Policies
Who runs Data Report Card, what we do and don't do with information, and how our grades are made. If you think a fact is wrong, we want to fix it.
Data Report Card grades how the companies in your life handle your personal data: whether you can get it, take it elsewhere, and delete it, and how hard they make it. Every grade is our assessment against a published rubric, built from facts we can point to and source. Like any rating system, it is ultimately our opinion and judgement call based on facts, but not a legal or factual conclusion.
Data Report Card is operated by Bricolage Inc., a Delaware corporation. Bricolage Inc. also builds consumer software. We disclose this because honesty about who runs a ratings site is part of earning your trust. It changes nothing about how the grades are made:
If you think a grade is wrong, tell us.
Effective June 28, 2026
The short version: we never receive the contents of your data.
When you use Data Report Card to collect your data footprint, your data moves directly from each company to your own device. Your exports and your account contents stay on your device. We never receive them, store them, or see them.
If you contribute to our research. You can optionally tell us about your experience requesting your data from a company. We store only a small set of non-identifying facts about that experience: which company, which jurisdiction, which data right, how many days the company took, whether the response was verified, and the signing domain of the confirmation email (a domain like example.com, never an address). We do not accept or store your name, your email, the email itself, its contents, or your data export — our server actively rejects any submission that tries to include them. You get an opaque receipt code to check your contribution's status; it is the only identifier and is not linked to you.
Connecting an account (optional). For a few providers, the secure sign-in step requires a one-time exchange that passes through our server. In that step a short-lived authorization code and access credential pass through in memory only — used once, never written to disk, never logged. Your actual data is fetched directly by your browser from the provider and written to your device; it never passes through our server.
Subscribing to our newsletter (optional). If you subscribe to our newsletter, your email address is collected and processed by Substack, Inc., our newsletter provider, under its own privacy policy and terms. We use it only to send you the newsletter, and you can unsubscribe from any issue. We never sell it, and we never use it to build a profile of you.
Ordinary website operation. Our site is served through a hosting and security provider (Cloudflare, Inc.), whose systems may log standard request metadata such as IP address and browser type at the network edge. We do not store your IP address in our own records.
We do not use third-party advertising or tracking cookies, and we do not load third-party analytics. The only data stored in your browser is functional and stays on your device. The only cookie we set is a session cookie used solely to sign in to our private, staff-only review area; it is never set when you browse the public site.
Contact: hello@datareportcard.com · Bricolage Inc., 2118 Wilshire Blvd. Suite 1098, Santa Monica, CA 90403.
Why our grades are opinions on disclosed facts
A Data Report Card grade is our opinion, formed by applying a published rubric to facts we disclose and source. We show our work so you can check it and, if a fact is wrong, correct it.
A grade is not a legal ruling, a finding of wrongdoing, or a measure of a company's overall integrity. It is a structured, sourced opinion about specific data practices, against a public rubric.
Data Report Card provides general information and our assessment of companies' data practices against a published rubric. It is not legal advice and not a legal ruling. Grades and commentary are our opinion based on the facts we disclose and source, which may change over time and may contain errors.
Company names and trademarks belong to their respective owners and are used to identify the companies we discuss. Their use does not imply affiliation with or endorsement by those companies.
We make no warranty that the information is complete, current, error-free, or that it accurately represents your own experience with your data or the companies. If you believe a fact is wrong, see Corrections — we want to fix it.
Grades move when the evidence moves. Every change is listed here with the date and the reason — including changes that lower a company’s grade, and changes we made because our own citation was weak.
A score change moved a published grade. source and note changes did not: they corrected the evidence behind a cell that kept its score.
Score unchanged (1). Two corrections. The stated response time is now 30 days, not 45 — Lyft edited the sentence on its account-deletion help page (published as ev-2026-0009). And the quote was mis-cited: Lyft's privacy policy, updated July 1 2026, carries no response-time statement at all, so the citation moves to the help page that actually contains it. 30 days is the statutory period rather than a fast turnaround, so the cell stays at the moderate rung — consistent with Notion at 1 and Pinterest at 2 for a 48-hour turnaround.
Score unchanged (1). Lyft documented an in-app deletion path (Privacy → Account Security) alongside the existing data privacy page, and the rationale now names it (published as ev-2026-0009). The cell still rests on the absence of a stated post-deletion purge timeline and the retention of some data for legal and compliance purposes; a stated timeline is the distinction that earns a 2 (R2).
Score unchanged (1). Rationale re-anchored under new calibration C5 (mandated-retention neutrality): the Clinical Health Record’s exclusion from the copy scope is the HIPAA-standard psychotherapy-notes carve-out, a legal mandate rather than a company choice, and no longer counts among the deciding facts. The cell rests on the missing fulfillment window and the “not always able to respect your request” hedge.
The August 2026 revision removed the contradictory "we do not sell or rent your personal data" claim. The notice now plainly admits sharing that "may be considered the sale of personal data" (including inferences and analytics) and lists stated opt-out rights for selling, targeted advertising and profiling. An honest admission with a working, findable opt-out scores the moderate rung under rule 3; the prior 0 rested on the claim-plus-contradiction shape.
Full read of the August 2026 revision found no stated post-deletion purge timeline and no in-app deletion path in the notice; erasure is a request-based right. A stated timeline is the distinction that earns a 2 (R2, Notion precedent), so the cell moves to 1.
Score unchanged (1). The Notice was rewritten: the old "not ‘sell’ (as defined under the CCPA)… preceding 12 months" sentence is gone. The cell now rests on the money-only no-sell plus the CCPA table’s admitted Sharing for Targeted Advertising with Advertising Partners, with a cookie-popup opt-out and GPC recognition.
Score unchanged (2). The rewritten Notice no longer states the 30-day purge, but the help center (Self-Serve Data Deletion, updated Jul 2026) states "All account and personal data will be permanently deleted within 30 days", self-serve. Citation moved to the help article.
Score unchanged (1). The rewritten Notice lists "Improve or create services and products, including our AI models" among data uses but no longer names the opt-out; the help center (Data Collection at Perplexity, updated Jul 2026) documents the AI Data Retention toggle, on by default. Citation moved to the help article.
Score unchanged (2). Rationale re-anchored to the rewritten Notice: rights exercised via support@perplexity.ai, with self-serve account data and thread history.
Score unchanged (1). The page no longer states the 10-30-minute delivery estimate the old rationale cited; completion now arrives by notification with no stated turnaround. The deciding fact remains the 4-day download window, joined by the password gate and possible additional verification.
Meta — Export a copy of your Facebook information ↗Score unchanged (2). Meta renamed the export tool from “Download Your Information” to “Export your information” in Meta Account settings and added scheduled export to a connected external service; the JSON machine-readable format and granular selection are still stated on the same page. The rationale now quotes the current wording.
Meta — Export a copy of your Facebook information ↗Telegram rewrote its privacy principles (event ev-2026-0002): the quoted sentence "We don’t use your data to show you ads" no longer exists, so the cell is re-sourced to the updated §5.6 and §5.6.1. The score holds at 2: Telegram states its ad-targeting data cannot be disclosed to any third parties, advertisers included — the same first-party shape that scores Apple a 2 — while the companies at 1 share data with outside ad partners. What changed is scope: the promise now covers the contents of chats and contact lists rather than "your data" wholesale, and sponsored messages can be matched to the categories of large public channels a user follows.
Telegram Privacy Policy — §5.6 and §5.6.1 ↗Followed a published event →The SpaceXAI policy (effective Aug 24, 2026; event ev-2026-0001) states deleted conversations and deleted accounts are removed "within 30 days" unless retention is required for legal, compliance, or safety purposes, and Private Chat auto-deletes within 30 days. A stated post-deletion purge timeline with clear scope is the distinction that earns a 2 — the same standard OpenAI and Anthropic meet with their stated 30-day purges.
SpaceXAI Privacy Policy — retention ↗Followed a published event →The 0 rested on the April policy’s statement that xAI "by default uses your X posts, profile data, and Grok conversations" to train. The SpaceXAI policy (event ev-2026-0001) drops X data from scope — SpaceXAI states it is a separate company from X Corp, and Grok on X is governed by X’s own policy. What remains is training on your Grok conversations by default with a documented opt-out ("Improve the model" in Settings, Private Chat excluded) — the same trains-by-default-with-opt-out shape that scores OpenAI and Anthropic a 1. X’s own sharing of public posts stays scored on the X report card, where it keeps its 0.
SpaceXAI — Consumer FAQs ↗Followed a published event →The April policy’s no-sell sentence is not in the SpaceXAI policy; the plain commitment now lives in the Consumer FAQs: "We do not sell your data or share it with third parties for marketing or advertising purposes." The score holds at 2 on that statement. Noted in the cell: the policy lists targeted advertising among its uses and the site’s cookie banner describes ad-partner targeting cookies — a tension the FAQ statement currently outweighs.
SpaceXAI — Consumer FAQs ↗Followed a published event →Re-verified against the SpaceXAI policy: the privacy portal and the access, correction, and deletion rights carry over, and some rights are now exercisable in the Service. Score unchanged; Portability and Friction & speed cells re-worded the same day for the same reason — the policy no longer names portability, and requests still require full legal name, location, and identity verification.
SpaceXAI Privacy Policy — §9 ↗Followed a published event →This cell cited xAI’s privacy policy, and the SpaceXAI policy that replaced it (event ev-2026-0001) states Grok on X is governed by X’s own policy. Re-sourced to X’s own help page, which states X may share public posts and Grok interactions with xAI for training, on by default with a settings opt-out. Score unchanged at 0.
X Help Center — About Grok ↗Followed a published event →The cited Copilot Privacy FAQ now covers only the older Copilot app; the FAQ shipped with the new app (Aug 18, 2026; event ev-2026-0007) replaces it. The score holds at 1 — trains on conversation activity by default with an opt-out, the same shape as OpenAI and Anthropic. The cell’s facts are updated: the training-excluded locations changed from the EEA, UK and Switzerland to six other countries, signed-out and under-18 users are excluded, and conversation history may personalize ads under a separate setting.
Microsoft — Privacy FAQ for Microsoft Copilot (new app) ↗Followed a published event →The February 2026 settlement was counted twice: it forced this cell to 0 and also applied the enforcement deduction. Under the two-lane rule — grades rest on a company's own published statements; regulator findings live in the enforcement record — the cell now scores Disney's own stated “Do Not Sell or Share” opt-out, and the settlement remains in the enforcement record, which still deducts. Data practices 7/12 → 8/12; with the −2 enforcement deduction the grade moves D → C. Nothing about the violation left the page; it stopped being billed twice.
The Walt Disney Privacy Center — Your US State Privacy Rights ↗Same correction as Disney+: the February 2026 settlement naming Hulu was counted twice — in this cell and in the enforcement deduction. The cell now scores Hulu's own stated “Do Not Sell or Share” opt-out; the settlement remains in the enforcement record, which still deducts. Data practices 7/12 → 8/12; with the −2 enforcement deduction the grade moves D → C.
Hulu — Your US State Privacy Rights ↗The February 2024 settlement bore this cell's score directly. Under the two-lane rule the cell now scores DoorDash's own stated “Do Not Sell or Share” link, and the settlement moves to the enforcement record, where it now applies the standard −2 deduction it previously did not. Data practices 7/12 → 8/12 with a −2 enforcement deduction; the grade is unchanged at C.
DoorDash — Privacy Policy (US) ↗Held, not yet re-sourced. Under the two-lane rule this cell should rest on Meta's own published statements, but Meta documents the Brazilian AI-training opt-out only in-product — there is no Meta-published page to cite. Rather than silently keep a third-party citation or drop a real opt-out, the cell now carries a visible re-source-pending marker and keeps the Future of Privacy Forum's account of the ANPD case until a copy of Meta's own notice is captured. Score unchanged.
FPF — ANPD Meta case ↗Score unchanged. Re-sourced from the ICO's statement to Meta's own announcement, which states the “Legitimate Interests” basis, the always-available objection form, and the ICO engagement in Meta's own words. Grades rest on a company's own published statements; a regulator's publication belongs in the enforcement record, not behind a cell score.
Meta — Building AI Technology for the UK ↗Score unchanged. Re-sourced from noyb's challenge announcement to Meta's own announcement, which states the “legitimate interest” basis and an objection form users can submit at any time. An advocacy filing cannot bear a grade; the contested-legality clause was removed with it.
Meta — Making AI Work Harder for Europeans ↗Score unchanged. Re-sourced from press coverage to Meta's own generative-AI page, matching the US cell: the objection form Meta announced for the EU and UK is not offered in Canada. The advocacy-challenge clause was removed with the press citation.
Meta — Generative AI & your data ↗The previous grade rested on press coverage about on-device processing. Oura's own privacy policy states it may use personal data to develop and support its own AI and machine-learning features, and documents no opt-out for that use. Data practices 10/12 → 9/12.
Oura — Privacy Policy ↗Score unchanged. Re-sourced to Reddit's own User Agreement, which grants a licence that “includes the right to use Your Content to train AI and machine learning models.” The reported deal values in the previous citation were press-only and have been removed rather than re-sourced.
Reddit — User Agreement ↗Score unchanged. Re-sourced to Uber's own US privacy notice, which states data is used “for analysis, research and product development, including training machine learning models,” with no opt-out documented.
Uber — US Privacy Notice ↗Score unchanged. Re-sourced to Anthropic's own privacy-policy update, which states consumer chats may be used to improve Claude “if you choose to allow it,” with no separate EEA opt-in. The dark-pattern characterisation in the previous note was an advocacy claim rather than a company statement and has been removed from this cell.
Anthropic — Privacy Policy update (eff. 28 Sep 2025) ↗Score unchanged. The previous note's “~7 business days” and “180 days backup” figures appear nowhere in Temu's own documents and came from a third-party how-to. Temu states retention only as “as long as necessary,” and a missing post-deletion timeline is what caps this at Moderate.
Temu — Privacy & Cookie Policy ↗Score unchanged. The previous note's “consumer reports indicate … up to ~45 days” was sourced to a competitor's marketing page. Temu's own US addendum documents the rights flow, identity verification and an appeal path, and states no response timeline.
Temu — Privacy Policy Addendum for U.S. Residents ↗Score unchanged. The note said the dashboard archive is delivered “within 30 days.” That figure no longer appears on the cited page in that sense — it now covers replies to privacy questions and authenticated child-account deletions. No export delivery timeframe is stated at all.
Microsoft — Privacy Statement ↗Score unchanged. The note dated the training change to “Sep 2025”; the announcement is 28 Aug 2025, effective 8 Oct 2025. It now quotes Anthropic's own wording — models are trained on Free / Pro / Max data “when this setting is on” — rather than asserting a default the page does not state.
Anthropic — Updates to our consumer terms ↗How /events is published and checked
Events reports breaches, policy changes, and export-format changes at the companies we grade. It records other parties’ actions; the grade-change log above records ours. An event never changes a grade by itself — if one warrants a re-review, the review happens through the normal grading process and lands in the change log, citing the event it followed.
The feed is published as one bulletin — a public JSON file and the page rendered from it. It is identical for every reader: there are no per-person versions, no subscriptions by company, and nothing about you in it. A note publishes even on quiet days, so you can tell quiet from broken.
Each bulletin carries a cryptographic signature, so any reader — or any software reading the feed — can check two things: it really came from Data Report Card, and nothing in it changed after publication. The signing key’s public half is drc-events-2026-01; the technical contract lives with the feed itself.
Disclosure: Bricolage Inc. also builds datamoby, a browser extension that can read this bulletin. The feed exists on its own merits — every entry would publish whether or not the extension existed. Data Report Card learns nothing about extension users, and grades never incorporate extension usage.
We grade from sourced facts, and facts change. We have one process for anyone — including a graded company — who wants something corrected, reconsidered, or removed.
If a sourced fact is wrong, that's a correction:
We review every correction. When a sourced fact is wrong, we fix it and, where it affects the grade, we re-score. Correcting a fact is the way to prompt a re-review.
For everything else, the same address reaches us:
We aim to respond to good-faith requests promptly. This process does not waive any rights or defenses available to us, including for protected opinion.
Effective June 28, 2026
These terms govern your use of Data Report Card (the "Site"), operated by Bricolage Inc. By using the Site, you agree to them.
Limitation of liability
THIS WEBSITE IS FOR GENERAL INFORMATION PURPOSES ONLY. INFORMATION IS BELIEVED TO BE ACCURATE, BUT IT IS PROVIDED AS-IS, WITH NO WARRANTIES ARE GIVEN AS TO ITS COMPLETENESS, APPLICABILITY, OR ACCURACY. USE OF THE WEBSITE IS AT THE USER’S OWN RISK. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL BRICOLAGE INC. BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR ANY LOSS OF PROFITS OR REVENUES, WHETHER INCURRED DIRECTLY OR INDIRECTLY, OR ANY LOSS OF DATA, USE, GOODWILL, OR OTHER INTANGIBLE LOSSES, RESULTING FROM (A) YOUR ACCESS TO OR USE OF OR INABILITY TO ACCESS OR USE OUR WEBSITE; (B) ANY CONDUCT OR CONTENT OF ANY THIRD PARTY ON THE WEBSITE; OR (C) UNAUTHORIZED ACCESS, USE, OR ALTERATION OF YOUR TRANSMISSIONS OR CONTENT.
IN NO EVENT SHALL THE AGGREGATE LIABILITY OF BRICOLAGE INC. FOR ALL CLAIMS RELATING TO THE WEBSITE EXCEED ONE HUNDRED U.S. DOLLARS ($100). THE LIMITATIONS OF THIS SUBSECTION SHALL APPLY TO ANY THEORY OF LIABILITY, WHETHER BASED ON WARRANTY, CONTRACT, STATUTE, TORT (INCLUDING NEGLIGENCE), OR OTHERWISE, AND WHETHER OR NOT BRICOLAGE INC. HAS BEEN INFORMED OF THE POSSIBILITY OF ANY SUCH DAMAGE.
Governing law and jurisdiction
These Terms and any dispute or claim arising out of or in connection with them, their subject matter, or any use of the website, shall be governed by, and construed in accordance with, the laws of the State of California, without giving effect to any choice or conflict of law provision or rule. Each party irrevocably agrees that the state and federal courts located in Los Angeles County, California shall have exclusive jurisdiction to settle any dispute or claim arising out of or in connection with these Terms or their subject matter.
Contact: hello@datareportcard.com · Bricolage Inc., 2118 Wilshire Blvd. Suite 1098, Santa Monica, CA 90403.