Midjourney logo

Midjourney

midjourney
High Risk
Updated August 2, 2026

Midjourney is a consumer-facing AI image and video generation service. Its Terms grant Midjourney a broad, perpetual, irrevocable, sublicensable license to all Content users input AND all Assets they generate, and by default user Content is publicly viewable and remixable unless a paid Stealth feature is purchased. The privacy policy explicitly lists model training as a purpose for data collection, engages in advertising-related data sharing, and reserves marketing use. There are no security certifications (SOC 2, ISO 27001, etc.) mentioned anywhere, and the documents are silent on encryption and formal security controls. While the policy provides genuine CCPA/GDPR rights and clear deletion SLAs (30 days), the extremely vendor-favorable content license, default public exposure of user content, and training use make this high risk for professional or proprietary use without contractual protection.

AI Transparency Facts

Independent analysis by TermsWatchdog · © 2026 TermsWatchdog

Input Data Ownership

High Risk

Users retain nominal ownership of their inputs, but the Terms grant Midjourney a perpetual, worldwide, irrevocable, sublicensable, royalty-free copyright license over all Content input into the Service. This license survives termination, meaning submitted prompts and uploaded images can be reproduced, sublicensed, and distributed by Midjourney indefinitely.

Confidence
90%

Output Data Ownership

Moderate Risk

Users own the Assets they create to the fullest extent permitted by law, but this is conditioned: companies (or their employees) with over $1M annual revenue must subscribe to a Pro or Mega plan to own their Assets, and Midjourney still holds a broad perpetual license over all Assets. By default Assets are publicly viewable and remixable by others unless the paid Stealth feature is used.

Confidence
85%

Training Data Usage

High Risk

The privacy policy explicitly states that personal data is collected through the process of training Midjourney's machine learning algorithms, and the broad content license permits derivative works. There is no consumer opt-out from training use disclosed, and prompts and uploaded images fall within the data that can be used to improve the Service.

Confidence
80%

Data Retention & Deletion

Low Risk

The documents provide clear deletion mechanisms and a concrete SLA: account and associated data are deleted within 30 days of a request, with a 7-day cancellation window. Deletion is available to any user regardless of location. Retention is otherwise described in general 'as long as necessary' terms with legal-obligation carve-outs.

Confidence
82%

Third-Party Data Sharing

Moderate Risk

Midjourney states it does not sell personal data but does share data with service providers and, notably, with third-party analytics and advertising partners via cookies to deliver relevant ads. Sharing for advertising extends beyond what the core image-generation service requires, though users are given a Privacy Settings opt-out and the sharing is disclosed.

Confidence
78%

Opt-Out Rights

Low Risk

The policy provides explicit opt-out mechanisms: a Do Not Sell/Share opt-out via the Privacy Settings page, cookie consent management for EEA/UK/Swiss users, and marketing opt-outs. These are meaningful, actionable controls, though there is no disclosed opt-out from model training use of inputs.

Confidence
75%

Compliance & Certifications

High Risk

The documents claim CCPA and GDPR alignment (with standard contractual clauses for EEA/UK/Swiss transfers) but name no third-party certifications or attestations. No SOC 2, ISO 27001, ISO 42001, NIST CSF, or EU AI Act references appear. As a consumer/adtech tool the universal baseline applies, and the near-total absence of security certifications warrants a RED rating.

Confidence
72%

Model Explainability & Auditability

High Risk

The documents provide no transparency into model behavior, no auditability provisions, and no enterprise audit rights. In fact, the Terms prohibit reverse engineering. There is no discussion of how the AI system reaches its outputs beyond a general acknowledgment that it is new and unpredictable technology.

Confidence
70%

Security Practices & Breach History

High Risk

Security disclosures are minimal and generic. The policy states data is stored on US servers with 'commercially acceptable means' of protection but discloses no specific controls (no mention of encryption at rest/in transit, penetration testing, bug bounty, or incident response), no breach history, and no trust center or security page. It expressly disclaims the ability to guarantee security.

Confidence
74%

Enterprise vs. Consumer Risk Delta

Moderate Risk

The consumer documents reveal material differences between tiers: the paid Stealth feature (Pro/Mega) prevents Assets from being published publicly, and companies over $1M revenue must hold Pro/Mega to own their Assets. These distinctions mean free and lower-tier users get materially worse privacy and ownership terms, but no separate enterprise agreement was supplied to evaluate.

Confidence
68%

Human Review of User Inputs

Moderate Risk

The documents do not explicitly state routine human review of prompts, but Midjourney reserves broad rights to investigate complaints and disclose usage history, posted materials, and profiles to third parties, and Content is by default publicly viewable. Staff and the community can therefore access user content, and automated input blocking is described.

Confidence
60%

Regulatory & Litigation Exposure

Moderate Risk

The documents address law enforcement cooperation and government data requests, notably committing to notify users of law enforcement requests unless legally prohibited. Disputes are subject to mandatory binding arbitration in California with a jury-trial waiver and a one-year limitation period, which limits users' litigation options. No specific pending litigation is disclosed.

Confidence
72%

PII & SPI Data Inventory

High Risk

Midjourney collects a broad range of PII (username, IP, email, contact/organizational info, usage data, cookies) and, per the CCPA table, also collects protected classification characteristics (via surveys), sensory data (uploaded images), commercial information, and inferences. While biometric and precise geolocation are marked NO, the collection of protected-class data and image content combined with advertising sharing and training use warrants RED.

Confidence
76%

Policy–Product Currency

Moderate Risk

No PRODUCT SURFACE section was supplied, so coverage cannot be independently verified; the INSUFFICIENT EVIDENCE RULE caps this at YELLOW. On recency, the Terms are dated May 27, 2026 (within 12 months of the analysis date) and the Privacy Policy June 2, 2025 (~14 months old). The documents do address AI/ML processing and training, but the mismatch of dates and lack of product evidence prevent a GREEN.

Confidence
45%

Cross-Document Consistency

Moderate Risk

Three documents were supplied, enabling a cross-document check. A minor entity-naming inconsistency exists (the Terms and most of the Privacy Policy refer to 'Midjourney, Inc.' while the Privacy Policy's Definitions section refers to 'Midjourney LLC'). Retention and deletion statements are broadly consistent across documents. No material or critical contradictions were found.

Confidence
65%

You've read all 15 risk ratings for Midjourney. Create a free account to see the exact policy wording behind each rating.