clause.watch Contracts Recent changes Start monitoring

Monitored company

Tapatalk

clause.watch tracks 2 legal documents published by Tapatalk, re-reading each one every six hours. Below is what each document covers, in plain English.

Privacy Policy

40,410 characters · Read the original

We monitor this document. A plain-English summary has not been published for it yet.

Privacy Shield

5,019 characters · Read the original

Tapatalk Privacy Shield Notice — User Overview

Effective date: August 1, 2023

Scope: This notice applies only to personal information transferred from the European Economic Area (EEA) and Switzerland to the United States (“EU Exported Data”). It supplements, rather than replaces, Tapatalk’s broader Privacy Policy.

> Important legal context: The EU–US Privacy Shield was invalidated by the Court of Justice of the European Union in 2020. The EU–US Data Privacy Framework later replaced it for participating organizations. This notice’s reference to Privacy Shield may therefore be outdated or legally incomplete. Users should review Tapatalk’s current Privacy Policy and transfer mechanism.

1. Data Collection and Usage

This document does not list specific categories of data collected. It refers users to Tapatalk’s separate Privacy Policy for:

  • The types of personal information collected
  • Processing purposes
  • Retention practices
  • Available privacy choices

The notice states that Tapatalk will process personal information only:

  • For purposes compatible with the reason it was originally collected; or
  • For purposes later authorized by the user

If Tapatalk intends to use data for a materially different purpose, it says it will provide an opportunity to opt out.

Practical risk: The actual scope of collection—including account information, device data, usage information, communications, location data, cookies, or forum content—cannot be determined from this notice alone. The separate Privacy Policy is essential.

2. User Rights

Eligible EEA and Swiss individuals may request:

  • Access to personal information Tapatalk holds
  • Correction or amendment of inaccurate information
  • Deletion where information is inaccurate or processed in violation of the stated principles

Tapatalk may request identity-verification information. Rights may be refused or limited where access would be excessively burdensome or expensive, or would infringe another person’s rights.

The notice directs users to the broader Privacy Policy for additional choices and means of limiting use or disclosure. It does not clearly describe all rights that may apply under GDPR or Swiss law, such as portability, restriction, objection, or withdrawal of consent.

3. Third-Party Sharing

Tapatalk’s separate Privacy Policy describes:

  • The categories of third parties receiving data
  • The purposes of disclosure

Where a third party acts as Tapatalk’s agent, Tapatalk states that it remains responsible for the agent’s acts inconsistent with the Privacy Shield Principles, unless otherwise provided by law.

Tapatalk may also disclose information to public authorities when legally required, including for:

  • Law enforcement
  • National security
  • Other lawful government requests

Risk: Government disclosures may occur without advance notice, and this notice does not explain the scope, frequency, or safeguards for such disclosures.

4. AI/ML Training

The notice contains no statement addressing artificial intelligence or machine-learning training.

It therefore does not confirm whether user data, posts, messages, support requests, metadata, or other content is used to train, evaluate, or improve AI models. Users must consult Tapatalk’s current Privacy Policy, product terms, or specific AI disclosures.

5. Key User Obligations and Restrictions

This document imposes no significant user conduct obligations, payment duties, or content restrictions. Its main practical requirements are procedural:

  • Users must submit requests in writing.
  • Users may need to provide information to verify identity.
  • Users should use the specified contact channels for privacy complaints.

The notice does not promise a particular deletion timeframe or guarantee that every request will be granted.

6. Liability and Disputes

Users should first contact:

  • Email: privacy@tapatalk.com
  • Mail: Tapatalk, Inc., Attn: Privacy Officer, 406 Broadway #158, Santa Monica, CA 90401

Tapatalk says it will investigate and attempt to resolve complaints within 45 days.

If unresolved, users may contact JAMS, a US-based dispute-resolution provider, free of charge. Under certain circumstances, users may also select binding arbitration under the Privacy Shield process.

The notice provides no general liability cap, damages exclusion, indemnity, or warranty terms. Those may appear elsewhere in Tapatalk’s Terms of Service or Privacy Policy. Government disclosure obligations may override ordinary privacy protections.

7. Changes

Tapatalk reserves the right to amend the notice from time to time, consistent with applicable framework requirements. It does not specify:

  • How users will be notified
  • How much advance notice will be given
  • Whether continued use constitutes acceptance

Users should periodically review the notice and related Privacy Policy, particularly because the stated Privacy Shield framework may no longer reflect the current legal basis for EU–US data transfers.

Change history

2026-08-22 · Privacy Shield

grew 7.9% · Observed by clause.watch

Summary

The diff only states that approximately 52 words were added, but it does not provide the actual added language or identify where it appears in the agreement.

Key Legal Changes
  • Cannot be determined: The substance, scope, and legal effect of the additions cannot be analyzed without the exact wording.
  • No deletions or replacements shown: The diff does not identify any removed or modified terms.
  • Risk assessment unavailable: It is not possible to assess changes involving liability, confidentiality, intellectual property, data security, governing law, or other contractual obligations.
Customer Data and AI Training
  • The provided diff contains no specific language addressing customer data or AI model training.
  • It is therefore unclear whether the new language:
  • Permits the provider to use customer data to train, fine-tune, or improve AI models;
  • Allows use of customer data in aggregated, de-identified, or identifiable form;
  • Grants the provider ownership or a broad license to customer inputs, outputs, or usage data;
  • Allows data to be shared with affiliates, vendors, or third-party AI providers;
  • Provides an opt-out, deletion right, retention limit, or confidentiality protection; or
  • Restricts use of customer data for model training or product development.
Recommended Next Step

Provide the actual 52-word addition, preferably with the surrounding contract language and markup. Without the text itself, no reliable legal interpretation or risk analysis can be performed.

2026-08-21 · Privacy Shield

shrank 7.3% · Observed by clause.watch

Summary

The diff indicates that approximately 52 words were removed, but the actual deleted language is not provided.

AI Training and Data Use

  • It is not possible to determine whether the removed text changed:
  • The provider’s right to use customer data to train, fine-tune, or improve AI models;
  • Whether customer data may be used for generalized model training;
  • Whether prompts, inputs, outputs, personal information, or confidential information are included;
  • Any opt-in, opt-out, consent, or objection rights;
  • Data retention, deletion, anonymization, or aggregation requirements; or
  • Restrictions on using customer data to train third-party or affiliated models.

Because the deleted language is unavailable, any limitation or protection concerning AI training may have been removed without being identifiable from the supplied diff.

Other Legal Risks

The missing 52 words could potentially affect important provisions concerning:

  • Confidentiality and permitted uses;
  • Intellectual-property ownership;
  • Data protection and privacy obligations;
  • Security and breach responsibilities;
  • Service-provider or subcontractor rights;
  • Liability, indemnification, or warranties; or
  • Termination and deletion of customer data.

The legal impact cannot be assessed reliably without seeing the exact deleted wording and its surrounding provisions.

Overall Assessment

This is an incomplete diff rather than a substantive redline. No specific contractual change can be confirmed from the information provided. The full deleted text, or a complete before-and-after version of the relevant clause, is needed to identify whether customer data may now be used for AI model training and whether any customer protections have been weakened.

2026-08-20 · Privacy Shield

grew 7.9% · Observed by clause.watch

Summary

The diff does not include the actual added language—only a statement that approximately 52 words were added. Without the wording of those additions, it is not possible to determine the legal or commercial impact.

AI Training and Customer Data

  • No conclusion can be reached about whether the changes:
  • Permit the provider to use customer data to train, fine-tune, or improve AI models;
  • Allow use of customer prompts, inputs, outputs, or other content for model development;
  • Restrict training to anonymized, aggregated, or de-identified data;
  • Provide an opt-out or require customer consent;
  • Allow human review or disclosure of data for AI-development purposes; or
  • Change ownership, confidentiality, security, or deletion obligations relating to customer data.

Other Potential Changes

The missing language could also affect:

  • Data-use rights and licensing;
  • Confidentiality and privacy obligations;
  • Intellectual-property ownership;
  • Liability, indemnification, or regulatory compliance;
  • Retention and deletion periods;
  • Subprocessor or third-party access; and
  • The customer’s ability to terminate or opt out.

Required Information

Please provide the actual 52-word addition, using the stated notation ({additions}, [deletions], and []{replacements}). A meaningful legal-risk analysis requires the precise wording and, ideally, the surrounding contract provision.

2026-08-20 · Privacy Policy

grew 2.0% · Observed by clause.watch

Summary

The provided diff does not include the actual amended contract language. It only states:

> “Added approximately 101 words to the document”

Accordingly, it is not possible to identify the legal effect of the changes or determine whether the customer’s data may be used to train AI models.

AI Training and Data Use

  • No substantive language regarding AI, machine learning, model training, data usage, data retention, or data sharing is included in the diff.
  • It cannot be determined whether the new text:
  • Permits or prohibits using customer data to train AI models;
  • Limits training to aggregated, anonymized, or de-identified data;
  • Allows use of prompts, inputs, outputs, metadata, or usage data for training;
  • Gives the provider ownership or broad license rights over customer data;
  • Allows sharing data with affiliates, vendors, or third-party AI providers;
  • Provides an opt-out or consent mechanism; or
  • Imposes deletion, confidentiality, security, or human-review obligations.

Other Legal Risks

No other contractual changes can be analyzed because the added 101 words were not provided. The word-count statement alone does not reveal whether the changes affect:

  • Liability or indemnification;
  • Confidentiality;
  • Intellectual-property ownership;
  • Data protection and privacy compliance;
  • Service levels or termination rights;
  • Payment obligations; or
  • Governing law and dispute resolution.

Information Needed

Please provide the full redline showing the actual additions, deletions, and replacements. Without the underlying text, any assessment of new rights, obligations, or risks—especially regarding AI model training—would be speculative.

2026-08-20 · Privacy Shield

shrank 7.3% · Observed by clause.watch

Summary of Important Changes

Scope of the Changes

The diff appears to revise Tapatalk’s Privacy Shield Notice, particularly its complaint-handling and dispute-resolution provisions. It does not show changes to provisions governing the collection, sharing, retention, sale, or use of customer data.

Privacy Complaints and Dispute Resolution

New or revised process

The revised language:

  • Identifies Tapatalk, Inc.’s Privacy Officer and provides a Santa Monica mailing address.
  • States that Tapatalk will investigate and attempt to resolve Shield-related complaints or disputes within 45 days of receipt.
  • Directs individuals with unresolved complaints to JAMS, described as Tapatalk’s U.S.-based, third-party dispute-resolution provider.
  • Provides a JAMS website and an online form for filing an EU-U.S. Privacy Shield or Safe Harbor claim.
  • Adds that individuals may have the option to select binding arbitration under certain circumstances.
Removed or narrowed contact route

The prior language expressly directed individuals to contact Tapatalk by email at privacy@tapatalk.com or in writing. The revised language appears to replace that direct email-based route with the JAMS process and online filing form.

Risk/impact: This may make the complaint process less direct and could impose procedural steps before a complainant can access further remedies. The arbitration language is qualified (“under certain circumstances”) and does not itself explain the scope, eligibility requirements, costs, or consequences of arbitration; those details are incorporated by reference to the Privacy Shield materials.

Changes to the Notice

The revised text states that Tapatalk may amend the Notice from time to time consistent with the Privacy Shield’s requirements.

Risk/impact: This gives Tapatalk continuing flexibility to modify the notice without an express requirement for individual consent or advance notice. However, the language appears to limit amendments by reference to applicable Privacy Shield requirements.

Privacy Shield Legal Status

The notice continues to rely on the Privacy Shield framework. That framework was invalidated for EU-U.S. transfers by the Court of Justice of the European Union in *Schrems II* in 2020. Depending on the notice’s current use and the relevant data transfers, continued reliance on this language may create compliance, transparency, and enforceability risks. Tapatalk should confirm whether the notice has been updated to reference the EU-U.S. Data Privacy Framework, standard contractual clauses, or another valid transfer mechanism.

AI Model Training

No changes concerning AI training were identified. The diff contains no express authorization or restriction regarding whether customer data, personal information, content, or communications may be used to train, fine-tune, evaluate, or improve AI models. Any such rights or limitations would need to be reviewed in the broader Privacy Policy, Terms of Service, or applicable data-processing terms.

2026-08-19 · Privacy Policy

shrank 1.9% · Observed by clause.watch

Summary of Important Changes

AI Model Training

  • No express provision was added or removed concerning use of customer or user data to train, fine-tune, evaluate, or improve artificial-intelligence models.
  • The revised wording refers generally to using information to:
  • Provide and improve Tapatalk services;
  • Personalize content;
  • Analyze usage; and
  • Enhance functionality and security.
  • These broad purposes could potentially encompass future machine-learning or AI development, but the policy does not clearly authorize AI training or explain whether user content, forum posts, private messages, or account data may be included.
  • Risk: The absence of a specific AI-training statement creates ambiguity and may be inadequate for transparency or consent requirements if Tapatalk uses user content for generative-AI or model-training purposes. Customers should seek express confirmation that their data and content will not be used for AI training unless separately disclosed and lawfully authorized.

Data Use and Legal Bases

  • The “How We Use Your Information” section is substantially reorganized and now expressly lists purposes including:
  • Providing and improving services;
  • Communicating updates and support responses;
  • Analyzing usage;
  • Enhancing functionality and security;
  • Complying with legal obligations; and
  • Enforcing policies.
  • The policy now more clearly identifies GDPR legal bases: consent, contractual necessity, and legitimate interests.
  • Risk: “Improve services,” “analyze usage,” and “enhance functionality” remain broad and may permit extensive secondary use. The policy does not clearly separate optional uses from uses necessary to provide the service.

Cookies, Tracking, and California Rights

  • Cookie language is expanded to cover personalization and usage analysis.
  • California residents are told they may review practices under CalOPPA, and the policy states there will be no discrimination for exercising rights.
  • The policy states Tapatalk does not currently respond to Do Not Track signals, while disclosing this under CalOPPA.
  • Cookie preferences may be managed through browser settings or a cookie consent tool.

Retention and Moderation Records

  • A specific retention period of up to six years after account closure is added, unless law requires otherwise.
  • Moderation records may be retained for compliance with the UK Online Safety Act 2023.
  • Risk: Six years is a substantial retention period, and the policy does not clearly identify which data is retained, why that duration is necessary, or whether deletion requests are limited.

Policy Changes and Legal Cooperation

  • Tapatalk may update the policy for operational, legal, or service changes, including GDPR, CalOPPA, and the UK Online Safety Act.
  • Significant changes will generally be notified by email or platform notice at least 30 days in advance where required; continued use constitutes acceptance.
  • The policy expressly states Tapatalk may cooperate with legal authorities regarding illegal activity and user safety.

Contact Information

  • Privacy inquiries may be directed to privacy@tapatalk.com; the policy indicates this is the contact point unless a formal Data Protection Officer is designated.

2026-08-18 · Privacy Shield

shrank 15.6% · Observed by clause.watch

Key Changes and Risks

1. Document scope materially narrowed
  • The notice changes from a general privacy-policy introduction covering all Tapatalk users to a Privacy Shield Notice applying only to personal information transferred from the EEA and Switzerland to the United States.
  • Information received from customers is expressly included, in addition to information collected from website, mobile-site, and app users.
  • Other users and processing activities are redirected to Tapatalk’s separate Privacy Policy.

Risk: Customers may need to consult multiple documents to understand how their data is processed. The operative terms may be unclear if the Privacy Policy and this notice differ.

2. Reliance on Privacy Shield frameworks
  • Tapatalk states that it complies with the former EU–US and Swiss–US Privacy Shield Frameworks, has certified adherence to the U.S. Department of Commerce, and accepts FTC jurisdiction.
  • The notice adds complaint procedures through Tapatalk, JAMS, and potential binding arbitration.

Risk: The EU–US Privacy Shield was invalidated by the Court of Justice of the European Union in *Schrems II* in 2020. Reliance on the Privacy Shield alone is legally insufficient for EEA transfers. The document should identify a currently valid transfer mechanism, such as the EU–U.S. Data Privacy Framework (if applicable), Standard Contractual Clauses, and transfer-impact safeguards.

3. New purpose-limitation and opt-out language
  • Tapatalk states it will process personal information only in ways compatible with the purposes described in its Privacy Policy or for purposes later authorized by the individual.
  • Before using data for a materially different purpose, Tapatalk will provide an opportunity to opt out.

Risk: “Compatible,” “materially different,” and the opt-out process are not defined. The language may permit broader secondary uses without affirmative consent, subject to a separate policy.

4. Third-party disclosures revised
  • Disclosures and purposes are now described by reference to the Privacy Policy.
  • If a third party acts as Tapatalk’s “agent,” Tapatalk accepts responsibility for acts inconsistent with the Privacy Shield Principles, unless otherwise permitted by law.
  • Government disclosures are described as responses to lawful requests by public authorities, including national-security and law-enforcement requests.

Risk: The notice does not identify the relevant third parties or impose detailed contractual controls, deletion obligations, or security standards. Government-access language may permit disclosures with limited transparency.

5. Access rights both clarified and restricted
  • Individuals may request access, correction, amendment, or deletion of their information.
  • Requests may be denied where access is unreasonably burdensome or expensive, would violate third-party rights, or is otherwise restricted by law.
  • Identity verification may be required.

Risk: The exceptions are broad and may reduce practical data-access and deletion rights.

6. AI-model training
  • No express change or authorization regarding using customer data to train, fine-tune, evaluate, or improve AI models appears in the provided diff.
  • The revised “compatible purposes” and “materially different purpose” language could become relevant to AI training, but it does not clearly authorize or prohibit such use.

Risk: The absence of explicit AI language creates uncertainty. Customers should seek a clear contractual statement addressing whether their data, prompts, content, metadata, or outputs may be used for AI training, whether data is anonymized, and whether customers can opt out.

7. Unilateral amendment right
  • Tapatalk expressly reserves the right to amend the notice from time to time.

Risk: The change mechanism does not specify advance notice, customer consent, or protection against materially adverse changes.

2025-03-18 · Privacy Policy

Date stated by the publisher in the document

The publisher records this document as revised on this date (“Last Updated: March 18, 2025”).

2023-08-01 · Privacy Shield

Date stated by the publisher in the document

The publisher records this document as revised on this date (“Effective Date: August 1, 2023”).

Between 2019-12-18 and 2020-02-17 · Privacy Policy

grew 6.9% · Reconstructed from Internet Archive captures

The wording changed. No written summary was produced for this revision.

Between 2019-05-26 and 2019-10-22 · Privacy Shield

shrank 13.2% · Reconstructed from Internet Archive captures

Summary

Information Provided

The diff states only that approximately 107 words were removed from the document. It does not identify:

  • Which provisions were deleted;
  • Whether any language was added or replaced;
  • The subject matter of the deleted text; or
  • Whether the deletions affect customer data, AI training, confidentiality, security, liability, or other legal rights.

AI Training and Data Use

No reliable conclusion can be drawn about changes to the use of customer data to train AI models.

The deleted language could potentially have:

  • Authorized or prohibited the provider from using customer data for AI model training;
  • Limited training to aggregated, anonymized, or de-identified data;
  • Required customer consent or provided an opt-out right;
  • Addressed use of prompts, outputs, metadata, or uploaded content;
  • Restricted human review or model improvement activities; or
  • Imposed deletion, retention, confidentiality, or security obligations.

Conversely, the removal may have eliminated a restriction on AI training or removed a customer protection. The legal effect cannot be determined without the actual text.

Potential Risks

Because the underlying wording is unavailable, the principal risk is lack of visibility into substantive deletions. In particular, deleting approximately 107 words may materially change:

  • The scope of the provider’s license to customer data;
  • Whether customer data may be used for commercial purposes;
  • Whether data may be used to train general-purpose or customer-specific AI models;
  • The customer’s ability to opt out or revoke permission;
  • Confidentiality and data-protection obligations; and
  • Allocation of responsibility for unauthorized use or disclosure.

Conclusion

The diff is insufficient for a legal risk analysis. The full prior and revised clauses—or a redline showing the exact 107 deleted words—are required to determine whether customer data may now be used for AI training and whether any related customer protections were removed.

Between 2019-01-25 and 2019-05-26 · Privacy Shield

shrank 4.2% · Reconstructed from Internet Archive captures

Summary

The provided diff only states that approximately 52 words were removed from the document. It does not identify the deleted language or show any replacement text.

Key Legal Implications

  • Scope of review is insufficient: Without the exact deleted wording, it is not possible to determine whether the change affects liability, confidentiality, intellectual property, data protection, termination, payment terms, or other legal rights.
  • AI-training provisions cannot be assessed: The diff does not reveal whether the deleted text addressed:
  • Use of customer data to train, fine-tune, or improve AI models;
  • Whether customer prompts, inputs, outputs, or personal information may be retained;
  • Whether data is used for shared or provider-specific model training;
  • Opt-out or consent requirements;
  • De-identification or aggregation standards;
  • Human review or access to customer data; or
  • Restrictions on using customer data to develop competing products.
  • Potential risk: If the removed language limited the provider’s ability to use customer data—or granted the customer an opt-out, confidentiality protection, or deletion right—its removal could materially expand the provider’s rights. Conversely, the deletion might remove an overly broad provider right, but that cannot be confirmed from the information supplied.

Conclusion

No reliable substantive or risk analysis can be performed from a statement that 52 words were removed. The actual deleted text, and any surrounding provisions or replacement language, is required—particularly to evaluate changes concerning AI-model training and customer-data use.

Between 2018-09-13 and 2019-01-25 · Privacy Shield

grew 5.6% · Reconstructed from Internet Archive captures

Summary of Important Changes

1. Complaint procedure revised

The complaint section has been substantially reorganized:

  • The prior wording instructed individuals to contact Tapatalk’s Privacy Officer directly and stated that Tapatalk would investigate and attempt to resolve Privacy Shield complaints or disputes within 45 days.
  • The revised wording states that Tapatalk commits, in compliance with the Privacy Shield Principles, to resolve complaints concerning its collection or use of personal information.
  • Individuals in the EEA and Switzerland are now directed to contact Tapatalk first by email at privacy@tapatalk.com or by mail at the listed Privacy Officer address.
  • The 45-day resolution period remains, although the revised language more clearly frames it as applying to “Privacy Shield-related” complaints and disputes.
Potential risk

The revised process may create a more formal escalation path and could be read as requiring individuals to contact Tapatalk before using the outside dispute-resolution process. The language should clearly state whether this initial contact is mandatory or merely recommended.

2. JAMS dispute-resolution information updated

The revised notice:

  • Retains JAMS as the U.S.-based, third-party dispute-resolution provider.
  • Adds a direct link to the JAMS Privacy Shield page and a specific form for filing an EU–U.S. Privacy Shield or Safe Harbor claim.
  • Clarifies that individuals may make a complaint directly through JAMS after Tapatalk has not satisfactorily addressed it.
Potential risk

The reference to the EU–U.S. Privacy Shield is legally outdated. The European Union Court of Justice invalidated the Privacy Shield framework in 2020. Continuing to describe it as an active framework may create compliance, transparency, and consumer-protection risks unless the notice is intended solely to address historical obligations or another currently valid mechanism.

3. Binding arbitration added

The revised language adds that an individual may, in certain circumstances, select binding arbitration to resolve an unresolved complaint under the Privacy Shield framework.

Potential risk

Binding arbitration can limit access to court proceedings and may restrict available remedies. The notice should explain:

  • When arbitration is available;
  • Whether arbitration is optional;
  • How to initiate it;
  • What remedies and procedural rights apply; and
  • Whether any costs are imposed on the individual.

4. Navigation changes

The addition of links such as “Getting Started,” “Tapatalk Groups,” “Tapatalk Mobile,” “Tapatalk VIP,” and “Support” appears administrative and does not materially change privacy rights or obligations.

5. AI-model training and data use

No changes in the supplied diff expressly address AI, machine learning, model training, automated systems, or use of customer data to train AI models. The revised complaint language refers generally to the collection or use of personal information, but it does not expand, restrict, authorize, or prohibit AI-training uses.

Between 2018-05-14 and 2018-12-05 · Privacy Policy

grew 16.7% · Reconstructed from Internet Archive captures

The wording changed. No written summary was produced for this revision.

Watch this company's contracts

We re-read these documents every six hours and email you when the wording changes.

Start monitoring free