Show HN: I graded 200 AI tools/apps and track any changes in their policies
Major tech companies are defaulting to training AI models on user data, with privacy becoming a paid premium feature rather than a standard right Of 80 tracked apps, 55 provide no opt-out mechanism whatsoever, while only 25 offer a toggle and 4 explicitly charge users to stop data training 36 apps do not train on user data, but 106 apps refuse to disclose their policy at all, creating a significant transparency gap The article tracks 222 apps across categories including AI assistants, productivi
Analysis
TL;DR
- Major tech companies are defaulting to training AI models on user data, with privacy becoming a paid premium feature rather than a standard right
- Of 80 tracked apps, 55 provide no opt-out mechanism whatsoever, while only 25 offer a toggle and 4 explicitly charge users to stop data training
- 36 apps do not train on user data, but 106 apps refuse to disclose their policy at all, creating a significant transparency gap
- The article tracks 222 apps across categories including AI assistants, productivity, finance, and social media, with a grading system from A to F
- Recent policy changes detected in September 2026 include notable updates from WhatsApp, Ring, DeepL, and Tabnine regarding data collection and training practices
Why It Matters
This represents a fundamental shift in how AI companies treat user privacy—moving from transparent opt-in models to hidden default-on data harvesting that requires payment to reverse. For AI practitioners and researchers, this highlights the growing ethical and legal risks of training on user-generated content without explicit consent, while the lack of opt-out mechanisms in most apps signals a potential regulatory reckoning ahead.
Technical Details
- The tracking methodology involves reading and dating exact terms of service, with a 180-day staleness rule that excludes outdated verdicts from published counts
- Apps are categorized into three groups: "Train on you by default" (with sub-classification for paid opt-outs), "Do not train on you," and "Will not say" (unclear policies)
- The grading system (A-F) is based on transparency and user control over data usage, with companies graded A or B allowed to display live grades on their own sites
- Data is collected through automated policy fetching, with failures logged (robots.txt blocks, access denials) and policies archived for diff comparison
- The "Clause of the Week" feature highlights specific policy language, such as Runna's clause allowing training, fine-tuning, and improvement of internal ML/AI models using user activity, performance, and location data
Industry Insight
- Companies should proactively offer clear opt-out mechanisms for data training rather than burying them in paid tiers, as regulatory frameworks like the EU AI Act increasingly mandate transparency in AI training data practices
- The trend of making privacy a paid feature risks significant reputational damage and potential legal challenges, especially as user awareness of AI data practices grows
- Organizations building AI products should invest in transparent data governance frameworks and consider third-party audits to maintain user trust in an increasingly scrutinized landscape
Disclaimer: The above content is generated by AI and is for reference only.