Privacy Policy Accuracy for AI Products

An AI product’s privacy policy must describe what happens to personal information when the business and its vendors process it. Statements about model training, human access, retention, and deletion need to account for the services and settings the product uses.

A misleading privacy statement creates legal exposure even when no statute prohibits the underlying practice. Under the FTC’s deception standard, a representation, omission, or practice is deceptive if it is likely to mislead consumers acting reasonably under the circumstances and is material to their decisions. State privacy laws impose additional disclosure requirements on businesses within their coverage.

The Vendors That Receive Personal Information

Your internal inventory should identify each vendor that receives personal information and what it receives. For an AI product, that inventory might include a model provider, hosting company, analytics service, payment processor, and vendor that converts text to speech. A subprocessor is a provider another processor engages to process personal data on its behalf, and those downstream arrangements also belong in the review.

The public disclosure requirements vary by law. California’s Online Privacy Protection Act requires operators of covered commercial websites and online services to identify categories of collected personal information and categories of third party recipients. It also requires disclosures about material policy changes and an effective date, among other items. It does not require a named list of every vendor. California Business and Professions Code § 22575.

The Texas Data Privacy and Security Act likewise requires covered controllers to disclose categories of personal data shared with third parties and categories of recipients, when applicable. A controller is the person or business that determines the purposes and means of processing personal data. California’s CCPA regulations require covered businesses to describe their information practices, including categories collected during the preceding 12 months, sources, purposes, and applicable sale and sharing disclosures. Texas Business and Commerce Code § 541.102; California regulation § 7011.

COPPA imposes more specific recipient disclosures on operators within its coverage. The amended rule requires the online notice to identify third party recipients, their specific categories, and the purposes of disclosure. COPPA applies to covered services directed to children under 13 and operators with actual knowledge that they collect personal information from children under 13. A product’s processing of information about a child does not, by itself, establish that COPPA applies. 16 C.F.R. § 312.4(d) and the FTC’s final rule.

Vendor conduct can expose the product operator to enforcement. In United States v. Apitor Technology Co., Ltd., the government alleged that software embedded in a children’s app collected precise location information without required parental consent. In Texas v. Allstate, the Texas Attorney General alleged that Allstate and Arity obtained driving and location information through software embedded in other companies’ apps and used or sold it without required notice and consent. These allegations concern what vendors received and did with personal information, including collection through another business’s product.

The Personal Information Included in Prompts

A prompt includes the instructions and content submitted to a model. Depending on the product, a model request might also include uploaded documents, account details, earlier messages, or information retrieved from connected services. When the request goes to an external model provider, that provider receives the information included in it.

You should have your technical team identify those fields and explain why each is included. An account email address might serve no purpose in a request to summarize a document, while a full document might be necessary for another feature. Security, fraud prevention, and other legitimate purposes also belong in the analysis. The question extends beyond whether a field improves the generated answer.

For businesses covered by the CCPA, collection, use, retention, and sharing must be reasonably necessary and proportionate to the disclosed collection purposes or another compatible disclosed purpose. The statute restricts further processing that is incompatible with those purposes. Disclosing unnecessary collection in a privacy policy does not satisfy that substantive requirement. California Civil Code § 1798.100(c).

The same review should include analytics and support tools. For example, a product might omit an account identifier from its model request but include it in a page address sent to an analytics vendor. The privacy disclosures should account for the personal information received through each relevant feature.

Training Permissions and Human Access

You should distinguish what a vendor’s contract permits from the settings and practices that apply to your account. A vendor might offer different terms for a consumer product, an unpaid developer service, and a paid business service. The product name alone does not establish whether customer information is used for training.

Google’s Gemini API terms, for example, distinguish paid and unpaid services and describe circumstances in which human reviewers process submitted content. A statement that no human can access user content requires support across your personnel, contractors, and providers. A promise limited to your employees should not imply that vendor personnel are also excluded.

You should review training and human access separately. A provider’s commitment against training does not necessarily exclude storage for abuse monitoring, access during a support investigation, or review required by law. Your privacy policy should describe the applicable practices without converting a limited contractual protection into an absolute promise.

Retention and Deletion Across Providers

Retention statements should distinguish records with different purposes and schedules. A product might retain an uploaded document for one period, a generated summary for another, and billing records for longer. You should identify those differences before stating that the product deletes “all data” after a fixed period.

California requires a covered business’s notice at collection to state the intended retention period for each category of personal information or the criteria used to determine it. COPPA requires covered operators to include their written retention policy in the online notice. Those requirements must be satisfied in the notices specified by the applicable law. California Civil Code § 1798.100(a)(3); 16 C.F.R. § 312.4(d).

Provider retention also affects the accuracy of your promises. If a provider retains prompts in security logs after your application deletes its copy, an unqualified statement that prompts are never retained misdescribes the service. You should distinguish deletion from active product storage, deletion by providers, backup expiration, and any legally permitted exceptions.

The FTC’s proceeding in In re Avast Limited illustrates the consequences of inconsistent privacy representations. The FTC alleged that Avast marketed software as protecting users from tracking while selling detailed browsing information through a subsidiary. In June 2024, the FTC finalized an order requiring $16.5 million and deletion of specified data and products or algorithms derived from it.

Google Integrations and App Store Disclosures

A product that connects to Google services must satisfy the requirements applicable to its use of Google user data. The additional Limited Use restrictions in Google’s API Services User Data Policy apply to specified sensitive and restricted authorization scopes. A scope defines the access an application requests, such as permission to read particular account information. You should identify the scopes your product requests before assessing those restrictions.

For data subject to the Limited Use requirements in Google’s Workspace API policy, permitted uses and transfers are restricted, and human access is allowed only under specified exceptions. The policy prohibits using or transferring covered data for general model training beyond a specific user’s personalized model for an appropriate feature. A personalized model must also satisfy the remaining policy requirements.

Google requires an affirmative statement, or similar wording, that the application’s use of information received from Workspace scopes complies with the applicable policy, including Limited Use. Google supplies an example statement without requiring every application to reproduce that example verbatim. Your product’s practices must support the statement you display.

Apple’s App Store privacy disclosures cover collection by the developer and third party partners under Apple’s definitions. Apple generally treats information as collected when it leaves the device and is accessible longer than necessary to service the request in real time. Some collection qualifies for optional disclosure only if all relevant conditions are satisfied, and developers must keep their answers accurate.

Google Play’s Data safety requirements use their own definitions of collection and sharing. Transfers to a service provider processing information on the developer’s behalf and instructions are excluded from the form’s definition of sharing, although collection may require disclosure. Neither platform form is a named vendor inventory. You should reconcile each form with your privacy policy using the definitions and exceptions applicable to that form.

Connecticut’s Disclosure About Model Training

Since July 1, 2026, covered controllers in Connecticut must state whether they collect, use, or sell personal data to train large language models. Their privacy notices must also state the month and year of the latest update. A statement that the business does not train models needs to account for relevant processing through its providers. Connecticut General Statutes § 42-520(b).

Connecticut also specifies how notices must be available, including conspicuous privacy links in applicable website and application locations, required language versions, and accessibility for people with disabilities. For retroactive material changes to notices or practices, controllers must notify affected consumers and provide a reasonable opportunity to withdraw consent to further materially different processing of previously collected information. Posting revised text alone does not satisfy those duties.

You should confirm the training disclosure against the provider’s applicable contract, account settings, and processing practices. An unpaid service does not establish that every submission trains a model, and a paid subscription does not establish a contractual prohibition against training. The statement needs support for the service the product uses.

Automated Decisions and Other Required Notices

Some AI uses require notices beyond the general privacy policy. California’s automated decisionmaking requirements apply to covered businesses using technology within the regulatory definition for significant decisions. Compliance is required beginning January 1, 2027. Section 7220 requires notice before the covered processing, including the specific purpose and applicable consumer rights. The business may include it in the notice at collection if all requirements are met. California regulations §§ 7200 and 7220.

Colorado’s Senate Bill 26-189, enacted in May 2026, replaced the state’s earlier AI law. Its requirements apply beginning January 1, 2027, and include notice at the point of interaction before covered automated technology materially influences a consequential decision. The statute addresses decisions in areas such as employment, housing, credit, and education, subject to its definitions and exceptions.

An AI feature that generates a score does not automatically fall within either regime. You should assess how the score is used, who makes the decision, and whether the decision and technology satisfy the applicable definitions. A generic statement that the product “uses AI” does not satisfy a requirement to explain a covered decision process.

Texas imposes prescribed notice wording when a covered controller sells sensitive personal data or biometric personal data. The required statement must appear in the same location and manner as the privacy notice. Whether a vendor transfer is a sale depends on the statutory definition and exclusions, including qualifying processing on the controller’s behalf. A voice recording or photograph is not automatically biometric data under that statute. Texas Business and Commerce Code §§ 541.001 and 541.102(b)–(c).

Keeping the Policy Accurate as the Product Changes

You should base the policy on a current account of the product’s collection, uses, recipients, retention, and deletion practices. Your technical team should confirm how the product operates, while legal review addresses the applicable requirements, vendor terms, and proposed representations. The public policy should contain the required disclosures in language users can understand, supported by a more detailed internal inventory.

A new provider, account tier, connected service, training use, or analytics feature should trigger review before the change takes effect. You should determine whether the change requires revised disclosures, direct notice, consent, or changes to platform declarations. Revising the policy does not authorize processing that applicable law or a provider’s contract prohibits.

This article is general information about the law, not legal advice, and reading it does not create an attorney-client relationship. Laws change and how they apply depends on your specific facts. For advice on your situation, consult a qualified attorney.

Need advice tied to your business issue?

Share the issue. Get direct attorney review. Receive a concrete recommendation.

Submit an Inquiry