Monitored company
SendGrid
clause.watch tracks 2 legal documents published by SendGrid, re-reading each one every six hours. Below is what each document covers, in plain English.
Privacy Policy
Twilio Privacy Notice: User-Focused Overview
*Last updated: April 9, 2026.* This summary is informational and does not replace the full Privacy Notice or Twilio’s contractual terms.
1. Data Collection and Use
Twilio acts either as:
- Data controller: Twilio decides why and how data is used—for accounts, websites, services, marketing, security, and business operations. This Notice primarily applies here.
- Data processor: Twilio processes data on behalf of a customer, such as communications sent through Twilio. In that situation, users generally must direct privacy requests to the relevant Twilio customer.
Types of data collected
Depending on the service and relationship, Twilio may collect:
- Identity and contact information: Name, email, phone number, company, job title, address, social-media URLs.
- Account and payment data: Login details, account IDs, API tokens, purchase history, billing details, and payment information.
- Verification data: Government IDs, proof of identity, subscriber records, physical service address, and information required for telecommunications services.
- Customer content: Email and text content, media, call recordings, transcripts, communication logs, and other uploaded data.
- Usage and technical data: Sender and recipient information, timestamps, routing details, delivery/open/click status, IP address, device identifiers, browser and operating-system information, and general city/town location.
- Third-party data: Information from carriers, partners, data-enrichment providers, connected services such as Google or Meta, and solution providers.
- Tracking data: Cookies, pixels, web beacons, browsing activity, and interactions with Twilio websites and platforms.
Twilio uses this information for account administration, billing, service delivery, routing, support, security, fraud prevention, legal compliance, product development, analytics, personalization, marketing, and targeted advertising. Twilio states it does not collect precise geolocation.
2. User Rights
Subject to applicable law and exceptions, users may have rights to:
- Know what data is collected, its sources, purposes, and recipients;
- Access or obtain a copy of data;
- Correct inaccurate information;
- Delete data;
- Receive portable, machine-readable data;
- Object to or restrict processing, including profiling;
- Withdraw consent;
- Opt out of certain third-party disclosures, materially different uses, marketing, cookies, and targeted advertising;
- Request human review of certain automated decisions.
Requests can generally be made through the Twilio console or Customer Support, with requests sent to privacy@twilio.com. Twilio may require identity verification. Deletion or account closure may be permanent and can cause loss of service or data. If Twilio is acting as a processor, it will generally refer the request to its customer.
3. Third-Party Sharing
Twilio says it does not sell personal data and will not share mobile information with third parties for marketing or promotional purposes. However, it may disclose data to:
- Carriers, telecommunications operators, and messaging providers to route communications;
- Independent providers such as WhatsApp, which may act as their own controllers;
- Vendors processing data for Twilio;
- Marketplace partners and integrations, including selected add-ons;
- Twilio affiliates worldwide;
- Law enforcement, regulators, courts, emergency services, or litigants;
- Buyers or advisers involved in mergers, sales, or reorganizations.
Data may be transferred internationally, primarily to the United States, using frameworks such as the Data Privacy Framework, Binding Corporate Rules, and Standard Contractual Clauses.
4. AI/ML Training
Yes. The Notice expressly allows AI/ML training for:
- Detecting fraud, abuse, bots, account takeovers, and security vulnerabilities;
- Improving network reliability using performance metrics;
- Service improvement and research.
The listed data may include customer content, communications metadata, support interactions, and telecommunications data. The Notice does not clearly promise that all content is de-identified before AI/ML training. This is a significant risk for sensitive communications.
Twilio also uses AI to transcribe and analyze calls through Conversational Intelligence, including personal data in voice calls.
5. Key User Obligations and Restrictions
Users should:
- Provide accurate account, identity, and subscriber information;
- Protect passwords, API tokens, and account access;
- Ensure they have permission and lawful grounds to upload or transmit communications and personal data;
- Follow applicable telecommunications, privacy, and anti-fraud laws;
- Avoid using services for abusive, fraudulent, unlawful, or unauthorized activity;
- Avoid using services in violation of age restrictions. Services are not intended for children under 13 in the U.S./UK or under 16 in the EEA.
Twilio may automatically approve, suspend, or restrict accounts suspected of fraud or abuse.
6. Liability and Disputes
This Notice does not itself provide a broad warranty or general limitation of liability; those terms may appear in the Terms of Service or applicable customer agreement. Twilio states it remains liable under the Data Privacy Framework for violations by third-party processors acting on its behalf, unless it proves it was not responsible.
Complaints should first be sent to Twilio. Unresolved matters may proceed to JAMS under the DPF, possible binding arbitration in limited circumstances, a data-protection authority, or court proceedings. European, UK, Brazilian, and other users may have additional local remedies.
7. Changes
The current version is posted at twilio.com/legal/privacy, with the “Last Updated” date. For significant changes affecting user rights, Twilio says it will provide advance notice through the console or email and obtain consent where legally required.
Terms
Twilio Terms of Service: Key User Implications
> Scope: These are primarily business/customer terms for using Twilio services. Important privacy details are incorporated by reference through the Twilio Data Protection Addendum (DPA), Privacy Notice, Acceptable Use Policy, Security Overview, SLAs, and potentially separate AI/ML Terms. Those documents should be reviewed alongside these Terms.
1. Data Collection & Usage
Data covered
“Customer Data” includes data:
- You or your end users provide to Twilio when using the services; and
- Generated for your use through the services.
The Terms do not provide a detailed list of personal data categories. Depending on the services, this may include communications content, phone numbers, account information, identifiers, authentication data, usage data, and other information transmitted through your applications.
How Twilio may use it
You retain ownership of Customer Data, but grant Twilio and its affiliates permission to process it as necessary to:
- Provide and support the services;
- Maintain security and prevent malicious code;
- Comply with legal, regulatory, law-enforcement, and telecommunications-provider requirements; and
- Perform other processing allowed by the DPA.
Twilio owns “Twilio Data,” including data derived from service use that does not identify you or a person, and Customer Data that Twilio anonymizes, de-identifies, or aggregates so it can no longer identify individuals.
Risk: The Terms do not state how long data is retained, provide detailed deletion procedures, or explain all permitted secondary uses. Those issues are primarily left to the DPA and Privacy Notice.
2. User Rights
These Terms themselves provide no comprehensive individual privacy-rights procedure. Rights relating to access, correction, deletion, restriction, portability, objection, or withdrawal of consent must be determined from the applicable DPA and Privacy Notice, including the role of the customer as controller/business and Twilio as processor/service provider.
You are responsible for:
- Providing legally required notices to end users;
- Obtaining all required consents and permissions; and
- Ensuring the data supplied to Twilio may lawfully be processed.
Practical implication: If you operate an application using Twilio, you generally must handle end-user privacy requests and configure Twilio appropriately to support them.
3. Third-Party Sharing
Twilio may disclose or provide access to Customer Data to:
- Its affiliates;
- Employees, contractors, professional advisers, and subcontractors with a need to know;
- Service providers/sub-processors identified under the DPA;
- Regulators, law enforcement, telecommunications providers, or courts when legally required; and
- Third-party services selected or connected by you.
Recipients must be subject to confidentiality or data-processing obligations, but Third-Party Services are governed by separate agreements and may create additional risks.
Twilio may also use your company name, logo, and a description of your use case in marketing materials, subject to trademark guidelines you provide. Government customers receive a special prior-consent protection.
4. AI/ML Training
These Terms do not expressly say that Customer Data is or is not used to train AI or machine-learning models.
They do give Twilio ownership of anonymized, de-identified, and aggregated data. That could potentially include use for analytics or product improvement, but the Terms do not specifically authorize or prohibit AI training using identifiable Customer Data.
Twilio has separate AI/ML Terms, which are incorporated only if applicable. Review those terms and the DPA before submitting sensitive data or using AI-enabled features. Do not assume that confidentiality language alone prevents model training.
5. Key Obligations and Restrictions
You are responsible for:
- All activity under your account and by your end users;
- Compliance with the Terms, Acceptable Use Policy, documentation, and applicable law;
- Preventing unauthorized access and promptly reporting it;
- Obtaining required consents;
- Lawful messaging, traffic, and communications practices;
- Taxes, carrier surcharges, and fines caused by your use; and
- Payment of generally non-refundable fees.
You may not resell, lease, transfer, or offer Twilio services standalone, except as integrated into your own products. Twilio may suspend services for policy violations, fraudulent traffic, security threats, legal restrictions, inaccurate account information, or nonpayment.
6. Liability and Disputes
Services are generally provided “as is.” Twilio disclaims implied warranties and liability for interception or loss of data while traveling over the internet or carrier networks. Beta, customer, and third-party services receive especially limited protection.
Neither party is liable for indirect or consequential damages, including lost profits, revenue, goodwill, business interruption, or lost data. Ordinary direct liability is capped at fees paid or payable for the affected services during the preceding 12 months.
The cap does not apply to customer responsibilities, payment obligations, or indemnification obligations—potentially creating substantial uncapped exposure for the customer.
Disputes generally require senior-level negotiation, followed by binding JAMS arbitration in San Francisco, London, or Singapore depending on location. Intellectual-property disputes are handled in specified courts. Governing law and venue vary by country.
7. Changes
Twilio will generally give at least 30 days’ written notice of material changes, by email or through the account portal. Exceptions apply where changes result from laws, regulations, or telecommunications-provider requirements.
The updated Terms are posted online, and continued use after the effective date constitutes acceptance. If you disagree, your remedy is to stop using the services. Service changes that are not backward-compatible may receive approximately 60 days’ notice, subject to security, legal, and carrier exceptions.
Change history
2026-09-04 · Privacy Policy
2026-09-03 · Privacy Policy
2026-09-02 · Privacy Policy
2026-09-02 · Privacy Policy
2026-09-01 · Privacy Policy
2026-08-31 · Privacy Policy
2026-08-30 · Privacy Policy
2026-08-29 · Privacy Policy
2026-08-28 · Privacy Policy
2026-08-28 · Privacy Policy
2026-08-25 · Privacy Policy
2026-08-25 · Privacy Policy
2026-08-24 · Privacy Policy
2026-08-23 · Privacy Policy
2026-08-22 · Privacy Policy
2026-08-21 · Privacy Policy
2026-08-21 · Privacy Policy
2026-08-19 · Privacy Policy
2026-08-19 · Privacy Policy
2026-08-18 · Privacy Policy
Summary of Changes
What Changed
- Approximately 299 words were removed from the document.
- No replacement language or added language was provided.
- Because the deleted text is not included, the specific legal and commercial effects cannot be determined.
AI Training and Customer Data
- The available diff does not show whether any provisions concerning AI training, machine learning, model improvement, or use of customer data were removed.
- It is therefore impossible to determine whether the revision:
- Permits or restricts using customer data to train AI models;
- Changes whether customer content, prompts, outputs, metadata, or usage data may be used for training;
- Removes consent, opt-out, or confidentiality protections;
- Changes ownership or licensing rights in customer data or AI-generated outputs; or
- Affects data-retention, anonymization, security, or deletion obligations.
Potential Risks
The removal of contract language can create risk if it eliminated protections or limitations, including:
- A prohibition or restriction on using customer data for AI training;
- A requirement to obtain the customer’s consent before such use;
- An opt-out mechanism;
- Confidentiality, privacy, or data-processing obligations;
- Restrictions on sharing data with affiliates or third-party AI providers;
- Limits on retaining or reusing customer content; or
- Indemnities, warranties, or liability provisions related to AI use.
However, these are only potential issues. The direction and significance of the change cannot be reliably assessed without the actual deleted text and the surrounding provisions.
Information Needed
To complete the analysis, provide either:
1. The full original and revised clauses; or
2. The approximately 299 words that were deleted, preferably with the surrounding section headings and numbering.
The deletion-only notation does not identify what obligations, permissions, or protections were removed.
2026-04-09 · Privacy Policy
The publisher records this document as revised on this date (“Last Updated: April 09, 2026”).
Between 2025-01-31 and 2025-09-23 · Terms
Summary of Important Changes
1. No Express Change to AI-Model Training
- The diff does not expressly add or remove language allowing Twilio to use Customer Data to train, fine-tune, evaluate, or improve AI models.
- It also does not appear to change any explicit “Customer Data,” “Usage Data,” or AI-training provision.
- However, the revised ownership language continues to state that Twilio owns “any data that is derived or generated” from its services. The scope of this wording is not clear from the excerpt and could potentially include aggregated, inferred, or machine-generated data derived from customer activity.
- Customers should review the full confidentiality, privacy, Data Protection Addendum, and any AI-specific terms to determine whether derived data, prompts, outputs, or service telemetry may be used for model development.
2. Published Documentation Becomes More Important
The changes expressly incorporate Twilio’s published documentation on its website into:
- Service performance obligations;
- Twilio’s ownership and confidentiality provisions; and
- The agreement’s order-of-precedence clause.
Risk
Twilio may be able to update online documentation without a formal amendment to the agreement, depending on the contract’s change-control language. Documentation could contain operational, data-use, security, or AI-related terms that become contractually relevant. Customers should monitor applicable documentation and preserve copies of the versions in effect at contracting and renewal.
3. New Tax-Exemption Responsibilities
Customers claiming tax or communications-surcharge exemptions must:
- Notify Twilio at
taxforms@twilio.com; and - Provide current exemption information or proof.
Exemption treatment applies prospectively once Twilio receives a valid certificate. Customers may bear additional charges for outdated, incomplete, or late documentation.
4. Notice Procedure Changed and Is More Specific
The revised notices provision states that:
- Customer notices to Twilio must be sent to
legalnotices@twilio.com; and - Twilio notices will be sent by email to the relevant contact(s) designated in the customer’s account.
Risk
Customers should ensure account contacts are current and monitored. Failure to update those contacts could result in missed legal, billing, suspension, or termination notices.
5. Contracting Entity Changes for Brazil
The Brazilian contracting entity changes from Twilio Japan G.K. to Teravoz Telecom Telecomunicações Ltda., with a São Paulo, Brazil address.
Potential Effect
This may change the applicable contracting party, invoicing and tax treatment, regulatory responsibilities, dispute forum, and potentially the governing-law provisions in the country table. Brazilian customers should confirm which entity contracts with them and whether existing orders or data-processing arrangements need updating.
6. Minor Clarifications
- Services are expressly tied to published documentation and service-level agreements.
- The website URL formatting was corrected.
- Navigation and disclosure text was reorganized, including government-request and civil-request resources.
Overall: The most significant practical risks concern incorporation of online documentation, ownership of derived/generated data, notice delivery, and the Brazilian entity change. The excerpt contains no clear new permission to train AI models, but the broader incorporated documents should be checked for such terms.
Between 2024-03-08 and 2024-06-07 · Privacy Policy
Summary of Important Changes
AI Model Training and Data Use
- No express new authorization to train AI models is visible in this diff. The changes do not add language stating that customer data, content, recordings, transcripts, prompts, outputs, or usage data may be used to train, fine-tune, evaluate, or improve artificial-intelligence or machine-learning models.
- The Privacy Notice continues to describe processing purposes broadly, including “research and development.” That wording may be broad enough to cover some product-improvement activities, but the diff does not clarify whether it includes AI training or whether customer data is excluded, de-identified, aggregated, or subject to an opt-out.
- The diff references data processed through the Conversational Intelligence Service, but does not clearly state whether such data is used for model training. Customers using that service should verify the underlying service terms, DPA, product documentation, and any AI-specific controls.
- Risk: The absence of explicit AI-training language creates uncertainty rather than clearly reducing risk. Customers should obtain written confirmation about whether their data is used for AI development and whether contractual restrictions or opt-outs apply.
Privacy Notice and Customer-Data Responsibilities
- The revised notice expressly states that, for complaints concerning a company using Twilio’s services, Twilio acts as a data processor and cannot resolve complaints about the customer’s data practices.
- Individuals are directed to contact the relevant Twilio customer—for example, the brand sending communications—rather than Twilio. This reinforces the customer’s responsibility for notices, lawful bases, rights handling, and marketing compliance.
- Twilio states that it is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission, adding regulatory-context language.
Complaints and Dispute Resolution
- The process is made more structured:
- Customers must generally submit complaints to Twilio first.
- Twilio will acknowledge complaints within 30 days and provide a substantive response without undue delay.
- Unresolved UK complaints may be escalated to the ICO.
- DPF-related complaints may be referred to JAMS, with possible binding arbitration under the DPF framework.
- These provisions may create additional procedural steps before escalation, although they preserve regulatory and court remedies where applicable.
Changes to the Privacy Notice
- Twilio may update the notice for legal, technical, or business reasons and will post the latest version online.
- For significant changes affecting rights, Twilio will provide advance notice through the console or email and obtain consent where legally required.
- Risk: This does not promise consent for every material change—only where applicable law requires it—so customers should monitor notices and maintain records of the version applicable to their processing.
Between 2023-10-27 and 2024-03-07 · Terms