omg.lol
- The policy allows AI training; it does not describe an opt-out.
- Your data is used for personalized ads, including by third-party ad companies.
- Data is shared with partners and affiliates; you can opt out.
- Staff may review your content; the policy does not describe an opt-out.
The only policy provided is Stripe’s: it collects payment, ID, and browsing data, uses it for ads, fraud, and AI, and keeps it after you leave.
Agent Trust Hub uses AI and may make mistakes. Review reports and confirm their contents before relying on them.
- Uses your content for AI training with no opt-out
Collected
Payment details, IDs and selfies, bank data, device info, and browsing activity.
Read the exact line
Privacy policy
“Some Transaction Data is Personal Data and may include: your name, email address, contact number, billing and shipping address, payment method information”
Training
They use it for payments, fraud checks, ads, and training AI models.
Read the exact line
Privacy policy
“Training artificial intelligence models to power our Services and protect against fraud and other harm.”
Sharing
Merchants, banks, ad partners, analytics firms, and other service providers can get it.
Read the exact line
Privacy policy
“we may provide your data to third-party partners, such as advertising partners, analytics providers, and social networks, who assist us in advertising our Services to you.”
Kept
They keep it after you leave for legal, tax, and fraud reasons; no short delete clock.
Read the exact line
Privacy policy
“Even after we stop providing Services directly to you or to a Business User that you're doing business with, and even after you close your Stripe account or complete a transaction with a Business User, we may continue to retain your Personal Data”
Controls
You can request access or deletion and opt out of some U.S. ad sharing.
Read the exact line
Privacy policy
“You can opt out of targeted advertising and any related data “sales” or “sharing” (for behavioral advertising) here.”
Fine print
Policy can change when they post it; no lawsuit, refund, or account-closure rules in this file.
Read the exact line
Privacy policy
“Any changes are effective the latter of when we post the revised Policy on the Services or otherwise provide notice of the update as required by law.”
Expand “Read the exact line” to see the source alongside the explanation.
What you can turn off
The controls and opt-outs their own documents describe, and where they say to find them.
Opt out of targeted ads. sale/sharing
Stripe Privacy Center / the opt-out linked as “here” in the U.S. section; GPC signals are honored
Request access or deletion of Stripe-held data
Privacy Center or contact as in Contact us; End Customers should ask the Business User first
Stop marketing emails
Unsubscribe link in marketing emails
Limit Link data sharing for marketing
Login to Link at app.link.com/settings and toggle off data sharing from the Messaging menu
If a switch is not where they say, the deletion request above still applies.
Line by line
The lines that matter most, worst first.
They say they train AI on personal data. This privacy text does not give you a switch to turn that off.
Read the exact line
Privacy policy
“Training artificial intelligence models to power our Services and protect against fraud and other harm.”
For example, details from a payment or support chat could be used to train their systems.
Ad and analytics companies can get your data so Stripe can show interest-based ads.
Read the exact line
Privacy policy
“we may provide your data to third-party partners, such as advertising partners, analytics providers, and social networks, who assist us in advertising our Services to you.”
For example, a social network might use Stripe data to show you more Stripe ads.
Closing an account does not mean they wipe your data. They keep it for legal, fraud, and tax reasons.
Read the exact line
Privacy policy
“Even after we stop providing Services directly to you or to a Business User that you're doing business with, and even after you close your Stripe account or complete a transaction with a Business User, we may continue to retain your Personal Data”
For example, old card and purchase records can stay on file after you stop using Link.
A selfie plus ID can be treated as biometric matching for identity checks.
Read the exact line
Privacy policy
“If you provide a selfie along with an image of your identity document, we may employ biometric technology to compare and calculate whether they match and verify your identity.”
For example, a merchant using Stripe Identity can ask you for a driver’s license photo and a selfie.
They say they do not sell data for cash, but U.S. law may still treat ad sharing as a sale. There is an opt-out.
Read the exact line
Privacy policy
“Stripe's provision of data to these parties may be considered a data “sale” or “sharing” (for behavioral advertising) as those terms are defined under the ”
For example, a California user can use their opt-out link to stop some ad sharing.
People or systems can review recorded calls and chats for training and quality.
Read the exact line
Privacy policy
“Analyzing call recordings and call and chat transcripts for quality assurance, training, and operational purposes.”
For example, a support call about a failed payment may be recorded and later reviewed.
They collect device, browser, and activity data beyond just the payment itself.
Read the exact line
Privacy policy
“We may collect information related to: The devices and browsers you use across our Sites and third-party websites, apps, and other online services”
For example, IP address, pages visited, and mouse activity can be logged for fraud and analytics.
They ask kids under 13 not to use the services, but this is a statement, not a described ID check.
Read the exact line
Privacy policy
“Our Services are not directed to children under the age of 13, and we request that they do not provide Personal Data to seek Services directly from Stripe.”
For example, a 12-year-old could still type in data unless something else blocks them.
They say they use security measures, but they also say nothing is 100% safe.
Read the exact line
Privacy policy
“We maintain organizational, technical, and administrative measures designed to protect the Personal Data covered by this Policy from unauthorized access, destruction, loss, alteration, or misuse.”
For example, they tell account holders to use a strong unique password.
The privacy rules can change when they post a new version, not always with extra warning.
Read the exact line
Privacy policy
“Any changes are effective the latter of when we post the revised Policy on the Services or otherwise provide notice of the update as required by law.”
For example, a new ads or AI use could apply after they update the page.
Words to know
Legal words from the lines above, in plain English.
- personal data
- Any information that is about you or can be linked to you, from your name to your phone's ID. For example, your email, your IP address and the list of apps on your phone are all personal data.
- third parties
- Any company or person other than you and the app, such as advertisers, partners or analytics firms. For example, an analytics company that receives a record of every screen you tap is a third party.
- retention
- How long a company keeps your data before deleting it. For example, a policy might keep your messages for 30 days after you delete them, or for as long as it likes.
- opt out
- Something is on by default and stays on until you find the setting and turn it off. For example, your chats may be used for training unless you go into settings and switch it off.
- targeted advertising
- Ads chosen for you based on what you have done across other apps and websites, not just this one. For example, you look at shoes in one app and see shoe ads in a totally different app the next day.
- biometric
- Measurements of your body that identify you, like your face, fingerprint or voice. For example, a selfie used to unlock the app or a voice recording matched to you.
- sell or share
- Under California law, selling means passing your data to others for money or other value; sharing means passing it on for targeted ads. For example, letting an ad network use your browsing history in return for ad space counts as a sale.
- CCPA
- California's privacy law, which gives residents the right to see, delete and stop the sale of their data. For example, a Californian can ask the app to stop selling their data and it must comply.
How we got here · grade F · score 29/100 · 15 of 15 policy answers backed by a verified quote · 5 not stated
What does the app collect beyond what it needs to work?
They collect payment and account data plus device IDs, browsing, IDs, selfies, bank details, and sometimes credit reports.
Does it record your voice, face or body, and what happens to that?
Selfies and ID photos can be used for biometric matching. New Zealand text says that biometric data is kept for one year.
Are your chats and uploads used to train AI models, and is that off by default?
They say they train AI models on personal data. This policy does not describe a way to opt out of that training.
Can employees or contractors read your conversations, and when?
Calls may be recorded and transcripts used for quality, training, and operations, with no review opt-out described.
Are you profiled or tracked for advertising?
They use interest-based ads and share data with advertising partners, analytics providers, and social networks.
Do they sell or share your data, and can you opt out?
They say they do not sell data for money, but U.S. ad sharing may count as a sale or share, with an opt-out.
What rights do they take over what you type and what the AI makes?
Not stated in the documents.
How long do they keep your data after you delete it, and can you delete it in the app?
Deletion is by request, and they keep data after account close for legal, fraud, tax, and partner rules.
Does it build a lasting memory or profile of you, and can you see, edit or turn it off?
Not stated in the documents.
Do they commit to basic security, and have they leaked data?
They describe organizational and technical security measures in general terms, not a named audit in this text.
Is there a real age gate, and are teens protected?
Services are not directed to children under 13; no age-assurance process is described here.
Will they tell you when the rules change, and is the policy specific?
The policy is dated April 28, 2026. Changes take effect when posted or when law requires notice.
Can they close your account without warning, and can you get your data out first?
Not stated in the documents.
If something goes wrong, who pays?
Not stated in the documents.
Do subscriptions renew on their own, and can you get a refund?
Not stated in the documents.
The privacy policy is 11,637 words at a college graduate level (Flesch reading ease 33).