TwinEthos homeRequest access

Control

Privacy notice does not say whether personal data is used to train large language models

Where a law requires it, the privacy notice states whether the controller collects, uses or sells personal data to train large language models, and the statement matches what the code does with personal data (training, fine-tuning, or sharing it for training).

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

Family: People are not told they are interacting with, or being processed by, an AI system · control id cond.privacy-notice-omits-llm-training-statement

Reach

1items this one guard addresses
1jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
0standards and frameworks on the same control

Law in force in Connecticut (US-CT).

Trust and provenance

How far the rules this guard addresses have been checked. Each rule links to its provision, with its citation, official text and its own panel.

This control
Audit-grade: meets all 3 checks of the TwinEthos audit standard that apply to it.
Lanes
Binding law — in force 1
Verification
Sources last verified 2 Oct 2026; each provision states how.
Data release
Data release 2026.10.03, data as of 2 Oct 2026, schema 0.3.9.
Legal review
None of the 1 rule has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice.
Audit standard
1 of 1 rule audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
2 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.

The guard to add

State in the privacy notice whether personal data is collected, used or sold to train large language models, and keep it true to the code's fine-tuning and training-data paths.

The privacy notice (the page or template the site and app link as 'Privacy') has a section on large language model training that answers the question either way: that personal data is not used or sold to train large language models, or which personal data is used, for which models, and who receives it. A release check ties the statement to the code: when the repository has fine-tuning or training-dataset paths fed by personal data (fine_tuning.jobs.create, training-file uploads, SFT or Trainer pipelines, dataset exports to partners), the notice must say yes, and the notice's last-updated month and year changes with it.

Where it goes: 12 repository artifacts, 14 user-facing text.

What reviewers look for: in the privacy notice source (privacy page, policy markdown or template), a statement that names large language model training and says whether personal data is collected, used or sold for it; if the code fine-tunes or trains on user data or exports it for training, the statement says so.

Example (Privacy notice (content/privacy.md)), before:

## How we use your information
We use your information to provide and improve our services.

After:

## How we use your information
We use your information to provide and improve our services.

## Training large language models
We do not collect, use or sell your personal data to train large language models. Chats are sent to our AI provider only to answer you and are not used for training.

_Last updated: July 2026_

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Binding law — in force (1)

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Tell people when they are interacting with AI — everywhere, not only where required

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.