TikTok
tiktokTikTok's U.S. consumer Terms of Service and Privacy Policy (both last updated July 15, 2026, operated by TikTok USDS Joint Venture LLC) describe a broad, vendor-favorable data regime. While users nominally retain ownership of their content and AI Input/Output, they grant a sweeping worldwide, sub-licensable, irrevocable license that explicitly extends to training machine learning models. The platform collects an exceptionally broad range of PII and sensitive personal information — including biometric identifiers (faceprints, voiceprints), precise location, clipboard contents, contacts, and financial data — and reserves broad rights to human and automated review of user content, messages, and AI interactions. The documents name no security certifications (no SOC 2, ISO 27001, GDPR, etc.), impose a $100/12-month liability cap, a one-year limitation period, and California-exclusive venue. Opt-out mechanisms exist for ads and cookies but not for the core training use of content. Given the breadth of data collected, the absence of any named compliance attestation, and the training-on-inputs posture, this is high risk for professional or regulated use without separate contractual protections.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
Users nominally retain ownership of their content, including prompts and files submitted to AI interfaces (defined as 'Input'). However, ownership is heavily qualified by an irrevocable, worldwide, sub-licensable license granted to TikTok. Ownership in name is undermined by the breadth of the license granted.
Output Data Ownership
Users own AI Output, but that ownership does not extend to other users' output, and Output may not be unique to a specific user. TikTok also retains all rights in its generative AI features. Output is provided 'as is' with no warranties.
Training Data Usage
The documents explicitly permit TikTok to use user content, including AI interactions, to train, test, and improve machine learning models and algorithms. The license granted is sub-licensable to service providers and business partners, and no opt-out from training is offered. This is a strongly vendor-favorable posture for any user submitting proprietary data.
Data Retention & Deletion
Users can delete videos, their account, or request deletion via a webform or in-app settings, and the policy describes retention tied to account life and legal obligations. However, no specific retention schedules or deletion SLAs are provided; retention is described only in open-ended terms ('as long as necessary'), and deleted content may persist if incorporated into other users' content.
Third-Party Data Sharing
TikTok states it does not sell personal information or share for cross-context behavioral advertising where restricted by law, and it discloses a broad set of recipients (service providers, payment processors, advertising/analytics partners, sellers, affiliates, TT Commerce & Global Services, and independent researchers). Sharing is disclosed and largely tied to service functions, but the breadth of advertising/analytics sharing and the sub-licensable content license push this to moderate risk.
Opt-Out Rights
The policy provides concrete opt-out mechanisms for ads personalization, cookies, marketing emails, and contact syncing, and supports access/correction/deletion requests. However, there is no opt-out from the core use of user content and AI interactions for training machine learning models, and do-not-track signals are explicitly ignored.
Compliance & Certifications
The documents reference CCPA and various state privacy laws (Washington My Health My Data Act, Connecticut, California), plus Executive Order 14352, but name no security or AI certifications or third-party attestations (no SOC 2, ISO 27001, ISO 42001, GDPR, NIST, or EU AI Act). For the universal baseline, no framework is certified with evidence, and the security posture is stated only as 'reasonable measures.'
Model Explainability & Auditability
The documents provide no meaningful transparency into AI model behavior or any enterprise auditing mechanism. They state the platform does not engage in profiling with legal/significant effects and describe customization, but offer no explainability or audit rights, and prohibit reverse engineering of algorithms.
Security Practices & Breach History
Security is described only as 'reasonable measures' with an explicit disclaimer that no system can be guaranteed secure. No specific controls (encryption at rest/in transit, access controls, penetration testing, bug bounty, incident response), no trust center, and no breach history or notification commitments are disclosed.
Enterprise vs. Consumer Risk Delta
The consumer Terms note that TikTok For Business, Ads Manager, and Business Center accounts are governed by separate terms not supplied here, and subscription services have their own terms. No enterprise data-handling carve-outs are described in the supplied consumer documents, so a meaningful delta cannot be established. This silence is itself a risk signal for business users.
Human Review of User Inputs
TikTok explicitly reserves the right to use both automated tools and human moderators to review user content, messages, AI interactions, and associated metadata for enforcement and model-improvement purposes. This applies to prompts and outputs submitted to AI features and is broad in scope.
Regulatory & Litigation Exposure
The policy discloses that TikTok will share information to comply with subpoenas, court orders, law enforcement requests, and government inquiries, and the Terms include extensive sanctions/export-control provisions, a California-exclusive venue, a one-year limitation period, and a mandatory informal dispute process. These are disclosed but broadly favor the vendor.
PII & SPI Data Inventory
TikTok collects an extremely broad range of PII (name, email, phone, IP, device IDs, contacts, usage, location) and sensitive personal information including biometric identifiers (faceprints, voiceprints), precise geolocation, financial/payment data, clipboard contents, keystroke patterns, and content that may reveal health, sexual orientation, immigration status, and religion. Although disclosed, the sheer breadth of SPI collection combined with broad training and sharing rights places this at high risk.
Policy–Product Currency
Both the Terms and Privacy Policy are dated July 15, 2026, well within 12 months of the analysis date, and they explicitly address AI-powered interfaces, generative AI features, machine learning training, and third-party AI integrations. However, no PRODUCT SURFACE was supplied, so coverage cannot be independently verified; under the insufficient-evidence rule the rating is capped at YELLOW.
Cross-Document Consistency
Three documents were supplied (Terms of Service, Privacy Policy, and a truncated Consumer Health Data policy). The Terms and Privacy Policy align on key points: both name TikTok USDS Joint Venture LLC as operator, both are dated July 15, 2026, and both describe training on user content/AI interactions and TT Commerce & Global Services as a partner. No contradictions were identified across the documents.
You've read all 15 risk ratings for TikTok. Create a free account to see the exact policy wording behind each rating.