Monitored company
Wistia
clause.watch tracks 2 legal documents published by Wistia, re-reading each one every six hours. Below is what each document covers, in plain English.
Privacy
Wistia Privacy Policy — User Overview
Effective date: March 20, 2026
*This is a practical summary, not legal advice.*
1. Data Collection & Usage
Wistia collects information you provide, including:
- Name, email, phone number, username, password/security information
- Payment information
- Profile details, communications, and uploaded videos, audio, images, and other content
- Recruiting information, such as resumes, employment history, interview notes, assessments, references, and background-check data
- Sensitive information that may appear in uploaded content or messages, including financial information, geographic location, health-related information, and information revealing ethnicity, religion, political opinions, or sexual orientation
It also automatically collects:
- IP address and inferred location
- Browser, operating system, device, and connection information
- Viewing and engagement activity, including which Media you watched, how often, and where viewing occurred
- Page requests, error information, and email-open confirmations
Wistia says it uses this information to operate, personalize, improve, and secure the Services; process payments; communicate with users; analyze engagement; support Customers’ marketing and content development; and conduct recruitment.
Wistia stores electronic Personal Information in the United States. Retention varies: unknown-user logs are generally kept 30 days, Media may remain for the Customer’s account plus up to three years, and other data is retained based on business needs, the Customer relationship, and legal requirements.
2. User Rights
Depending on applicable law, users may request:
- Access to specific Personal Information and categories collected
- Correction or updating
- Deletion or restriction of use
- Data portability in a machine-readable format
- Information about sources, purposes, retention, and third parties
- A list of third parties receiving data
- Objection to or challenge of processing
- Withdrawal of consent
- Limits on use of certain Sensitive Personal Information
- Opt-out of disclosure or sharing with Customers and other third parties
Requests are submitted through Wistia’s Privacy & Data Requests page. Wistia says it will confirm receipt within 10 days and generally respond within 30 days, subject to verification and lawful extensions. It may deny requests it cannot verify.
Important consequences: deleting data, withdrawing consent, or opting out of Customer sharing may limit access to certain Media or Services. Backups and anonymized aggregate data may remain after deletion.
3. Third-Party Sharing
Wistia may share data with:
- Customers: Potentially identifiable viewing information, IP address, location, device/browser data, names, contact details, profile content, communications, job information, and firmographic data. Customers may use this for marketing and organizational development.
- Service providers and agents: Payment processors, analytics providers, and other vendors performing services for Wistia.
- Analytics providers: Tracking data may be used by providers for their own purposes, potentially including marketing or advertising, and they may be able to identify you by combining it with other data.
- Affiliates, third-party websites, and YouTube/Google: Their own privacy policies apply.
- Business purchasers: Data may transfer in a sale, acquisition, bankruptcy, or similar change of control.
- Authorities: Wistia may disclose information for legal compliance, fraud prevention, credit-risk reduction, safety, or law enforcement.
Public profiles, comments, messages, and uploaded content may be visible to other users and reused by others.
4. AI/ML Training
The policy does not clearly state whether Personal Information or Media is used to train Wistia’s or third-party AI models.
Wistia uses AI to organize, summarize, analyze, transcribe, create content, support meetings, and perform Service functions. If you use integrated external AI Tools, both Wistia and the AI provider may access your submitted Media and generated AI Content. Wistia expressly states that this processing is by an external third party and is not governed by this Privacy Policy. Users should review the separate AI Policy and provider terms before submitting confidential or sensitive content.
5. Key Obligations and Restrictions
Users must:
- Protect account passwords and prevent unauthorized access
- Obtain explicit consent from people appearing in uploaded Media or whose Personal Information is submitted
- Avoid registering or submitting information if under 16, except through approved School services
- Understand that voluntarily public content may become broadly available
- Review third-party privacy policies when using linked services, Google Drive, YouTube, analytics, or AI Tools
6. Liability & Disputes
The policy provides no broad user compensation or security guarantee. Wistia says it uses reasonable safeguards but cannot guarantee complete security.
For EU, UK, and Swiss data transferred under the Data Privacy Framework, users must generally complain to Wistia first, then may use BBB National Programs’ independent dispute process at no cost. Binding arbitration may be available under specified DPF conditions. The policy does not otherwise provide a detailed general dispute-resolution clause.
7. Changes
Wistia may amend the policy. If its information-use practices change, it says it will post an announcement on the Website or send an email. Continued use after changes are posted constitutes acceptance. Users should monitor notices, since opting out of ordinary emails does not stop legal notices.
Terms
Wistia Terms of Service: User-Focused Overview
*Effective March 13, 2026. This summary is informational, not legal advice. The Terms incorporate Wistia’s Privacy Policy, Artificial Intelligence Policy, Data Processing Agreement (if applicable), Acceptable Use Policy, plans, and other supplemental terms. Those documents may materially change the analysis.*
1. Data Collection and Usage
Wistia defines Customer Data broadly as registration information and other transaction data collected in connection with the Services. Specifically identified Transactional Data includes:
- Playback events, timestamps, watch duration, and re-watch patterns
- Device and technical information, such as screen width and browser/version
- Geographic location, referrer information, and UTM parameters
- Information associated with the account, users, uploaded media, and service usage
Wistia also processes Customer Content, including uploaded videos, audio, text, images, scripts, and related files. To provide the Services, Wistia may stream, embed, distribute, transcode, create thumbnails, and automatically generate summaries, chapters, captions, subtitles, translations, or dubbing.
The customer retains ownership of Customer Content and Customer Data, but grants Wistia a broad, worldwide, royalty-free, irrevocable license to use Content as necessary to provide the Services. Customers are responsible for ensuring they have all permissions and rights needed for uploaded material.
Wistia may retain and use anonymized or aggregated Customer Data—such as content-play counts and audience interactions—to improve or market its Services, including after termination. Customers are responsible for maintaining their own backups.
2. User Rights
The Terms state that the customer owns Customer Data and Customer Content. However, they do not provide a detailed procedure for:
- Accessing or correcting personal data
- Deleting data
- Porting or exporting data
- Objecting to processing or withdrawing consent
Those rights and procedures are governed primarily by the incorporated Privacy Policy and, where applicable, the DPA and privacy laws. In education settings, the school—not Wistia—must generally handle privacy-rights requests from students or other individuals.
After termination, Wistia may delete archived Customer Data, but it is not obligated to do so. It may also retain aggregated/anonymized data for service improvement and marketing.
3. Third-Party Sharing
Wistia may use contractors and third-party service providers to provide the Services. It may disclose Customer Data when reasonably necessary to:
- Provide the Services
- Comply with subpoenas, warrants, investigations, or legal requirements
- Provide data to integrated AI tools and platforms
Wistia says it does not share personally identifiable information such as usernames and email addresses for its aggregated analytics use. However, information submitted to third-party AI platforms is governed by those platforms’ own terms and privacy policies. Wistia disclaims responsibility for how those services store, use, alter, or delete Customer Content or Data.
4. AI/ML Training
The Terms expressly permit Wistia to make Customer Data available to integrated AI Tools and AI Platforms. The separate Artificial Intelligence Policy controls additional details.
The Terms also permit Wistia to use anonymized Customer Data, combined with other customers’ data, to improve or market its Services. They do not clearly state that identifiable Customer Content is used to train Wistia’s general-purpose AI models. Nevertheless, data sent to third-party AI platforms may be subject to those platforms’ own retention and training practices.
AI-generated content may not be owned by the customer or qualify for intellectual-property protection. Customers should review the AI Policy and each provider’s privacy policy before submitting confidential, personal, or proprietary material.
5. Key User Obligations and Restrictions
Users must:
- Be at least 18 years old
- Maintain secure usernames and passwords and report unauthorized access
- Ensure account users and administrators comply with the Terms
- Stay within plan limits for storage, bandwidth, seats, and other usage
- Pay overage, upgrade, or additional-seat charges when applicable
- Maintain compatible systems and backups
- Comply with applicable laws and the Acceptable Use Policy
Prohibited conduct includes scraping or data mining, reverse engineering, circumventing suspensions, creating multiple free or beta accounts, interfering with the Services, and reselling or sublicensing access. Wistia may suspend or terminate accounts for violations.
Paid subscriptions generally renew automatically. Cancellation must follow Wistia’s procedures and usually requires notice at least two months before the end of the current term. Fees are generally nonrefundable, including unused service after cancellation or downgrade. Asset-level services become noncancelable and nonrefundable once initiated, except where required by law.
6. Liability and Disputes
The Services are generally provided “as is,” without guarantees of uninterrupted, error-free operation or fitness for a particular purpose.
For paid Services, most liability is capped at the fees paid for the relevant Services during the preceding 12 months. For free and beta Services, direct damages are capped at $100. Consequential, indirect, punitive, special, lost-profit, lost-revenue, and data-loss damages are broadly excluded.
Important exceptions include certain indemnity obligations, fees, prohibited-use violations, fraud, and death or bodily injury. Customers must indemnify Wistia for claims arising from Customer Content, Customer Data, legal noncompliance, prohibited use, or DPA breaches.
Massachusetts law governs. Disputes must generally be brought in state or federal courts in Middlesex County, Massachusetts. The prevailing party may recover reasonable attorneys’ fees and costs. There is no arbitration clause in the provided Terms.
7. Changes to Services and Terms
Wistia may change, discontinue, or migrate Services and plans. It may change the Terms by posting website notice, sending email, or using another method intended to attract attention. Continued use after the effective date constitutes acceptance. Users who disagree must stop using the Services; the Terms do not provide a separate opt-out process while retaining access.
Change history
2026-08-23 · Privacy
Summary
The provided diff does not include the actual contract language. It only states:
> “Added approximately 478 words to the document”
Accordingly, it is not possible to determine:
- What provisions were added, deleted, or replaced;
- Whether liability, indemnity, confidentiality, payment, termination, or governing-law terms changed;
- Whether the customer’s data may be accessed, stored, disclosed, or transferred;
- Whether customer data, prompts, outputs, or usage information may be used to train, fine-tune, evaluate, or improve AI models;
- Whether any opt-out, consent, deletion, security, or data-retention rights were added or removed.
AI-Training Analysis
No conclusions can be drawn about AI-model training from the information provided. The statement that approximately 478 words were added does not identify whether those words authorize:
- Training or fine-tuning models using customer content;
- Use of customer data for service improvement or product development;
- Human review or annotation of customer data;
- Sharing data with affiliates, vendors, or model providers;
- Retention of data after termination;
- Aggregation, anonymization, or de-identification of customer data; or
- Any customer right to prohibit or limit such uses.
Information Needed
Please provide the actual redline text, including the added language in {} and any deleted or replaced language in []/[]{}. Once provided, the changes can be analyzed for legal effect, risk allocation, and especially any permissions concerning the use of customer data to train or improve AI models.
2026-08-22 · Privacy
Executive Summary
The diff appears to replace and substantially reorganize the Privacy Policy rather than merely make wording edits. It introduces numbered sections, updates the covered privacy laws, expands certain service and data descriptions, and changes how users contact Wistia. The provided diff does not clearly add or remove authorization to use customer data to train AI models.
Important Changes and Risks
1. Broader and reorganized scope
- The policy is reframed to cover Wistia’s Websites, Media, and Services, including media hosted by Wistia and user engagement with that media.
- “Users” now includes individuals who view or use customer-hosted Media, not only people who directly interact with Wistia.
- The policy continues to distinguish Students and Schools, but the wording is reorganized and expressly refers users to a separate Schools & Students Privacy Policy Addendum.
- The policy adds or updates references to numerous laws, including newer U.S. state privacy statutes, GDPR, UK GDPR, Swiss law, and PIPEDA.
Risk: Customers may need to reassess whether their viewers, employees, students, and other third parties are adequately notified and whether required consents or contractual disclosures are in place.
2. Data minimization language added
The revised policy states that Wistia does not collect Personal Information indiscriminately and limits the type and amount collected to what is necessary for purposes identified in the policy.
Risk: This is a potentially helpful limitation, but it is qualified by broad purposes and does not necessarily restrict data use to a customer’s instructions or prohibit secondary uses.
3. Expanded description of collected information
The revised text expressly identifies information collected when users visit Websites, register for or subscribe to Media or Services, contact Wistia, or otherwise interact with the Services. It also adds or restates collection of payment information, account credentials, and profile information.
4. AI-related provisions
- The diff changes only a grammatical reference from “software’s” to “software's” and changes quotation punctuation around “AI Content.”
- The policy continues to state that Wistia may integrate publicly available third-party AI platforms, applications, and software to benefit Customers.
- It states that AI Content processed by an external third party is not subject to Wistia’s Privacy Policy.
No clear AI-training change: The supplied diff does not expressly state that Customer Media, Personal Information, prompts, outputs, or usage data may be used to train Wistia’s or third-party AI models. It also does not expressly prohibit such training.
Risk: Because third-party AI processing is outside Wistia’s policy, customers should review the applicable AI Tool terms and confirm whether those providers may retain inputs or use them for model training.
5. Rights, contacts, and effective date
- Contact information is consolidated under a Data Protection Office.
- Non-discrimination language is reorganized and expressly addresses discounts, benefits, penalties, and service differences.
- The revised policy states an effective date of March 20, 2026.
2026-08-21 · Privacy
Structured Summary of Important Changes
1. Major restructuring and expanded scope
- The policy has been substantially reorganized into 16 numbered sections, with a new “Jump to section” table of contents.
- The covered services are clarified and expanded to include Wistia’s:
- Websites and the
wistia.comdomain; - Hosted Media;
- Applications, features, content, and other Services offered from time to time.
- The policy now expressly covers information collected when users access, listen to, view, or otherwise use Media, not merely when they interact with Websites or register for Services.
- “Users” now expressly includes individuals who view or use Customer-created Media, while “Customers” are separately identified as businesses or organizations creating and distributing Media.
2. Broader legal coverage
The revised policy updates and expands the list of applicable privacy laws, including:
- CCPA and CPRA;
- Colorado, Connecticut, Montana, Oregon, Texas, Virginia, and Utah privacy laws;
- GDPR, UK GDPR, Swiss data-protection law, and PIPEDA.
This may increase the rights available to users and the compliance obligations Wistia assumes. However, the revised presentation appears to contain drafting and numbering inconsistencies that should be checked before publication.
3. Collection and use of personal information
- The policy replaces the general statement that Wistia does not collect information “indiscriminately” with a more specific data-minimization statement: Wistia limits information to what is necessary to fulfill purposes identified in the policy.
- Examples of collected information are restated and expanded, including registration details, account credentials, payment information, Media-related information, and engagement data.
- The policy more clearly states that Wistia measures viewer engagement with Customer Media, potentially including information about people who are not Wistia account holders.
Risk: Customers should assess whether Media analytics and viewer engagement data may include identifiable or sensitive information and whether appropriate notices and consents are provided to viewers.
4. AI-related changes and training risk
- The diff continues to state that Wistia may integrate publicly available third-party AI platforms, applications, and software (“AI Tools”).
- User-selected AI functionality may create “AI Content.”
- Information processed by an external AI provider remains subject to that provider’s privacy policy, not Wistia’s Privacy Policy.
No express change was identified authorizing Wistia to use Customer data, Media, Personal Information, or AI Content to train Wistia’s or third-party AI models. The diff also does not add an explicit prohibition on model training.
Risk: Because third-party AI processing is carved out to external providers’ policies, Customers should separately review whether those providers:
- retain prompts, uploads, transcripts, or generated content;
- use inputs or outputs for model training or service improvement;
- permit opt-outs;
- transfer data internationally; or
- use human review.
A separate AI/data-processing agreement may be advisable, particularly for confidential, biometric, student, health, or other sensitive data.
5. Consent and legal basis
- The prior “acknowledgment” of the policy is revised to state that users consent to Wistia’s collection, use, and sharing of information.
- The revised policy adds a dedicated section explaining legal bases, including consent, contractual necessity, legal obligations, and legitimate interests.
Risk: A broad consent formulation may not substitute for legally required, specific consent—particularly for cookies, sensitive data, children’s data, biometric information, or third-party AI processing.
6. Children and students
- Student coverage is reframed around individuals under 16 receiving school-related services.
- The separate Schools & Students Privacy Policy Addendum remains relevant.
Customers serving minors should confirm that the revised policy and addendum clearly allocate notice, consent, deletion, and school/customer responsibilities.
7. Other notable changes
- A Data Protection Office contact address and expanded contact methods are added.
- The effective date is stated as March 20, 2026.
- Non-discrimination language is revised and now expressly addresses discounts, benefits, penalties, and service differences.
- Numerous typographical, quotation, and cross-reference changes appear; the final document should be carefully proofread.
2026-08-21 · Privacy
Summary
The provided diff does not include the actual added or deleted contractual language. It only states:
> “Added approximately 478 words to the document”
Accordingly, the legal and commercial effect of the changes cannot be reliably analyzed.
AI Training and Customer Data
No substantive language is provided concerning:
- Whether the customer’s data may be used to train, fine-tune, or improve AI models;
- Whether prompts, inputs, outputs, telemetry, or usage data may be retained;
- Whether data may be shared with affiliates, subprocessors, or third-party AI providers;
- Whether customer data is anonymized, aggregated, or de-identified before use;
- Whether the customer can opt out of model training;
- Whether the provider obtains rights to use customer content after termination;
- Ownership of model outputs or improvements derived from customer data; or
- Security, confidentiality, deletion, or geographic-transfer restrictions applicable to AI processing.
Therefore, no conclusion can be reached about whether the changes expand or restrict the provider’s rights to use customer data for AI training.
Other Legal Risks
The absence of the actual diff also prevents assessment of potential changes to:
- Liability caps or indemnities;
- Warranties and disclaimers;
- Termination rights;
- Confidentiality obligations;
- Data-protection compliance;
- Intellectual-property ownership or licensing;
- Subcontracting and subprocessors;
- Audit rights; or
- Governing law and dispute resolution.
Required Information
Please provide the full redline or the exact text of the 478 added words, including any surrounding provisions needed to understand defined terms and cross-references. Without that text, any more specific analysis would be speculative.
2026-08-18 · Privacy
Summary of Important Changes
1. Major restructuring and expanded scope
- The policy has been substantially reorganized into 16 numbered sections, with new navigation headings.
- The scope now expressly covers:
- Wistia’s Websites, Media, and Services;
- Individuals who view or use Media, not only customers or account holders;
- Viewer engagement and usage data.
- The policy continues to exclude companies Wistia does not own or control and their personnel, but the prior wording regarding certain school-related processing has been reorganized and may be less immediately clear.
Risk: The expanded definition of “Users” may allow Wistia to treat viewers, employees, prospects, and other individuals interacting with customer content as directly covered by the policy, even where they have no direct relationship with Wistia.
2. Broader legal coverage
The revised policy replaces the former general list of privacy laws with a more structured list covering numerous U.S. state laws, including the CCPA/CPRA, CPA, CTDPA, MCDPA, OCPA, TDPA, VCDPA, and UCPA, as well as GDPR, UK GDPR, Swiss DPA, and PIPEDA.
Risk: The policy appears intended to support broader regulatory compliance, but the numerous statutory references do not necessarily establish that Wistia will provide every right under every listed law in all circumstances. Customers should not treat the list alone as a contractual compliance commitment.
3. Collection and minimization language
New language states that Wistia does not collect Personal Information “indiscriminately” and limits the type and amount collected to what is “necessary” for purposes identified in the policy.
The examples of information collected are largely retained, including registration details, contact information, account credentials, and payment information.
Potential benefit: This is more explicit data-minimization language.
Risk: “Necessary” is not precisely defined and may still permit broad collection for business, analytics, marketing, service development, and customer-related purposes described elsewhere.
4. AI tools and AI-model training
The diff retains language stating that Wistia may integrate publicly available third-party AI platforms, applications, and software to benefit customers. It also retains that:
- Users may choose to use AI Tools during Media creation;
- Content generated through those tools is “AI Content”;
- Information processed by an external third party is not subject to Wistia’s Privacy Policy.
Important limitation
The provided diff does not add an express provision authorizing Wistia to use customer Media, Personal Information, prompts, outputs, or usage data to train Wistia’s or third-party AI models. It also does not add a clear prohibition on such training.
Risk: The policy leaves unresolved whether customer data submitted to AI features may be:
- retained by the external AI provider;
- used to train or improve that provider’s models;
- used by Wistia for model development or product improvement; or
- subject to customer contractual restrictions.
Customers should obtain separate contractual assurances, AI-provider terms, or a data-processing addendum addressing training, retention, deletion, confidentiality, and use of customer data.
5. Contact information and effective date
The revised policy adds a formal Data Protection Office contact block and states an effective date of March 20, 2026.
Between 2019-09-25 and 2020-10-06 · Terms
Summary
The provided diff only states that approximately 75 words were removed from the document. It does not identify:
- Which provisions were deleted;
- Whether any language was added or replaced;
- Whether the deletions affect customer data rights, confidentiality, security, intellectual property, or liability; or
- Whether the customer’s data may be used to train AI models.
AI Training and Data-Use Analysis
No conclusions can be drawn from the supplied information about AI model training. The diff does not show whether the document:
- Permits or prohibits using customer data to train, fine-tune, or improve AI models;
- Limits training to de-identified, aggregated, or anonymized data;
- Allows human review or labeling of customer data for AI development;
- Gives the provider rights to retain customer data after termination;
- Restricts use of customer inputs, outputs, prompts, or generated content; or
- Requires deletion, segregation, or confidentiality of data used in connection with AI services.
Risk Assessment
The deletion of approximately 75 words could create material risk if it removes:
- A prohibition on using customer data for model training;
- Consent or notice requirements;
- Data deletion or retention obligations;
- Confidentiality, security, or data-processing restrictions;
- Customer ownership or license limitations; or
- Indemnity, audit, or liability protections.
However, the direction and significance of the change cannot be determined without the actual deleted text and the surrounding provisions.
Information Needed
Please provide the full redline showing the deleted language, including the relevant surrounding sections. The analysis should specifically compare any provisions concerning:
1. Customer data and personal information;
2. Service improvement, analytics, or product development;
3. Artificial intelligence or machine learning;
4. Data retention and deletion;
5. Confidentiality and security;
6. Intellectual-property ownership and licenses; and
7. Liability, indemnification, and compliance obligations.
Between 2019-12-28 and 2020-03-06 · Privacy
Summary
Information Provided
The diff only states:
> “Added approximately 478 words to the document”
It does not include the actual added, deleted, or replaced contract language.
Legal and Risk Analysis
Because the substantive text is missing, it is not possible to determine:
- What contractual obligations have changed;
- Whether liability, indemnity, confidentiality, warranties, termination, or governing-law provisions were modified;
- Whether the customer’s data may be collected, accessed, retained, disclosed, or shared with third parties;
- Whether customer data, prompts, outputs, or usage information may be used to train, fine-tune, test, or improve AI models;
- Whether the customer has opted out of AI training or has any deletion, audit, or control rights;
- Whether the provider may use data in de-identified, aggregated, or identifiable form;
- Whether customer data may be transferred across borders or processed by subprocessors; or
- Whether the changes create new security, privacy, intellectual-property, or regulatory risks.
AI Training-Related Changes
No AI-training provisions are included in the supplied diff. Therefore, no conclusion can be reached about whether the revised agreement:
- Authorizes training on customer content;
- Limits training to de-identified or aggregated data;
- Prohibits use of customer data for model training;
- Permits use of data to improve the provider’s services or models;
- Grants the provider rights in customer inputs or outputs; or
- Changes the customer’s ability to opt out.
Required for Further Review
Please provide the actual marked-up contract text, including the approximately 478 added words and any surrounding deleted or replacement language. The specific clauses are necessary to identify the legal effect and any new risks.
Between 2018-04-21 and 2019-09-25 · Terms
Summary of Important Changes and Risks
1. AI tools and use of Customer Data — Material change
The revised terms expressly state that Wistia’s Services integrate publicly available AI platforms and AI tools. This creates several new data-use and confidentiality considerations:
- Customer Data may be made available to integrated AI tools and platforms. The language appears to permit Wistia to provide Customer Data to third-party AI providers in connection with the Services.
- Wistia may use anonymized Customer Data, including metrics such as the number of plays of Customer Content. The terms do not clearly define the anonymization standard or identify all permitted purposes.
- Customer Confidential Information shared with an AI platform or tool through the Services is expressly excluded from the normal confidentiality protections. Customers are directed instead to the relevant third-party websites and privacy policies.
- The ordinary confidentiality provision requiring return or deletion of information upon termination does not apply to Customer Confidential Information shared with third-party AI platforms. Their retention and deletion practices will be governed by their own policies.
- The revised service description includes automatic generation or display of summaries, chapters, closed captions, and similar outputs, which may involve automated or AI-based processing of Customer Content.
Key risks
- Customer may have limited control over which third parties receive its data and how those parties use, retain, or further process it.
- Third-party AI providers’ terms may permit broader use, including model improvement or training, unless separately restricted by their policies or a DPA.
- Confidentiality, deletion, and security obligations may not flow through to AI providers.
- Customers should confirm whether Customer Content, Personal Information, prompts, outputs, and metadata are used to train or improve AI models. The quoted language does not clearly prohibit such use.
2. Incorporated policies and supplemental terms
The agreement continues to incorporate the Privacy Policy, Privacy-AI Policy, DPA, and other supplemental or customer agreements by reference. This increases the importance of reviewing those documents because they may contain the operative limits on AI processing, data retention, subprocessors, and security.
The order of precedence appears to place Supplemental Terms and Policies above the main agreement, potentially allowing those documents to modify or qualify the general terms.
3. Confidentiality and third-party services
The terms expressly identify AI platforms as Third Party Services outside Wistia’s control. Wistia disclaims responsibility for those services and directs customers to their separate policies. This may reduce Wistia’s contractual responsibility for third-party AI processing.
4. Other notable changes
- A specific DMCA designated-agent address, telephone number, and email address are added.
- Notices to Wistia may be sent to support@wistia.com.
- Wistia may disclose Customer’s status as a Wistia customer in the ordinary course.
- Several changes standardize wording, punctuation, capitalization, and defined terms, without an apparent substantive effect.
- The revised text clarifies the distinction between the Free Version, Paid Version, and applicable Plans.
Overall assessment: The principal substantive development is the express authorization and disclosure of integrated third-party AI processing, coupled with reduced confidentiality and deletion protections for information shared with those providers.
Between 2017-06-11 and 2019-05-19 · Privacy
Between 2016-09-30 and 2018-04-21 · Terms
Summary
The provided diff only states that approximately 75 words were removed from the document. It does not identify:
- Which provisions were deleted;
- Whether any language was added or replaced;
- Whether the deletion affects customer data rights, confidentiality, security, or liability; or
- Whether the deletion changes how customer data may be used to train, fine-tune, evaluate, or improve AI models.
AI-Training Implications
No reliable conclusion can be drawn about AI-model training from the information provided. The deleted language could potentially have:
- Restricted the provider from using customer data to train or improve AI models;
- Required customer consent or an opt-out;
- Limited training use to de-identified, aggregated, or non-personal data;
- Explained whether prompts, outputs, files, or usage data are retained for training;
- Allocated ownership or licensing rights in data used for model development; or
- Required deletion, security controls, or confidentiality protections.
Conversely, the deletion may have removed a provider permission or limitation, but the direction of the legal change cannot be determined without the actual text.
Risk Assessment
The main risk is uncertainty. A 75-word deletion could materially alter the agreement, especially if it removes:
- A prohibition or limitation on AI training;
- A customer approval or opt-out right;
- A commitment not to use customer content for model improvement;
- A data-deletion or retention obligation; or
- A warranty, indemnity, or confidentiality protection.
The characterization of the change also matters: a deletion may leave surrounding language broader or more permissive, even if no replacement text was added.
Information Needed
Please provide the actual deleted text and any surrounding provisions, ideally using a full redline showing additions, deletions, and replacements. Without that text, it is not possible to identify the important legal changes or determine whether customer data may now be used to train AI models.
Between 2009-07-30 and 2015-04-26 · Terms
Summary of Important Changes
1. New AI-platform provisions and data use
- The revised Terms expressly state that Wistia’s Services integrate with publicly available AI Platforms and AI Tools.
- Customer Data may be made available to those integrated AI services. The language appears to permit the use of anonymized Customer Data, including metrics such as the number of plays of Customer Content.
- The excerpt does not clearly state that Wistia may use identifiable Customer Content to train its own AI models. However, allowing Customer Data to be sent to third-party AI providers creates a related risk because those providers’ own terms and privacy policies may govern whether data is retained, used for service improvement, or used to train models.
- Customers should confirm:
- What data is sent to each AI provider;
- Whether Customer Content, prompts, outputs, metadata, or usage data are retained;
- Whether providers may use the data for model training;
- Whether customers can opt out; and
- Whether data is anonymized, aggregated, or de-identified before transfer.
2. Confidentiality carve-outs for AI services
- New language provides that the confidentiality provisions do not govern Customer Confidential Information shared with an AI Platform or AI Tool through Wistia’s Services.
- Information about how those providers may use Customer Confidential Information is directed to their separate websites and privacy policies.
- This is a significant reduction in contractual protection. Wistia’s confidentiality obligations may not apply once information is transferred to an AI provider, and the applicable third-party policies may be changeable, less protective, or inconsistent with Customer’s confidentiality requirements.
- The same carve-out appears in the termination provisions: Wistia’s obligation to return or permanently erase Confidential Information does not govern information shared with AI providers. Customer may therefore have limited ability to require deletion after termination.
3. Expanded and clarified service structure
- The introduction is substantially reorganized and now expressly distinguishes:
- The Free Version;
- Paid Versions; and
- Beta, pilot, or limited-release features.
- The revised structure adds navigation headings and incorporates the Privacy Policy, Wistia’s AI Privacy Policy, DPA, and other customer agreements by reference.
- Incorporation by reference means important obligations may exist outside the Terms and may be located in separately maintained online policies.
4. Definitions and operational changes
- Numerous definitions are added or clarified, including Account Owner, Additional Subscription, Asset-Level Services, Bandwidth, Customer Data, Plans Page, Seat, Team Account, Transactional Data, and Usage Capacity.
- “Transactional Data” expressly includes playback events, timestamps, watch data, browser information, geographic location, referrer information, and UTM parameters. This clarifies the breadth of usage and behavioral data Wistia may collect and process.
- The revised Terms also add or clarify restrictions on scraping, data mining, bots, and automated access.
5. Other notable changes
- A detailed DMCA designated-agent address and procedure is added.
- Notice provisions are updated to include Wistia’s support email.
- The displayed text appears heavily reformatted and duplicated in places; the final clean version should be reviewed to ensure no sections were accidentally omitted or misordered.