15 AI Privacy Policy Examples
Compare verified privacy disclosures from ChatGPT, Gemini, Claude, Copilot, Midjourney, and other AI tools, then adapt 15 original clause templates to your own product.
Quick answer
An AI product's privacy notice should explain the ordinary privacy topics plus the AI-specific data flow: what prompts, uploads, outputs, feedback, and derived data are collected; why they are used; whether people or model providers receive them; whether they train a model; how long they remain; and what controls or rights are available. The wording must match the deployed system and vendor contracts.
- Examples
- 15 editable clauses
- Core data
- Inputs, outputs, and feedback
- Key checks
- Training, providers, and retention
These are drafting examples, not legal advice. Verify every statement against your product and its current provider terms; replace unsupported wording with accurate, sourced text.
Create your own
Map your AI data flow into a privacy policy draft
Answer guided questions about prompts, uploads, providers, training, retention, and controls, then review and edit the resulting policy.
- AI data-flow questions
- Editable draft
- Free account available
On this page
What makes an AI privacy policy different?
AI does not replace the normal privacy analysis. It adds data flows that are easy to miss: a prompt may contain personal data about the user or someone else; an upload can create embeddings or classifications; a provider may retain abuse-monitoring logs; feedback can bundle the original interaction; and product analytics is different from training or fine-tuning a model.
A separate “AI privacy policy” is not always necessary. The important outcome is a clear, accessible notice that matches the product, contracts, retention schedule, and user controls. Interface notices, AI-content labels, impact assessments, or contractual terms may still be needed alongside it.
Map the full flow
Trace data from collection through providers, logs, training, outputs, and deletion.
Separate purposes
Do not collapse service delivery, safety, analytics, evaluation, and model training into one phrase.
Verify every control
Test opt-outs, deletion, access, and human-review routes before promising them.
First-party evidence
Privacy examples from 15 AI tools and providers
These are concise PolicyForge summaries of current official sources—not copied policy text or permanent guarantees. Product, plan, region, settings, and feature choices can change the result. Sources were checked August 11, 2026.
Example 1
OpenAI (ChatGPT & API)
OpenAI's current materials give ChatGPT users a model-improvement control and state that business products and the API are not used for model training by default. Those are different product rules, so a notice should identify the service actually used.
Verify for your implementation
- Consumer data-control setting
- Business or API training default
- Retention and feedback exceptions
Example 2
Google Gemini (Apps & API)
Google's Gemini Apps Privacy Hub describes activity controls, human review, and product-specific retention. Its developer documentation separately says paid Gemini API prompts and responses are not used to improve Google products, while free and paid API treatment differs.
Verify for your implementation
- Gemini Apps Activity setting
- Human-review retention
- Free versus paid API terms
Example 3
Anthropic Claude
Anthropic's Privacy Center separates consumer Claude accounts from commercial products. It says commercial chats and coding sessions are not used for training unless the customer opts into a program or submits feedback, while consumer use depends on choices and safety-review conditions.
Verify for your implementation
- Consumer improvement choice
- Commercial-product treatment
- Feedback and safety-review exceptions
Example 4
Microsoft Copilot & Azure AI
Microsoft says Microsoft 365 Copilot Chat prompts and responses are not used to train underlying foundation models. Azure's current data-privacy documentation separately explains that customer prompts, completions, embeddings, and training data are not used to train foundation models without permission.
Verify for your implementation
- Exact Copilot product
- Microsoft 365 permissions and retention
- Azure deployment geography and abuse monitoring
Example 5
Meta AI & Llama
Meta's Privacy Center says generative-AI training information can come from public sources and Meta products, and that messages and replies with AI may be used to improve models. It also explains that deleting source information does not immediately undo patterns a trained model learned.
Verify for your implementation
- Public and product data used
- Regional objection options
- Treatment of AI chats and deleted information
Example 6
Midjourney
Midjourney's privacy policy lists text, image, and spoken-input prompts among collected data. Its product documentation says creations can be discoverable in an open-by-default community and explains when Stealth mode is needed for private creation.
Verify for your implementation
- Prompt and upload collection
- Public visibility of creations
- Stealth-mode and deletion limits
Example 7
Stability AI (DreamStudio)
DreamStudio's privacy policy says generated content and associated metadata—including image specifications, seeds, and text prompts—are stored in account history so users can retrieve prior creations. That hosted-service behavior should not be generalized to self-hosted models.
Verify for your implementation
- Hosted versus self-hosted processing
- Account-history storage
- Deletion and metadata treatment
Example 8
GitHub Copilot
GitHub's current model-hosting documentation says individual Copilot interaction data may be used to improve models subject to user settings, and individual subscribers can opt out. The page distinguishes those accounts from business and enterprise arrangements.
Verify for your implementation
- Individual versus organization plan
- Prompts, suggestions, and code context
- Training opt-out and model-host terms
Example 9
Grammarly
Grammarly says generative-AI prompts and relevant context can be shared with vetted service providers to deliver the feature, and those providers may not train on user content. Its own Product Improvement and Training control lets eligible individual users opt out of Grammarly's training use.
Verify for your implementation
- Saved documents versus other text
- LLM service providers
- Account and organization training settings
Example 10
Notion AI
Notion says it and its AI subprocessors do not use customer data to train models by default. Its security guidance also documents plan- and feature-dependent provider retention, including different defaults for Enterprise and non-Enterprise workspaces.
Verify for your implementation
- Current AI subprocessors
- Workspace plan and feature
- Provider, embedding, and deleted-page retention
Example 11
Zoom AI Companion
Zoom says communications-like customer content is not used to train Zoom or third-party AI models. Its technical library also explains that AI Companion must process content to provide features and may retain some customer content for support and debugging, subject to feature and account settings.
Verify for your implementation
- Enabled AI Companion feature
- Host and participant notices
- Model provider and retention configuration
Example 12
Salesforce Einstein & Agentforce
Salesforce describes the Einstein Trust Layer as features, processes, and policies for privacy, accuracy, and responsible AI. Its documentation identifies controls such as configurable data masking for supported generative-AI features; customers should verify which controls apply to their deployment.
Verify for your implementation
- Supported feature and Trust Layer setting
- Data masking and audit configuration
- Connected model and retention terms
Example 13
Adobe Firefly
Adobe's current Firefly FAQ says its models were trained on licensed content such as Adobe Stock together with public-domain content, and that Content Credentials are applied to certain exports. Product and enterprise terms should still be checked for customer-content and custom-model use.
Verify for your implementation
- Firefly feature and account type
- Customer or custom-model training
- Content Credentials and output terms
Example 14
Spotify recommendations & AI features
Spotify's privacy policy says it generally keeps streaming history for the life of an account to support retrospective playlists and personalized recommendations. Spotify also documents that listening in a Private Session does not affect recommendations or appear in Wrapped.
Verify for your implementation
- History used for personalization
- Private-session behavior
- Separate terms for newer AI features
Example 15
Tesla Autopilot, FSD & vehicle AI
Tesla's privacy support page says most camera processing occurs on the vehicle and that sharing camera recordings generally depends on the driver's Data Sharing choice, with specified safety-event exceptions. It separately describes operational and diagnostic vehicle data.
Verify for your implementation
- On-device versus transmitted data
- Driver consent and safety-event exceptions
- Association with an account or vehicle
15 editable AI privacy policy clauses
These are original PolicyForge templates, not copied company policies. Replace every bracketed field, delete inapplicable clauses, and verify all vendor and system behavior before publishing.
Inputs, outputs, and model use
The core data flows created by chat, uploads, outputs, training, and feedback.
Clause 1
Chat prompts and responses
Use when: A user sends text to an AI chat or assistant feature.
“When you use [AI feature], we collect the prompts you submit, the responses generated for you, and related technical data such as [usage data]. We use this information to provide the feature, maintain security, and [other current purpose].”
Review before using
- List only data the product actually collects
- Separate service delivery from optional improvement purposes
Clause 2
Files, images, audio, or other uploads
Use when: The AI feature analyzes user-provided documents or media.
“If you upload [files/images/audio] to [feature], we process the upload and information derived from it to [summarize/classify/generate]. Do not upload information you are not authorized to share. We retain uploads for [period or event] unless [exception].”
Review before using
- Name derived data as well as the original upload
- Verify the real retention and deletion path
Clause 3
Generated outputs and history
Use when: The product stores AI-generated results or conversation history.
“We store generated outputs and conversation history so you can [access, continue, or manage] prior work. You can delete [which records] through [control]. Deletion from active systems takes [period], subject to [narrow backup, security, or legal exceptions].”
Review before using
- Do not promise immediate deletion if backups remain
- Explain whether deleting history also deletes provider copies
Clause 4
Model training or improvement
Use when: Customer inputs or outputs may improve a model or AI feature.
“[We do / do not] use prompts, uploads, or generated outputs to train or fine-tune [which model or feature]. When this use is optional, you can change your choice in [setting] or contact [method]. The choice does not affect [state any real limit or effect].”
Review before using
- Distinguish foundation-model training, fine-tuning, evaluation, and product analytics
- Verify defaults for every plan and provider
Clause 5
Business or API data exclusion
Use when: Commercial/API data receives different training or retention treatment.
“For [business/API plan], we do not use customer content to train shared models. We process that content to provide and secure the service and retain it for [period], unless the customer configures [available control] or a longer period is required for [specific reason].”
Review before using
- Confirm the contract and every subprocesser's terms
- Avoid implying zero retention when abuse monitoring or logs exist
Clause 12
Ratings and feedback on AI outputs
Use when: Thumbs-up/down, corrections, or comments are collected for evaluation.
“When you rate or comment on an AI response, we collect the feedback, the related [prompt/output/context], and your account identifier [if applicable]. We use it to investigate issues and evaluate or improve [which service or model].”
Review before using
- Disclose the context bundled with feedback
- State whether feedback can be used for training
Providers, people, and retention
Who can receive or review AI data, how long it remains, and where it is processed.
Clause 6
Human review of AI interactions
Use when: Staff or contractors may review prompts, outputs, or flagged interactions.
“Authorized [employees/contractors] may review a limited set of AI interactions for [support, safety, evaluation, or abuse prevention]. Access is [how limited]. Do not submit [sensitive categories] unless the feature expressly requests them for [purpose].”
Review before using
- State who can review and why
- Do not call review de-identified if reviewers can reconnect it to an account
Clause 7
Third-party model providers
Use when: User data is sent to an external AI API or infrastructure provider.
“We send [data categories] to [provider] to generate [result]. [Provider] processes this information on our behalf under [contractual role, if accurate]. Its retention and model-training treatment for this service is [verified treatment]. See [subprocessor or provider link] for more detail.”
Review before using
- Name the provider or clearly identify the recipient category
- Check transfers, retention, and training terms for the exact product tier
Clause 8
AI data retention schedule
Use when: Prompts, logs, feedback, and outputs have different retention periods.
“We retain AI conversation history for [period], security and abuse logs for [period], and feedback you submit for [period]. We then delete or de-identify the information, subject to [specific legal, dispute, security, or backup exception].”
Review before using
- Use separate periods when systems differ
- Make the schedule operationally reproducible
Clause 14
International AI processing
Use when: Model providers or support teams process data in other countries.
“We and our AI service providers process information in [countries/regions]. Where required, we use [transfer mechanism] and safeguards described in [link]. You can request information about applicable safeguards through [contact method].”
Review before using
- Map every relevant provider and support location
- Do not name a transfer mechanism that has not been executed
Higher-impact uses and user controls
Sensitive data, automated decisions, personalization, children, and privacy requests.
Clause 9
Sensitive-data boundaries
Use when: The AI feature is not intended to receive certain sensitive information.
“[Feature] is not designed to process [health, financial, biometric, children's, or other excluded data]. Please do not submit that information. If we identify prohibited content, we may [delete, restrict, or investigate] it as described in [policy or control].”
Review before using
- A warning does not replace technical controls for foreseeable use
- Match excluded categories to the real product and contracts
Clause 10
Automated decisions about people
Use when: AI makes or materially supports a decision affecting an individual.
“We use [system] to [make or support] decisions about [purpose]. It considers [main data categories]. [Human role] reviews [which decisions]. Where applicable, you may request [information, correction, opt-out, or human review] through [method].”
Review before using
- Obtain qualified review for employment, credit, housing, health, or other high-impact uses
- Explain the actual human role rather than saying only “human in the loop”
Clause 11
AI personalization and recommendations
Use when: Algorithms rank content, products, or actions for a user.
“We use [activity, preferences, or other signals] to personalize [recommendations/rankings]. You can [change signals, reset history, or disable personalization] through [control]. [Sponsored or commercial influence] is handled as described in [link].”
Review before using
- Identify the most important signal categories
- Keep advertising and endorsement disclosures separate
Clause 13
Children and teen users
Use when: An AI product excludes children or has age-specific processing.
“[Service/AI feature] is intended for people aged [age] or older. We do not knowingly collect personal data from children below [age/rule]. If you believe a child provided data contrary to this notice, contact [method] so we can review and take appropriate action.”
Review before using
- Age thresholds vary by product, consent model, and jurisdiction
- Use age assurance or parental controls where required; wording alone is not enough
Clause 15
Privacy rights and AI controls
Use when: Users need one route for access, deletion, correction, objection, or AI-specific controls.
“Depending on where you live, you may have rights regarding personal data used by our AI features. You can [access/delete/export/change training settings] through [product control] or submit a request at [method]. We may need to verify your identity and will explain if an exception applies.”
Review before using
- Separate universal product controls from jurisdiction-dependent legal rights
- Test that every linked control and request channel works
Apply the clauses
Build a draft around your deployed AI system
Use the examples for structure, then answer questions about the actual data, model providers, retention, training choices, and rights workflow.
- Tailored to your answers
- Editable before publishing
- No compliance guarantee
AI privacy inventory
Verify these facts before drafting
Privacy and AI rules work together
GDPR transparency duties apply when personal data is processed, including through AI systems. The EDPB has addressed when personal data is involved in AI-model development and deployment. California's privacy regulations and automated-decisionmaking work add another layer for covered businesses. The EU AI Act can require separate transparency information for defined systems and content. One policy paragraph rarely satisfies every obligation by itself.
AI privacy policy FAQ
What should an AI privacy policy include that a regular privacy policy doesn't?
Alongside the usual privacy disclosures, describe AI-specific data flows that actually apply: prompts and uploads, generated outputs, logging and retention, model training or fine-tuning, human review, third-party model providers, automated decisions, and deletion or opt-out choices. The policy should distinguish current practices from optional or future uses.
Do I need a separate privacy policy for my AI product?
Not necessarily. AI-specific disclosures can sit in the main privacy policy, a product notice, or a clearly linked addendum. Choose the format that makes the processing understandable and keeps the information easy to update. Other AI transparency notices may be required separately from a privacy policy.
Can users opt out of having their data used to train AI models?
That depends on the data, purpose, legal basis, product terms, and laws that apply. Some providers offer training controls or exclude certain business and API data by default. Clearly state whether inputs or outputs are used for training, what controls are available, and any limits on deletion or opt-out requests.
How does the EU AI Act affect AI privacy policies?
The EU AI Act adds risk-management and transparency duties for certain AI providers and deployers, while GDPR governs personal-data processing. Some AI Act information belongs in product interfaces, technical documentation, or AI-content disclosures rather than the privacy policy. Coordinate the notices so they are accurate and do not conflict.
What happens to my conversations with AI chatbots under privacy law?
A conversation can contain personal data when it identifies or relates to a person. Explain what conversation data is collected, why it is used, how long it is retained, whether people or third parties can review it, whether it contributes to model improvement, and how users can exercise available privacy controls. Do not encourage users to submit sensitive information unless the product is designed to handle it.
Do I need to disclose if my product uses third-party AI models like GPT-4 or Claude?
If a third-party model provider receives personal data, your disclosures should accurately explain the relevant recipient or processor, the data sent, the purpose, retention or training treatment, and any international transfer information required by applicable law. Naming the provider can also help users understand the product's data flow.
How should an AI privacy policy address automated decision-making?
Describe whether AI makes or materially influences decisions about people, the data and purpose involved, and the consequences and safeguards that apply. GDPR has specific rules for certain solely automated decisions with legal or similarly significant effects, including information and safeguards in defined circumstances; not every AI-assisted decision falls within that rule.
How often should I update my AI privacy policy?
Review the disclosures whenever you add or replace a model, change training or retention practices, introduce human review, add a new AI feature, change vendors, or enter a new regulated market. A regular review cadence is useful, but event-driven updates are what keep the policy aligned with the product.
Ready to draft
Create an AI privacy policy while the data map is fresh
Start with guided questions, verify every statement against the deployed workflow and provider contracts, and edit the draft before publishing.
- Free account available
- Editable output
- Review before publishing