Reviewed August 2026

    15 AI Privacy Policy Examples

    Compare verified privacy disclosures from ChatGPT, Gemini, Claude, Copilot, Midjourney, and other AI tools, then adapt 15 original clause templates to your own product.

    15 clause templatesPrimary sources linked20 min read
    PolicyForge Editorial Team|Checked against primary privacy and AI sources; examples are PolicyForge templates
    Editorial contentUpdated August 2026
    Quick answer

    Quick answer

    An AI product's privacy notice should explain the ordinary privacy topics plus the AI-specific data flow: what prompts, uploads, outputs, feedback, and derived data are collected; why they are used; whether people or model providers receive them; whether they train a model; how long they remain; and what controls or rights are available. The wording must match the deployed system and vendor contracts.

    Examples
    15 editable clauses
    Core data
    Inputs, outputs, and feedback
    Key checks
    Training, providers, and retention

    These are drafting examples, not legal advice. Verify every statement against your product and its current provider terms; replace unsupported wording with accurate, sourced text.

    Create your own

    Map your AI data flow into a privacy policy draft

    Answer guided questions about prompts, uploads, providers, training, retention, and controls, then review and edit the resulting policy.

    • AI data-flow questions
    • Editable draft
    • Free account available

    What makes an AI privacy policy different?

    AI does not replace the normal privacy analysis. It adds data flows that are easy to miss: a prompt may contain personal data about the user or someone else; an upload can create embeddings or classifications; a provider may retain abuse-monitoring logs; feedback can bundle the original interaction; and product analytics is different from training or fine-tuning a model.

    A separate “AI privacy policy” is not always necessary. The important outcome is a clear, accessible notice that matches the product, contracts, retention schedule, and user controls. Interface notices, AI-content labels, impact assessments, or contractual terms may still be needed alongside it.

    Map the full flow

    Trace data from collection through providers, logs, training, outputs, and deletion.

    Separate purposes

    Do not collapse service delivery, safety, analytics, evaluation, and model training into one phrase.

    Verify every control

    Test opt-outs, deletion, access, and human-review routes before promising them.

    First-party evidence

    Privacy examples from 15 AI tools and providers

    These are concise PolicyForge summaries of current official sources—not copied policy text or permanent guarantees. Product, plan, region, settings, and feature choices can change the result. Sources were checked August 11, 2026.

    Example 1

    OpenAI (ChatGPT & API)

    AI assistants and APIs

    OpenAI's current materials give ChatGPT users a model-improvement control and state that business products and the API are not used for model training by default. Those are different product rules, so a notice should identify the service actually used.

    Verify for your implementation

    • Consumer data-control setting
    • Business or API training default
    • Retention and feedback exceptions

    Example 2

    Google Gemini (Apps & API)

    AI assistants and APIs

    Google's Gemini Apps Privacy Hub describes activity controls, human review, and product-specific retention. Its developer documentation separately says paid Gemini API prompts and responses are not used to improve Google products, while free and paid API treatment differs.

    Verify for your implementation

    • Gemini Apps Activity setting
    • Human-review retention
    • Free versus paid API terms

    Example 3

    Anthropic Claude

    AI assistants and APIs

    Anthropic's Privacy Center separates consumer Claude accounts from commercial products. It says commercial chats and coding sessions are not used for training unless the customer opts into a program or submits feedback, while consumer use depends on choices and safety-review conditions.

    Verify for your implementation

    • Consumer improvement choice
    • Commercial-product treatment
    • Feedback and safety-review exceptions

    Example 4

    Microsoft Copilot & Azure AI

    Enterprise AI

    Microsoft says Microsoft 365 Copilot Chat prompts and responses are not used to train underlying foundation models. Azure's current data-privacy documentation separately explains that customer prompts, completions, embeddings, and training data are not used to train foundation models without permission.

    Verify for your implementation

    • Exact Copilot product
    • Microsoft 365 permissions and retention
    • Azure deployment geography and abuse monitoring

    Example 5

    Meta AI & Llama

    Consumer and open models

    Meta's Privacy Center says generative-AI training information can come from public sources and Meta products, and that messages and replies with AI may be used to improve models. It also explains that deleting source information does not immediately undo patterns a trained model learned.

    Verify for your implementation

    • Public and product data used
    • Regional objection options
    • Treatment of AI chats and deleted information

    Example 6

    Midjourney

    Image and video generation

    Midjourney's privacy policy lists text, image, and spoken-input prompts among collected data. Its product documentation says creations can be discoverable in an open-by-default community and explains when Stealth mode is needed for private creation.

    Verify for your implementation

    • Prompt and upload collection
    • Public visibility of creations
    • Stealth-mode and deletion limits

    Example 7

    Stability AI (DreamStudio)

    Image generation

    DreamStudio's privacy policy says generated content and associated metadata—including image specifications, seeds, and text prompts—are stored in account history so users can retrieve prior creations. That hosted-service behavior should not be generalized to self-hosted models.

    Verify for your implementation

    • Hosted versus self-hosted processing
    • Account-history storage
    • Deletion and metadata treatment

    Example 8

    GitHub Copilot

    Developer AI

    GitHub's current model-hosting documentation says individual Copilot interaction data may be used to improve models subject to user settings, and individual subscribers can opt out. The page distinguishes those accounts from business and enterprise arrangements.

    Verify for your implementation

    • Individual versus organization plan
    • Prompts, suggestions, and code context
    • Training opt-out and model-host terms

    Example 9

    Grammarly

    Writing assistants

    Grammarly says generative-AI prompts and relevant context can be shared with vetted service providers to deliver the feature, and those providers may not train on user content. Its own Product Improvement and Training control lets eligible individual users opt out of Grammarly's training use.

    Verify for your implementation

    • Saved documents versus other text
    • LLM service providers
    • Account and organization training settings

    Example 10

    Notion AI

    AI workspaces

    Notion says it and its AI subprocessors do not use customer data to train models by default. Its security guidance also documents plan- and feature-dependent provider retention, including different defaults for Enterprise and non-Enterprise workspaces.

    Verify for your implementation

    • Current AI subprocessors
    • Workspace plan and feature
    • Provider, embedding, and deleted-page retention

    Example 11

    Zoom AI Companion

    Meeting AI

    Zoom says communications-like customer content is not used to train Zoom or third-party AI models. Its technical library also explains that AI Companion must process content to provide features and may retain some customer content for support and debugging, subject to feature and account settings.

    Verify for your implementation

    • Enabled AI Companion feature
    • Host and participant notices
    • Model provider and retention configuration

    Example 12

    Salesforce Einstein & Agentforce

    CRM and enterprise agents

    Salesforce describes the Einstein Trust Layer as features, processes, and policies for privacy, accuracy, and responsible AI. Its documentation identifies controls such as configurable data masking for supported generative-AI features; customers should verify which controls apply to their deployment.

    Verify for your implementation

    • Supported feature and Trust Layer setting
    • Data masking and audit configuration
    • Connected model and retention terms

    Example 13

    Adobe Firefly

    Creative AI

    Adobe's current Firefly FAQ says its models were trained on licensed content such as Adobe Stock together with public-domain content, and that Content Credentials are applied to certain exports. Product and enterprise terms should still be checked for customer-content and custom-model use.

    Verify for your implementation

    • Firefly feature and account type
    • Customer or custom-model training
    • Content Credentials and output terms

    Example 14

    Spotify recommendations & AI features

    Personalization

    Spotify's privacy policy says it generally keeps streaming history for the life of an account to support retrospective playlists and personalized recommendations. Spotify also documents that listening in a Private Session does not affect recommendations or appear in Wrapped.

    Verify for your implementation

    • History used for personalization
    • Private-session behavior
    • Separate terms for newer AI features

    Example 15

    Tesla Autopilot, FSD & vehicle AI

    Vehicle AI

    Tesla's privacy support page says most camera processing occurs on the vehicle and that sharing camera recordings generally depends on the driver's Data Sharing choice, with specified safety-event exceptions. It separately describes operational and diagnostic vehicle data.

    Verify for your implementation

    • On-device versus transmitted data
    • Driver consent and safety-event exceptions
    • Association with an account or vehicle

    15 editable AI privacy policy clauses

    These are original PolicyForge templates, not copied company policies. Replace every bracketed field, delete inapplicable clauses, and verify all vendor and system behavior before publishing.

    Inputs, outputs, and model use

    The core data flows created by chat, uploads, outputs, training, and feedback.

    Clause 1

    Chat prompts and responses

    Use when: A user sends text to an AI chat or assistant feature.

    When you use [AI feature], we collect the prompts you submit, the responses generated for you, and related technical data such as [usage data]. We use this information to provide the feature, maintain security, and [other current purpose].

    Review before using

    • List only data the product actually collects
    • Separate service delivery from optional improvement purposes

    Clause 2

    Files, images, audio, or other uploads

    Use when: The AI feature analyzes user-provided documents or media.

    If you upload [files/images/audio] to [feature], we process the upload and information derived from it to [summarize/classify/generate]. Do not upload information you are not authorized to share. We retain uploads for [period or event] unless [exception].

    Review before using

    • Name derived data as well as the original upload
    • Verify the real retention and deletion path

    Clause 3

    Generated outputs and history

    Use when: The product stores AI-generated results or conversation history.

    We store generated outputs and conversation history so you can [access, continue, or manage] prior work. You can delete [which records] through [control]. Deletion from active systems takes [period], subject to [narrow backup, security, or legal exceptions].

    Review before using

    • Do not promise immediate deletion if backups remain
    • Explain whether deleting history also deletes provider copies

    Clause 4

    Model training or improvement

    Use when: Customer inputs or outputs may improve a model or AI feature.

    [We do / do not] use prompts, uploads, or generated outputs to train or fine-tune [which model or feature]. When this use is optional, you can change your choice in [setting] or contact [method]. The choice does not affect [state any real limit or effect].

    Review before using

    • Distinguish foundation-model training, fine-tuning, evaluation, and product analytics
    • Verify defaults for every plan and provider

    Clause 5

    Business or API data exclusion

    Use when: Commercial/API data receives different training or retention treatment.

    For [business/API plan], we do not use customer content to train shared models. We process that content to provide and secure the service and retain it for [period], unless the customer configures [available control] or a longer period is required for [specific reason].

    Review before using

    • Confirm the contract and every subprocesser's terms
    • Avoid implying zero retention when abuse monitoring or logs exist

    Clause 12

    Ratings and feedback on AI outputs

    Use when: Thumbs-up/down, corrections, or comments are collected for evaluation.

    When you rate or comment on an AI response, we collect the feedback, the related [prompt/output/context], and your account identifier [if applicable]. We use it to investigate issues and evaluate or improve [which service or model].

    Review before using

    • Disclose the context bundled with feedback
    • State whether feedback can be used for training

    Providers, people, and retention

    Who can receive or review AI data, how long it remains, and where it is processed.

    Clause 6

    Human review of AI interactions

    Use when: Staff or contractors may review prompts, outputs, or flagged interactions.

    Authorized [employees/contractors] may review a limited set of AI interactions for [support, safety, evaluation, or abuse prevention]. Access is [how limited]. Do not submit [sensitive categories] unless the feature expressly requests them for [purpose].

    Review before using

    • State who can review and why
    • Do not call review de-identified if reviewers can reconnect it to an account

    Clause 7

    Third-party model providers

    Use when: User data is sent to an external AI API or infrastructure provider.

    We send [data categories] to [provider] to generate [result]. [Provider] processes this information on our behalf under [contractual role, if accurate]. Its retention and model-training treatment for this service is [verified treatment]. See [subprocessor or provider link] for more detail.

    Review before using

    • Name the provider or clearly identify the recipient category
    • Check transfers, retention, and training terms for the exact product tier

    Clause 8

    AI data retention schedule

    Use when: Prompts, logs, feedback, and outputs have different retention periods.

    We retain AI conversation history for [period], security and abuse logs for [period], and feedback you submit for [period]. We then delete or de-identify the information, subject to [specific legal, dispute, security, or backup exception].

    Review before using

    • Use separate periods when systems differ
    • Make the schedule operationally reproducible

    Clause 14

    International AI processing

    Use when: Model providers or support teams process data in other countries.

    We and our AI service providers process information in [countries/regions]. Where required, we use [transfer mechanism] and safeguards described in [link]. You can request information about applicable safeguards through [contact method].

    Review before using

    • Map every relevant provider and support location
    • Do not name a transfer mechanism that has not been executed

    Higher-impact uses and user controls

    Sensitive data, automated decisions, personalization, children, and privacy requests.

    Clause 9

    Sensitive-data boundaries

    Use when: The AI feature is not intended to receive certain sensitive information.

    [Feature] is not designed to process [health, financial, biometric, children's, or other excluded data]. Please do not submit that information. If we identify prohibited content, we may [delete, restrict, or investigate] it as described in [policy or control].

    Review before using

    • A warning does not replace technical controls for foreseeable use
    • Match excluded categories to the real product and contracts

    Clause 10

    Automated decisions about people

    Use when: AI makes or materially supports a decision affecting an individual.

    We use [system] to [make or support] decisions about [purpose]. It considers [main data categories]. [Human role] reviews [which decisions]. Where applicable, you may request [information, correction, opt-out, or human review] through [method].

    Review before using

    • Obtain qualified review for employment, credit, housing, health, or other high-impact uses
    • Explain the actual human role rather than saying only “human in the loop”

    Clause 11

    AI personalization and recommendations

    Use when: Algorithms rank content, products, or actions for a user.

    We use [activity, preferences, or other signals] to personalize [recommendations/rankings]. You can [change signals, reset history, or disable personalization] through [control]. [Sponsored or commercial influence] is handled as described in [link].

    Review before using

    • Identify the most important signal categories
    • Keep advertising and endorsement disclosures separate

    Clause 13

    Children and teen users

    Use when: An AI product excludes children or has age-specific processing.

    [Service/AI feature] is intended for people aged [age] or older. We do not knowingly collect personal data from children below [age/rule]. If you believe a child provided data contrary to this notice, contact [method] so we can review and take appropriate action.

    Review before using

    • Age thresholds vary by product, consent model, and jurisdiction
    • Use age assurance or parental controls where required; wording alone is not enough

    Clause 15

    Privacy rights and AI controls

    Use when: Users need one route for access, deletion, correction, objection, or AI-specific controls.

    Depending on where you live, you may have rights regarding personal data used by our AI features. You can [access/delete/export/change training settings] through [product control] or submit a request at [method]. We may need to verify your identity and will explain if an exception applies.

    Review before using

    • Separate universal product controls from jurisdiction-dependent legal rights
    • Test that every linked control and request channel works

    Apply the clauses

    Build a draft around your deployed AI system

    Use the examples for structure, then answer questions about the actual data, model providers, retention, training choices, and rights workflow.

    • Tailored to your answers
    • Editable before publishing
    • No compliance guarantee

    AI privacy inventory

    Verify these facts before drafting

    Every prompt, upload, output, feedback, log, and derived-data category
    Each purpose: delivery, safety, support, analytics, evaluation, or training
    Every model, hosting, moderation, and support provider receiving the data
    Provider retention and training terms for the exact product and plan
    Human access, review criteria, roles, and access controls
    Separate retention periods and deletion behavior, including backups
    Automated decisions, consequences, human role, and recourse
    Working access, deletion, objection, training, and personalization controls

    AI privacy policy FAQ

    What should an AI privacy policy include that a regular privacy policy doesn't?

    Alongside the usual privacy disclosures, describe AI-specific data flows that actually apply: prompts and uploads, generated outputs, logging and retention, model training or fine-tuning, human review, third-party model providers, automated decisions, and deletion or opt-out choices. The policy should distinguish current practices from optional or future uses.

    Do I need a separate privacy policy for my AI product?

    Not necessarily. AI-specific disclosures can sit in the main privacy policy, a product notice, or a clearly linked addendum. Choose the format that makes the processing understandable and keeps the information easy to update. Other AI transparency notices may be required separately from a privacy policy.

    Can users opt out of having their data used to train AI models?

    That depends on the data, purpose, legal basis, product terms, and laws that apply. Some providers offer training controls or exclude certain business and API data by default. Clearly state whether inputs or outputs are used for training, what controls are available, and any limits on deletion or opt-out requests.

    How does the EU AI Act affect AI privacy policies?

    The EU AI Act adds risk-management and transparency duties for certain AI providers and deployers, while GDPR governs personal-data processing. Some AI Act information belongs in product interfaces, technical documentation, or AI-content disclosures rather than the privacy policy. Coordinate the notices so they are accurate and do not conflict.

    What happens to my conversations with AI chatbots under privacy law?

    A conversation can contain personal data when it identifies or relates to a person. Explain what conversation data is collected, why it is used, how long it is retained, whether people or third parties can review it, whether it contributes to model improvement, and how users can exercise available privacy controls. Do not encourage users to submit sensitive information unless the product is designed to handle it.

    Do I need to disclose if my product uses third-party AI models like GPT-4 or Claude?

    If a third-party model provider receives personal data, your disclosures should accurately explain the relevant recipient or processor, the data sent, the purpose, retention or training treatment, and any international transfer information required by applicable law. Naming the provider can also help users understand the product's data flow.

    How should an AI privacy policy address automated decision-making?

    Describe whether AI makes or materially influences decisions about people, the data and purpose involved, and the consequences and safeguards that apply. GDPR has specific rules for certain solely automated decisions with legal or similarly significant effects, including information and safeguards in defined circumstances; not every AI-assisted decision falls within that rule.

    How often should I update my AI privacy policy?

    Review the disclosures whenever you add or replace a model, change training or retention practices, introduce human review, add a new AI feature, change vendors, or enter a new regulated market. A regular review cadence is useful, but event-driven updates are what keep the policy aligned with the product.

    Ready to draft

    Create an AI privacy policy while the data map is fresh

    Start with guided questions, verify every statement against the deployed workflow and provider contracts, and edit the draft before publishing.

    • Free account available
    • Editable output
    • Review before publishing