Monitored company
Softonic
clause.watch tracks 2 legal documents published by Softonic, re-reading each one every six hours. Below is what each document covers, in plain English.
Privacy Policy
Softonic Privacy Policy: Key Points for Users
*Policy reviewed/published: 9 June 2026. This summary is informational and not legal advice.*
1. Data Collection and Use
Softonic International, S.A., based in Barcelona, Spain, is the data controller. Its Data Protection Officer can be contacted at dpo@softonic.com.
Softonic may collect:
- Identity and contact data: name, surname, email address, and, in business contexts, company information and potentially identification numbers or passport details.
- Account and usage data: registration details, interactions with the services, download history, reviews, uploaded applications, lists, and feedback.
- Employment information: professional and academic details from job applicants, potentially obtained from LinkedIn or recruitment agencies.
- Payment information: financial or account details needed to process payments, including information obtained from banks, payment providers, or Google Payments.
- Technical, traffic, and device data: IP address, device identifiers, advertising IDs, page views, events, navigation activity, file metadata, directory structures, and compressed-package contents for Softonic Hub’s APK/XAPK scanning and installation functions.
- Cookie and advertising data: browsing activity, interests, advertising profiles, and behavioural information, depending on consent settings.
Purposes include providing and administering the services, account management, customer support, fraud prevention, security, service improvement, analytics, advertising personalisation, recruitment, legal compliance, and commercial communications. Softonic relies on contracts, legal obligations, legitimate interests, and—especially for marketing cookies, third-party advertising, and certain communications—user consent.
2. User Rights
Depending on location, users may generally:
- Access their personal data and information about its use.
- Correct inaccurate or incomplete data.
- Request deletion, subject to legal retention requirements.
- Restrict processing in certain circumstances.
- Object to legitimate-interest processing, profiling, and automated decision-making.
- Obtain data portability where processing is based on contract or consent.
- Withdraw consent at any time, including consent for cookies.
- In California, opt out of the sale or sharing of data, including cross-context behavioural advertising, and use recognised opt-out signals such as Global Privacy Control.
Requests can be made through dpo@softonic.com. Complaints may be made to the relevant regulator, including Spain’s AEPD, the UK ICO, Switzerland’s FDPIC, or California privacy authorities.
3. Third-Party Sharing
Softonic may disclose data to:
- Government authorities, courts, and law enforcement where legally required.
- Banks, payment processors, and services such as Google Payments.
- Vendors providing hosting, analytics, CRM, marketing, and other operational services.
- Programmatic advertising partners listed in the Cookie Banner.
- Lawyers, auditors, accountants, and other advisers involved in legal or business matters.
- Developers, companies, or other users when feedback is posted or displayed.
Softonic may share audience information with advertisers through hashed, isolated, aggregated, or anonymised matching environments. However, advertising and cookie partners may separately process browsing and behavioural data under their own policies.
Some recipients may be outside the European Economic Area. Softonic says it uses safeguards such as EU Standard Contractual Clauses, but exceptional legal transfer mechanisms may also apply.
Apps, developers, official app stores, linked websites, and external platforms are independent data controllers. Softonic disclaims responsibility for their privacy practices; users should review their policies before downloading or providing information.
4. AI/ML Training
The policy does not expressly state whether personal data, reviews, usage data, or other user content is used to train artificial-intelligence or machine-learning models. It describes analytics, advertising, aggregated statistics, fraud prevention, and service improvement, but does not provide a specific AI-training commitment or prohibition. Users seeking certainty should ask Softonic directly or request clarification from the DPO.
5. Key User Obligations and Restrictions
Users must:
- Provide truthful, accurate, and current information.
- Update Softonic when personal details change.
- Not impersonate others or use unauthorised celebrity, brand, or similar names.
- Obtain permission and inform third parties before submitting their personal data to Softonic.
- Ensure minors under 14 have required parental or guardian authorisation.
Mandatory form fields may be necessary to receive services. Users may bear responsibility for harm caused by inaccurate or unauthorised information.
6. Liability and Disputes
The policy contains no detailed governing-law, arbitration, or court-jurisdiction clause. It does, however, state that Softonic is not responsible for third-party privacy policies or processing, and accepts limited responsibility regarding minors’ unsupervised use. Data may be retained for legal claims, and financial records may be kept for up to six years after the relationship ends where legally permitted.
7. Policy Changes and Retention
Changes will be made conspicuous and may be communicated by email. Registered-user data is generally retained during the relationship and deleted after a valid request unless legally required. Job-application data is normally retained for one year; financial and legally relevant data may be retained longer.
Terms of use
Change history
2026-09-06 · Terms of use
2026-09-05 · Terms of use
2026-09-05 · Privacy Policy
Summary of Important Changes
1. AI model training
- No express change or new provision concerning the use of customer data to train, fine-tune, evaluate, or improve AI models is shown in this diff.
- The revised text does not grant Softonic an identifiable new right to use customer data for AI training.
- However, the policy’s general descriptions of data analysis, service improvement, cookies, analytics, and third-party disclosures remain potentially broad. If Softonic uses data from these activities for AI-related purposes, the policy may not clearly explain:
- what data is used;
- whether data is personal, pseudonymised, or anonymised;
- the purposes and legal basis for AI processing;
- whether data is shared with AI vendors;
- retention and opt-out rights; or
- whether data is transferred internationally.
- Risk: The absence of a specific AI-training disclosure could create transparency and purpose-limitation concerns if AI development is occurring outside the purposes reasonably understood by users.
2. Consent and objection rights
- Several references previously stating that processing was based on the user’s “explicit, free and unequivocal consent” have been replaced with wording stating that users who do not wish their data processed for those purposes may object by contacting Softonic.
- The revised wording then retains the statement that consent is obtained when data is collected and adds that consent may be withdrawn by contacting dpo@softonic.com.
- Risk: This creates ambiguity about whether the relevant processing is based on:
- prior opt-in consent;
- a later right to object;
- withdrawal of consent; or
- another legal basis, such as legitimate interests.
- A right to object is not always equivalent to a right to withdraw consent, particularly under the GDPR. The policy should clearly identify the legal basis and the practical effect of each request.
3. Data Protection Officer contact
- The DPO contact address dpo@softonic.com is now inserted into the policy.
- This improves accessibility and makes the contact route more explicit.
4. Legal and drafting updates
- Formatting has been standardised for GDPR, UK DPA, FADP, CCPA, and US State Privacy Laws references.
- Links and punctuation have been corrected in several places.
- The policy states that it was reviewed and published on 9 June 2026.
5. Potential drafting/implementation issue
- A large block of section titles appears appended to the end of the policy without spacing or formatting.
- Risk: This may be a publication or template error that harms readability, accessibility, and potentially the requirement to provide clear, intelligible privacy information.
2026-09-05 · Privacy Policy
Summary of Important Changes
1. No express change to AI-model training
- The diff does not expressly mention artificial intelligence, machine learning, model training, model improvement, generative AI, or the use of customer data to train AI models.
- Accordingly, there is no clearly stated new authorization—or restriction—concerning AI training in the text provided.
- If Softonic intends to use customer data for AI training, that purpose is not identified in this diff. The existing or separate policy language should be reviewed to determine whether it permits such use.
2. Consent language has been materially revised
Several provisions replace language stating that users could object to certain processing at any time by contacting Softonic with language stating:
> “Based on the explicit, free and unequivocal consent that you give us at the time of collecting your data…”
Legal significance and risks
- The revised wording appears to make prior consent at the time of collection the legal basis for the relevant processing, rather than a process based on consent that could later be refused or objected to.
- It may reduce clarity about how users can withdraw consent. Although another provision still says consent may be withdrawn at any time by contacting Softonic, the revised wording should clearly explain:
- what processing requires consent;
- how consent is obtained;
- how consent can be withdrawn; and
- the consequences of withdrawal.
- Under the GDPR, consent must be specific, informed, freely given, and as easy to withdraw as to provide. Bundled or vague consent language may create compliance risk.
- The repeated replacement appears to affect multiple processing purposes, including cookies and potentially processing connected with applications or Services. The exact scope is unclear from the diff.
3. Minor legal and drafting updates
- The title changes from “SoftonicPrivacy Policy” to “Softonic Privacy Policy.”
- References to GDPR, UK DPA, FADP, CCPA, and US State Privacy Laws are reformatted, without an apparent substantive change.
- Contact details and references to the DPO, Cookies Policy, Terms of Use, complaint authorities, and cookie-banner vendors are mainly punctuation or formatting changes.
- The policy’s stated publication/review date—9 June 2026—and the table-of-contents-style list of section headings appear to have been removed from the displayed text. Removing the review date may reduce transparency about when the policy was last updated.
Overall risk assessment
The principal substantive change is the shift toward explicit consent obtained at data collection. Softonic should ensure the consent mechanism is granular, documented, and easy to withdraw. No specific AI-training permission is added in the supplied diff.
2026-09-01 · Privacy Policy
Summary
The diff states only that approximately 96 words were added, but it does not provide the actual added language.
Key Changes
- Substantive changes: Cannot be identified without the text of the 96 added words.
- Customer data use: No determination can be made about whether the additions:
- Permit customer data to be used to train, fine-tune, or improve AI models;
- Allow use of customer prompts, inputs, outputs, or personal information for model development;
- Authorize sharing of customer data with affiliates, vendors, or third-party AI providers;
- Change data-retention, deletion, confidentiality, or de-identification obligations;
- Grant the provider ownership or broad usage rights in customer data or generated outputs.
- New legal risks: Cannot be assessed from the word-count description alone.
Information Needed
Please provide the actual 96-word addition, preferably with the surrounding contract language. The precise wording is necessary to evaluate:
1. Whether customer data may be used for AI training or other model-development purposes;
2. Whether consent is automatic, optional, or subject to an opt-out;
3. Whether data is used in identifiable, aggregated, or de-identified form;
4. Whether the provider may retain or reuse data after termination;
5. Whether the change affects confidentiality, intellectual-property ownership, security, or liability; and
6. Whether the added language conflicts with existing restrictions elsewhere in the agreement.
Conclusion: The provided diff is insufficient to identify any substantive contractual or AI-data-use changes.
2026-08-31 · Privacy Policy
Summary
Available Information
- The diff only states: “Removed approximately 96 words from the document.”
- The actual deleted language is not provided.
- No additions, replacements, or the identity of the removed provisions are shown.
AI Training and Data-Use Changes
- It is not possible to determine whether the deletion changes:
- The customer’s consent to use its data for training AI models;
- Whether customer data, prompts, outputs, or usage data may be used to train, fine-tune, or improve models;
- Whether data is anonymized, aggregated, or retained;
- Whether the customer can opt out of AI training or withdraw consent;
- Restrictions on using confidential, personal, or regulated information;
- Ownership or permitted use of inputs and outputs; or
- Data-retention, deletion, security, or subprocesser obligations.
Potential Legal Significance
Removing approximately 96 words could materially alter the agreement if the deleted text addressed:
- Data-use permissions or limitations;
- Confidentiality;
- Privacy and regulatory compliance;
- Intellectual-property rights;
- Service-provider or processor obligations;
- Liability, indemnification, or warranties; or
- Customer opt-out or deletion rights.
A deletion may either reduce the provider’s express rights to use customer data or remove protections that limited such use. The direction and effect cannot be determined without the actual language.
Required for a Reliable Analysis
Please provide the full redlined text, including the words shown as deleted. At minimum, provide:
1. The 96 deleted words;
2. The surrounding contract section; and
3. Any related definitions of “Customer Data,” “Usage Data,” “Content,” “AI,” or “Services.”
Conclusion: Based on the diff supplied, no specific contractual change—or specific change concerning AI-model training—can be identified.
2026-08-28 · Terms of use
2026-08-28 · Privacy Policy
Summary
The provided diff does not include the actual 96 added words. It only states that approximately 96 words were added. As a result, the legal impact cannot be reliably assessed.
AI Training and Customer Data
There is not enough information to determine whether the changes:
- Permit the provider to use customer data to train, fine-tune, or improve AI models;
- Expand use of customer data beyond providing the contracted services;
- Allow use of customer content in aggregated, de-identified, or anonymized form;
- Permit human review or access to customer data for model development;
- Give the provider rights to retain customer data after termination;
- Apply different rules to inputs, outputs, telemetry, metadata, or usage data; or
- Allow data to be shared with affiliates, subprocessors, or third-party AI providers.
Risk Assessment
No specific new legal risks can be identified without the inserted language. The added text could materially affect:
- Data ownership and licensing rights;
- Confidentiality and privacy obligations;
- Compliance with data-protection laws;
- Restrictions on processing personal or sensitive information;
- Security and breach responsibilities;
- Data deletion and retention requirements; and
- The customer’s ability to opt out of AI training.
Information Needed
Please provide the actual 96-word addition, preferably with the surrounding contract language or a marked-up version. The analysis should focus especially on terms such as train, improve, develop, fine-tune, machine learning, artificial intelligence, customer data, content, inputs, outputs, aggregated, de-identified, anonymized, usage data, and service improvement.
2026-08-28 · Privacy Policy
Summary of Changes
Information Provided
- The diff states only that approximately 96 words were removed from the document.
- The actual deleted language is not included.
- No additions, replacements, or specific clause text are shown.
Legal and Commercial Impact
Because the deleted wording is unavailable, it is not possible to determine:
- Which contractual rights or obligations changed.
- Whether liability, indemnity, confidentiality, security, intellectual property, termination, or payment provisions were affected.
- Whether any customer protections were removed.
- Whether the deletion creates ambiguity or shifts risk to either party.
Customer Data and AI Model Training
The provided diff does not identify whether customer data may be used to train, fine-tune, evaluate, or improve AI models.
In particular, there is insufficient information to determine whether the deleted language:
- Prohibited or limited use of customer data for AI training.
- Required customer consent before such use.
- Allowed use of de-identified, aggregated, or derived data.
- Restricted use of prompts, inputs, outputs, metadata, or usage data.
- Required deletion or retention limits for data used in model development.
- Addressed whether third-party AI providers could access customer data.
- Allocated ownership or intellectual-property rights in training data or model outputs.
If the removed text contained an AI-data restriction, its deletion could materially expand the provider’s ability to use customer information. Conversely, if it contained a provider permission, deletion could narrow that right. The legal effect cannot be assessed without the actual language and surrounding provisions.
Risk Assessment
Current assessment: Indeterminate—potentially material.
The notation “Removed approximately 96 words” is not enough to assess the change. The precise deleted text, the clause heading, and any related definitions or surviving provisions are necessary to identify legal consequences.
Recommended Next Step
Provide the complete redline, including:
1. The exact 96 deleted words.
2. The surrounding clause and section heading.
3. Any additions or replacements elsewhere that relate to data use, analytics, or AI.
4. Relevant definitions of “Customer Data,” “Usage Data,” “Aggregated Data,” and “Services Data.”
Until then, assume that any deleted limitation on data use—including AI training—requires specific review.
2026-08-27 · Terms of use
2026-08-26 · Terms of use
2026-08-26 · Privacy Policy
Summary of Important Changes
1. Contact and policy corrections
- The document title was corrected from “Softonic Privacy” to “Softonic Privacy Policy.”
- Formatting and spacing were standardized throughout legal references, including the GDPR, UK DPA, FADP, CCPA, and U.S. State Privacy Laws.
- Softonic’s Data Protection Officer contact email was added: dpo@softonic.com.
- Various links and references were corrected, including the Cookies Policy, Terms of Use, Cookie Banner, and regulator websites.
- The policy now states that it was reviewed and published on 9 June 2026.
2. Significant change to consent and objections
The most important substantive change concerns processing previously described as based on the user’s “explicit, free and unequivocal consent.”
The revised wording states that users who do not wish their data processed for these purposes may object at any time by contacting Softonic’s DPO, while retaining a later reference to consent being given when data is collected.
Risks and implications
- This creates ambiguity about the legal basis for processing: it is unclear whether Softonic relies on consent, a right to object, or both.
- An objection right is not equivalent to consent withdrawal in all circumstances. Under data-protection law, the consequences may differ depending on whether processing is based on consent, legitimate interests, or another legal basis.
- Requiring users to email the DPO may be less accessible than providing a direct consent-management or opt-out mechanism.
- The duplicated and awkwardly integrated wording could make the policy difficult to interpret and may weaken transparency regarding how users can stop processing.
3. Third-party disclosures
The reference to programmatic advertising vendors was clarified to point to the Cookie Banner. This confirms or reinforces disclosure of data to advertising technology providers, but does not materially explain:
- Which data is shared;
- The purposes and legal bases for sharing;
- Whether vendors use the data for their own purposes; or
- Whether data is used to create profiles or for targeted advertising.
These issues may remain a transparency risk, particularly for users subject to the GDPR, UK GDPR, CCPA, or other U.S. privacy laws.
4. AI model training
No express change regarding AI training was identified. The diff does not add or remove language stating that customer data, personal information, usage data, or content may be used to train, fine-tune, evaluate, or improve artificial-intelligence or machine-learning models.
Accordingly, the revised policy provides no clear new authorization or restriction on AI training. If Softonic or its vendors use customer data for AI development, the policy may still need specific disclosure of the data involved, purposes, legal basis, opt-out rights, retention, and third-party access.
5. Presentation issue
A large block of section headings was appended without spacing or apparent structure. This appears to be a publication or formatting error and could impair readability and legal transparency.
2026-08-26 · Terms of use
2026-08-25 · Terms of use
2026-08-25 · Privacy Policy
Summary
The diff indicates that approximately 96 words were removed from the document. However, the actual deleted language is not provided, so it is not possible to determine the legal or commercial effect of the changes.
Potential Impact
Because the deleted text is unspecified, the following issues cannot be assessed:
- Whether customer rights or provider obligations were reduced.
- Whether limitations of liability, indemnities, warranties, confidentiality, or termination rights changed.
- Whether data ownership, access, retention, deletion, or security terms were affected.
- Whether customer data may now be used for product improvement, analytics, or other secondary purposes.
- Whether any restrictions on using customer data to train, fine-tune, evaluate, or improve AI models were removed.
- Whether the contract previously required consent, anonymization, opt-out rights, or prohibited the use of customer data for AI training.
AI Training and Data Use
No specific conclusion can be drawn about AI-model training from the redacted diff alone. If the removed language addressed any of the following, its deletion could materially change the customer’s risk:
- A prohibition on using customer data or prompts to train AI models.
- A requirement to obtain the customer’s prior consent.
- An opt-out mechanism.
- Limits restricting use to aggregated or de-identified data.
- Requirements to delete training data after termination.
- Restrictions on using outputs, feedback, or usage data for model development.
- Commitments that customer content would not be reviewed by personnel or shared with model providers.
Risk Assessment
Assessment: Unable to determine. The notation “Removed approximately 96 words from the document” does not identify which provisions were deleted or whether the deletion was substantive, editorial, or duplicative.
To complete the analysis, the exact deleted text—or a redline showing the surrounding provision—should be provided.
2026-08-25 · Privacy Policy
Summary
The diff only states that approximately 96 words were added, but it does not include the actual added language or identify where those words appear.
Key Legal Changes
- Cannot be determined: The substance, scope, and legal effect of the additions cannot be analyzed without the text of the new provisions.
- No confirmed changes identified: The diff does not show any deletions, replacements, or specific revisions to existing terms.
AI Training and Customer Data
- No determination possible: The available diff does not reveal whether customer data may be:
- Used to train, fine-tune, or improve AI models;
- Shared with affiliates, vendors, or third-party model providers;
- De-identified, aggregated, or retained for model development;
- Excluded from training by default or only upon customer opt-out;
- Used for product analytics, benchmarking, or service improvement.
Potential Risks Requiring Review
The added language should be reviewed specifically for:
1. Data-use rights: Whether the provider receives a broad or perpetual license to customer data.
2. AI-training permissions: Whether training use is expressly permitted, restricted, or subject to consent.
3. Confidentiality: Whether customer data used for AI development remains protected as confidential information.
4. Data retention and deletion: Whether data or model outputs may remain after termination or deletion requests.
5. Third-party disclosures: Whether data may be transferred to external AI providers or subprocessors.
6. Customer controls: Whether customers can opt out, limit categories of data, or obtain audit or transparency rights.
7. Liability and compliance: Whether the customer bears responsibility for data submitted to AI systems or related regulatory risks.
Conclusion: The actual 96-word addition is required before any reliable legal or AI-data analysis can be performed.
2026-08-24 · Privacy Policy
Summary of Important Changes
1. AI-model training
- No express change concerning AI training appears in the supplied diff.
- The revisions do not add or remove language stating that customer data, personal information, content, usage data, or other inputs may be used to train, fine-tune, evaluate, or improve artificial-intelligence or machine-learning models.
- Accordingly, this diff does not create a clearly stated new authorization for AI training. However, any broader wording elsewhere in the unchanged policy—such as use of data for analytics, service improvement, personalization, fraud prevention, or advertising—could still be relevant depending on how Softonic operates its AI systems. The full policy and related terms should be reviewed for such language.
2. Consent and objection rights
The most significant substantive change replaces language stating, in effect:
> Users who did not want their data processed for certain purposes could object at any time by contacting Softonic.
with language stating:
> Processing is based on the user’s “explicit, free and unequivocal consent” given when the data is collected.
Risks and implications
- This appears to shift the legal basis from a general processing framework—potentially including legitimate interests and a later objection right—to an express-consent model.
- The new wording may make consent at collection a condition for the relevant processing activities, rather than emphasizing a later right to object.
- Although the policy still states that consent may be withdrawn, it should clearly explain:
- how consent is obtained;
- whether consent is genuinely optional;
- how withdrawal works;
- whether withdrawal affects only future processing; and
- whether services remain available after withdrawal.
- Repeated replacement language appears to apply this change to cookies and possibly other listed processing purposes. The scope should be verified against the complete policy and cookie banner.
3. Third-party disclosures
- The policy now refers to programmatic advertising vendors listed in the Cookie Banner, rather than merely referencing the vendors generally.
- This may make the cookie banner an important source of information about recipients and tracking partners. Users may need to consult both documents to understand disclosures.
- The change does not itself add a new recipient, but it may reduce transparency if the vendor list is dynamic, difficult to access, or not retained.
4. Other changes
- Most remaining edits are grammatical, punctuation, formatting, or terminology changes.
- The policy’s review/publication date and table of contents appear to have been removed from the displayed text. This may make version tracking and navigation less transparent.
- Regulatory references and complaint-authority links have been standardized, without an apparent substantive change to rights or obligations.
Overall: The key legal change is the apparent move toward explicit consent at collection for certain processing activities. No specific AI-training permission or restriction is added in this diff.
2026-08-24 · Terms of use
2026-08-23 · Terms of use
2026-08-23 · Terms of use
2026-08-23 · Privacy Policy
Summary of Important Changes
Substantive privacy and compliance changes
- Data Protection Officer contact added: The policy now identifies dpo@softonic.com as a contact address, including for exercising rights and objecting to processing. This gives customers a clearer method for contacting Softonic, but Softonic should ensure the address is monitored and consistently used throughout the policy.
- Change to consent and objection language: Several passages replace wording stating that processing was based on the customer’s “explicit, free and unequivocal consent” with language stating that customers may object if they do not wish their data to be processed and may contact the DPO.
- This appears to shift the presentation from an affirmative-consent model to an objection or opt-out model.
- The revised text then reinstates the statement that consent is obtained when data is collected, creating potential ambiguity about the actual legal basis for processing.
- Softonic should clarify, for each purpose, whether processing relies on consent, legitimate interests, or another legal basis, and whether withdrawal or objection is available.
- Cookie consent clarification: The policy more clearly states that consent to cookies may be withdrawn at any time and refers users to the Cookies Policy. This strengthens transparency, but the cookie banner and withdrawal mechanism should match the policy.
- Privacy-law terminology standardized: References to the GDPR, UK DPA, UK GDPR, FADP, CCPA, and U.S. State Privacy Laws have been cleaned up. This appears primarily editorial and does not materially expand or restrict rights.
- Third-party disclosures clarified: The reference to programmatic advertising vendors now points to the Cookie Banner. Users may need to consult that separate resource to identify recipients, which could reduce transparency if the vendor list is difficult to find or not kept current.
- Publication date and apparent contents list added: The policy states it was reviewed and published on 9 June 2026. A large list of section headings has also been appended, apparently as a table of contents or navigation text. If displayed to users as written, this may be a drafting or formatting error.
AI model training
- No express change concerning AI training was identified.
- The diff does not add or remove language authorizing Softonic to use customer data, content, usage data, or personal information to train, fine-tune, evaluate, or improve AI models.
- The policy should nevertheless be reviewed in full for existing AI-related provisions, particularly under analytics, service improvement, third-party disclosures, and legitimate-interest processing.
2026-08-22 · Terms of use
2026-08-22 · Privacy Policy
Summary of the Diff
Scope of Change
- The diff states that approximately 96 words were removed from the document.
- The actual deleted language is not provided, so the legal effect of the change cannot be determined reliably.
AI Training and Customer Data
- The available diff contains no specific language addressing:
- Whether customer data may be used to train, fine-tune, or improve AI models;
- Whether prompts, inputs, outputs, or usage data may be retained;
- Whether data is anonymized, aggregated, or de-identified before use;
- Whether customer data may be shared with affiliates, vendors, or model providers;
- Whether the customer can opt out of AI training or model improvement; or
- Ownership and permitted uses of data-derived models or outputs.
- Accordingly, it is impossible to determine whether the deletion:
- Removes a customer protection or opt-out right;
- Broadens or narrows the provider’s ability to use customer data;
- Eliminates a restriction on AI training; or
- Has no effect on AI-related data use.
Potential Legal Risks
Because the deleted text is not included, the principal risk is loss of important contractual protections without visibility into their content. The removed provisions could have addressed:
- Confidentiality and data-security obligations;
- Limits on secondary use of customer data;
- Data retention and deletion;
- Intellectual-property ownership;
- Regulatory compliance, including privacy and data-protection laws;
- Allocation of liability for unauthorized data use; or
- Audit, notice, consent, or termination rights.
Recommended Review
To complete the analysis, provide either:
1. The exact approximately 96 words that were deleted; or
2. The full “before” and “after” versions of the affected provision.
The deleted language should be reviewed specifically for terms such as “train,” “fine-tune,” “improve,” “develop,” “machine learning,” “artificial intelligence,” “models,” “inputs,” “outputs,” “usage data,” “aggregated,” “de-identified,” and “service improvement.”
2026-08-22 · Terms of use
2026-08-21 · Terms of use
2026-08-21 · Privacy Policy
Summary
The supplied diff does not include the actual contractual language that was added, deleted, or replaced. It only states:
> “Added approximately 96 words to the document”
Accordingly, it is not possible to determine:
- What contractual terms changed;
- Whether customer rights or obligations were expanded;
- Whether liability, confidentiality, security, or termination provisions changed; or
- Whether the customer’s data may now be used to train, fine-tune, evaluate, or improve AI models.
AI-Training and Data-Use Analysis
No substantive language addressing AI models, machine learning, model training, data retention, data processing, or use of customer content is provided in the diff.
Therefore, no conclusion can be reached about whether the changes:
- Permit use of customer data or inputs for AI training;
- Allow use of outputs, usage data, metadata, or de-identified data for model improvement;
- Apply training rights to personal, confidential, or proprietary information;
- Permit sharing of customer data with affiliates, vendors, or model providers;
- Require consent or provide an opt-out;
- Restrict deletion or impose retention periods; or
- Allocate intellectual-property, confidentiality, privacy, or security risks.
Key Limitation
The diff should include the actual 96 added words and any deleted or replacement text. Without that language, there are no identifiable legal changes to analyze and no basis for assessing new customer risks.
2026-08-20 · Privacy Policy
Summary of Important Changes
1. AI-model training
- No express change concerning the use of customer data to train, develop, fine-tune, evaluate, or improve AI models is visible in this diff.
- The diff does not add terms authorizing AI training or describe whether personal data, user content, usage data, or feedback may be provided to AI providers.
- If Softonic uses customer data for AI-related purposes, this policy remains unclear on that point. Customers may need to rely on other policies, terms, consent notices, or provider disclosures.
2. Consent replaces the previous objection-based wording
Several provisions change from:
- customers being able to object at any time by contacting Softonic; to
- processing being based on the customer’s “explicit, free and unequivocal consent” given when data is collected.
Risks and implications
- The new wording appears to make consent the stated legal basis for certain activities, including cookies and related processing.
- The prior express right to object by contacting Softonic has been removed from these passages and replaced with a right to withdraw consent.
- Withdrawal of consent is not always legally or practically identical to objection, particularly where the processing may previously have relied on another legal basis.
- The policy should clearly identify the specific processing purposes covered by consent and explain how consent can be withdrawn without disadvantage.
3. Data protection contact information may have been removed
- The prior reference to contacting the Data Protection Officer at dpo@softonic.com appears to have been deleted, leaving only punctuation.
- This may make it less clear how customers can exercise rights or contact Softonic about privacy issues.
- The change could create usability and compliance concerns, especially if no replacement contact method appears elsewhere in the policy.
4. Other disclosure and scope wording
- References to the Services, Cookie Policy, Cookie Banner, and third-party programmatic advertising vendors are mainly editorial or formatting changes.
- The policy continues to reference disclosures to advertising vendors, but this diff does not materially expand or restrict those disclosures.
- The list of applicable laws has been cleaned up and now expressly includes the UK GDPR and US State Privacy Laws; this appears clarificatory rather than a major change in processing.
5. Policy date and navigation
- The statement that the policy was reviewed and published on 9 June 2026, together with a list of policy-section headings, appears to have been removed.
- Removing the effective/review date may make it harder for customers to determine which version governs their data.
2026-08-19 · Terms of use
Between 2021-10-13 and 2023-09-01 · Terms of use
Between 2021-08-12 and 2023-05-01 · Privacy Policy
Summary
The diff only states that approximately 96 words were removed, without identifying the deleted language.
AI Training and Data Use
- It is not possible to determine whether the agreement’s provisions on using customer data to train AI models were changed.
- The deleted language could have:
- Authorized or prohibited training AI models on customer data;
- Defined whether customer data includes prompts, outputs, uploaded files, or personal information;
- Required customer consent before training;
- Addressed anonymization, aggregation, or de-identification;
- Restricted use of data for improving products or services; or
- Allocated ownership, confidentiality, security, or deletion rights relating to training data.
Potential Legal Risk
The deletion may materially alter the parties’ rights and obligations, but its impact cannot be assessed without the actual deleted text and surrounding provisions. In particular, removing a restriction or consent requirement could broaden the provider’s ability to use customer data, including for AI training. Conversely, removing an authorization could limit such use or create ambiguity.
Required Information
Please provide the actual deleted language—ideally with the surrounding unchanged text or a redline. Without it, no reliable conclusion can be reached about changes to data usage, AI model training, confidentiality, privacy, ownership, or other legal obligations.