Monitored company
Unity
clause.watch tracks 3 legal documents published by Unity (unity.com), re-reading each one every six hours. Below is what each document covers, in plain English.
Generative AI Privacy Notice
Unity Generative AI Privacy Notice: User Overview
*Based on the notice last reviewed July 24, 2025. This notice supplements Unity’s main Privacy Policy, Cookie Policy, and any applicable AI or developer-data terms. Those documents may contain important additional rules and rights.*
1. Data Collection and Use
Information you provide
Unity may collect:
- Prompts: Text, code, images, audio-visual content, files, and other materials submitted to the AI Tools.
- Outputs: Responses generated from your prompts.
- Communications: Information posted in community pages, forums, or sent to Unity.
- Personal or confidential information included in prompts: Unity warns that such information may be collected and could be reproduced in Outputs.
Information collected automatically
Unity may collect:
- Usage activity, including actions, first and last session dates, and session length.
- Device details, including operating system, hardware/software versions, platform, screen size, and CPU/graphics characteristics.
- Approximate location derived from your IP address, such as city, state, or country.
- Metadata and other information associated with uploaded files.
- Other account, cookie, and service data covered by Unity’s main Privacy Policy.
Purposes
Unity may use this information to:
- Provide, operate, troubleshoot, maintain, and improve the AI Tools.
- Create and administer accounts, process payments, and provide support.
- Prevent fraud, piracy, cyberattacks, identity theft, and other harmful or criminal activity.
- Enforce licenses and terms of service.
- Conduct analytics, testing, audits, research, and business reporting.
- Develop new products and personalize content, services, marketing, or offers.
- Send newsletters and marketing communications, subject to applicable consent requirements.
- Aggregate or anonymize data and use or disclose the resulting data for any purpose.
- Train and enhance machine-learning algorithms.
Practical risk: The notice does not promise that prompts, uploaded files, or Outputs will remain confidential. Users should avoid entering trade secrets, sensitive personal information, credentials, regulated data, or confidential client material unless separate terms provide adequate protection.
2. AI/ML Training
Yes. Unity expressly states that it may use Personal Information for training and enhancing machine-learning algorithms to improve its Services.
The notice does not clearly explain:
- Whether all prompts and Outputs are used or only selected data.
- Whether users can opt out.
- How long training data is retained.
- Whether data is de-identified before training.
- Whether human reviewers or external providers may access it.
Any applicable Additional Terms or documentation may limit use of “Developer Data,” so those should also be reviewed.
3. Third-Party Sharing
This notice does not provide a detailed list of recipients. Instead, it directs users to Unity’s main Privacy Policy for information about sharing.
Potential categories may include service providers, payment processors, hosting and analytics providers, security vendors, affiliates, professional advisers, regulators, or parties involved in corporate transactions—but these categories should be confirmed in the main policy.
Unity may also disclose aggregated or anonymized information for any purpose after it is no longer considered Personal Information. Data may be transferred outside the country where it was collected; details are deferred to the main Privacy Policy.
4. User Rights
Subject to applicable law, users may have rights to:
- Access Personal Information.
- Update or correct it.
- Delete it.
- Make other privacy requests described in the main Privacy Policy.
Account holders may contact dpo@unity3d.com. The notice does not specify response deadlines, identity-verification requirements, appeal procedures, or whether all AI prompts and Outputs can be deleted. Those details are in the main Privacy Policy and applicable law.
5. Key User Obligations and Restrictions
Users should:
- Avoid submitting confidential, sensitive, or third-party personal information without authorization.
- Understand that prompts may be reproduced in Outputs.
- Comply with Unity’s terms, licenses, and applicable Additional Terms.
- Not use the AI Tools if under 13; Unity states they are not intended for children under 13.
- Obtain necessary permissions for uploaded content and personal data.
- Review Outputs before relying on them; the notice does not guarantee accuracy, originality, confidentiality, or suitability.
6. Liability and Disputes
This notice contains no specific liability disclaimer, warranty terms, governing-law clause, arbitration provision, class-action waiver, or dispute-resolution procedure. Those issues are likely addressed in Unity’s Terms of Service, license agreements, or other applicable terms—not this privacy notice.
The notice does state that Unity may process information for legal compliance, fraud prevention, security, and license enforcement. Users should not assume this notice creates contractual promises about confidentiality, deletion, security, or AI performance.
7. Retention and Policy Changes
Unity retains information as long as needed or permitted for the purposes collected, while the relationship continues, when legally required, or when needed for legal claims, investigations, or regulatory matters. No fixed retention period is provided.
Unity may change its practices and notice at any time. It may send an email or provide notice within some or all offerings, but it also encourages users to check the notice regularly. There is no guaranteed advance notice or explicit consent requirement for every change.
Legal
Unity Legal Information: Key User Implications
> Important: This document is primarily an index and summary of Unity’s legal terms. It does not provide the full Terms of Service, Privacy Policy, DPA, or dispute provisions. The linked agreements control, so users should review the terms applicable to their product, plan, location, and role.
1. Data Collection & Usage
The document does not list specific categories of personal data collected. It directs users to Unity’s Privacy Hub and Data Processing Addendum (DPA) for details.
Based on the summary, Unity distinguishes between:
- Data processed to operate its products and services
- User-controlled project materials and content
- Other account, usage, support, billing, or technical information likely addressed in the Privacy Policy
A significant stated limitation is that Unity “will not use your project materials for product improvements unless authorized by you.” However, this wording does not necessarily mean that all user-related data is excluded from analytics, security, service operation, or product improvement. The full Privacy Policy should be checked for definitions and exceptions.
The DPA governs processing of personal information where applicable, particularly when Unity acts as a processor for a business customer.
2. User Rights
The document does not specify individual rights directly. Rights are governed by the Privacy Hub and DPA and may depend on the user’s jurisdiction and account type.
Potential rights may include:
- Accessing personal information
- Correcting or deleting information
- Restricting or objecting to certain processing
- Data portability
- Withdrawing consent where processing relies on consent
- Complaining to a data protection regulator
Business customers should review the DPA for allocation of responsibilities, including handling data-subject requests, security obligations, and international transfers.
3. Third-Party Sharing
The summary states that Unity may selectively resell third-party software products and cloud services. It does not explain the full extent of data sharing with those providers.
Users should examine the Privacy Policy and relevant service terms for:
- Service providers and subprocessors
- Payment providers, especially for Unity IAP and Webshop services
- Advertising, analytics, hosting, and support providers
- Legal, regulatory, security, or corporate transaction disclosures
- International data transfers
Use of third-party products may also subject users to separate third-party terms and privacy policies.
4. AI and Machine-Learning Training
Unity has clarified that AI agents, assistants, and automated tools may access the platform through an authorized framework.
The document expressly says Unity will not use project materials for product improvements unless authorized by the user. This suggests project content is not automatically used to train or improve Unity AI/ML systems, but the statement is not a complete AI-training policy.
Key uncertainties requiring review of the full terms include:
- What counts as “project materials”
- Whether prompts, metadata, telemetry, or outputs are treated differently
- How authorization is obtained or withdrawn
- Whether third-party AI tools connected to Unity have separate data practices
5. Key User Obligations
Users are responsible for:
- Their own account activity
- Any AI agent, assistant, script, or automated tool acting through their account
- Complying with the applicable Unity and product-specific terms
- Following Asset Store licenses and any asset-specific restrictions
- Complying with payment, subscription, advertising, webshop, and third-party service rules
- Protecting account credentials and preventing unauthorized access
Users should be particularly cautious when granting automated tools account access, because actions taken by those tools may be treated as the user’s actions.
Unity also clarified auto-renewals, Enterprise plans, support procedures, and account closure. These may create continuing payment or access obligations, so renewal and cancellation terms should be reviewed carefully.
6. Liability & Disputes
This document provides no substantive dispute-resolution or liability terms. Those provisions are likely in the Unity Terms of Service and applicable Additional Terms.
Users should check for:
- Warranty disclaimers
- Liability caps and exclusions
- Indemnification duties
- Governing law and venue
- Arbitration or class-action restrictions
- Suspension or termination rights
- Treatment of prepaid fees and account closure
Different products—such as Asset Store, Webshop, Rewards, or third-party services—may impose additional rules.
7. Changes and Notice
The update is stated to be effective June 30, 2026. Unity says it has updated its terms and directs users to review the individual agreements.
The document does not explain the required notice method for future changes. Users should determine from the Terms of Service whether notice may be provided by:
- Website posting
- In-product notification
- Continued use of the services
Continued use after the effective date may constitute acceptance, depending on the applicable agreement.
Privacy Policy
Privacy Policy Overview
Important Scope Limitation
The text provided is primarily a privacy-policy hub or index, not the full Developer Privacy Policy, Game Player/App User Policy, Cookie Policy, DPA, or Generative AI Notice. It identifies several separate documents but does not include their detailed terms. Accordingly, many important rights, obligations, retention periods, sharing practices, and legal remedies cannot be confirmed from this text alone.
1. Data Collection and Use
Unity states that it may collect or receive Personal Information through:
- Developer Services, including websites and services used by parties developing or distributing games or apps using Unity technology.
- Applications owned by third parties that use Unity technology, in the case of game players and app users.
- Offline interactions, such as phone calls, industry events, or visits to Unity business locations.
- Cookies and similar technologies, including for functionality, analytics, personalization, and advertising.
- Generative AI tools, which are covered by a separate supplemental notice.
The excerpt does not specify the categories of information collected—for example, account details, device identifiers, usage data, precise location, payment information, or communications—or the precise purposes, retention periods, or legal bases for processing. Those details must be reviewed in the applicable full policy.
2. User Rights
The excerpt does not list specific user rights. Depending on the user’s location and role, the full policies may address rights such as:
- Accessing or obtaining a copy of personal information
- Correcting inaccurate information
- Deleting information
- Restricting or objecting to processing
- Data portability
- Opting out of certain advertising or sale/sharing activities
- Withdrawing consent
- Filing a complaint with a data-protection authority
Rights may differ between developers, customers, game players, app users, school users, and users of Generative AI Tools. The applicable policy and local law will control.
3. Third-Party Sharing
The documents indicate that Unity may share or disclose information as described in its applicable privacy policies. The hub specifically refers to:
- Sub-processors: Third-party companies processing personal data for Unity, listed under the DPA.
- Cookies and advertising partners: Third parties may receive information for analytics, personalization, and advertising.
- Unity-powered third-party apps: Unity may process information collected through apps owned by other companies.
- International transfers: The DPA materials reference EU/UK/Swiss Standard Contractual Clauses, indicating that data may be transferred internationally.
The excerpt does not identify the actual recipients, categories of data shared, or whether information is sold or shared for targeted advertising.
4. AI/ML Training
A separate Generative AI Supplemental Privacy Notice covers Personal Information collected through Generative AI Tools. However, this excerpt does not state whether user inputs, outputs, prompts, uploaded files, usage data, or other information are used to train or improve AI models.
Users should not assume that data is excluded from model training. The AI supplement should be checked specifically for:
- Training or model-improvement rights
- Human review
- Retention of prompts and outputs
- Opt-out mechanisms
- Use of submitted confidential or proprietary information
5. Key Obligations
No substantive user obligations or restrictions appear in the excerpt. However, the DPA is incorporated into the Unity Terms of Service and may impose obligations on business customers, particularly concerning:
- Lawful collection and instructions for processing
- Security and confidentiality
- Data-subject requests
- Breach notifications
- International transfers
- Use of approved sub-processors
The FAQ expressly warns that Unity does not provide legal advice. Businesses remain responsible for determining whether their own data practices comply with applicable law.
6. Liability and Disputes
The provided text contains no liability caps, warranties, indemnities, governing-law provisions, arbitration clauses, forum-selection terms, or dispute procedures. These are likely located in the Terms of Service, DPA, or other contractual documents rather than this privacy-policy hub.
7. Changes and Notice
The excerpt does not explain how policy changes are communicated. It references multiple separate notices and amendments, including updated international-transfer clauses. Users should check:
- The “last updated” date of each applicable policy
- Whether changes are posted online, emailed, or announced in-product
- Whether continued use constitutes acceptance
- Whether material changes receive advance notice
Main Practical Risks
The largest risks are uncertainty about data categories, third-party recipients, international transfers, retention, AI training, and available remedies. Users should review the complete policy applicable to their role, the Cookie/Advertising Policy, the Generative AI Notice, and—if acting as a business—the Terms of Service and DPA before submitting sensitive or confidential information.
Change history
2026-09-06 · Generative AI Privacy Notice
Summary of Important Changes
1. Expanded and clarified scope
- The notice is now expressly limited to Personal Information collected through use of Unity’s AI Tools.
- It refers users to Unity’s main Privacy Policy for account data, other products and services, sharing, transfers, safeguards, and privacy rights.
- “Developer Data” imported or linked through the Unity Cloud Dashboard is expressly defined and will be used as instructed by the developer, subject to applicable additional terms and documentation.
2. AI training and model-improvement uses
Important change
- The previous language expressly stated that Personal Information could be used for “training and enhancing our machine learning algorithms.”
- The revised language replaces that simple statement with broader and more detailed purposes, including:
- Research to improve the accuracy, effectiveness, usability, or popularity of AI Tools;
- Data analysis and testing;
- Improving AI Tool efficiency and maintenance;
- Analytics, reporting, and identifying usage trends;
- Developing, enhancing, improving, or modifying current and future products and services;
- Understanding user preferences and personalizing interactions or offers.
Legal and practical risk
- Although the revised text is more specific in some respects, it still permits broad use of Personal Information for AI improvement and related business purposes.
- The revised notice states that these activities may be based on user consent or Unity’s legitimate interest. This may reduce the need for express consent in some jurisdictions and could make opting out more difficult.
- The retention section continues to identify training and enhancement of machine-learning algorithms as a retention purpose. No specific deletion period for training data, model inputs, outputs, or derived model artifacts is provided.
3. Broader analytics and personalization
- The prior focus on aggregated trend reports about AI Tool usage is expanded to include:
- Predicting or analyzing user preferences;
- Personalized services and tailored content or offers;
- Promotional-campaign effectiveness;
- Business and product-development decisions.
- This creates additional profiling and personalization risks, particularly where legitimate interest rather than consent is relied upon.
4. Aggregation and anonymization
- Unity may aggregate or anonymize Personal Information so it is no longer considered Personal Information.
- The revised language allows resulting data to be used for developing, enhancing, modifying, and operating products and services, and states it may be used or disclosed for any purpose.
- Risk: the notice does not explain the anonymization methodology, re-identification safeguards, or whether users can object before data is transformed and reused.
5. Security, compliance, and monitoring purposes
The revised purposes expressly add or clarify processing for:
- Fraud, identity-theft, cyberattack, and criminal-activity prevention;
- Audits and legal, regulatory, or contractual compliance;
- Monitoring and security operations;
- Internal-process testing and reporting.
6. Children and retention
- The revised text retains the under-13 restriction but states that AI Tools are not intended for children under 13, rather than simply emphasizing non-collection.
- Retention criteria are expanded to include ongoing relationships, consent or legitimate interest, legal obligations, and litigation or regulatory considerations. No definite AI-training retention limit is stated.
2026-09-04 · Generative AI Privacy Notice
Summary of Important Changes
1. AI-training language removed or narrowed
- The prior notice expressly stated that Unity used Personal Information for “training and enhancing” machine-learning algorithms to improve its Services.
- That express AI-training purpose appears to be deleted and replaced with broader purposes, including:
- Business reporting;
- Personalized services;
- Analyzing or predicting user preferences;
- Preparing aggregated usage reports;
- Improving websites and Services; and
- Operational improvements.
- The revised language therefore no longer clearly says that Personal Information is used to train models. However, it also does not expressly prohibit such use. The broader “improve the Services,” analytics, and operational-improvement purposes could potentially encompass model training or fine-tuning.
Risk: The change may reduce transparency rather than eliminate AI-training risk. Users may have difficulty determining whether Prompts, Outputs, account data, or usage data are used to train generative-AI or machine-learning systems.
2. Broader description of data covered
The revised notice expressly covers:
- Unity account data;
- Data collected from use of Unity AI Tools;
- Other data collected through Unity’s Sites, Products, and Services; and
- Data generated from use of the AI Tools.
The notice continues to define user-submitted code, images, audio-visual content, data, and other materials as “Prompts,” with AI-generated responses defined as “Outputs.” Personal or confidential information included in Prompts remains within the collection framework.
Risk: Customers should not assume that confidential information included in Prompts is excluded from Unity’s processing or model-improvement activities.
3. New aggregation and anonymization rights
The revised language states that Unity may aggregate and/or anonymize Personal Information so it is no longer considered Personal Information, then use and disclose the resulting data for any purpose.
Risk: The notice does not explain the anonymization standard, whether data can be reidentified, or whether anonymized data may be used to develop or train AI models. “Any purpose” is materially broad.
4. Legal bases are reorganized and potentially broadened
The revised notice identifies contractual necessity, legal obligations, consent, and legitimate interests as possible bases. Legitimate interests expressly include operational improvements, service offerings, personalization, analytics, and responding to customers.
Risk: Reliance on legitimate interests may allow processing without separate consent, subject to applicable law and balancing requirements. The notice does not provide a specific opt-out for AI training or model improvement.
5. Retention language changed
Retention is now described as lasting as long as needed or permitted based on the purpose, ongoing account or Service use, legal obligations, and Unity’s legal position.
Risk: No specific retention period is provided, including for Prompts, Outputs, or data used for analytics or AI development.
6. Other notable changes
- Children’s language is clearer: Unity states it does not knowingly collect information from children under 13 and will delete it if collected without verified parental consent.
- The notice relies more heavily on Unity’s main Privacy Policy for sharing, transfers, safeguards, and privacy rights.
- Unity expressly reserves the right to change its practices and the notice, with users encouraged to check the page regularly.
2026-09-03 · Legal
Summary of Important Changes
1. Sub-processor notification method changed
- New process: Beginning July 30, updates to Unity’s sub-processor list will be posted on the list itself.
- Email notifications are no longer automatic: Customers must opt in to receive email alerts by contacting dpo@unity3d.com.
- Risk: Customers who do not opt in may not receive direct notice of new or replacement sub-processors. This could make it harder to monitor who processes customer data and to exercise any contractual objection or termination rights tied to sub-processor changes.
- Action: Customers should review Unity’s sub-processor list regularly and consider opting in for email notifications.
2. Other contractual areas identified as changing
The introductory language states that changes also concern:
- Auto-renewal;
- Enterprise plans;
- Support; and
- Account-closure procedures.
However, the supplied diff does not show the substantive revised wording for those provisions. Their legal impact cannot be assessed from this excerpt alone. Customers should review the referenced individual terms carefully, particularly for changes to renewal deadlines, cancellation rights, service suspension, support obligations, data deletion, and post-termination access.
3. Data use and AI-model training
- No provision in the supplied diff expressly changes how customer data is used to train AI models.
- The excerpt does not add or modify language granting Unity a right to use customer content, personal data, telemetry, or other customer information to train, fine-tune, evaluate, or improve AI models.
- The references to Unity’s Privacy Hub and Data Processing Addendum appear primarily editorial or navigational in this excerpt; no substantive AI-training permission is shown.
- Because the actual Privacy Hub, DPA, and linked product terms may contain relevant provisions, customers should separately verify whether those documents address:
- Training or improvement of AI systems;
- Use of customer content or prompts;
- Aggregated or de-identified data;
- Opt-out rights; and
- Retention or deletion after account closure.
4. Editorial and reference changes
Several changes merely standardize punctuation, quotation marks, possessives, or links. These do not appear to create material new obligations by themselves.
Overall assessment: The clearest substantive risk in this excerpt is the shift from direct sub-processor email notifications to a posting-and-opt-in model. No AI-training change is identifiable from the provided text.
2026-09-03 · Generative AI Privacy Notice
Summary
The provided diff does not include the actual contractual language. It only states that approximately 345 words were added. As a result, it is not possible to determine:
- What contractual provisions changed;
- Whether the customer’s data may be used to train AI models;
- Whether new data-sharing, licensing, confidentiality, or security rights were added;
- Whether liability, indemnity, termination, or compliance obligations changed; or
- Whether the added language creates new customer risks.
AI Training and Data Use
No substantive language addressing AI, machine learning, model training, model improvement, prompts, inputs, outputs, or use of customer data is included in the material provided. Therefore, no conclusion can be reached about whether customer data may be used to train or improve AI models.
Information Needed
Please provide the actual text of the diff, including:
- Additions in
{braces}; - Deletions in
[brackets]; and - Replacements in the format
[]{}.
Once the contractual wording is provided, the changes can be reviewed for AI-training rights and other legal risks.
2026-09-03 · Generative AI Privacy Notice
Key Changes and Risks
1. AI-training language removed or reframed
- The prior notice expressly stated that Unity could use Personal Information for the “purposes of training and enhancing our machine learning algorithms” to improve its Services.
- That express AI-training purpose is deleted and replaced with broader purposes, including:
- Managing the contractual relationship;
- Complying with legal obligations;
- Acting on consent or legitimate interests;
- Business reporting;
- Providing personalized services;
- Analyzing or predicting user preferences;
- Preparing aggregated usage reports; and
- Improving Unity’s websites and Services.
Risk assessment
The change does not clearly prohibit AI training. Instead, it removes a direct statement about training while retaining broad rights to analyze, personalize, improve, and generate data from user information. Unity could potentially characterize some model development or algorithm improvement as “improving the Services,” although the revised wording is less explicit about whether Prompts, Outputs, or other Personal Information will be used to train general-purpose AI models.
This creates uncertainty about:
- Whether user Prompts and Outputs are used for model training;
- Whether training is limited to service-specific models or includes broader/general-purpose models;
- Whether Confidential Information is excluded;
- Whether users can opt out; and
- How long training data or model-derived information is retained.
2. Broader data scope
The revised notice expressly covers:
- Unity account data;
- Data collected from use of Unity AI Tools;
- Other data collected through Unity’s Sites, Products, and Services; and
- Data collected as a result of using those services.
The notice also continues to describe Prompts as potentially containing code, images, audio-visual content, data, Personal Information, or Confidential Information. Users therefore remain exposed to risk if they submit sensitive, proprietary, or regulated information.
3. Expanded secondary-use rights
Unity may aggregate and/or anonymize Personal Information and generate “other data” for its use, which it may “use and disclose for any purpose.”
Risk
This is a significant commercial and privacy risk. The provision does not explain:
- The anonymization standard;
- Whether re-identification is prohibited;
- Whether derived datasets may be shared with affiliates or vendors; or
- Whether data generated from AI usage could be used for product development, analytics, or commercial purposes unrelated to the original request.
4. Legal bases are more generalized
The revised language organizes processing around contractual necessity, legal obligations, consent, and legitimate interests. However, many purposes—including personalization, analytics, and service improvement—may rely on legitimate interests rather than specific consent.
5. Retention is less specific
The notice now states that data is retained as long as needed or permitted based on the purpose, legal obligations, ongoing account relationship, or Unity’s legal position. No concrete retention period is provided, and there is no specific deletion period for Prompts, Outputs, training datasets, or model artifacts.
6. Other notable changes
- Children’s language is more complete: Unity states it does not knowingly collect information from children under 13 and will delete it absent verified parental consent.
- The notice relies more heavily on Unity’s main Privacy Policy for sharing, transfers, safeguards, and privacy rights.
- Unity reserves the right to change its practices and notice, with notice potentially provided only through some offerings.
Bottom line: The explicit AI-training disclosure is removed, but broad analytics, personalization, service-improvement, aggregation, and “any purpose” provisions preserve substantial flexibility and leave the treatment of AI training data unclear.
2026-09-02 · Generative AI Privacy Notice
Summary
The provided diff does not include the actual amended legal language. It only states:
> “Added approximately 345 words to the document”
As a result, it is not possible to determine:
- What contractual terms were added or changed;
- Whether customer data may be used to train, fine-tune, evaluate, or improve AI models;
- Whether such use requires customer consent or is automatic;
- Whether data is anonymized, aggregated, or otherwise protected;
- Whether the provider may share customer data with affiliates, vendors, or model providers;
- Whether the customer can opt out or request deletion;
- Whether new intellectual-property, confidentiality, privacy, security, or indemnity risks were introduced; or
- Whether the changes apply retroactively to previously submitted data.
AI-Training Review
No AI-training language appears in the supplied material. The statement that approximately 345 words were added is not sufficient to identify whether the additions:
- Authorize training on customer prompts, inputs, outputs, files, or other content;
- Permit retention of data for model development;
- Allow human review or use by third-party service providers;
- Grant the provider rights to commercialize models trained using customer data; or
- Restrict the customer’s ability to opt out.
Information Needed
Please provide the actual redlined text, using the stated notation:
- Additions:
{new language} - Deletions:
[deleted language] - Replacements:
[old language]{new language}
Once the substantive text is provided, the changes can be analyzed for legal effect, including any new or expanded rights to use customer data for AI training and related privacy, confidentiality, intellectual-property, and regulatory risks.
2026-09-02 · Legal
Summary of Important Changes
1. Sub-processor notification process
- The diff changes the description of sub-processor notifications.
- Deleted language: Unity would post sub-processor changes to its sub-processor list starting July 30 and offered email alerts by opting in at
dpo@unity3d.com. - Replacement language: The text now refers generally to “our ongoing commitment” to transparency and a stable platform, without expressly stating:
- when updates will be posted;
- that customers can opt in to email notifications; or
- the email address for opting in.
Risk and practical effect
This appears to reduce the specificity of Unity’s notification commitment. Customers may have less certainty about how, when, and where they will be informed of new or replacement sub-processors. Depending on the applicable DPA, this could affect customers’ ability to monitor subprocessors and exercise any objection or termination rights.
The diff appears repetitive and partially malformed, so the final published wording should be checked carefully.
2. Contract and service terms
The introductory language continues to direct customers to review individual terms concerning:
- auto-renewal;
- Enterprise plans;
- support; and
- account closure.
However, the supplied diff does not show the actual revised provisions governing those subjects. The excerpt therefore does not permit a meaningful assessment of whether renewal, termination, support obligations, or Enterprise-plan rights have substantively changed.
3. Asset Store Provider Agreement
- The wording changes from “providers' use” to “providers’ use”.
- This is a typographical or formatting correction only and does not appear to change legal meaning.
4. Privacy, intellectual property, and DPA references
- References to Unity’s privacy and intellectual-property positions are reformatted, including apostrophe and quotation-mark changes.
- The Unity Data Processing Addendum is described as incorporated into and forming an integral part of the Unity Terms.
- The changes shown are primarily typographical or editorial; no substantive amendment to the DPA’s processing obligations is visible in this excerpt.
5. AI-model training and customer data
- No express change concerning AI training was identified.
- The diff does not add or remove language authorizing Unity to:
- use customer content, prompts, telemetry, or personal information to train AI models;
- use data to improve machine-learning systems;
- retain data for model training; or
- exclude customer data from training.
- Any AI-training rights may exist elsewhere in the Terms, Privacy Hub, DPA, product-specific terms, or an acceptable-use policy and should be reviewed separately.
Overall assessment
The clearest potentially substantive change is the removal of specific sub-processor notification mechanics. The remaining visible edits appear mainly editorial, while the actual changes to auto-renewal, Enterprise plans, support, and account closure are not included in the provided text.
2026-09-01 · Generative AI Privacy Notice
Summary of Important Changes
1. Scope of the Notice
- The notice is now expressly limited to Personal Information collected through use of Unity’s AI Tools.
- Users are directed to Unity’s main Privacy Policy for data collected through other Unity sites, products, services, and account activity.
- The revised language more clearly states that AI-related processing may involve:
- Unity account data;
- Data generated through use of AI Tools; and
- Other data collected through Unity’s sites, products, and services.
Risk: The boundary between this notice and the main Privacy Policy is important. Users may need to consult both documents to understand the full range of processing and sharing.
2. AI Training and Model Improvement
Deleted or narrowed language
The prior text expressly stated that Unity processed Personal Information:
> “For the purposes of training and enhancing our machine learning algorithms, aimed at improving the Services we provide.”
That express AI-training purpose and its associated explanation of the legal basis have been removed.
New language
The revised text instead describes processing for:
- Business reporting;
- Personalized services;
- Analyzing or predicting user preferences;
- Preparing aggregated trend reports about AI Tool usage;
- Improving Unity websites and services; and
- Aggregating and/or anonymizing Personal Information.
Important interpretation: Removal of the express “training” wording does not necessarily mean Unity has stopped using customer data for AI training. The revised purposes—“improving” services, analyzing usage trends, and generating other data—could potentially include development, testing, fine-tuning, or evaluation of machine-learning systems. However, the revised notice is less explicit about whether Prompts, Outputs, or other customer content are used to train general-purpose models, internal models, or only to provide and improve the user’s service.
Risk: The revised language may create greater ambiguity and potentially broader discretion to use data for analytics, personalization, service improvement, or model-related activities without a specific training disclosure or clear opt-out.
3. Aggregated and Anonymized Data
- Unity now states that it may aggregate and/or anonymize Personal Information so it is no longer considered Personal Information.
- Unity may then use and disclose the resulting data “for any purpose.”
Risk: The notice does not explain the anonymization standard, whether re-identification testing is performed, or whether Prompt and Output data are included. If anonymization is incomplete, privacy and confidentiality risks may remain.
4. Legal Bases for Processing
The revised notice organizes processing around contractual necessity, legal obligations, consent, and legitimate interests.
Risk: Several activities—including service improvement, analytics, personalization, and potentially AI-related development—may rely on legitimate interest rather than specific consent. This can make objection or withdrawal rights more significant, but their practical availability is not explained in this notice.
5. Retention
- Retention language is now more general and based on the ongoing relationship, legal obligations, and Unity’s legal position.
- Specific references to fraud, cybersecurity, audits, maintenance, and operational purposes were removed.
Risk: No specific retention period is provided for Prompts, Outputs, or data used for analytics or model improvement. Data may potentially be retained while an account remains active or while Unity considers retention legally or operationally advisable.
6. Other Changes
- Children’s language is clearer: Unity states it does not knowingly collect information from children under 13 and will delete it absent verified parental consent.
- Unity reserves the right to change the notice and encourages users to check the page regularly.
2026-09-01 · Legal
Summary of Important Changes
1. Sub-processor notification process — material change
- Beginning July 30, updates to Unity’s sub-processor list will be posted on the online Sub-processor List.
- Customers will no longer necessarily receive direct email notifications automatically. To receive email alerts, customers must opt in by contacting
dpo@unity3d.com. - Risk: Customers may miss changes to vendors that process their data unless they actively monitor the list or complete the opt-in process. This could affect customers’ ability to review vendors, assess compliance obligations, or exercise any contractual objection rights within applicable deadlines.
- Customers should confirm:
- Whether the DPA provides a right to object to new sub-processors;
- When the objection period begins; and
- Whether posting to the list is sufficient notice under the contract.
2. AI model training and customer data
- The provided diff contains no express change authorizing or prohibiting Unity from using customer data, content, prompts, telemetry, or personal information to train, fine-tune, or improve AI models.
- The references to Unity’s Privacy Hub and Data Processing Addendum (DPA) appear to be organizational or formatting changes rather than substantive amendments to AI-training rights.
- Nevertheless, customers should review the linked Privacy Hub, DPA, and any product-specific terms for separate language addressing:
- Use of customer content or usage data to train AI models;
- De-identification or aggregation;
- Service improvement and analytics;
- Retention and deletion; and
- Whether enterprise data is excluded from model training by default or only upon request.
3. Other apparent changes
- The notice refers generally to updates concerning:
- Auto-renewal;
- Enterprise plans;
- Support; and
- Account-closure procedures.
- However, the supplied diff does not show the actual revised language for those subjects, so their legal effect cannot be determined from this excerpt.
- New or revised links to FAQs and policy pages may make external web content more important to the contractual relationship. Customers should preserve copies of the referenced terms and check whether Unity may update them unilaterally.
4. Drafting and formatting issues
- The diff contains duplicated and malformed text, including constructions such as
flowsSub-processor notificationsand inconsistent quotation marks around “DPA.” - These may be publication or extraction errors, but customers should obtain the final posted version and confirm which text controls.
2026-09-01 · Generative AI Privacy Notice
Summary
The provided diff does not include the text of the approximately 345 added words. It only states that new language was added.
Substantive Changes
- No contractual provisions are visible for review.
- It is therefore not possible to determine whether the additions change:
- The parties’ rights or obligations;
- Liability, indemnification, confidentiality, or security terms;
- Data ownership or permitted data uses;
- Service-provider access to customer data; or
- Termination, retention, or deletion requirements.
AI Training and Customer Data
- The supplied diff contains no visible language addressing whether customer data may be:
- Used to train, fine-tune, evaluate, or improve AI models;
- Combined with other customers’ data;
- Used to create aggregated, anonymized, or de-identified datasets;
- Reviewed by personnel or third-party providers for model development; or
- Retained after termination for AI-training or product-improvement purposes.
- No conclusion can be drawn about whether customer data is excluded from AI training, used only with consent, or used by default.
Risk Assessment
The risk cannot be assessed from the information provided. The actual 345 words are necessary to identify new permissions, limitations, safeguards, or customer-consent requirements.
Information Needed
Please provide the text of the additions and any associated deletions or replacements. The AI-training provisions should be reviewed specifically for:
1. The definition of “Customer Data” and whether prompts, outputs, files, metadata, or personal information are included;
2. Whether training or improvement uses are permitted by default or require opt-in consent;
3. Whether data is anonymized or de-identified before use;
4. Whether customer data may be shared with affiliates, contractors, or other customers;
5. Retention and deletion timelines; and
6. Audit rights, security commitments, and remedies for unauthorized use.
2026-08-31 · Legal
Summary
The diff states only that approximately 43 words were removed from the document. The actual deleted language is not provided.
AI Training and Customer Data
- No determination can be made about whether the changes affect the use of customer data to train AI models.
- The deletion could potentially remove:
- Permission to use customer data, prompts, outputs, or usage data for training or improving AI models;
- Restrictions or opt-out rights concerning AI training;
- Commitments to de-identify, aggregate, or protect customer data;
- Limitations on using data to train models shared with other customers or third parties; or
- Disclosure of whether human reviewers or service providers may access the data.
- Conversely, the deleted language could have imposed restrictions on AI training, meaning its removal could expand the provider’s rights. The direction of the legal change cannot be determined without the deleted text.
Other Legal Risks
Because the removed wording is unavailable, it is also impossible to assess whether the deletion changes:
- Data ownership or licensing rights;
- Confidentiality obligations;
- Security commitments;
- Data retention or deletion requirements;
- Liability, indemnity, or warranty provisions;
- Customer termination or audit rights; or
- Compliance obligations under privacy or data-protection laws.
Recommended Review
Obtain the actual redline or the 43 deleted words before accepting the change. Pay particular attention to any language referring to “customer data,” “content,” “inputs,” “outputs,” “usage data,” “machine learning,” “artificial intelligence,” “improve,” “train,” “develop,” “aggregate,” “de-identify,” or “service providers.”
2026-08-30 · Generative AI Privacy Notice
Key Changes and Legal Risks
1. AI-training language removed or narrowed
- The prior notice expressly stated that Unity may use Personal Information “for the purposes of training and enhancing our machine learning algorithms” to improve its Services.
- That express AI-training purpose appears to have been deleted.
- The replacement describes processing for:
- Business reporting;
- Personalized services;
- Usage trend reports;
- Website and Service improvements;
- Analytics and operational purposes; and
- Aggregating or anonymizing Personal Information.
Risk and interpretation
This is not necessarily a complete opt-out from AI training. The revised language still permits Unity to use data to improve AI Tools and generate other data. In particular, Unity may aggregate or anonymize Personal Information and then use or disclose the resulting data “for any purpose.” Depending on whether the data is truly anonymized, this could still support model development, testing, evaluation, or other commercial uses.
The revised notice does not clearly state:
- Whether Prompts or Outputs are used to train models;
- Whether Personal or Confidential Information in Prompts is excluded from training;
- Whether training is performed by Unity or third-party AI providers;
- Whether users can opt out;
- How long training data or model-derived data is retained; or
- Whether deletion requests can remove data already incorporated into models.
Users should not assume that removal of the express “training” reference guarantees that their data will not be used for AI development.
2. Broader and more flexible data-use framework
The notice now covers data resulting from use of Unity’s AI Tools, including account data and other data collected through Unity Sites, Products, and Services. It refers users to the main Privacy Policy for much of the detail.
Unity also adds purposes involving:
- Predicting user preferences;
- Personalized interactions, information, and offers;
- Aggregated usage reports; and
- General improvement of websites and Services.
These purposes are broader and less specific than the former operational list, creating greater uncertainty about secondary uses.
3. Legal bases changed
The revised language organizes processing around contractual necessity, legal obligations, consent, and legitimate interests. This may give Unity more flexibility to rely on legitimate interests, particularly for analytics, personalization, operational improvements, and business reporting.
The notice does not explain how users may object where legitimate interests are used.
4. Aggregated/anonymized data may be used indefinitely and broadly
Unity may aggregate or anonymize Personal Information so it is no longer considered Personal Information, then use or disclose the resulting data for any purpose. This creates a significant risk if anonymization is reversible or insufficient, especially for distinctive Prompts, code, or creative content.
5. Retention and policy changes
Retention is now tied to ongoing service use, legal obligations, and Unity’s legal position, including litigation and regulatory investigations. This provides no fixed deletion period.
Unity also expressly reserves the right to change its practices and the notice at any time, with notice potentially limited to an email or in-product communication.
2026-08-29 · Generative AI Privacy Notice
Summary
The provided diff does not include the actual contractual language. It only states:
> “Added approximately 345 words to the document”
Accordingly, it is not possible to determine:
- What provisions were added, deleted, or replaced;
- Whether liability, confidentiality, security, intellectual property, or termination terms changed;
- Whether the customer’s data may be used to train, fine-tune, evaluate, or improve AI models;
- Whether such use is subject to consent, opt-out rights, de-identification, aggregation, or customer-specific restrictions; or
- Whether the provider may share customer data with affiliates, subcontractors, or third-party model providers.
AI Training and Data-Use Risk
No conclusion can be drawn about AI-model training because the relevant added language is not included. The key terms to review would include:
- Training or improvement rights: permission to use customer content, prompts, outputs, or usage data to train or improve models;
- Scope of data: whether the right covers confidential information, personal data, uploaded files, metadata, or derived data;
- Consent mechanism: automatic permission versus affirmative consent or an opt-out;
- De-identification: whether data must be anonymized before use and how that is defined;
- Retention: how long data is retained for training or evaluation;
- Third-party access: disclosure to model providers, affiliates, or service providers;
- Ownership and feedback: rights in inputs, outputs, fine-tuned models, and improvements; and
- Regulatory protections: compliance with privacy, confidentiality, and data-protection laws.
Please provide the full marked-up text, including the words shown in {additions}, [deletions], and []{} replacements, for a substantive legal-risk analysis.
2026-08-28 · Generative AI Privacy Notice
Summary
The provided diff states only that approximately 345 words were removed. It does not identify the deleted language or show any replacement text.
AI Training and Data Use
- No determination is possible regarding whether the changes affect:
- Use of customer data to train, fine-tune, or improve AI models;
- Whether customer data may be used for generalized model training;
- Whether prompts, inputs, outputs, or usage metadata are retained;
- Any opt-out, consent, or deletion rights;
- Restrictions on human review or third-party AI providers; or
- Ownership and confidentiality of AI-generated outputs.
Potential Legal Risks
Because the deleted text is unavailable, the removal could have eliminated important customer protections, including:
- Limits on the provider’s ability to use customer data;
- Confidentiality, security, or data-processing obligations;
- Prohibitions on selling or sharing data;
- Restrictions on model training or product improvement;
- Data deletion and return obligations;
- Audit, compliance, or breach-notification rights;
- Liability, indemnity, or remedies provisions; or
- Service-level commitments and termination rights.
Alternatively, the deleted language may have removed provider permissions or operational terms, but that cannot be confirmed from the information supplied.
Required Information
To perform a meaningful legal comparison, the actual deleted text and any replacement language are required. In particular, provide the portions addressing:
- Customer data and confidential information;
- AI, machine learning, model training, or product improvement;
- Data retention, deletion, and security;
- Subprocessors and third-party services; and
- Ownership, licensing, and permitted uses of inputs and outputs.
Bottom line: The current diff is insufficient to identify any substantive contractual change or determine whether customer data may be used to train AI models.
2026-08-28 · Generative AI Privacy Notice
Summary
The provided diff does not include the actual added language. It only states:
> “Added approximately 345 words to the document”
Accordingly, it is not possible to determine:
- What contractual terms changed;
- Whether customer data may be used to train, fine-tune, or improve AI models;
- Whether any new data rights, licenses, or permissions were granted;
- Whether confidentiality, privacy, security, or retention obligations changed;
- Whether the customer assumes additional liability or indemnification obligations; or
- Whether the changes affect termination, deletion, audit, or regulatory-compliance rights.
AI-Training Review
No conclusion can be reached about AI-model training because the relevant text is missing. The added provisions should be reviewed specifically for language concerning:
- Use of customer data, prompts, inputs, outputs, content, or metadata;
- Training, retraining, fine-tuning, improving, developing, or evaluating models;
- Use of data in aggregated, de-identified, anonymized, or derived form;
- Whether use is automatic or requires the customer’s consent or opt-in;
- Whether data may be shared with affiliates, subprocessors, or third-party model providers;
- Retention and deletion of data used for training;
- Ownership of or license rights in customer content and model outputs; and
- Restrictions on using confidential, personal, regulated, or sensitive information.
Information Needed
Please provide the full text of the additions and any surrounding or replaced language. Without the actual wording, a substantive legal-risk analysis cannot be performed.
2026-08-27 · Generative AI Privacy Notice
Summary of Important Changes
1. AI scope and data covered
- The notice is more clearly limited to information collected through use of Unity’s AI Tools.
- It now expressly refers to:
- Unity account data;
- Data generated by use of the AI Tools; and
- Other data collected through Unity’s Sites, Products, and Services.
- Prompts and Outputs remain defined, and the notice continues to warn that personal or confidential information included in Prompts will be processed.
Risk: The expanded reference to account, AI-use, and broader Unity service data may make the boundary between AI data and non-AI data less clear. Customers should not assume that only the text of their Prompts is covered.
2. AI model training language removed or narrowed
- The previous text expressly stated that Unity could use information for “training and enhancing” machine-learning algorithms to improve its Services.
- That express purpose and its associated legal-basis language appear to have been removed in the revised text.
- The revised notice instead describes purposes such as:
- Preparing aggregated trend reports about AI Tool usage;
- Improving Unity websites and Services;
- Personalizing interactions and providing tailored information or offers; and
- Delivering content through Unity websites and Services.
Important risk: Although the explicit training authorization is no longer stated, the revised purposes—particularly improving Services, analyzing usage trends, and operational improvement—could still support development or refinement of AI systems depending on how Unity conducts those activities. The notice does not clearly say that Prompts or Outputs will not be used to train models, nor does it provide an opt-out, deletion mechanism for training data, model-retention limits, or restrictions on use of customer content in future models.
3. Broader secondary use of data
- Unity adds or emphasizes analysis of preferences, personalized services, and tailored offers.
- These activities may be conducted based on consent or Unity’s legitimate interests.
- Unity may aggregate or anonymize Personal Information and then use or disclose the resulting data “for any purpose.”
Risk: “Any purpose” is broad. Anonymization may reduce privacy protections, but the notice does not explain the technical standard, whether re-identification is prohibited, or whether derived datasets may be used for AI development.
4. Legal bases changed
- The revised notice reorganizes processing justifications around contractual necessity, legal obligations, consent, and legitimate interests.
- Some former purpose-specific descriptions are replaced with more general legal-basis language.
Risk: The broader reliance on legitimate interests may permit processing without affirmative consent, subject to applicable law and balancing requirements.
5. Retention, rights, and other changes
- Retention is now described by general criteria, including the customer relationship, legal obligations, and Unity’s legal position. No specific AI-training retention period is provided.
- Detailed AI-specific access, testing, maintenance, audit, and reporting language is replaced largely by references to the main Privacy Policy.
- Children’s protections are strengthened: Unity states it does not knowingly collect information from children under 13 and will delete improperly collected information.
- Unity expressly reserves the right to change the notice and encourages users to check it regularly.
Overall Assessment
The clearest change is removal of the express statement authorizing AI-model training. However, the revised language does not affirmatively prohibit training and leaves substantial ambiguity about whether AI-use data, Prompts, Outputs, or derived information may be used to develop or improve models.
2026-08-25 · Generative AI Privacy Notice
Summary of Important Changes and Risks
1. Scope and organization
- The notice is reframed to cover Personal Information collected through use of Unity’s AI Tools, rather than describing Unity’s broader processing activities.
- Much of the detailed information about transfers, safeguards, privacy rights, sharing, and retention is removed from this notice and replaced with references to Unity’s main Privacy Policy.
- Users must therefore consult multiple documents to understand the full processing terms, increasing the risk that important limitations or rights are less visible.
2. Use of customer data for AI training
Explicit training language removed
The prior notice expressly stated that Unity could use information for:
> “the purposes of training and enhancing our machine learning algorithms”
That language is removed from the listed purposes and from the retention section.
Replacement language remains broad
The revised notice authorizes processing for purposes including:
- Research to improve the accuracy, effectiveness, usability, or popularity of AI Tools;
- Data analysis and testing;
- Improving AI Tool efficiency and maintenance;
- Developing, enhancing, improving, or modifying Unity’s products and services;
- Identifying usage trends and determining which services interest users;
- Personalization and preparing aggregated trend reports.
Although “training machine learning algorithms” is no longer stated expressly, these replacement purposes could still encompass model evaluation, tuning, development, or other AI-related improvement activities. The notice does not clearly say whether Prompts, Outputs, or Personal Information are excluded from model training.
Aggregated or anonymized data
Unity may aggregate or anonymize Personal Information so it is no longer considered Personal Information, then use and disclose the resulting data for any purpose, including developing new products and services. This creates a significant residual risk because:
- The notice does not define the anonymization standard;
- It does not explain whether prompts or outputs may be incorporated into derived datasets;
- “For any purpose” is materially broad;
- Re-identification or confidential-information leakage risks are not addressed.
3. Customer and developer data
The revised language states that Unity will otherwise use Developer Data imported or linked through the Unity Cloud Dashboard as instructed by the customer. This is potentially favorable, but the scope and interaction with AI improvement purposes are unclear. Customers should verify whether separate Unity Developer Data Additional Terms impose different permissions or restrictions.
4. Legal bases and retention
- The revised notice relies more heavily on contractual necessity, legal obligations, consent, and legitimate interests.
- Processing for analytics, personalization, and AI Tool improvement may be based on Unity’s legitimate interests, rather than necessarily requiring consent.
- Retention is described broadly, including retention while an account or relationship continues, for legal obligations, or for Unity’s legal position. No specific retention period is provided.
- The prior explicit training-retention statement is removed, but broad retention for analytics and business purposes remains.
5. Children and other risks
- The under-13 restriction remains, but the revised text says Unity will delete information it believes came from a child without verified parental consent.
- The notice continues to direct users to the main Privacy Policy for rights, sharing, safeguards, and international transfers.
- Overall, the revision narrows the express training authorization but preserves broad AI improvement, analytics, derived-data, and legitimate-interest permissions.
2026-08-25 · Generative AI Privacy Notice
Key Changes and Risks
1. AI-training language removed or materially narrowed
- The prior notice expressly stated that Unity used Personal Information for “training and enhancing” its machine-learning algorithms to improve its Services.
- That express purpose is deleted in the revised language. The new notice instead describes processing of:
- Unity account data;
- data resulting from use of Unity AI Tools; and
- other data collected through Unity Sites, Products, and Services.
- The revised text refers generally to managing the contractual relationship, legal obligations, consent, and legitimate interests, but does not clearly state whether Prompts, Outputs, or other AI-use data will be used to train or improve AI models.
Risk/impact: This creates ambiguity rather than a clear prohibition on training. The deletion may reduce transparency, but the broader data-processing language and references to service improvement, analytics, personalization, and aggregated data could still support model-improvement activities. Customers should not assume that AI inputs are excluded from training.
2. Prompts may contain sensitive information
- The notice continues to cover user-submitted code, images, audio-visual content, data, and other materials (“Prompts”) and generated “Outputs.”
- It states that if users include personal or confidential information in Prompts, Unity will process it.
Risk/impact: Users bear a significant practical risk if they submit trade secrets, proprietary code, personal data, or regulated information. The notice does not appear to provide a specific commitment that such content will not be used for training, disclosed to model providers, or retained only briefly.
3. Broader use of aggregated/anonymized data
- Unity may aggregate and/or anonymize Personal Information so it is no longer considered Personal Information.
- The resulting data may be used and disclosed “for any purpose.”
Risk/impact: This is a broad residual-use right. The notice does not explain the anonymization standard, re-identification safeguards, or whether derived datasets, usage patterns, or model-training artifacts could be retained indefinitely.
4. Legal bases are reorganized and broadened
- The revised notice repeatedly identifies contractual necessity, legal obligations, consent, and legitimate interests as bases for processing.
- Legitimate interests expressly include operational improvements, business reporting, personalization, service offerings, and analytics.
Risk/impact: Reliance on legitimate interests may permit processing without a separate opt-in, depending on applicable law. The notice does not identify a dedicated opt-out for AI improvement or model training.
5. Retention framework changed
- Retention is now tied to the purpose of collection, applicable law, the customer relationship, continued Service use, legal obligations, and Unity’s legal position.
- This replaces more specific operational-retention descriptions.
Risk/impact: The revised standard remains open-ended and may permit retention for as long as an account or relationship continues, including for litigation or regulatory purposes.
6. Other notable changes
- Scope is clarified as applying specifically to AI Tools, with the main Privacy Policy governing other processing.
- Unity may change the notice and encourages users to check the page regularly.
- Children’s language is more explicit: Unity states it does not knowingly collect information from children under 13 and will delete it upon discovery, subject to parental-consent qualifications.
2026-08-23 · Generative AI Privacy Notice
Summary
Information Provided
The diff only states:
> “Added approximately 345 words to the document”
It does not include the actual added language, deleted language, or replacement language.
Legal and Risk Analysis
No substantive legal analysis is possible without the text of the changes. In particular, it is not possible to determine whether the amendments:
- Permit the customer’s data to be used to train, fine-tune, validate, or improve AI models;
- Expand the provider’s rights to access, retain, analyze, or share customer data;
- Distinguish between customer content, personal data, metadata, prompts, outputs, or usage data;
- Apply data-use permissions to human review, automated processing, or third-party service providers;
- Make training rights opt-in, opt-out, unconditional, or limited to de-identified or aggregated data;
- Change confidentiality, security, data-retention, deletion, or intellectual-property obligations;
- Allocate responsibility for model outputs, data leakage, or regulatory compliance; or
- Add rights to use customer data after termination.
Key Limitation
Because the actual redline is missing, no new risks or changes can be reliably identified. The statement that approximately 345 words were added does not reveal whether those additions are favorable, unfavorable, or merely administrative.
Information Needed
Please provide the full diff, including:
- Added text in
{braces}; - Deleted text in
[brackets]; and - Replacements in the specified
[]{}format.
Once provided, the changes can be analyzed for AI-training permissions, data ownership, confidentiality, privacy, security, retention, and liability risks.
2026-08-22 · Generative AI Privacy Notice
Summary of Important Changes
1. Scope of the Notice Expanded and Clarified
- The notice now expressly applies to personal information collected through use of Unity’s AI Tools, rather than more generally through Unity products.
- It clarifies that AI-related processing may include:
- Unity account data;
- Data generated through use of the AI Tools; and
- Other data collected through Unity’s sites, products, and services.
- Users are directed to Unity’s main Privacy Policy for broader information about data processing, rights, sharing, transfers, and safeguards.
Risk: Users may need to consult multiple policies to understand the complete data lifecycle. The boundary between AI Tool data and other Unity data remains broad.
2. Prompts and Confidential Information
- The notice continues to define user-submitted code, images, audio-visual content, and other materials as “Prompts,” with AI-generated responses defined as “Outputs.”
- It expressly warns that users may include personal or confidential information in Prompts.
Risk: The diff does not provide a clear restriction stating that confidential information will not be used for model training, disclosed to service providers, or retained beyond producing the Output. Customers should avoid submitting trade secrets, personal data, or other sensitive material unless separate contractual protections apply.
3. AI Training Language Changed
- The prior language expressly authorized use of personal information “for the purposes of training and enhancing” Unity’s machine-learning algorithms to improve the Services.
- That express training purpose appears to have been removed or replaced in the revised text with broader purposes, including:
- Business reporting;
- Personalized services;
- Analysis and prediction of user preferences;
- Aggregated trend reports about AI Tool usage; and
- General service and website improvement.
- The revised text also states that Unity may aggregate or anonymize personal information to generate other data for its use, which it may “use and disclose for any purpose.”
Risk: Although the standalone training authorization appears narrower or removed, the revised purposes remain broad enough that AI Tool data could potentially support model development, analytics, personalization, or other product activities. The notice does not clearly state whether Prompts or Outputs are excluded from training, whether data is de-identified before training, how long training data is retained, or whether users can opt out.
4. Legal Bases for Processing
- The revised notice presents multiple possible bases for processing: contract, legal obligation, consent, and legitimate interests.
- Processing for personalization, analytics, and related activities may rely on legitimate interests rather than consent.
Risk: “Legitimate interest” may permit processing without a separate opt-in, subject to applicable law and objection rights. The notice does not identify which specific AI-data uses rely on which legal basis.
5. Aggregation, Anonymization, and Disclosure
- Unity may aggregate or anonymize personal information so it is no longer considered personal information.
- Resulting data may be used and disclosed for any purpose.
Risk: There is no detail about the anonymization standard, re-identification safeguards, or whether source Prompts and Outputs are irreversibly anonymized. This language may reduce users’ ability to control downstream use of derived datasets.
6. Retention and Other Changes
- Retention language is more general: information is retained as long as needed or permitted for the relevant purpose and consistent with law.
- Retention criteria include the ongoing relationship, service provision, legal obligations, and litigation or regulatory needs.
- The notice adds clearer children’s privacy language and a general reference to security safeguards and international transfers.
Overall assessment: The revised notice improves structure and cross-references but leaves material uncertainty about whether AI inputs and Outputs may be used to train or improve models. A customer seeking protection should request express contractual language prohibiting training or requiring prior consent, deletion, limited retention, confidentiality, and an opt-out mechanism.
2026-08-21 · Legal
Summary of Important Changes
1. Sub-processor notification process
Change: Unity will change how it notifies customers about Sub-processor updates. Beginning July 30, updates will be posted to Unity’s Sub-processor list. Customers who want email alerts must opt in by contacting dpo@unity3d.com.
Legal/practical impact:
- This appears to replace or reduce any automatic, direct notification obligation with a web-posting and opt-in email model.
- Customers may need to monitor the Sub-processor list themselves or affirmatively request email notifications.
- Failure to opt in could result in customers not receiving timely notice of new or changed Sub-processors.
- Customers should verify whether the underlying DPA permits this notification method and whether it preserves any objection, termination, or other rights triggered by a Sub-processor change.
- The effective date—July 30—should be confirmed, including the applicable year and whether existing customers must separately opt in.
2. References to other contractual changes
The introduction states that changes were made to:
- Auto-renewal language;
- Enterprise plan terms;
- Support processes; and
- Account-closure processes.
However, the supplied diff does not show the substantive wording of those changes. Their legal effect cannot be assessed from this excerpt. The updated terms should be reviewed separately for changes to renewal deadlines, cancellation rights, service termination, data deletion, support commitments, or post-termination access.
3. Data use and AI model training
No express change concerning AI training was identified in the supplied diff.
The excerpt contains general references to Unity’s Privacy Hub, collection, use, and disclosure of information, and the Data Processing Addendum. It does not add or modify language expressly authorizing Unity to:
- Use customer data, content, prompts, telemetry, or personal information to train AI models;
- Retain data for model training;
- Share data with AI providers for training; or
- Opt customers in or out of AI-training activities.
Because the diff references the Privacy Hub and DPA, customers should nevertheless compare those documents for any separate AI-related provisions. The absence of an AI-training change in this excerpt does not confirm that no such language exists elsewhere.
4. Other changes
The remaining edits appear primarily editorial or navigational, including revised links, headings, punctuation, and possessive formatting. No material change to intellectual-property ownership, privacy rights, or licensing obligations is apparent from those edits alone.
2026-08-20 · Legal
Key Changes
1. Sub-processor notification process — Potentially important
- The prior language stated that, beginning July 30, sub-processor changes would be posted to Unity’s sub-processor list and that customers could opt in to email alerts at
dpo@unity3d.com. - The revised language appears to replace those specific details with a general statement that the changes are part of Unity’s “ongoing commitment” to transparency.
- The diff is malformed and repeats portions of the text, so it is unclear whether:
- the sub-processor list will still be updated;
- email notifications will still be available; or
- the July 30 effective date remains applicable.
Risk: Customers may lose a clear contractual or practical notification mechanism and may need to monitor Unity’s website themselves. This could affect the time available to object to new sub-processors or assess data-transfer risks. The final language should expressly confirm the notification method, timing, and objection rights.
2. Broader terms-update introduction
- References to changes involving auto-renewal, Enterprise plans, support, and account-closure procedures appear to remain, but the text now emphasizes that these are part of Unity’s ongoing transparency efforts.
- The revision directs customers to review the individual terms for details and references frequently asked questions.
Risk: The introductory language does not itself explain the substantive changes. Customers must review the linked or incorporated documents to identify operational or financial consequences.
3. Asset Store terminology
- “providers’” replaces “providers'.”
Impact: Non-substantive typographical or punctuation correction. No apparent change to rights or obligations.
4. Privacy and intellectual-property information
- “Unity's” is changed to the typographically equivalent “Unity’s.”
- The Privacy Hub is still described as covering Unity’s collection, use, and disclosure of information.
- The DPA remains incorporated into the Unity Terms.
Impact: No substantive privacy or data-processing change is apparent from this diff.
5. AI-model training
- No express change addresses the use of customer data to train, fine-tune, evaluate, or improve AI models.
- The excerpt does not add or remove any AI-training authorization, opt-out right, data-retention rule, or restriction on using customer content for model development.
- Because the Privacy Hub, DPA, and linked terms may be incorporated by reference, those documents should be reviewed separately for AI-related provisions.
Overall Assessment
The principal potential risk is the apparent removal or obscuring of specific sub-processor notification procedures. Most other changes are editorial, introductory, or cross-reference updates. The redline should be clarified before acceptance because its formatting makes the intended legal effect uncertain.
2026-08-20 · Legal
Summary
The provided diff does not include the actual contract language. It only states that “approximately 43 words” were added. Without the text of those additions—or the surrounding provisions—it is not possible to determine:
- What contractual obligations or rights changed;
- Whether liability, indemnity, confidentiality, or termination terms were affected;
- Whether customer data may be collected, accessed, retained, disclosed, or transferred differently; or
- Whether the customer’s data may be used to train, fine-tune, evaluate, or improve artificial intelligence models.
AI Training and Data-Use Review
No specific change concerning AI model training or customer-data use can be identified from the information provided. The added language should be reviewed for terms such as:
- “train,” “fine-tune,” “develop,” “improve,” or “enhance” models;
- “inputs,” “outputs,” prompts, files, or other customer content;
- rights to use data in “de-identified,” “aggregated,” or anonymized form;
- data-retention or deletion periods;
- sharing with affiliates, vendors, or model providers; and
- opt-out, consent, or restrictions on using customer data for model development.
Risk Assessment
Because the 43 added words are not shown, the legal and commercial risk cannot be assessed. In particular, it is unclear whether the amendment:
1. Expands the provider’s license to customer data;
2. Permits use of customer data for AI training without separate consent;
3. Allows retention of data after termination;
4. Removes confidentiality or security protections; or
5. Shifts responsibility to the customer for AI-generated outputs or data-related claims.
The actual added language and any affected surrounding provisions are required for a reliable analysis.
2026-08-19 · Legal
Summary of Important Changes
1. Sub-processor notification process — potentially significant
The previous language stated that:
- Sub-processor changes would be posted to Unity’s sub-processor list beginning July 30; and
- Customers could opt in to receive email alerts by contacting
dpo@unity3d.com.
That language has been replaced with a general statement that the changes are part of Unity’s “ongoing commitment” to transparency and providing a stable platform for creators.
Legal and practical risks
- The revised text appears to remove the express commitment to post changes from a specified date.
- It also removes the express email-alert opt-in process.
- Customers may therefore have less certainty about how, when, and where they will be notified of new or changed sub-processors.
- If the DPA or applicable law gives customers objection or termination rights following a sub-processor change, the reduced notice language could make it harder to identify when those rights are triggered.
- The change may be merely editorial if a separate DPA or sub-processor policy contains the operative notification obligations. Those documents should be checked.
2. General terms and Enterprise/support language
The introduction refers to changes concerning:
- Auto-renewal;
- Enterprise plans;
- Support; and
- Account-closure processes.
However, the supplied diff does not show the actual revised provisions for those topics. The repeated and concatenated text suggests the redline may be incomplete or technically corrupted.
Recommendation: Do not rely on this excerpt alone to assess those changes. Obtain the complete clean and redlined versions of the relevant terms.
3. Privacy, DPA, and intellectual-property references
The changes to:
- “Unity's” to “Unity’s”;
- “providers'” to “providers’”; and
- quotation marks around “DPA”
appear to be typographical or formatting updates only. No substantive change to rights, obligations, data processing, or intellectual-property ownership is apparent from this excerpt.
4. AI-model training and use of customer data
No express change concerning AI training is shown.
The diff does not add or remove language stating whether Unity may:
- Use customer data, content, prompts, telemetry, or other inputs to train or improve AI models;
- Use data to train models operated by Unity or third parties;
- Use de-identified, aggregated, or derived data for AI development; or
- Exclude customer data from model training.
Because the excerpt is incomplete and references the Privacy Hub and DPA, those documents should be separately reviewed for any AI-training, machine-learning, data-use, or service-improvement provisions.
2026-08-18 · Legal
Summary of Important Changes
1. Sub-processor notification process — material change
- Beginning July 30, updates to Unity’s sub-processor list will be posted on the Sub-processor list rather than apparently being provided through the prior notification process.
- Customers who want email notifications must opt in by contacting
dpo@unity3d.com. - Risk: Customers who do not opt in may no longer receive direct email notice of new or changed sub-processors. This could reduce practical visibility into vendors that process customer data and may make it harder to exercise contractual objection or review rights within any applicable deadline.
- Customers should monitor the Sub-processor list or opt in to email alerts.
2. Contract and product-navigation updates
The introductory language now refers to changes involving:
- Auto-renewal language;
- Enterprise plans;
- Support and account-closure procedures; and
- Sub-processor notifications.
However, the supplied diff does not include the substantive revised auto-renewal, Enterprise, support, or account-closure terms. Their legal effect cannot be assessed from this excerpt.
The wording also adds that the changes are intended to provide a “stable” experience for creators. This appears explanatory and does not itself create a clear legal obligation.
3. Access to FAQs and terms
- A reference to “Frequently Asked Questions” and a link to the relevant material were added or substituted in the access/navigation language.
- Risk: FAQs may help explain the terms, but their contractual status is unclear from the excerpt. Customers should not assume an FAQ overrides the operative agreement unless the contract expressly says so.
4. Asset Store and privacy wording
- The Asset Store provision changes “providers’” typography only; no substantive change is apparent.
- References to Unity’s privacy and intellectual-property positions were reformatted, including use of a straight quotation mark in “DPA.” No substantive change is apparent.
- The DPA remains described as incorporated into and forming part of the Unity Terms.
5. Customer data and AI-model training
- No express change concerning the use of customer data to train AI models appears in the supplied diff.
- The excerpt does not add or remove language authorizing Unity to use customer content, personal information, telemetry, prompts, assets, or other customer data for AI training.
- The sub-processor notification change could indirectly affect AI-related processing if a newly listed vendor provides AI or model-training services, making monitoring of the sub-processor list important.