{
  "data": {
    "author": "Quynh Tran-Thanh",
    "faq": null,
    "kicker": "Blog · 11 October 2026",
    "lede": "A friend's team spent three weeks reviewing a vendor, then rejected it over what the terms left out. So I checked the terms of 925 products. Almost half restrict benchmarking, and identity vendors read worse than they should.",
    "readingMinutes": 6,
    "words": 1267
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/blog/what-the-terms-say-about-your-data",
    "json": "https://www.anchorterminal.com/blog/what-the-terms-say-about-your-data.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/blog/what-the-terms-say-about-your-data.md",
    "slim": "https://www.anchorterminal.com/blog/what-the-terms-say-about-your-data.min.md"
  },
  "markdown": "By Quynh Tran-Thanh, 11 October 2026. 1,267 words, about 6 min to read.\n\n## A vendor review started this\n\nA friend of mine is an engineer at a large SaaS company. Their team spent three weeks reviewing a vendor and then rejected it. The reason was in the terms and conditions, which did not say how the vendor's model was trained or where its training data came from.\n\nThree weeks is a long time to spend finding out what a document leaves out. Anchor Terminal reads each vendor's terms of service and privacy policy as part of the grade [[1]](#ref-1), so I ran the same kind of review across the whole directory.\n\n## What was read\n\nEvery listing with a hosted service is checked for a terms of service and a privacy policy. A rule-based reader looks for the things a reader expects each document to state and for a short list of clauses worth knowing, and a second reader checks the result against the text [[1]](#ref-1). It is a reading by rules and not legal advice.\n\nOne limit matters for my friend's case. The readings ask whether a customer's data is used to train the vendor's models. They do not yet ask whether a vendor says where its own training data came from, which is the question that ended that review.\n\n- 925: hosted products checked\n- 1,268: documents read\n- 42: with no public terms\n- 105: with terms we could not read\n\nHosted listings on 11 October 2026\n\n## Who is missing\n\nA further 24 products have no public privacy policy [[1]](#ref-1). The 42 with no public terms are not all a concern. Some are open-source projects with nothing to sign. The ones I would raise in a review are commercial services that hold sensitive data and publish only website terms, with the customer agreement kept for the sales process.\n\nIdentity verification is the clearest case. ComplyAdvantage, Jumio, Socure and Trulioo each publish a privacy notice and no customer terms [[2]](#ref-2). Trulioo's docs refer to a Customer Agreement between Trulioo and each customer, which is not public [[2]](#ref-2).\n\nThe same pattern shows in other sectors that handle money and travel.\n\n- **Banking data.** MX publishes end-user website terms dated 15 January 2020 and no client or developer agreement for its Platform API. Enable Banking's FAQ refers to a contract agreed by email [[3]](#ref-3).\n- **Payroll.** Worklio's only public terms date from 21 December 2014 and predate its embedded API. Gusto's site answers our reader with a bot check, so its terms and privacy policy were not read [[4]](#ref-4).\n- **Travel.** Expedia Rapid and Skyscanner keep their API terms in a partner contract [[5]](#ref-5).\n\nIn my view this is the first finding for anyone doing a review. A buyer cannot compare what is not published, and the vendors asking for the most sensitive data are among the ones publishing the least.\n\n## The clauses that turn up most\n\nThese are shares of the 623 terms of service and 645 privacy policies we read [[1]](#ref-1).\n\n| Clause | Share of documents |\n| --- | --- |\n| Access can be ended without notice or for any reason | 63% of terms |\n| Benchmarking or competitive use is restricted | 48% of terms |\n| Arbitration is required or class actions are waived | 39% of terms |\n| The terms or the service can change without notice | 38% of terms |\n| Automated access is restricted | 37% of terms |\n| A service level or uptime commitment is mentioned | 37% of terms |\n| Personal data is sold or shared for advertising | 29% of privacy policies |\n| No date of last update is given | 26% of privacy policies |\n\nTwo of these surprised me. Almost half of all terms restrict benchmarking, which is the activity a vendor review consists of. And these are tools sold for use by software agents, yet 37% of their terms restrict automated access.\n\nTraining is the clause people ask about first. Of the 815 hosted listings where we read at least one document, 143 say customer content may be used to train or improve models with no opt-out found, and 79 more say so and give an opt-out [[1]](#ref-1).\n\n## The sectors that should do better\n\nEach hosted listing scores up to 20 points for its two documents. The average is 14.6 [[1]](#ref-1). Messaging averages 17.2 and CRM 16.7. The sectors below hold identity documents, salaries, tax records and bank transactions, and all four sit under the average.\n\n| Sector | Hosted listings | Average of 20 |\n| --- | --- | --- |\n| Payroll | 11 | 13.0 |\n| Tax | 10 | 13.0 |\n| Identity verification | 11 | 13.1 |\n| Banking data | 14 | 13.3 |\n\nIdentity verification is the one I think should be best and is not. Beyond the four vendors with no public terms, six of the ten vendors whose documents we read say customer data may train models, with no opt-out found [[2]](#ref-2). The wording is direct.\n\n- Socure's privacy notice says \"Identity documents and images may also be used to train and test machine learning models\" [[6]](#ref-6).\n- Veriff's says its algorithms are \"built, trained and tested on training sets, which consist of real data\" or anonymised data [[7]](#ref-7).\n- Sumsub's terms have the customer grant permission to use personal data for developing and testing the services, including by means of artificial intelligence [[8]](#ref-8).\n\nDidit allows model training by default and lets an administrator switch it off in the console. The same policy says verification data is kept indefinitely by default unless the customer sets a shorter period [[9]](#ref-9).\n\nBanking data has its own version. TrueLayer's end-user terms say \"We may also use your data to improve our AI models\" [[10]](#ref-10). Basiq's privacy policy says content collected from a financial institution may be kept indefinitely, even after the account is terminated [[11]](#ref-11). Teller's developer privacy policy is dated 12 October 2020 and Belvo's end-user privacy policy 22 February 2021 [[3]](#ref-3). Across the directory, 97 hosted listings link a document that has not been updated for three years or more [[1]](#ref-1).\n\n## Uses of data people do not expect\n\nThese came from the second readers' notes. Each is one vendor's clause, quoted or summarised from its own document, and I am not suggesting the practice is unique to that vendor.\n\n- **Candidate data can be sold.** Gem's privacy policy says it may sell or share personal information, sensitive personal information included, to give people more opportunities to seek employment with other companies [[12]](#ref-12). Ashby's says it may receive personal information from data brokers [[13]](#ref-13).\n- **Using the product can make you a case study.** Amplitude's terms give it the right to use the customer's name and logo in marketing, and the customer agrees to take part in a case study [[14]](#ref-14).\n- **Liability can stop at 100 dollars.** BambooHR's developer terms and HiBob's API terms each cap total liability at 100 US dollars, for APIs that reach employee records [[15]](#ref-15) [[16]](#ref-16).\n- **Keystrokes can be recorded.** Intuit's privacy statement, which covers Mailchimp, says session replays include clicks, mouse movements, scrolls and keystrokes [[17]](#ref-17). Doppler, a secrets manager, says activity on its services may be captured with session replay tools [[18]](#ref-18).\n- **Recordings can be kept without limit.** Recall.ai's privacy policy says all media associated with a recording is retained indefinitely by default, with a setting to change it [[19]](#ref-19).\n- **A voice can count as biometric data.** Fireflies.ai's privacy policy says voice data may be considered biometric information in some jurisdictions [[20]](#ref-20).\n\n## What I would take into a review\n\nI think three checks cover most of what this data shows.\n\n1. Ask for the customer agreement before the security questionnaire. If a vendor publishes only website terms, the document that governs your data is one you have not seen.\n2. Search both documents for training, retention and advertising. A default that allows training with a console switch is a different risk from no switch at all.\n3. Check the date. A privacy policy last updated in 2020 says nothing about what the vendor has built since.\n\nEvery listing shows its own reading, with the vendor's sentence under each answer, so any figure here can be traced to a document [[1]](#ref-1).\n\n---\n\n- Older: [Most agent tools can't pass a due-diligence questionnaire](https://www.anchorterminal.com/blog/agent-tools-arent-ready-for-enterprise.md)\n- Newer: [The Log, issue 1: decide, declare, depart](https://www.anchorterminal.com/blog/the-log/issue-1-decide-declare-depart.md)\n- All posts: https://www.anchorterminal.com/blog/index.md\n\n## References\n\nRead on 11 October 2026.\n\n[1] Anchor Terminal, our readings of vendors' terms and privacy policies, 11 October 2026. Source for the 925 hosted listings, the 1,268 documents read, the clause shares, the sector averages, the training counts and the 97 listings with a document three years old or more. Each listing shows its reading with the vendor's sentences, and the method is on this page. https://www.anchorterminal.com/benchmark/\n\n[2] Anchor Terminal, identity verification listings, 11 October 2026. Source for ComplyAdvantage, Jumio, Socure and Trulioo publishing no customer terms, for Trulioo's Customer Agreement, and for six of ten vendors with a training clause and no opt-out found. https://www.anchorterminal.com/categories/identity-verification\n\n[3] Anchor Terminal, banking data listings, 11 October 2026. Source for MX's and Enable Banking's terms and the dates of Teller's and Belvo's privacy policies. https://www.anchorterminal.com/categories/banking-data\n\n[4] Anchor Terminal, payroll listings, 11 October 2026. Source for Worklio's 2014 terms and Gusto's unread documents. https://www.anchorterminal.com/categories/payroll\n\n[5] Anchor Terminal, travel listings, 11 October 2026. Source for Expedia Rapid and Skyscanner keeping API terms in a partner contract. https://www.anchorterminal.com/categories/travel\n\n[6] Socure, Global Services Privacy Notice, effective 1 October 2026. Source for the sentence on identity documents and images training machine learning models. https://www.socure.com/privacy-en\n\n[7] Veriff, Privacy Notice, 16 April 2026. Source for training sets consisting of real data or anonymised data. https://www.veriff.com/privacy-notice\n\n[8] Sumsub, Terms and Conditions, 21 May 2026. Source for clause 6.9 on using personal data to develop and test the services. https://sumsub.com/terms-and-conditions/\n\n[9] Didit, Privacy Policy, 7 October 2026. Source for model training allowed by default with an opt-out, and for indefinite default retention of verification data. https://didit.me/terms/privacy-policy/\n\n[10] TrueLayer, End User Terms of Service, 12 May 2026. Source for the sentence on using data to improve AI models. https://truelayer.com/legal/enduser_tos/\n\n[11] Basiq, Privacy Policy. Source for content being kept indefinitely after an account is terminated. https://docs.basiq.io/en/articles/382581-basiq-privacy-policy\n\n[12] Gem, Privacy Policy, 26 August 2025. Source for selling or sharing personal information, sensitive personal information included. https://www.gem.com/compliance/privacy\n\n[13] Ashby, Privacy Policy, 24 September 2025. Source for receiving personal information from data brokers. https://www.ashbyhq.com/resources/privacy\n\n[14] Amplitude, Terms of Service, 21 July 2026. Source for the right to use the customer's name and logo and the agreement to take part in a case study. https://amplitude.com/terms\n\n[15] BambooHR, Developer Terms of Service, 1 February 2026. Source for the 100 US dollar liability cap. https://www.bamboohr.com/legal/developer-terms-of-service\n\n[16] HiBob, API Terms of Use. Source for the 100 US dollar liability cap. https://apidocs.hibob.com/docs/api-terms-of-use\n\n[17] Intuit, Global Privacy Statement, 9 March 2026. Source for session replays including clicks, mouse movements, scrolls and keystrokes. https://www.intuit.com/privacy/statement/\n\n[18] Doppler, Privacy Policy, 17 September 2026. Source for heatmapping and session replay tools on its services. https://www.doppler.com/legal/privacy\n\n[19] Recall.ai, Privacy Policy, 1 February 2023. Source for media being retained indefinitely by default. https://www.recall.ai/privacy\n\n[20] Fireflies.ai, Privacy Policy, 28 September 2026. Source for voice data counting as biometric information in some jurisdictions. https://fireflies.ai/privacy-policy\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-11",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Blog",
        "url": "https://www.anchorterminal.com/blog/"
      },
      {
        "name": "Terms and privacy",
        "url": ""
      }
    ],
    "description": "Quynh Tran-Thanh on the terms and privacy policies of 925 hosted agent tools. Who publishes none, which clauses turn up most, and why identity verification, payroll and banking data read worse than they should.",
    "facts": [
      "Quynh Tran-Thanh",
      "11 October 2026"
    ],
    "h1": "Nobody reads the terms. We read 1,268.",
    "image": "https://www.anchorterminal.com/assets/og/blog-terms-privacy.png",
    "path": "/blog/what-the-terms-say-about-your-data",
    "published": "2026-10-11",
    "section": "blog",
    "title": "Nobody reads vendor terms. We read 1,268 of them | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-11",
    "url": "https://www.anchorterminal.com/blog/what-the-terms-say-about-your-data"
  },
  "tokens": {
    "markdown": 3300,
    "slim": 2180
  },
  "version": 1
}
