Monitored company
UserGuiding
clause.watch tracks 2 legal documents published by UserGuiding, re-reading each one every six hours. Below is what each document covers, in plain English.
Privacy Policy
Privacy Policy Overview
1. Data Collection and Use
UserGuiding collects information depending on how you interact with it:
- Website visitors: Browser type, operating system, referring URLs, clickstream activity, and website usage. Cookies and similar technologies are used for functionality, preferences, analytics, advertising, and personalized content.
- Account users: Name, company, email, phone number, session information, and usage data. This supports account administration, product features, collaboration, notifications, and analytics.
- Chrome Extension users: A unique ID, operating system, and country, used to create and share onboarding materials.
- Subscribers/customers: Contact details, company information, and payment information for service delivery, billing, legal compliance, and communications.
- Support and marketing contacts: Contact information, job title, company, problem details, session and usage information, and potentially information obtained from third-party sources.
The stated legal bases include contract performance, legitimate interests, legal obligations, and consent—particularly for marketing cookies and certain marketing activities.
Important scope issue: If you are an end user of a third-party website that uses UserGuiding’s software, UserGuiding generally acts as the data processor, while that website operator is the data controller. Your privacy requests should normally be directed to that website operator, not UserGuiding.
2. User Rights
Depending on your jurisdiction, you may have the right to:
- Access your personal data
- Correct inaccurate information
- Request deletion, subject to legal retention requirements
- Restrict processing
- Receive data in a portable format
- Object to legitimate-interest processing or direct marketing
- Withdraw consent
- Complain to a data protection authority
California residents additionally have rights to know how information is used, request deletion, opt out of sale or sharing, and receive equal treatment for exercising privacy rights. UserGuiding states that it does not sell or share California personal information.
The policy does not clearly provide a dedicated privacy-request email address or detailed verification procedure. Users may need to contact the “UserGuiding Privacy Team” using the company’s general contact channels.
3. Third-Party Sharing
UserGuiding shares data with service providers supporting:
- Cloud hosting and storage
- Analytics
- Customer support and communications
- Security and content delivery
- Payment processing
- Advertising, marketing, and CRM
These providers are described as contractually limited to specified purposes and required to protect the data. However, the policy does not identify all providers or explain precisely what data each receives.
Data may be stored on AWS servers in the European Union and United States. International transfers rely on the EU-U.S. Data Privacy Framework, UK extension, Standard Contractual Clauses, or the UK IDTA.
4. AI/ML Training
The policy does not expressly state whether personal data, account content, usage information, support conversations, or other user-submitted material is used to train artificial intelligence or machine-learning models.
Accordingly, users should not assume that data is excluded from AI training. The policy’s general references to analytics, product improvement, marketing, and service providers leave this issue unresolved. Customers handling sensitive information should seek clarification or review the contract, Data Processing Agreement, and any AI-specific terms.
5. Key User Obligations and Restrictions
The policy imposes relatively few direct user obligations. Key practical points are:
- Users under 18 should not provide personal data; UserGuiding does not knowingly collect children’s data.
- Users should manage cookie preferences through the Cookie Policy tools.
- Account and subscription users should provide accurate information and use the service consistently with the separate Terms of Service.
- End users of subscriber websites should direct privacy requests to the relevant website operator.
The policy does not itself describe prohibited content, acceptable use rules, or account-security responsibilities; those likely appear in the Terms of Service.
6. Liability and Disputes
The policy states that UserGuiding uses “commercially reasonable” safeguards, including encryption, access controls, monitoring, and incident response, but does not guarantee absolute security.
It provides no detailed limitation of liability, governing-law clause, arbitration requirement, or general dispute procedure. Those issues must be checked in the separate Terms of Service. For EU-U.S. Data Privacy Framework complaints, UserGuiding states that unresolved complaints may involve regulatory authorities and, in some circumstances, binding arbitration. The company is subject to FTC enforcement for DPF compliance.
7. Policy Changes
UserGuiding may revise the policy for changes in practices, technology, or law. For material changes, it says it will provide notice by email and/or a prominent website notice where appropriate. Users are encouraged to review the policy periodically. The wording does not guarantee advance notice for every change or specify how much notice will be given.
Terms of Service
Terms of Service Review
Important Limitation
The material provided does not appear to be Terms of Service or a Privacy Policy. It is primarily marketing and navigation content for a product-adoption platform, listing features, resources, languages, and calls to action such as “Start for Free” and “Book a Demo.”
Accordingly, the document does not contain sufficient legal terms to determine the issues below. Users should obtain and review the company’s actual Terms of Service, Privacy Policy, Data Processing Addendum, and any AI-specific terms before using the service.
1. Data Collection & Usage
The text does not explain:
- What personal data is collected
- Whether the platform collects names, email addresses, account details, device information, or usage data
- Whether it uses cookies, tracking technologies, session recordings, surveys, or analytics
- How long data is retained
- The purposes for which data is used
- Whether customer-provided data may include information about a customer’s own users
The listed features—particularly Session Replay, Analytics, In-App Surveys, NPS Surveys, AI Assistant, and Knowledge Base—suggest that the service may process substantial behavioral, interaction, and content data. However, the excerpt does not establish what is actually collected or how those features operate.
2. User Rights
No user privacy rights are stated. The text does not address whether users may:
- Access or obtain a copy of their data
- Correct inaccurate data
- Delete data
- Restrict or object to processing
- Export data
- Withdraw consent
- Opt out of marketing communications or tracking
- Appeal automated decisions
These rights may depend on the user’s location and applicable laws, such as the GDPR, UK GDPR, or certain U.S. state privacy laws. The actual Privacy Policy should identify the process and contact details for making requests.
3. Third-Party Sharing
The document does not state whether data is shared with:
- Cloud hosting providers
- Analytics and advertising providers
- Customer-support or CRM platforms
- Payment processors
- Integration partners
- Affiliates or business successors
- Government authorities
The “Integrations” reference indicates that data may be exchanged with third-party services, but no specific permissions, safeguards, or list of providers is provided. Users should check whether the company acts as a processor/service provider for customer data and whether customers remain responsible for obtaining consent from their own end users.
4. AI/ML Training
The excerpt mentions an AI Assistant, but does not explain:
- Whether prompts, uploaded content, or outputs are stored
- Whether customer data is used to train general AI models
- Whether data is used only to provide the service
- Whether customers can opt out of model training
- Which AI vendors may receive data
- Whether human reviewers can access inputs or outputs
This is a significant unresolved issue. Users should not assume that data submitted to the AI Assistant is confidential or excluded from model training without an express contractual statement.
5. Key Obligations
No binding user obligations or restrictions are included. The missing Terms of Service should be reviewed for rules concerning:
- Prohibited or unlawful content
- Security of account credentials
- Responsibility for authorized users
- Intellectual-property rights
- Use of session replay and tracking features
- Compliance with privacy and consent laws
- Service limitations and acceptable-use rules
- Suspension or termination rights
Organizations using analytics, session recording, surveys, or onboarding tools may have additional obligations to notify and obtain consent from their own users.
6. Liability & Disputes
The excerpt contains no provisions regarding:
- Warranties or disclaimers
- Service availability
- Data-loss responsibility
- Security incidents
- Indemnification
- Liability caps or exclusions of consequential damages
- Governing law
- Arbitration, courts, venue, or class-action waivers
These terms can materially affect a user’s ability to recover damages or bring a claim.
7. Changes
No change-notification procedure is provided. The actual agreement should state:
- How users are notified of updates
- When changes become effective
- Whether continued use constitutes acceptance
- Whether material changes receive advance notice
- What happens if users reject the changes
Bottom Line
This excerpt is promotional content, not an operative legal agreement. It provides virtually no enforceable information about privacy, data use, AI training, user obligations, liability, disputes, or policy changes. Users should obtain the complete legal documents and pay particular attention to session replay, analytics, integrations, AI data use, data deletion, liability caps, and termination provisions.
Change history
2026-09-06 · Privacy Policy
Summary of Important Changes
1. New Privacy Policy and Expanded Scope
The diff adds a substantially rewritten Privacy Policy for YNOT PARTNERS, INC., described as a wholly owned subsidiary of YNOT Partners Yazılım Pazarlama Danışmanlık Anonim Şirketi in Türkiye.
The policy distinguishes between:
- Website visitors and subscribers: UserGuiding acts as a data controller.
- End users of subscriber websites: UserGuiding acts as a data processor, while the subscriber remains the controller.
This distinction is important because end-user processing is stated to be governed by the subscriber’s privacy policy and the parties’ Data Processing Agreement (DPA), rather than this Privacy Policy.
2. Broader Categories of Data Collected
The policy expressly identifies collection of:
- Browser, operating system, referring URL, clickstream, and website-use data.
- Account and subscription information, including names, contact details, company information, payment information, session information, and usage information.
- Chrome Extension data, including a unique ID, operating system, and country.
- Customer support information, including problem specifications and session/usage information.
- Marketing data obtained from both users and third-party sources.
Purposes include service delivery, analytics, personalization, advertising, marketing, lead generation, security, collaboration, and product improvement.
Risk: Several purposes are broad, and the policy does not always specify precise retention periods, data elements, or limits on secondary use.
3. AI and Model-Training Terms
The diff does not add an express provision stating that customer data may or may not be used to train AI models.
The website navigation references:
- “AI Assistant”
- “MCP Server”
- “Ask Your AI Tools About Your Users”
However, the Privacy Policy does not explain:
- Whether customer or end-user data is used to train, fine-tune, evaluate, or improve AI models.
- Whether prompts, outputs, usage data, or knowledge-base content are retained.
- Whether data is shared with AI vendors or subprocessors.
- Whether customers can opt out of AI training or processing.
- Whether customer data is isolated from other customers’ data.
- Whether AI-generated outputs are used for profiling or automated decision-making.
Key risk: The absence of an express restriction on AI training leaves uncertainty about whether “product improvement,” analytics, support, or third-party-provider provisions could be interpreted to permit AI-related secondary use. Customers should request specific contractual language addressing AI training and model-provider access.
4. Vendors, Transfers, and Security
The policy adds broad categories of service providers, including cloud infrastructure, analytics, communications, security, payment, and marketing providers. Data may be stored on AWS servers in the EU and United States.
Transfers rely on the EU-U.S. Data Privacy Framework, UK extension, SCCs, and the UK IDTA.
Security commitments are described as “commercially reasonable,” with no absolute security guarantee.
5. California and Other Privacy Rights
The policy adds or expands rights relating to access, deletion, correction, portability, objection, consent withdrawal, restriction, and complaints. It also includes CCPA/CPRA service-provider representations, including that UserGuiding will not sell or share subscriber-provided California personal information.
6. Drafting and Compliance Concerns
Potential issues include:
- Incomplete wording: “how awe collect.”
- “How We Use Your Information” appears incomplete or lacks a clear consolidated list.
- Retention periods are deferred to a separate Data Retention Policy.
- The DPA and referenced policies are not included, so important processing restrictions cannot be verified.
- The policy’s broad “product improvement” language should be clarified in relation to AI systems.
2026-09-06 · Privacy Policy
Executive Summary
The diff appears to contain substantial website-navigation and content restructuring, but very few clear substantive changes to the Privacy Policy itself. The redline format is heavily affected by navigation text being inserted, removed, or rearranged.
Important Changes
1. New product and navigation content
The revised text adds or reorganizes links relating to:
- Feature requests and public roadmaps
- AI Assistant and AI Knowledge Base
- Product tours, session replay, surveys, analytics, and onboarding
- An “MCP Server” described as allowing users to “Ask Your AI Tools About Your Users”
These appear primarily to be marketing or navigation changes rather than contractual privacy terms. However, the references to AI-related products may indicate expanded functionality that is not separately explained in the Privacy Policy.
2. Privacy-policy scope is clarified
The policy expressly distinguishes between:
- Website visitors and subscribers, for whom UserGuiding acts as a data controller; and
- End users of a subscriber’s website, for whom UserGuiding acts as a data processor.
It states that subscriber end-user data is governed by the applicable Data Processing Agreement, not this Privacy Policy. Customers should therefore review the DPA carefully, particularly for product analytics, session replay, AI features, subprocessors, and model-related processing.
3. Broad categories of data and purposes
The policy describes collection of usage, session, clickstream, support, marketing, and account information. Purposes include improving services, analytics, personalization, marketing, security, and lead generation.
The heading “How We Use Your Information” is followed by no clearly itemized explanation in the supplied diff. This creates ambiguity about whether data may be used for additional purposes beyond those listed in the collection tables.
4. International transfers and third parties
The policy states that data may be stored in the EU and United States and transferred using the EU-U.S. Data Privacy Framework, SCCs, and the UK IDTA. It also authorizes categories of service providers for hosting, analytics, communications, security, payments, and marketing.
The policy does not identify specific providers, retention periods, or detailed safeguards for each category.
AI Training and Model Use
No express provision was identified stating that customer data, subscriber end-user data, support content, session recordings, or usage data:
- May be used to train, fine-tune, or evaluate AI models;
- May be disclosed to AI providers for model development;
- Will be de-identified before AI use; or
- Will be excluded from model training.
The new references to an AI Assistant, AI Knowledge Base, and MCP Server are potentially relevant but do not themselves grant or restrict AI-training rights. This is a significant transparency gap. Customers should request confirmation, preferably in the DPA or written terms, that their data will not be used to train general-purpose or third-party AI models without authorization.
2026-09-04 · Privacy Policy
Contract/Privacy Policy Change Summary
1. New Privacy Policy and Expanded Scope
The diff introduces a comprehensive Privacy Policy for YNOT PARTNERS, INC., a wholly owned subsidiary of YNOT Partners Yazılım Pazarlama Danışmanlık Anonim Şirketi in Türkiye.
The policy applies to:
- Website visitors, for whom UserGuiding acts as a data controller.
- Subscribers’ representatives and employees, also as a data controller.
It expressly excludes end users of customer websites where UserGuiding’s JavaScript is embedded. For those individuals, UserGuiding states that:
- The customer is the data controller.
- UserGuiding is the data processor.
- Processing is governed by the customer’s DPA, not this Privacy Policy.
Risk: Customers should verify that the DPA adequately addresses all processing performed through UserGuiding’s products, including session recordings, analytics, AI features, and any subprocessors.
2. New Data Collection and Use Disclosures
The policy identifies collection of:
- Browser, operating system, referring URL, clickstream, cookie, and tracking data.
- Account and contact information, including names, company, email, telephone number, and session/usage data.
- Chrome Extension identifiers, operating system, and country.
- Payment information.
- Customer-support information, including problem specifications and session/usage information.
- Marketing data obtained directly and from third-party sources.
Purposes include service delivery, product functionality, collaboration, analytics, security, marketing, personalized content, advertising, lead generation, and product improvement.
Risk: The purposes are broad, particularly “improve products,” analytics, advertising, and personalized content. The policy does not provide detailed limitations, retention periods, or a complete mapping between data categories and purposes.
3. AI Model Training
There is no express provision authorizing or prohibiting the use of customer or end-user data to train, fine-tune, evaluate, or improve AI models.
The navigation includes references to “AI Assistant,” “Knowledge Base,” and “MCP Server,” and the site promotes asking AI tools about users. However, the substantive privacy text does not explain:
- Whether customer data is used for AI training.
- Whether prompts, outputs, knowledge-base content, or telemetry are retained.
- Whether data is shared with AI vendors.
- Whether customers can opt out.
- Whether data is anonymized or segregated by customer.
- Whether end-user data is used to improve shared models.
Important risk: The absence of a clear AI-data-use restriction creates material ambiguity. Customers should seek a written commitment that their data—and their end users’ data—will not be used to train generalized AI models without express consent, and should review the DPA and subprocessors list for AI providers.
4. Third-Party Providers and International Transfers
New disclosures permit use of providers for cloud hosting, analytics, communications, security/CDN, payments, and marketing. Data may be stored in AWS facilities in the EU and United States.
Transfers rely on:
- The EU-U.S. Data Privacy Framework and UK extension.
- EU Standard Contractual Clauses.
- The UK International Data Transfer Agreement.
Risk: The policy does not identify specific providers, processing locations, or detailed transfer safeguards. The DPF should be independently verified for the relevant entity and processing activities.
5. Retention, Security, and Rights
The policy adds commercially reasonable security measures, including encryption, access controls, assessments, monitoring, and incident response. It states that data is retained for the account duration, legal-compliance periods, or as otherwise necessary, then deleted or anonymized.
It also adds GDPR-style rights, California CCPA/CPRA provisions, children’s privacy language, and a process for policy updates.
Risk: “Commercially reasonable” safeguards and broadly stated retention standards provide limited contractual certainty. The policy also contains drafting/formatting errors, including “how awe collect,” which should be corrected.
2026-09-04 · Terms of Service
Summary of Important Changes
1. New Terms of Service Added
The diff appears to add a complete set of UserGuiding Terms of Service, including:
- Identification of YNOT Partners Yaz. Paz ve Dan. A.Ş. as the service provider.
- Agreement formed by accessing or using the website/service.
- User acceptance of the terms through registration or use.
- UserGuiding’s right to amend the Terms at its sole discretion by posting updated terms or providing notice.
- Immediate termination rights for violations.
Risk: The amendment mechanism is broad and does not specify advance notice, a notice period, or a customer termination right if the changes are unacceptable. Customers may be bound by the version posted at the time of use.
2. Subscription and Payment Terms
New provisions state that:
- Subscriptions renew automatically monthly or annually.
- Customers must contact support to cancel renewal.
- A valid credit card authorizes UserGuiding to charge subscription fees.
- Failed payments may result in an invoice requiring manual payment.
- Payments are nonrefundable, including unused periods, upgrades, downgrades, and partial billing periods.
- Customers are responsible for applicable taxes, excluding U.S. federal and state taxes.
Risks:
- Automatic renewal and a potentially inconvenient cancellation process may create inadvertent renewal obligations.
- The no-refund policy shifts the risk of unused or prematurely terminated service to the customer.
- The tax language may impose additional costs, including potentially uncertain or disputed taxes.
3. Monitoring, Content Removal, and Enforcement
UserGuiding disclaims any obligation to prescreen or monitor use but reserves the right to monitor and remove information or content it considers violative or objectionable. It may also cooperate with law enforcement.
Risks:
- “Otherwise objectionable” is broad and subjective.
- There is no stated notice, appeal, or restoration process before content removal or enforcement action.
4. Suspension, Termination, and Data Loss
UserGuiding may terminate:
- Unpaid accounts with no activity for 60 days.
- Accounts that are more than 60 days past due.
- Accounts for breach, at UserGuiding’s sole discretion.
Upon cancellation, accounts or content may be deactivated or deleted, with no recovery. The customer is solely responsible for cancellation.
Risks:
- Customers could permanently lose account content without a stated export period, backup obligation, or retrieval assistance.
- Termination rights are largely one-sided and lack cure periods.
- The 60-day inactivity rule could affect free or unpaid accounts unexpectedly.
5. AI Training and Customer Data
The diff includes references to “AI Assistant,” “AI,” and “MCP Server: Ask Your AI Tools About Your Users.” However, it does not add an express provision stating:
- Whether customer data, user data, prompts, recordings, analytics, or account content may be used to train AI models;
- Whether data is used for model improvement or only to provide the service;
- Whether customers can opt out;
- Whether data is anonymized or aggregated;
- Which AI providers or subprocessors receive the data; or
- How AI-related data retention and deletion operate.
Important conclusion: No explicit authorization or prohibition concerning AI-model training is visible in this diff. The Terms also lack a clear customer-data ownership, confidentiality, processing, or AI-use framework, so the Privacy Policy and any Data Processing Agreement should be reviewed separately.
2026-09-04 · Privacy Policy
Summary
Overall assessment
The provided diff appears to be a fragment of website navigation or product-interface text, not a contract, privacy policy, or terms-of-service provision. It does not contain substantive legal language governing customer rights, data processing, confidentiality, or AI training.
Changes identified
- Product/navigation text changed
- The text:
Sign in with GoogleSign in with Google. Opens in new tabProductPublic- appears to have been replaced with:
ProductPublic- This looks like a user-interface or accessibility-text change rather than a legal amendment.
- Product feature list remains visible
- The surrounding text lists product features, including:
AI AssistantKnowledge BaseAnalyticsSession Replay- Other customer-engagement tools
- The diff does not explain how these features operate or what data they process.
AI-model training and customer data
- No express change identified regarding:
- Whether customer data may be used to train AI models;
- Whether prompts, uploads, knowledge-base content, or generated outputs are used for model improvement;
- Whether data is shared with AI vendors or subprocessors;
- Opt-out or deletion rights;
- Retention, anonymization, or de-identification of customer data;
- Whether customer data is used to train proprietary or third-party models.
- The appearance of the label “AI Assistant” does not itself create or change a contractual right to use data for AI training. Any such permission would normally need to appear in applicable terms, a privacy policy, data-processing addendum, or product-specific terms.
Risk assessment
- No new legal risk can be reliably identified from this fragment.
- The principal concern is lack of information: the presence of an AI-related product does not disclose its data practices. Customers should review the governing privacy policy, terms of service, AI terms, and data-processing agreement for provisions addressing model training and use of customer content.
- If this diff is intended to represent a legal-document change, it is incomplete or improperly formatted and should not be treated as a reliable record of the amendment.
2026-09-03 · Terms of Service
Important Changes Summary
1. Website and product-navigation changes
The diff substantially changes the website’s product menus and marketing navigation. New or reorganized references include:
- Feature requests and public roadmap
- Custom alerts, session replay, AI assistant, knowledge base, and checklists
- In-app surveys, analytics, segmentation, banners, and onboarding tools
- Product updates, webinars, ebooks, blog content, and integrations
- Additional competitor-comparison pages and resource links
These appear to be marketing or navigation changes rather than amendments to the contractual terms.
2. Product and AI-related references
The updated website prominently references:
- AI Assistant
- AI-related onboarding/checklist functionality
- “UserGuiding MCP Server: Ask Your AI Tools About Your Users”
These references may indicate new or expanded AI-enabled features. However, the diff does not provide contractual details about:
- Whether customer data is used to train UserGuiding’s or third-party AI models
- Whether customer data is used to improve models generally
- Whether inputs, outputs, prompts, recordings, analytics, or user-content are retained
- Whether data is anonymized, aggregated, or de-identified before model use
- Whether third-party AI providers receive customer data
- Whether customers can opt out of AI processing or model training
- Ownership or permitted use of AI-generated outputs
Risk: The website’s AI references could create practical data-protection and confidentiality concerns, particularly if customer information is submitted to AI features. The Terms of Service shown here do not expressly authorize or restrict AI training. Customers should review the Privacy Policy, security documentation, data-processing agreement, and any AI-specific terms before enabling these features.
3. Terms of Service
No material substantive change to the Terms of Service is apparent in the supplied diff. The same provisions remain, including:
- UserGuiding may change the Terms at its sole discretion by posting updates.
- Subscriptions automatically renew unless cancelled.
- Payments are generally nonrefundable.
- Customers are responsible for applicable taxes.
- UserGuiding may remove content and suspend or terminate accounts.
- Inactive unpaid accounts may be terminated after 60 days.
- Cancellation may result in deletion and irreversible loss of account content.
- UserGuiding may modify or discontinue the service without notice.
These provisions continue to present customer risks, especially unilateral terms changes, broad termination rights, limited refund rights, and permanent data deletion after cancellation.
4. Overall assessment
The principal change is expansion and reorganization of marketing and product content, including AI-related offerings. No explicit new clause concerning use of customer data to train AI models appears in the diff. Nevertheless, the absence of clear AI-data terms is itself a risk because the operational treatment of data is not defined in the displayed Terms of Service.
2026-09-03 · Privacy Policy
Structured Summary of Important Changes
1. Website and Product-Content Changes
The revised content adds or reorganizes references to UserGuiding’s product offerings, including:
- Feature requests and public roadmap tools
- Custom alerts and session replay
- AI Assistant
- Knowledge Base
- Product updates and announcement modals
- Tooltips, onboarding checklists, product tours, surveys, analytics, segmentation, and in-app surveys
- Integrations and other customer resources
The navigation and marketing copy also appear to have been substantially restructured, including updated links, menu labels, language options, and resource pages. These changes appear primarily editorial and operational rather than contractual.
2. Privacy Policy Scope and Roles
The privacy policy expressly distinguishes between:
- Website visitors and subscribers, for whom UserGuiding acts as a data controller; and
- End users of subscribers’ websites, for whom UserGuiding acts as a data processor under the subscriber’s instructions.
This is important for customers embedding UserGuiding’s JavaScript: the subscriber remains responsible for determining the lawful basis, notices, and data-subject response process for its end users. The policy states that this processing is governed by the applicable Data Processing Agreement (DPA), not the public privacy policy.
3. Data Collection and Uses
The policy describes collection of browser, clickstream, session, usage, contact, account, payment, and marketing information. Purposes include:
- Providing and managing the service
- Enabling product features and collaboration
- Analytics and product improvement
- Customer support and security
- Marketing, advertising, personalization, and lead generation
The broad references to “session and usage information,” analytics, product improvement, and third-party marketing providers may permit extensive behavioral-data processing. Customers should review the DPA and product settings to determine whether session-replay, analytics, or end-user data is collected and whether consent is required.
4. AI Model Training
No express provision authorizing or prohibiting the use of customer data to train AI models is identifiable in the supplied diff.
Although “AI Assistant” and related AI product references appear in the website content, the privacy policy does not clearly state:
- Whether customer or end-user data is used to train, fine-tune, or evaluate AI models;
- Whether prompts, outputs, knowledge-base content, or usage data are retained;
- Whether data is shared with AI vendors;
- Whether customer data is isolated from other customers; or
- Whether customers can opt out of AI training.
This ambiguity is a significant contractual and privacy risk, particularly for confidential business information and end-user personal data. Customers should seek an explicit written commitment in the DPA or service terms.
5. Compliance and Drafting Risks
The policy states that UserGuiding will not sell or share California personal information and describes service-provider restrictions. It also adds EU/UK transfer mechanisms, including the Data Privacy Framework, SCCs, and UK IDTA.
Potential issues include apparent drafting defects such as “how awe collect,” incomplete headings, and a broad “How We Use Your Information” section without detailed listed purposes. These defects may create uncertainty about notice and transparency obligations.
6. Recommended Action
Before accepting the revised terms, confirm:
1. Whether AI features process customer data through third-party models;
2. Whether any data is used for model training or product improvement;
3. Available opt-out, deletion, and retention controls; and
4. That the DPA expressly limits AI processing and protects confidential and personal data.
2026-09-03 · Privacy Policy
Important Changes Summary
1. New Privacy Policy Added
The diff adds a comprehensive Privacy Policy for YNOT PARTNERS, INC., a wholly owned subsidiary of YNOT Partners Yazılım Pazarlama Danışmanlık Anonim Şirketi in Türkiye. It covers:
- Website visitors, for whom UserGuiding acts as a data controller.
- Subscribers’ representatives and employees, also as a data controller.
- End users of customers’ websites, for whom UserGuiding claims to act as a data processor under the customer’s instructions and DPA.
Legal significance
This controller/processor distinction is important. Customers remain responsible for providing privacy notices and handling data-subject requests concerning their own end users. The DPA—not this Privacy Policy—is said to govern that processing.
2. Expanded Categories and Uses of Personal Data
The policy identifies data collected through:
- Website visits, cookies, clickstream data, and referring URLs.
- Account creation and login, including session and usage information.
- The Chrome extension, including a unique ID, operating system, and country.
- Subscriptions and payments.
- Customer support interactions, including session and usage information.
- Marketing interactions and third-party sources.
Purposes include service delivery, account management, analytics, personalization, advertising, marketing, lead generation, support, security, and product improvement.
New risks
- The purposes are broad, particularly “improve products,” analytics, advertising, and lead generation.
- “Session and usage information” is not specifically defined, creating uncertainty about whether recordings, keystrokes, behavioral data, or customer-content data may be included.
- Marketing data may be obtained from third parties, but the policy does not identify those sources in detail.
3. AI Model Training
No express provision authorizes using customer data or end-user data to train, fine-tune, evaluate, or improve AI models.
The diff does add navigation references to “AI Assistant” and related product pages, but this is a product/navigation change only. It does not state:
- Whether customer data is used to train AI models;
- Whether prompts, outputs, transcripts, or knowledge-base content are retained;
- Whether data is shared with AI vendors;
- Whether customers can opt out or require data exclusion; or
- Whether AI processing applies to processor-held end-user data.
Key concern
The absence of an AI-specific limitation leaves ambiguity. Broad language such as “improve products” could potentially be argued to cover AI development, depending on the governing contract, DPA, and actual practices. Customers should seek an explicit contractual statement prohibiting training on their data unless expressly authorized.
4. Third-Party Providers and International Transfers
The policy newly describes provider categories including cloud hosting, analytics, communications, security/CDN, payment, and marketing vendors. Data may be stored on AWS servers in the EU and United States, using the EU-U.S. Data Privacy Framework, SCCs, and UK IDTA.
Risks
- Vendor identities, subprocessors, and processing locations are not listed.
- U.S. transfers may create regulatory and government-access concerns.
- The policy relies on general “commercially reasonable” security language and disclaims absolute security.
5. Retention, Rights, and California Terms
The policy adds general retention commitments, deletion or anonymization language, data-subject rights, and CCPA/CPRA service-provider certifications.
Drafting issue
The phrase “how awe collect” appears to be a typographical error. The sections “How We Use Your Information” and “How to Exercise Your Rights” also appear incomplete or insufficiently detailed.
2026-09-02 · Privacy Policy
Summary of Important Changes
1. AI and Training-Data Use
- The revised content prominently references AI-related products, including “AI Assistant” and “MCP Server: Ask Your AI Tools About Your Users.”
- However, the Privacy Policy does not expressly state:
- Whether customer data, end-user data, prompts, outputs, session recordings, analytics, or support data may be used to train, fine-tune, evaluate, or improve AI models;
- Whether data is shared with third-party AI providers;
- Whether customer data is used for UserGuiding’s own models or only to provide an AI feature;
- Whether customers can opt out of model training;
- Whether submitted data is retained by AI providers; or
- Whether inputs and outputs are isolated between customers.
- The policy’s broad language regarding using information to “improve products,” “enhance platform security,” and compile analytics could potentially be argued to cover AI development, but it is too vague to provide clear notice or contractual assurance.
- Risk: Customers may reasonably expect that their data will not be used for AI training, while the policy does not clearly prohibit that use. A separate contractual AI-data clause, DPA provision, or product-specific notice should be reviewed.
2. Clearer Controller/Processor Allocation
The revised policy expressly distinguishes:
- UserGuiding as a data controller for website visitors and subscriber representatives/employees; and
- UserGuiding as a data processor for end users of subscribers’ websites.
It states that subscriber end-user processing is governed by the DPA, not this Privacy Policy, and directs end users to the subscriber.
Risk: The policy does not provide the DPA or explain whether the DPA contains specific restrictions on AI training, subprocessors, retention, or secondary use. Those terms may therefore be decisive.
3. Expanded Processing Disclosures
The policy now identifies categories of data and purposes for:
- Website visits and cookies;
- Accounts and logins;
- Chrome-extension use;
- Subscriptions and payments;
- Customer support; and
- Marketing activities.
It also lists provider categories, including cloud hosting, analytics, communications, security, payment processing, and marketing.
Risks:
- The section titled “How We Use Your Information” appears incomplete.
- Purposes such as analytics, product improvement, personalized content, advertising, and lead generation are broad.
- No specific list of subprocessors, retention periods, or detailed deletion standards is provided.
4. International Transfers and Security
The policy states that data is stored on AWS servers in the EU and United States and relies on:
- The EU-U.S. Data Privacy Framework and UK extension; and
- EU Standard Contractual Clauses and the UK IDTA where applicable.
It also describes encryption, access controls, monitoring, and incident response.
Risk: Transfer safeguards may not address customer-specific restrictions on sensitive data or AI-provider transfers.
5. California and Individual Rights
The revision adds or clarifies:
- Access, correction, deletion, restriction, portability, objection, consent withdrawal, and complaint rights; and
- California “Service Provider” commitments, including no sale or sharing and limits on combining or using subscriber data.
These provisions are favorable, but they do not expressly address AI training or model-improvement use.
2026-09-02 · Terms of Service
Summary
The provided diff does not include the actual amended contract language. It only states:
> “Added approximately 1176 words to the document”
Accordingly, it is not possible to identify:
- Which contractual provisions changed;
- New customer obligations or provider rights;
- Changes to liability, indemnity, confidentiality, security, or termination terms;
- Whether customer data may be used to train, fine-tune, evaluate, or improve AI models;
- Whether data may be shared with affiliates, subprocessors, or third-party model providers; or
- Whether customers can opt out of AI training or require deletion of data used for that purpose.
AI Training and Data-Use Risk
No conclusions can be drawn about AI-model training from the information provided. The word-count increase does not establish whether the new language:
- Authorizes training on customer content, prompts, outputs, telemetry, or usage data;
- Permits use of data in aggregated, de-identified, or identifiable form;
- Allows retention of data after account termination;
- Grants the provider broad rights to create derivative works or improve services;
- Applies training rights by default or only with customer consent; or
- Provides an opt-out, deletion right, or restrictions for confidential or personal data.
Information Needed
Please provide the full redline or the text showing additions, deletions, and replacements using the specified notation. Once provided, the analysis can identify the material legal changes and separately summarize any provisions concerning:
1. Customer data ownership and permitted uses;
2. AI training, model improvement, and service analytics;
3. Personal information and confidential information;
4. Data retention, deletion, and portability;
5. Subprocessors and third-party AI providers;
6. Security and incident-notification obligations;
7. Indemnities, warranties, and liability limits; and
8. Customer opt-out or consent rights.
2026-09-01 · Terms of Service
Summary of Important Changes
1. Apparent change is primarily website/navigation content
The diff appears to contain extensive website-navigation and content changes, including:
- New or reorganized links for feature requests, public roadmaps, alerts, session replay, AI assistant, knowledge base, surveys, analytics, and product updates.
- Updated resource links, including webinar recordings, product blog articles, ebooks and guides, and a CEO feedback channel.
- Revised footer and navigation links, including additional competitors and resources.
- Language and localization navigation changes, including English, Portuguese, Brazilian Portuguese, Spanish, and French.
These changes do not appear to amend the substantive Terms of Service.
2. No material change identified in the Terms of Service
The Terms of Service text shown in the diff appears substantively unchanged. It continues to provide that:
- Use of the Service constitutes agreement to the Terms.
- UserGuiding may change the Terms at its sole discretion by posting an updated version.
- Subscriptions automatically renew unless cancelled.
- Payments are made in advance and are generally nonrefundable.
- Customers are responsible for applicable taxes.
- UserGuiding may investigate violations and remove objectionable content.
- Unpaid or inactive accounts may be terminated after 60 days.
- UserGuiding may suspend or terminate accounts for breach.
- Cancellation may result in deletion or forfeiture of account content, which cannot be recovered.
- UserGuiding may modify or discontinue the Service without notice.
These provisions remain important customer risks because they permit unilateral terms changes, automatic renewal, broad termination rights, irreversible deletion of account content, and no refunds for unused service periods.
3. AI and customer-data training implications
No express contractual provision was added or removed concerning:
- Use of customer data to train AI models;
- Whether customer content is used for model training or product improvement;
- Whether data is anonymized, aggregated, or de-identified before such use;
- Customer opt-out or consent rights;
- Ownership of AI outputs or training data;
- Restrictions on using confidential, personal, or regulated information for AI training; or
- Third-party AI providers and related data transfers.
The diff does add or highlight marketing and navigation references to an “AI Assistant,” “AI” features, and an “MCP Server” that can ask AI tools about users. Those references may indicate expanded AI functionality, but they do not themselves establish contractual permission to train models on customer data. Customers should review the Privacy Policy, data-processing terms, security documentation, and any AI-specific terms before using those features.
4. Drafting/data-quality concern
The diff contains substantial duplicated and malformed navigation text. This may be a website-rendering or extraction issue rather than an intentional legal amendment. The operative Terms should be confirmed against the published version and version history.
2026-08-30 · Terms of Service
Diff Analysis
Key Limitation
The supplied diff contains only the statement:
> “Added approximately 1176 words to the document”
It does not include the actual added, deleted, or replaced legal language. As a result, it is not possible to reliably identify:
- Changes to rights or obligations
- New fees, liability, indemnity, or termination provisions
- Changes to confidentiality or data-security obligations
- Whether customer data may be used to train, fine-tune, evaluate, or improve AI models
- Whether such use is subject to consent, opt-out rights, anonymization, retention limits, or restrictions on human review
- Changes in ownership or licensing of customer data, inputs, outputs, or model-generated materials
AI-Training Risk Assessment
No conclusion can be reached about AI-model training from the information provided. The statement that approximately 1,176 words were added does not reveal whether the new language:
- Permits use of customer data or prompts for model training
- Authorizes use of data for product improvement or service analytics
- Allows sharing with affiliates, contractors, or AI providers
- Applies training rights to confidential, personal, regulated, or proprietary information
- Gives the customer an opt-out or requires affirmative consent
- Permits retention of data after termination
- Limits use to de-identified or aggregated information
- Grants the provider ownership or a broad license to customer content
Information Needed
Please provide the actual redline text, including:
- Additions in
{curly brackets} - Deletions in
[square brackets] - Replacements in
[]{} - Any surrounding provisions necessary to understand the changes
Once provided, the changes can be analyzed for legal effect, risk level, and specific AI-data-use implications.
2026-08-29 · Terms of Service
Diff Analysis
Executive Summary
The diff appears primarily to reflect website navigation, marketing content, and footer changes rather than substantive revisions to the Terms of Service. The legal Terms text shown in the diff is materially duplicated and does not reveal a clear change to contractual rights or obligations.
Important Changes
1. New product and marketing content
The additions introduce or reorganize references to:
- Feature requests and public roadmaps
- Custom alerts, session replay, AI Assistant, and Knowledge Base
- Product tours, tooltips, checklists, surveys, analytics, and onboarding tools
- Product updates, webinars, blogs, ebooks, and other marketing resources
- An “MCP Server” described as allowing users to “Ask Your AI Tools About Your Users”
These appear to be product-navigation or promotional changes, not operative contract terms.
2. AI-related references
The diff adds or rearranges product names and links containing:
- “AI Assistant”
- “AI”
- “Knowledge Base”
- “UserGuiding MCP Server”
- “Ask Your AI Tools About Your Users”
However, the diff does not include language stating that:
- Customer data will be used to train artificial intelligence or machine-learning models;
- Customer content may be used to improve, fine-tune, or develop AI systems;
- User data will be shared with AI providers or model operators;
- Customers can opt out of AI training;
- Data will be anonymized, aggregated, retained, or deleted for AI purposes; or
- AI-generated outputs are subject to particular disclaimers or liability limitations.
Accordingly, no express change regarding training AI models can be identified from this diff. The new AI/MCP references may nevertheless warrant review of the separate Privacy Policy, Data Processing Addendum, security documentation, and product-specific terms. Those documents may contain data-use permissions not present in the Terms of Service.
3. Terms of Service
The displayed Terms include provisions allowing UserGuiding to:
- Modify the Terms at its sole discretion by posting changes online;
- Suspend or terminate accounts for violations;
- Monitor or remove content at its discretion;
- Terminate inactive unpaid accounts after 60 days;
- Delete account content upon cancellation, with no recovery;
- Modify or discontinue the service without notice; and
- Enforce automatic renewal and generally nonrefundable payments.
These provisions appear unchanged in substance in the supplied diff. They remain material customer risks, particularly unilateral online amendments, permanent content deletion, service discontinuation without notice, and limited refund rights—but they should not be attributed to this diff unless the complete prior version confirms otherwise.
Recommended Follow-Up
Confirm the underlying versions using a clean text comparison. Separately review all AI-related privacy and data-processing terms, especially whether customer content, usage data, session replays, survey responses, or knowledge-base materials may be used to train or improve models.
2026-08-28 · Terms of Service
Summary
The provided diff does not include the actual amended contractual language. It only states:
> “Added approximately 1176 words to the document”
Accordingly, it is not possible to identify the specific legal changes, new obligations, allocation of risk, or modifications concerning customer data or AI-model training.
AI Training and Customer Data
No substantive language is provided addressing whether:
- Customer data may be used to train, fine-tune, or improve AI models;
- Customer prompts, inputs, outputs, or personal information may be retained or reviewed;
- Data may be used in aggregated, de-identified, or anonymized form;
- Customer data may be shared with affiliates, vendors, or model providers;
- Customers may opt out of AI training or withdraw consent;
- Data is deleted after termination or subject to retention periods; or
- The provider offers confidentiality, security, or contractual restrictions on model training.
Risk Assessment
The principal risk is that the material needed to assess these issues is missing. The statement that approximately 1,176 words were added does not reveal:
- Whether the new terms expand the provider’s rights to use customer data;
- Whether previously prohibited AI training is now permitted;
- Whether consent is automatic or requires affirmative action;
- Whether the provider can use data for commercial model development;
- Whether customer data can become incorporated into model outputs; or
- Whether the customer bears additional indemnity, confidentiality, privacy, or regulatory risk.
Required Information
Please provide the full redline showing the additions, deletions, and replacements. In particular, the clauses addressing data use, confidentiality, privacy, artificial intelligence, machine learning, model training, service improvement, retention, and third-party providers are necessary for a meaningful legal analysis.
2026-08-28 · Terms of Service
Executive Summary
The diff appears primarily to add or update website navigation, marketing content, resource links, and footer text. The actual Terms of Service language appears unchanged in the material provided. No new contractual provision expressly authorizes UserGuiding to use customer data to train artificial-intelligence models.
Important Changes
1. New or updated product and navigation references
The additions reference various products and features, including:
- Feature requests and public roadmaps
- Custom alerts
- Session replay
- AI Assistant
- Knowledge Base
- Onboarding checklists and product tours
- In-app surveys and analytics
- Product updates, segmentation, and banners
- Integrations and workflow tools
These appear to be website navigation or marketing references rather than operative contractual terms. Nevertheless, references to Session Replay, Analytics, Surveys, and AI Assistant indicate that the service may process substantial user-activity and behavioral data.
2. AI-related references
The updated website content includes references to:
- “AI Assistant”
- “AI tools”
- “UserGuiding MCP Server: Ask Your AI Tools About Your Users”
However, the diff does not add language addressing:
- Whether customer data, account content, prompts, outputs, or usage data may be used to train AI models
- Whether data is used to train UserGuiding’s models or third-party models
- Whether customer data is de-identified, aggregated, or retained for training
- Whether customers can opt out
- Ownership or confidentiality of AI inputs and outputs
- Human review or disclosure of AI-generated results
- Restrictions on using personal, confidential, or regulated information with AI features
Risk: Although there is no express training authorization in the Terms shown, the AI marketing references create uncertainty about data flows and permitted uses. Customers should review the Privacy Policy, Data Processing Agreement, security documentation, and any AI-specific terms before using these features.
3. Terms of Service provisions reproduced without apparent change
The Terms continue to provide that:
- UserGuiding may change the Terms by posting updated versions.
- Subscriptions automatically renew.
- Payments are generally nonrefundable.
- UserGuiding may monitor, remove, or delete content at its discretion.
- Accounts may be suspended or terminated for violations or inactivity.
- Cancellation may result in deletion and irreversible loss of account content.
- UserGuiding may modify or discontinue the service without notice.
These are significant existing risks, but they do not appear to be newly introduced by this diff.
Bottom Line
The diff does not show a new contractual right to train AI models using customer data. Its main effect is expanded promotion of AI and data-intensive features, which warrants clarification of data-use, retention, confidentiality, and opt-out terms.
2026-08-27 · Privacy Policy
Summary of Important Changes
1. New Privacy Policy
The diff adds a comprehensive Privacy Policy for YNOT PARTNERS, INC., described as a wholly owned subsidiary of YNOT Partners Yazılım Pazarlama Danışmanlık Anonim Şirketi in Türkiye. It covers:
- Website visitors, for whom UserGuiding acts as a data controller.
- Subscriber representatives and employees, also treated as data subjects whose information UserGuiding controls.
- Data collected through accounts, subscriptions, the Chrome extension, customer support, marketing, cookies, and tracking technologies.
Risk: The policy contains drafting errors and inconsistencies, including “how awe collect,” missing punctuation, and references to sections that appear incomplete or empty (for example, “How We Use Your Information” and “How to Exercise Your Rights”). These defects may create ambiguity about the actual processing practices and reduce transparency.
2. Customer End-User Data Is Excluded from the Policy
The new policy expressly states that data collected from end users of a Subscriber’s website is not covered by this Privacy Policy. In that context:
- UserGuiding acts as a data processor/service provider.
- The Subscriber is the controller/business.
- Processing is governed by the parties’ Data Processing Agreement (DPA).
- End users are directed to contact the Subscriber for privacy requests.
Risk: Customers must review the DPA carefully. Important rights, permitted uses, retention periods, subprocessors, security obligations, and AI-related restrictions may exist there rather than in this policy. The policy does not itself confirm that customer data will be segregated from UserGuiding’s own data.
3. AI and Model-Training Changes
The diff adds or highlights products and marketing references to:
- “AI Assistant”
- “MCP Server”
- “Ask Your AI Tools About Your Users”
However, the Privacy Policy does not expressly state:
- Whether customer or end-user data is used to train, fine-tune, evaluate, or improve AI models.
- Whether prompts, outputs, usage data, session replays, surveys, or analytics are sent to third-party AI providers.
- Whether data is retained by AI providers.
- Whether customer data is used to train shared or general-purpose models.
- Whether customers can opt out or require deletion from AI systems.
- What safeguards apply to confidential, sensitive, or regulated information processed by AI features.
Key risk: The absence of an express “no training” commitment should not be interpreted as a contractual prohibition on AI training. Customers should seek clarification and, ideally, obtain written contractual language stating whether their data—and their end users’ data—may be used for AI training or model improvement.
4. Other Material Terms
- Data may be hosted in the EU and United States.
- Transfers rely on the EU-U.S. Data Privacy Framework, SCCs, and the UK IDTA.
- Broad categories of third-party providers include analytics, communications, security, payment, cloud, and marketing vendors.
- Retention is described generally, with specific periods deferred to a separate Data Retention Policy.
- California service-provider commitments prohibit sale, sharing, and certain independent uses of Subscriber data.
Recommended Follow-Up
Request the current DPA, subprocessors list, Cookie Policy, Data Retention Policy, and specific written confirmation regarding AI data use, model training, third-party AI vendors, opt-out rights, and deletion obligations.
2026-08-26 · Privacy Policy
Summary of Important Changes
1. New Privacy Policy framework and scope
The diff adds a detailed Privacy Policy covering:
- Website visitors, for whom UserGuiding acts as a data controller.
- Subscribers and their representatives/employees, also treated as data controllers.
- End users of Subscriber websites, for whom UserGuiding acts as a data processor under the Subscriber’s instructions and applicable DPA.
Risk: The policy places primary responsibility for end-user disclosures and data-subject requests on Subscribers. Customers should verify that their DPA, privacy notices, and product configuration accurately reflect the data UserGuiding processes.
2. Expanded descriptions of collected data and purposes
The policy identifies data collected through:
- Website visits and cookies, including clickstream and referring URLs.
- Accounts and logins, including session and usage data.
- The Chrome Extension.
- Subscriptions and payments.
- Customer support interactions, including session and usage information.
- Marketing activities, including data from third-party sources.
Purposes include service delivery, analytics, personalization, advertising, lead generation, security, support, and product improvement.
Risk: “Improve products,” “analytics,” “enhance user experience,” and similar language is broad and may permit uses beyond strictly providing the service. The policy does not specify detailed retention periods or clearly limit all analytics and improvement activities to aggregated or de-identified data.
3. AI model training and AI-related use
The diff includes navigation references to “AI Assistant,” “Knowledge Base,” and “AI” features, but the substantive Privacy Policy does not expressly state:
- Whether customer or end-user data is used to train, fine-tune, evaluate, or improve AI models.
- Whether prompts, outputs, knowledge-base content, session recordings, or product analytics are sent to third-party AI providers.
- Whether data is used for UserGuiding’s general-purpose models or only for customer-specific functionality.
- Whether customers can opt out, restrict processing, or require deletion from AI systems.
- How confidential information, personal data, or customer content is protected in AI workflows.
Key risk: The absence of an express training prohibition or permission creates uncertainty. Customers should seek contractual clarification, particularly for session replay data, support content, knowledge bases, and Subscriber end-user data.
4. Vendors, retention, security, and international transfers
The policy adds categories of third-party providers for hosting, analytics, communications, security, payments, and marketing. It states that data may be stored in AWS facilities in the EU and United States and relies on the EU-U.S. Data Privacy Framework, SCCs, and the UK IDTA.
Retention is described generally, with specific periods deferred to a separate Data Retention Policy.
Risk: Customers should review the referenced DPA, subprocessors, Cookie Policy, and Data Retention Policy for binding details and deletion obligations.
5. California, privacy rights, and drafting issues
The policy adds GDPR-style rights, California service-provider commitments, children’s privacy provisions, and breach/security language.
Potential drafting concerns include apparent errors such as “how awe collect,” an incomplete “How We Use Your Information” section, and limited detail on exercising rights and deleting accounts. These could create interpretation and compliance risks.
2026-08-26 · Terms of Service
Structured Summary of Important Changes
1. New Terms of Service added
The diff appears to add a complete Terms of Service for UserGuiding, operated by YNOT Partners Yaz. Paz ve Dan. A.Ş. The terms state that they are a legally binding agreement and that use of the website or service constitutes acceptance.
Key legal effects
- UserGuiding may change the Terms at any time and at its sole discretion by posting an updated version online or providing other notice. Continued use is governed by the latest posted version.
- UserGuiding may terminate an account without notice for violations of the Terms.
- UserGuiding disclaims any obligation to pre-screen or monitor customer content, but reserves the right to do so and to remove content it considers violative or objectionable.
2. Subscription and payment terms
The added terms establish:
- Monthly or annual recurring billing.
- Automatic renewal unless cancelled.
- Cancellation through customer support, with no stated advance-notice period.
- A requirement to provide a valid credit card and authorization to charge subscription fees.
- Manual payment obligations if automatic billing fails.
- All payments are nonrefundable, including unused service periods, partial periods, and upgrades or downgrades.
- Customer responsibility for applicable taxes, excluding U.S. federal and state taxes.
Customer risk
The automatic-renewal and nonrefund provisions may create payment exposure, particularly if cancellation is not processed promptly or if the customer stops using the service without formally cancelling.
3. Termination, cancellation, and data loss
UserGuiding may terminate:
- Unpaid accounts with no activity for 60 days.
- Accounts that are more than 60 days past due.
- Accounts for breach, in UserGuiding’s sole discretion.
The customer must cancel by emailing info@userguiding.com with the subject line “Account Cancellation.”
Cancellation may result in:
- Account deactivation or deletion.
- Loss of access.
- Permanent forfeiture of all account Content, expressly stated to be unrecoverable.
Customer risk
The Terms do not provide a data-export period, backup obligation, transition assistance, or guaranteed retrieval window before deletion. Customers should maintain independent backups and confirm deletion and retention practices separately.
4. Service and pricing changes
UserGuiding may modify or discontinue the website or any part of it, temporarily or permanently, with or without notice. Service ends at the conclusion of the current paid period, with no refund for unused time.
5. AI model training and data use
No express provision was added stating that customer data, account content, usage data, prompts, recordings, or other information may be used to train, fine-tune, evaluate, or improve AI models.
The diff does add or retain references to “AI Assistant,” “Knowledge Base,” “MCP Server,” and related product or marketing content. However, these references are not contractual authorization for AI training and do not explain:
- Whether customer data is used to train models;
- Whether data is shared with AI providers;
- Whether customers can opt out;
- Whether data is anonymized or de-identified;
- Retention, deletion, or human-review practices.
Customers should review the Privacy Policy, DPA, AI terms, and security documentation for these issues.
2026-08-25 · Terms of Service
Summary
The provided diff states only that approximately 1,178 words were removed from the document. It does not identify which provisions were deleted, and no replacement language is shown.
AI Training and Customer Data
- No specific change can be confirmed regarding whether customer data may be used to train, fine-tune, evaluate, or improve AI models.
- However, if the deleted material included provisions addressing data use, the deletion could materially change:
- Whether the provider may use customer content or personal data for AI training;
- Whether such use is limited to aggregated, de-identified, or anonymized data;
- Whether the customer must opt in or may opt out;
- Ownership and licensing rights in customer data and model outputs;
- Confidentiality, security, and data-retention obligations;
- Restrictions on using customer data to train models serving other customers; and
- Notice, consent, audit, or deletion requirements.
Other Potential Risks
Because the deleted text is not provided, it is not possible to determine whether the amendment also removes or weakens:
- Data protection and privacy obligations;
- Confidentiality protections;
- Security commitments and breach-notification duties;
- Service levels, warranties, or indemnities;
- Liability caps or exclusions;
- Termination, data-return, or deletion rights;
- Restrictions on subcontractors or third-party AI providers; or
- Customer audit and regulatory-compliance rights.
Assessment
A deletion-only diff is potentially significant, but its legal effect cannot be reliably analyzed without the actual removed language and the surrounding provisions. The deletion should be treated as unresolved and potentially risk-increasing, particularly if the document concerns AI-enabled services or customer data.
To complete the review, provide either:
1. The deleted 1,178 words; or
2. The full “before” and “after” versions of the relevant sections.
2026-08-22 · Terms of Service
Summary
Key Limitation
The supplied diff does not include the actual amended legal language. It only states:
> “Added approximately 1178 words to the document”
Because the additions, deletions, and replacements are not shown, it is not possible to reliably identify:
- Changes to customer data rights or obligations
- Whether customer data may be used to train, fine-tune, evaluate, or improve AI models
- New data-sharing or disclosure rights
- Changes to confidentiality, security, retention, or deletion obligations
- New indemnities, warranties, liability limits, or regulatory responsibilities
- Whether the customer has any opt-out, consent, or audit rights
AI Training and Data-Use Risk
No conclusion can be drawn about AI-model training from the information provided. The actual added language should be reviewed for terms such as:
- “train,” “fine-tune,” “develop,” “improve,” or “enhance” models
- “machine learning,” “artificial intelligence,” or “models”
- “customer data,” “inputs,” “outputs,” “usage data,” or “derived data”
- Rights to use data in “de-identified,” “aggregated,” or “anonymized” form
- Use by affiliates, subcontractors, vendors, or third-party model providers
- Retention after termination or deletion of customer content
- Customer consent, opt-out, or restrictions on commercial use
- Whether prompts, outputs, metadata, or telemetry are included in the permitted data
Information Needed
Please provide the full diff, including the text inside:
{additions}[deletions][]{replacements}
Without the underlying wording, any substantive legal analysis would be speculative.
2026-08-22 · Terms of Service
Summary of Important Changes
1. No substantive Terms of Service changes identified
The legal Terms of Service text appears unchanged in the diff. The following provisions remain in place:
- UserGuiding may amend the Terms at its sole discretion by posting updated terms.
- Subscriptions automatically renew unless cancelled.
- Fees are generally nonrefundable, including for partial or unused periods.
- Customers are responsible for applicable taxes.
- UserGuiding may remove content and cooperate with law enforcement.
- UserGuiding may suspend or terminate accounts for violations or inactivity.
- Cancelling an account may result in deletion, loss of access to, and permanent forfeiture of account content.
- UserGuiding may modify or discontinue the service without notice.
These existing provisions continue to present customer risks, particularly the broad unilateral amendment right, nonrefundable billing structure, and lack of data recovery after cancellation.
2. AI-related references in the updated website content
The additions and replacements introduce or reorganize marketing and navigation references to:
- “AI Assistant”
- “AI” as a product feature
- “UserGuiding MCP Server: Ask Your AI Tools About Your Users”
These references appear in product menus and blog listings rather than in the Terms of Service.
3. Customer data used to train AI models
No express provision was added or identified that authorizes UserGuiding to use customer data, account content, user activity, feedback, or other customer materials to train AI models.
The diff does not state:
- Whether customer data is used to train UserGuiding’s models or third-party models;
- Whether data is used for model improvement, evaluation, or fine-tuning;
- Whether AI inputs or outputs are retained;
- Whether customers can opt out of AI training;
- Whether data is anonymized or aggregated before AI use;
- Whether customer content is shared with AI providers; or
- Whether AI features process personal, confidential, or regulated information.
Accordingly, the new AI references create a potential transparency and privacy concern, but they do not themselves establish a contractual right to train models on customer data. The Privacy Policy, product-specific terms, data processing agreement, and AI feature documentation should be reviewed separately.
4. Other apparent changes
Most remaining differences concern website navigation, marketing copy, resource links, language options, product categories, and footer content. They do not appear to change contractual rights or obligations. Some blocks are duplicated or malformed, suggesting the diff may include scraped website markup rather than a clean legal-document revision.
2026-08-22 · Privacy Policy
Structured Summary of Important Changes
1. New Privacy Policy Added
The diff adds a comprehensive Privacy Policy for YNOT PARTNERS, INC., described as a wholly owned subsidiary of YNOT Partners Yazılım Pazarlama Danışmanlık Anonim Şirketi in Türkiye.
It identifies UserGuiding’s roles as:
- Data controller for website visitors and subscribers’ representatives/employees.
- Data processor for end users of subscribers’ websites using UserGuiding’s JavaScript snippet.
- Service provider under the CCPA when processing California personal information for subscribers.
Risk/impact
The policy creates a clearer allocation of responsibility for subscriber end-user data, but it also places significant compliance obligations on subscribers as the controllers of that data. The policy states that end-user processing is governed by a separate Data Processing Agreement (DPA), not this Privacy Policy. Customers should therefore review the DPA carefully, particularly its provisions on permitted processing, subprocessors, security, deletion, international transfers, and AI-related use.
2. Data Collection and Uses Described
The new policy lists collection of:
- Browser, operating system, referring URL, clickstream, and website usage data.
- Account, contact, company, payment, session, and usage information.
- Chrome Extension identifiers, operating system, and country.
- Customer support and marketing information, including data from third-party sources.
Purposes include service delivery, analytics, personalization, advertising, marketing, security, support, collaboration, and product improvement.
Risk/impact
Some purposes are broad, including “improve products,” “enhance platform security,” analytics, advertising, and lead generation. The policy does not clearly define the boundaries of product improvement or identify whether customer content, session recordings, feedback, or other usage data may be used for automated systems or model development.
3. AI Training and Model Use
The diff does not expressly add or authorize using customer data, subscriber end-user data, session information, feedback, or other personal data to train AI models.
The website navigation references products such as “AI Assistant” and an “MCP Server,” but these references do not establish:
- Whether customer data is used to train generative AI or machine-learning models.
- Whether data is used for UserGuiding’s general or commercial model training.
- Whether data is retained by AI providers.
- Whether customers can opt out.
- Whether customer content is isolated between customers.
- Whether AI subprocessors receive personal or confidential information.
Key risk
The absence of an express AI-training restriction or permission creates contractual uncertainty. Customers should seek confirmation in the DPA, Terms of Service, security documentation, or a separate AI addendum before permitting sensitive data to be processed through AI features.
4. International Transfers and Subprocessors
The policy states that data may be stored on AWS servers in the European Union and United States. It relies on the EU-U.S. Data Privacy Framework, UK extension, EU Standard Contractual Clauses, and UK IDTA.
It also identifies broad categories of service providers, including cloud infrastructure, analytics, communications, security, payment, and marketing providers.
Risk/impact
The policy does not name individual subprocessors or provide detailed change-notification or objection procedures. Customers should verify the current subprocessor list and applicable transfer safeguards.
5. Drafting and Operational Issues
Several provisions appear incomplete or contain drafting defects, including:
- “how awe collect” appears to be a typographical error.
- “How We Use Your Information” is followed by no detailed list.
- “How to Exercise Your Rights” and “Deleting Your Account” appear incomplete.
- Retention periods are deferred to a separate Data Retention Policy not included in the diff.
These gaps may create ambiguity about actual practices and the procedures available to data subjects.
2026-08-21 · Privacy Policy
Key Changes and Legal Risks
1. New, substantially expanded Privacy Policy
The diff adds a detailed Privacy Policy for YNOT PARTNERS, INC., identifying it as the UserGuiding entity responsible for the service. It distinguishes between:
- Website visitors and subscribers: UserGuiding acts as a data controller.
- End users of subscriber websites: UserGuiding acts as a data processor on behalf of the subscriber.
This controller/processor distinction is important because the policy states that end-user data is governed by the subscriber’s Data Processing Agreement (DPA) rather than this Privacy Policy.
Risk
Customers and end users may need to review the DPA to understand the actual permitted uses, retention periods, subprocessors, security obligations, and data deletion procedures for end-user data. The Privacy Policy does not provide those details.
2. Broader categories of data collection and use
The policy describes collection of:
- Browser, operating-system, referring-URL, clickstream, session, and usage data
- Account, contact, company, job-title, payment, and support information
- Data obtained from third-party sources for marketing
Purposes include service delivery, analytics, personalization, advertising, lead generation, product improvement, security, and customer support.
Risk
Some purposes—particularly analytics, advertising, personalization, marketing, and “improve products”—are broad. The policy does not clearly define data minimization limits or distinguish identifiable customer data from aggregated or de-identified data.
3. No express AI-training authorization or prohibition
The diff does not add a clear provision stating whether customer data, subscriber end-user data, support content, session recordings, usage data, or other inputs may be used to:
- Train, fine-tune, or evaluate artificial-intelligence or machine-learning models
- Improve UserGuiding’s AI features
- Train third-party models
- Create generalized or commercial models from customer data
The navigation references AI products and an “MCP Server” that allows AI tools to ask about users, but the operative privacy language does not explain how data supplied to or retrieved by those tools is used.
AI-related risk
This creates material uncertainty for customers concerned about confidential information, personal data, or regulated data being used for model training. “Improve products” or “analytics” could potentially be interpreted broadly, but neither phrase expressly authorizes AI training. Customers should seek written confirmation and review the DPA, Terms of Service, AI terms, and subprocessors list.
4. Third-party providers and international transfers
The policy adds categories of providers for hosting, analytics, communications, security, payments, and marketing. Data may be stored on AWS servers in the EU and United States, with transfers relying on the EU-U.S. Data Privacy Framework, SCCs, and the UK IDTA.
Risk
The policy does not identify specific providers, including any AI providers, or explain whether providers may retain data for their own model-training purposes.
5. Retention, security, and rights
The policy adds general retention commitments, deletion or anonymization language, security safeguards, international-transfer mechanisms, data-subject rights, and California privacy provisions.
Remaining concerns
- Retention periods are not stated; the policy refers to a separate Data Retention Policy.
- “Commercially reasonable” security language is qualified by a no-guarantee disclaimer.
- The policy’s “How We Use Your Information” section appears incomplete or overly general.
- Customer account deletion and rights-exercise procedures are not clearly explained.
2026-08-21 · Terms of Service
Summary
The provided diff does not include the actual amended contract language. It only states:
> “Added approximately 1178 words to the document”
Accordingly, it is not possible to determine:
- What contractual provisions were added or changed;
- Whether liability, indemnity, confidentiality, privacy, security, or termination terms were modified;
- Whether the customer’s data may be used to train, fine-tune, evaluate, or improve AI models;
- Whether such use is subject to consent, opt-out rights, anonymization, aggregation, or restrictions;
- Whether the provider may retain customer data or inputs after termination;
- Whether data may be shared with affiliates, vendors, or third-party AI providers; or
- Whether the customer receives ownership or usage rights in AI-generated outputs.
AI-Training Risk Assessment
No conclusion can be reached regarding AI-training practices because the added wording is not provided. The statement that approximately 1,178 words were added is not itself a legal amendment and does not reveal the substance of those additions.
Information Needed
Please provide the full redline or the text of the added provisions, including any sections addressing:
- Customer data, content, inputs, or prompts;
- Product or service improvement;
- Artificial intelligence or machine learning;
- Model training, fine-tuning, or evaluation;
- De-identification, anonymization, or aggregation;
- Data retention and deletion;
- Subprocessors or third-party model providers; and
- Confidentiality, privacy, and security obligations.
Once the actual text is available, the changes can be analyzed for legal effect and customer risk.
2026-08-19 · Terms of Service
Summary of Changes
1. Website navigation and product-category changes
The diff appears to modify website navigation and marketing copy rather than contractual terms.
Added navigation items:
- Feature Requests
- Public Roadmap
- AI Assistant
- Knowledge Base
- Resource Centers
- In-App Surveys
- Analytics
- Product Updates
- Segmentation
- Banners
- Customization
- Use Cases
- User Onboarding
- Other product categories, including Session Replay, Product Tours, Hotspots & Tooltips, and Onboarding Checklists.
Other changes:
- The phrase “let your users request features and follow your roadmap” was updated to reference both Feature Requests and Public Roadmap.
- Product categories appear to have been reorganized, with some items moved or renamed—for example, “Product” and “Custom” appear in different positions.
- Additional marketing/navigation labels were added, including “Announcement Modals,” “Tooltips,” “NPS Surveys,” and “User Onboarding.”
2. Legal and risk implications
No operative legal provisions, contractual rights, obligations, warranties, liability terms, privacy terms, or data-processing provisions are shown in this diff.
The additions may indicate that the provider now advertises or offers additional functionality, particularly:
- AI Assistant
- Analytics
- Session Replay
- In-App Surveys
- Product Updates
- Feature Requests/Public Roadmap
However, the diff alone does not establish:
- What data these features collect;
- Whether customer data is shared with third parties;
- Whether data is retained or used for product improvement;
- Whether customer content is publicly displayed through a Public Roadmap or Feature Requests feature; or
- Whether the provider has rights to use customer data to train artificial intelligence models.
3. AI-model training
There is no express change concerning the use of customer data to train AI models. Although “AI Assistant” was added or repositioned in the product navigation, the diff contains no language granting or restricting rights to:
- Train, fine-tune, or improve AI models using customer data;
- Use prompts, outputs, files, or usage data for model training;
- Share data with AI providers; or
- Opt out of AI training.
Any AI-training terms would need to be reviewed in the applicable agreement, privacy policy, data-processing addendum, or AI-specific terms.
2026-08-19 · Privacy Policy
Summary of Available Changes
Overall Change
- The diff indicates that approximately 1,916 words were added to the document.
- No actual added language, deleted language, or replacement text is provided.
- As a result, the legal effect of the changes cannot be reliably determined.
Customer Data and AI Training
- The provided diff does not identify whether customer data may be used to train, fine-tune, evaluate, or improve AI models.
- It is therefore not possible to determine whether the revised terms:
- Permit use of customer content for model training;
- Require customer consent or provide an opt-out;
- Limit training to de-identified or aggregated data;
- Allow use by affiliates, vendors, or subprocessors;
- Permit retention of prompts, outputs, or uploaded materials;
- Grant the provider ownership or broad usage rights in customer data; or
- Impose confidentiality, security, or deletion obligations relating to AI systems.
Other Legal Risks
The added 1,916 words may materially change provisions concerning, for example:
- Data ownership and licenses;
- Confidentiality and privacy;
- Intellectual-property rights;
- Security and breach notification;
- Service limitations and disclaimers;
- Indemnification and liability caps;
- Subprocessors and third-party services;
- Data retention and deletion;
- Suspension or termination rights; and
- Governing law and dispute resolution.
However, none of these changes can be confirmed without the actual wording.
Required for Further Analysis
Please provide the full redlined text or the specific additions, deletions, and replacements. The substantive language is necessary to identify:
1. New customer obligations;
2. Expanded provider rights;
3. Changes to data use or AI-training permissions;
4. Conflicts with existing confidentiality or privacy commitments; and
5. Material increases in legal, commercial, or compliance risk.
Between 2024-12-17 and 2025-07-20 · Terms of Service
Summary
The supplied diff only states that approximately two words were removed. It does not identify:
- Which words were deleted
- The provision or section affected
- Whether the deletion changes the parties’ rights or obligations
- Whether any language concerning customer data, artificial intelligence, machine learning, or model training was changed
Legal and Commercial Impact
Because the actual deleted words are unavailable, the legal effect cannot be reliably assessed. Even a short deletion could materially change:
- Permission to use or disclose customer data
- Ownership or licensing rights
- Confidentiality obligations
- Data retention or deletion requirements
- Liability, indemnification, or compliance obligations
- The scope of services or permitted business purposes
AI Training and Customer Data
No specific change concerning the use of customer data to train AI models can be identified from the provided information.
In particular, the diff does not show whether the agreement now:
- Permits or prohibits training AI or machine-learning models using customer data
- Allows use of customer data to improve products or services
- Requires customer consent for model training
- Restricts training to aggregated, anonymized, or de-identified data
- Gives the provider ownership of model outputs, embeddings, or derived data
- Requires deletion or segregation of customer data from training datasets
Conclusion
The diff is insufficient for meaningful legal analysis. The exact deleted words and the surrounding sentence or paragraph are needed to determine whether the change creates any new risk, especially regarding AI model training or other uses of customer data.
Between 2024-09-06 and 2025-06-18 · Privacy Policy
Structured Summary of Important Changes
1. Major Addition: New Privacy Policy
The diff adds a comprehensive Privacy Policy for YNOT PARTNERS, INC., identified as a wholly owned subsidiary of YNOT Partners Yazılım Pazarlama Danışmanlık Anonim Şirketi in Türkiye. The policy covers:
- Website visitors, for whom UserGuiding acts as a data controller.
- Subscribers’ representatives and employees, also treated as data subjects whose data UserGuiding controls.
- Various categories of personal data, including contact details, payment information, usage data, session information, clickstream data, and marketing data.
Risk: The policy appears to apply primarily to website visitors and subscribers, while expressly excluding end users of subscribers’ websites. The allocation of controller/processor responsibilities should match the parties’ contracts and actual processing activities.
2. End-User Data and DPA Structure
The new policy states that, when subscribers embed UserGuiding’s JavaScript:
- UserGuiding acts as a data processor.
- The subscriber remains the data controller.
- End-user processing is governed by the parties’ Data Processing Agreement (DPA) rather than this Privacy Policy.
- End users must direct privacy requests to the subscriber.
Risk: This is legally important but may not be sufficient if UserGuiding independently determines purposes of processing, uses the data for analytics or product development, or processes it outside the subscriber’s instructions. The DPA should clearly address telemetry, profiling, aggregated data, subprocessors, international transfers, retention, deletion, and AI-related processing.
3. AI Model Training: No Express Authorization or Prohibition
The diff does not expressly state that customer data, subscriber end-user data, support content, usage data, or feedback may—or may not—be used to train, fine-tune, evaluate, or improve AI models.
The website references products and content involving:
- “AI Assistant”
- “MCP Server”
- “Ask Your AI Tools About Your Users”
- AI-related product functionality
However, the new privacy language does not explain:
- Whether customer data is submitted to third-party AI providers.
- Whether prompts, outputs, telemetry, or uploaded content are retained.
- Whether data is used to train UserGuiding’s or third parties’ models.
- Whether customer data is used for generalized product improvement.
- Whether customers can opt out or require zero-retention processing.
- Whether AI providers may use data for their own purposes.
Risk: This omission creates material ambiguity and potential conflict with customer expectations, contractual restrictions, GDPR purpose limitation, and CCPA service-provider obligations. A separate AI/data-use clause and corresponding DPA language should expressly prohibit training on identifiable customer or end-user data unless specifically authorized, or clearly obtain the required consent and contractual permissions.
4. Broad Usage and Third-Party Disclosures
The policy permits use for service delivery, analytics, security, marketing, personalization, lead generation, and product improvement. It also identifies broad provider categories, including cloud hosting, analytics, communications, security, payment, marketing, and CRM providers.
Risk: “Improve products” and similar language may be broad enough to encompass AI development or model training. Provider categories do not identify specific vendors or explain their data-use rights. A subprocessor list and precise limitations would reduce risk.
5. International Transfers and Security
The policy states that data is stored on AWS servers in the EU and United States and relies on:
- EU-U.S. Data Privacy Framework and UK extension.
- EU Standard Contractual Clauses.
- UK IDTA.
It also promises commercially reasonable safeguards, encryption, access controls, monitoring, and incident response.
Risk: Transfer mechanisms and security commitments should be consistent with the actual hosting and AI-provider architecture, including any processing outside the EU/US.
6. Drafting and Compliance Concerns
Notable issues include:
- Typographical error: “how awe collect.”
- Some headings and sections appear incomplete or repetitive.
- “How We Use Your Information” is followed by no detailed list beyond cookies and service providers.
- Retention periods are deferred to a separate policy that is not included.
- The policy appears to be dated 2026 but does not identify an effective date.
These issues may reduce transparency and make the notice harder to enforce or rely upon.
Between 2023-12-11 and 2024-07-03 · Terms of Service
Summary
The supplied diff states only: “Added approximately 4 words to the document.” It does not identify the added wording or show any deleted or replaced language.
Legal and Risk Analysis
- No substantive changes can be assessed from the information provided.
- It is not possible to determine whether the change affects:
- Customer data ownership or licensing rights
- Data privacy, confidentiality, or security obligations
- Use of customer data for analytics, product improvement, or AI model training
- The provider’s ability to retain, disclose, commercialize, or sublicense customer data
- Customer consent, opt-out rights, or deletion requirements
- Liability, indemnification, warranties, or regulatory compliance
AI Training/Data-Use Changes
No language concerning the use of customer data to train, fine-tune, evaluate, or improve AI models appears in the supplied diff. Accordingly, no conclusion can be reached about whether the agreement expands or restricts such use.
Required Information
To perform a meaningful review, provide the actual four added words and any surrounding sentence or paragraph, including any deleted or replacement text.
Between 2019-10-22 and 2021-10-11 · Privacy Policy
No