Midjourney
midjourneyMidjourney is a consumer-facing AI image and video generation service. Its Terms grant Midjourney a broad, perpetual, irrevocable, sublicensable license to all Content users input AND all Assets they generate, and by default user Content is publicly viewable and remixable unless a paid Stealth feature is purchased. The privacy policy explicitly lists model training as a purpose for data collection, engages in advertising-related data sharing, and reserves marketing use. There are no security certifications (SOC 2, ISO 27001, etc.) mentioned anywhere, and the documents are silent on encryption and formal security controls. While the policy provides genuine CCPA/GDPR rights and clear deletion SLAs (30 days), the extremely vendor-favorable content license, default public exposure of user content, and training use make this high risk for professional or proprietary use without contractual protection.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
Users retain nominal ownership of their inputs, but the Terms grant Midjourney a perpetual, worldwide, irrevocable, sublicensable, royalty-free copyright license over all Content input into the Service. This license survives termination, meaning submitted prompts and uploaded images can be reproduced, sublicensed, and distributed by Midjourney indefinitely.
Output Data Ownership
Users own the Assets they create to the fullest extent permitted by law, but this is conditioned: companies (or their employees) with over $1M annual revenue must subscribe to a Pro or Mega plan to own their Assets, and Midjourney still holds a broad perpetual license over all Assets. By default Assets are publicly viewable and remixable by others unless the paid Stealth feature is used.
Training Data Usage
The privacy policy explicitly states that personal data is collected through the process of training Midjourney's machine learning algorithms, and the broad content license permits derivative works. There is no consumer opt-out from training use disclosed, and prompts and uploaded images fall within the data that can be used to improve the Service.
Data Retention & Deletion
The documents provide clear deletion mechanisms and a concrete SLA: account and associated data are deleted within 30 days of a request, with a 7-day cancellation window. Deletion is available to any user regardless of location. Retention is otherwise described in general 'as long as necessary' terms with legal-obligation carve-outs.
Third-Party Data Sharing
Midjourney states it does not sell personal data but does share data with service providers and, notably, with third-party analytics and advertising partners via cookies to deliver relevant ads. Sharing for advertising extends beyond what the core image-generation service requires, though users are given a Privacy Settings opt-out and the sharing is disclosed.
Opt-Out Rights
The policy provides explicit opt-out mechanisms: a Do Not Sell/Share opt-out via the Privacy Settings page, cookie consent management for EEA/UK/Swiss users, and marketing opt-outs. These are meaningful, actionable controls, though there is no disclosed opt-out from model training use of inputs.
Compliance & Certifications
The documents claim CCPA and GDPR alignment (with standard contractual clauses for EEA/UK/Swiss transfers) but name no third-party certifications or attestations. No SOC 2, ISO 27001, ISO 42001, NIST CSF, or EU AI Act references appear. As a consumer/adtech tool the universal baseline applies, and the near-total absence of security certifications warrants a RED rating.
Model Explainability & Auditability
The documents provide no transparency into model behavior, no auditability provisions, and no enterprise audit rights. In fact, the Terms prohibit reverse engineering. There is no discussion of how the AI system reaches its outputs beyond a general acknowledgment that it is new and unpredictable technology.
Security Practices & Breach History
Security disclosures are minimal and generic. The policy states data is stored on US servers with 'commercially acceptable means' of protection but discloses no specific controls (no mention of encryption at rest/in transit, penetration testing, bug bounty, or incident response), no breach history, and no trust center or security page. It expressly disclaims the ability to guarantee security.
Enterprise vs. Consumer Risk Delta
The consumer documents reveal material differences between tiers: the paid Stealth feature (Pro/Mega) prevents Assets from being published publicly, and companies over $1M revenue must hold Pro/Mega to own their Assets. These distinctions mean free and lower-tier users get materially worse privacy and ownership terms, but no separate enterprise agreement was supplied to evaluate.
Human Review of User Inputs
The documents do not explicitly state routine human review of prompts, but Midjourney reserves broad rights to investigate complaints and disclose usage history, posted materials, and profiles to third parties, and Content is by default publicly viewable. Staff and the community can therefore access user content, and automated input blocking is described.
Regulatory & Litigation Exposure
The documents address law enforcement cooperation and government data requests, notably committing to notify users of law enforcement requests unless legally prohibited. Disputes are subject to mandatory binding arbitration in California with a jury-trial waiver and a one-year limitation period, which limits users' litigation options. No specific pending litigation is disclosed.
PII & SPI Data Inventory
Midjourney collects a broad range of PII (username, IP, email, contact/organizational info, usage data, cookies) and, per the CCPA table, also collects protected classification characteristics (via surveys), sensory data (uploaded images), commercial information, and inferences. While biometric and precise geolocation are marked NO, the collection of protected-class data and image content combined with advertising sharing and training use warrants RED.
Policy–Product Currency
No PRODUCT SURFACE section was supplied, so coverage cannot be independently verified; the INSUFFICIENT EVIDENCE RULE caps this at YELLOW. On recency, the Terms are dated May 27, 2026 (within 12 months of the analysis date) and the Privacy Policy June 2, 2025 (~14 months old). The documents do address AI/ML processing and training, but the mismatch of dates and lack of product evidence prevent a GREEN.
Cross-Document Consistency
Three documents were supplied, enabling a cross-document check. A minor entity-naming inconsistency exists (the Terms and most of the Privacy Policy refer to 'Midjourney, Inc.' while the Privacy Policy's Definitions section refers to 'Midjourney LLC'). Retention and deletion statements are broadly consistent across documents. No material or critical contradictions were found.
You've read all 15 risk ratings for Midjourney. Create a free account to see the exact policy wording behind each rating.