon Web Services
- Chorus
- Databricks
- Deeptrace/Coresignal, described as a web-data API provider used exclusively for Profile Cards in the Stakeholder Mapping feature
- Fivetran
- Mandrill/Mailchimp
- Microsoft Azure
- MongoDB
- Salesforce
- Segment
- Amplitude
- New Relic
Risk: Customer data may be processed by a broader ecosystem of cloud, analytics, marketing, support, and data-intelligence providers. The description of Coresignal is narrower, but the other provider descriptions generally do not specify data minimization, retention, model-training restrictions, or whether data is used only at the customer’s direction.
2. AI-model training and product development
No language in the diff expressly authorizes use of customer data to:
- Train foundation, generative, or other AI models;
- Improve third-party AI services;
- Create or commercialize models or derived datasets; or
- Permit providers to retain customer data for model training.
Nevertheless, the new disclosure table repeatedly lists “Analytics & Product Development” as a purpose of use. It also lists service providers and online advertising/analytics providers as recipients for numerous data categories, including contact, device, company, site-usage, campaign, and inference data.
Risk: “Product development” and analytics language is broad enough that, depending on the operative customer agreement and privacy statement, it could be argued to cover machine-learning development or AI feature improvement. The disclosure does not clarify whether customer-content data, prompts, workspace information, or derived data are excluded from training. Customers seeking a no-training commitment should obtain an express contractual restriction.
3. Broader disclosure and “sale/share” classifications
The new table states that online advertising and/or analytics providers may receive or receive “sold/shared” categories including:
- Contact information
- Device information
- Company information
- Site-usage information
- Campaign information
- Inference data
Billing, product-usage, profile, certification, and certain other information are stated not to be sold or shared.
Risk: “Inference data” is expressly identified and may be disclosed to advertising or analytics providers. This could include profiles or predictions about users and may create profiling, confidentiality, and regulatory concerns.
4. California privacy-rights revisions
The update:
- Recognizes legally required browser-based preference signals, such as Global Privacy Control;
- States that sensitive personal information is not used or disclosed except for purposes for which opt-out is unavailable;
- Adds access, correction, deletion, restriction, and related rights;
- Clarifies that ordinary Do Not Track signals are not recognized;
- Adds a Shine the Light disclosure; and
- Adds a detailed category/purpose/recipient table.
These revisions generally improve statutory disclosure detail but also document broader categories of processing and recipient access.
Recommended Follow-Up
Confirm in the governing agreement whether customer data, prompts, outputs, telemetry, and derived data may be used for AI training or product improvement. If not intended, require explicit language prohibiting training, retention for training, and disclosure to providers for those purposes.
2026-09-03 · California Privacy
Summary of Important Changes
1. Subprocessor list expanded and reformatted
The subprocessor notice has been substantially updated and appears to add or clarify the following providers and functions:
- Deeptrace dba Coresignal — web-data API provider, stated to be used exclusively for Profile Cards in the Stakeholder Mapping feature.
- Salesforce Cloud — customer support services.
- Amplitude — cloud-based product analytics.
- New Relic — cloud-based product analytics.
- Existing providers and functions—including Adobe, Amazon Web Services, Chorus, Databricks, Fivetran, Mailchimp/Mandrill, Microsoft Azure, MongoDB, Segment, and others—are presented in a consolidated list.
Risk implications
- The list indicates broader use of analytics, data-centralization, customer-support, and enrichment providers. These providers may process customer, user, usage, profile, or other personal information.
- Coresignal’s use for Profile Cards suggests that information from an external web-data source may be combined with information relating to users or stakeholders. The notice does not explain the source, accuracy, retention, or correction process for that data.
- The excerpt does not show updated contractual safeguards, retention limits, security terms, or restrictions on provider use. Those terms should be reviewed separately in the data-processing agreement and each provider’s role should be confirmed.
2. No express AI-training authorization identified
The diff does not add language expressly stating that customer data, Customer Content, personal information, prompts, outputs, or usage data may be used to train, fine-tune, evaluate, or improve AI models.
However, the revised California privacy disclosure lists “Analytics & Product Development” as a purpose of use for numerous categories, including:
- Contact information
- Product and site usage information
- Profile and company information
- Campaign and certification information
- Inference data
This is not the same as an express AI-training right, but the broad “product development” language could potentially encompass development or improvement of AI-enabled features unless other contract terms restrict it. The diff provides no clear prohibition or commitment that customer data will not be used for model training.
Recommended clarification: obtain an explicit written statement addressing whether customer data is used for AI training, whether it is used by subprocessors, whether data is de-identified, and whether customers can opt out.
3. California privacy disclosures expanded
The notice now includes a detailed category-by-category table identifying:
- Purposes of use
- Categories of recipients
- Categories of information allegedly “sold” or “shared” for advertising or analytics
It identifies online advertising or analytics providers as recipients for several categories, including contact, device, company, site-usage, campaign, and inference data. Billing, product-usage, profile, and certification information are stated not to be “sold” or “shared.”
Risk implications
- “Sharing” with advertising or analytics providers may create broader tracking and profiling exposure.
- The notice now states that sensitive personal information is not used or disclosed except for permitted business purposes.
- Opt-out instructions were revised to direct users to the “Your Privacy Choices” link or email privacy@mural.co, rather than relying primarily on browser-based preference signals. This may affect how California opt-out requests are submitted and honored.
2026-09-03 · California Privacy
Executive Summary
The diff appears to update the privacy-policy webpage, correct formatting, expand California privacy disclosures, and clarify one subprocessor’s function. No express change was identified concerning use of customer data to train AI models. The diff does not add or remove language authorizing AI training, model improvement, machine learning, or use of customer content for generalized model development.
Important Changes
1. Subprocessor description clarified
- The subprocessor list is reformatted and made more readable.
- Deeptrace dba Coresignal is now described as a “public web data API provider used exclusively for Profile Cards in the Stakeholder Mapping feature.”
- This narrows or clarifies the stated purpose of that provider, but confirms that data may be processed through a third-party web-data service for the Profile Cards feature.
- The list identifies numerous U.S.-based providers, including Adobe, Amazon Web Services, Chorus, Databricks, Fivetran, Mailchimp/Mandrill, Microsoft Azure, MongoDB, Salesforce, Segment, Amplitude, and New Relic.
Risk: The subprocessor disclosure is not, by itself, a contractual limitation on all data use. Customers should confirm that the underlying data-processing terms restrict providers to necessary service functions and address retention, security, confidentiality, and onward transfers.
2. California privacy-rights language expanded and reorganized
The CCPA section now:
- States that legally recognized browser-based preference signals, such as Global Privacy Control, will be recognized as required by applicable law.
- Adds information about financial incentives, although it says such information will be provided if incentives are offered.
- Adds the right to limit the use or disclosure of sensitive personal information where applicable.
- States that sensitive personal information is not used or disclosed except for business purposes for which the CCPA does not provide an opt-out right.
- Lists additional rights, including access, correction, deletion, and restriction of processing or disclosure.
- Cross-references the Privacy Statement’s sections on rights and retention.
Risk: These statements may create operational compliance obligations, particularly around honoring browser signals and responding to access, deletion, correction, and restriction requests.
3. Do Not Track disclosure added
The policy now distinguishes ordinary Do Not Track (DNT) signals from legally required browser-based preference signals. It states that the company does not currently recognize or respond to browser-initiated DNT signals, while separately recognizing legally required preference signals.
4. Shine the Light disclosure added or expanded
The policy explains California’s Shine the Light rights and states that the company does not disclose personal information to third parties for their own direct-marketing purposes.
5. Data-category table added
The revised disclosure identifies categories such as contact, billing, usage, device, profile, company, campaign, certification, and inference data, together with purposes and recipient categories. Certain categories—especially contact, device, company, site-usage, campaign, and inference data—may be “sold” or “shared” with online advertising or analytics providers under CCPA terminology.
AI-Training Conclusion
The diff contains no clear authorization or prohibition regarding training AI models using customer data. The references to “Analytics & Product Development” are broad but do not expressly state that customer content is used for AI training. This issue remains ambiguous and should be addressed expressly in the governing agreement or privacy/data-processing terms.
2026-09-02 · California Privacy
Summary of Important Changes
1. Subprocessor and Data-Location Updates
- The subprocessor list has been reformatted and expanded with additional descriptions.
- Deeptrace dba Coresignal is now described as a U.S.-based web-data API provider used exclusively for Profile Cards in the Stakeholder Mapping feature.
- Amplitude is now identified as a cloud-based product analytics service.
- Salesforce is identified as a cloud-based customer-support provider.
- The updated list continues to identify providers including Adobe, Amazon Web Services, Chorus, Databricks, Fivetran, Mailchimp/Mandrill, Microsoft Azure, MongoDB, New Relic, Segment, and others.
- The notice states that the prior document is outdated and directs users to the latest version. This may create uncertainty about which subprocessors and processing terms applied during a particular period.
Risk: Customers should verify whether their contractual data-processing agreement requires advance notice, objection rights, or approval for newly added subprocessors. The list primarily identifies U.S. processing locations, which may raise cross-border transfer and regulatory compliance issues for customers subject to GDPR or similar laws.
2. AI-Model Training
- The diff does not expressly add or remove any provision authorizing use of customer data to train, fine-tune, or improve AI models.
- No language specifically states that customer content, inputs, outputs, or personal information will—or will not—be used for AI training.
- However, the revised CCPA disclosures broadly identify “Analytics & Product Development” as a purpose of use for nearly every category of personal information. Depending on the governing agreement and the meaning assigned to that phrase, it could potentially support activities such as service improvement, analytics, or development of automated systems.
- The disclosure does not clarify whether such information is de-identified, aggregated, retained, or shared with AI vendors for model training.
Risk: The absence of an express AI-training restriction leaves ambiguity. Customers requiring “no training on customer data” protections should seek a separate contractual commitment covering customer content, personal information, prompts, outputs, derived data, retention, and use by subprocessors.
3. California Privacy Disclosures and Opt-Out Process
- The CCPA section has been substantially rewritten.
- The prior reference to opting out through a recognized browser-based preference signal is replaced with instructions to use the “Your Privacy Choices” link or email privacy@mural.co.
- The revised language expressly recognizes browser-based opt-out signals, including Global Privacy Control, but frames their operation as applying in accordance with applicable law.
- The company now states that it does not use or disclose sensitive personal information except for business purposes for which opt-out is unavailable under applicable law.
- A detailed table has been added listing categories of personal information, purposes of use, recipients, and categories of information “sold” or “shared” for advertising or analytics.
Risk: The expanded disclosures identify online advertising and analytics providers as recipients of several categories of information, including contact, device, company, site-usage, campaign, and inference data. Customers should assess whether these disclosures affect their own obligations when submitting employee, customer, or other personal data.
2026-08-19 · California Privacy
Summary of Important Changes
1. AI Training and Model Development
- No express change authorizes use of customer data to train AI models. The diff does not add language specifically permitting training, fine-tuning, evaluation, or improvement of artificial intelligence or machine-learning models using customer content or customer data.
- However, the updated privacy disclosures continue to identify “Analytics & Product Development” as a purpose of processing for multiple data categories, including contact, usage, device, profile, company, campaign, certification, and inference data.
- The disclosure also identifies Databricks as a data-intelligence platform and adds or clarifies several analytics and product-analytics providers, including Amplitude and New Relic. These provisions could support broad internal analytics or product-improvement activities, but they should not be read as a clear contractual restriction or permission regarding AI training.
- Risk: If the underlying agreement or privacy statement elsewhere contains AI-training terms, this diff does not narrow them. Conversely, if the customer expects a “no training” commitment, the updated broad product-development language may be insufficiently protective because it does not expressly exclude model training or require deletion of training data.
2. Subprocessors and Data Sharing
- The subprocessor listing has been reorganized and expanded/clarified. It identifies providers and functions including Adobe, Amazon Web Services, Chorus, Databricks, Fivetran, Mailchimp/Mandrill, Microsoft Azure, MongoDB, Salesforce, Segment, Amplitude, and New Relic.
- Deeptrace d/b/a Coresignal is described as a public web-data API provider used exclusively for Profile Cards in the Stakeholder Mapping feature.
- Risk: Customers receive greater visibility into downstream vendors, but the listing confirms broader reliance on analytics, cloud, customer-support, and data-centralization providers. The diff does not show new contractual limits on those providers’ independent use, retention, or AI-related processing.
3. California Privacy Rights
- The opt-out process is updated to recognize legally recognized browser-based preference signals, such as Global Privacy Control, in accordance with applicable law.
- The prior email-based opt-out language is removed or replaced with broader statutory descriptions.
- The notice now states that the company does not use or disclose sensitive personal information except for business purposes for which the CCPA does not provide an opt-out.
- California rights are expanded or restated to include access, correction, deletion, and restriction requests, with cross-references to the main Privacy Statement.
4. Do Not Track and Advertising Disclosures
- The company expressly states that it does not currently recognize or respond to browser-initiated Do Not Track signals, while distinguishing DNT from legally required preference signals.
- New disclosures state that certain categories—including contact, device, company, site-usage, campaign, and inference data—may be “sold” or “shared” with online advertising or analytics providers for advertising and analytics purposes.
- The notice states that billing, payment, product-usage, profile, certification, and certain other data categories are not sold or shared for those purposes.
Overall Risk Assessment
The most significant practical change is increased specificity about analytics, advertising, inference data, and subprocessors. No direct AI-training authorization appears in the diff, but the broad analytics and product-development purposes leave potential ambiguity that should be addressed expressly if customer data must not be used for AI-model development.
2026-07-01 · Terms of Service
The publisher records this document as revised on this date (“Effective date: July 1, 2026”).
Between 2025-09-15 and 2025-10-30 · Terms of Service
2023-03-06 · California Privacy
The publisher records this document as revised on this date (“Last updated: Mar 6, 2023”).