A privacy policy tells you what a company does with information about you. Before you create an account, buy something, or install an app, use it to answer five questions:

For U.S. consumers, the notice is a map of a company's data practices, not a guarantee that your information can never be exposed. Legal rights depend on your state, the type of information, and whether the business is covered by a particular law. The California Attorney General's guide to reading a privacy policy recommends learning what a business collects and how it uses that information as one way to protect your privacy.

What a privacy policy does and does not do

A privacy policy, sometimes called a privacy notice, should describe how the company handles personal information. Typical sections cover information you provide (name, email, shipping address, payment details), information collected automatically through a website, app, device, or browser, purposes for using the information, sharing with service providers, affiliates, advertisers, or other parties, retention and security practices, and how to contact the company about privacy rights.

The Federal Trade Commission's privacy policy is one public example. It explains how an organization collects, uses, shares, and protects personal information, and it shows the range involved: basic contact details in most cases, and more sensitive records in limited circumstances.

The policy is not terms of service. Those are the rules for using the account or service, including payment, suspension, and disputes. It is not a cookie banner either. A settings panel may let you accept or reject certain tracking technologies, but that panel is not the full notice.

A statement about encryption or other safeguards is not a promise that a breach is impossible. And if the policy permits disclosure to partners, affiliates, or vendors, don't assume your information stays inside the company until you've read those sections.

One document may cover several products, regions, or legal regimes. Confirm it applies to the specific website, app, account, or purchase in front of you.

Privacy policy terms explained in plain English

Businesses don't all use the same definitions, and state laws don't either. Treat the definitions section as part of the document, not leftover legal filler.

Personal information or personal data generally means information that identifies you, relates to you, or can reasonably be linked to you. The California Attorney General's consumer guidance gives examples including a name, home address, phone number, email address, Social Security number, driver's license number, financial information, and biometric information. Device identifiers, online activity, location, and inferences drawn from your activity can appear too. Scan for both obvious identifiers and less obvious data tied to your account or device.

Sensitive information usually gets extra space: government identification numbers, financial account details, precise location, health information, biometric data. The exact definition and the controls you get depend on the law that applies. Don't assume every sensitive category is handled the same way. See whether the company explains why each category is needed and whether you can decline to provide it.

Collection means obtaining information. That can happen when you create an account, fill out a form, make a purchase, contact support, use a site or app, connect a social or other third-party account, or grant access to a device feature. Check whether the notice separates what you typed in from what is collected automatically or received from another company.

Use or processing is a broad label for collecting, organizing, storing, analyzing, using, or deleting information. A policy may list service delivery, fraud prevention, analytics, personalization, advertising, customer support, or legal compliance. The useful test is whether the purpose is specific enough to understand. "Improving our business" tells you less than "measuring how customers use the app to fix errors."

Disclosure, sharing, and selling all describe giving information to another party, but a law or a policy may define them differently. Recipients often include payment, hosting, shipping, or customer-support providers; corporate affiliates; advertising or analytics companies; professional advisers; government agencies when legally required; and a buyer during a merger, sale, or other business transfer.

In California, "sale" and "sharing" can have specific legal meanings. Don't rely on the everyday sense of those words. Read the company's California privacy section and the California Attorney General's CCPA information before you decide whether an opt-out applies.

A service provider or processor handles information for the business, such as a payment processor or cloud host. That doesn't mean the provider cannot access the information. It means the relationship may limit how the provider can use it. Look for the categories of providers, their purposes, and whether the policy distinguishes them from companies that use data for their own advertising or analytics.

Retention is how long a business keeps information, or the criteria it uses to decide. A clearer notice may give a period, such as the life of an account plus a stated number of years, or explain why different records are kept for different lengths of time. "Unless required by law" or "as long as necessary" may be legitimate wording and still leave the real question unanswered: necessary for what purpose? If the period matters, ask the company for a more specific answer.

Some companies also profile you or use automated decision-making to infer interests, personalize content, detect fraud, or make decisions. Search for "profiling," "machine learning," "artificial intelligence," and "automated decision-making." A general claim that the company uses AI doesn't tell you whether your messages, files, purchase history, or other information train or improve a system. If that distinction matters, ask directly and save the reply.

How to read a privacy policy section by section

You don't have to read every paragraph in order. Search the page and write down what you find.

Start with scope and date: which company, product, and region the notice covers, and when it was last updated. A group may publish separate notices for different services.

Then the data categories. What is required, optional, automatic, or obtained from others? You may be providing more than the service needs to fulfill your request. A retailer may need a name and shipping address to deliver an order. An app that asks for contacts, microphone access, or precise location should explain what those permissions do. If a form doesn't mark optional fields clearly, check privacy settings or ask support before you submit. Review location, contacts, photos, microphone, and similar app permissions the same way.

Purposes come next. The same email address might send an order confirmation, answer a support request, and carry marketing. Those uses aren't interchangeable. Look for separate controls for marketing, personalized advertising, analytics, and account messages. Unsubscribing from promotional email may not stop security or account notices.

Sharing language is where "partners" can hide very different relationships. Some policies name recipients; others list only categories. "Service providers" is more specific than "business partners," but you may still need a vendor list or cookie notice. Watch for transfers during a sale or merger as well. Customer records can move as part of a business transaction. That clause won't describe a particular deal, but it flags a situation worth understanding.

Read retention and deletion together. There may be a separate account-deletion process, and the company may still keep transaction, tax, fraud-prevention, dispute, or legal records after the account closes. That doesn't automatically make the policy improper. It does mean you shouldn't assume deletion erases every copy held by the company, its providers, or a party that already received the information.

Finish with choices, security, and changes. Can you access, correct, delete, or opt out, and is there a working request method? What safeguards and incident contacts are described? Safeguards reduce risk; they don't eliminate it. How will the company announce future changes? A new purpose or sharing practice may appear in a later version.

A notice that clearly identifies data categories, purposes, recipients, retention, rights, and a real contact method is easier to evaluate. Vague language isn't automatically unlawful, but it should prompt a question before you hand over sensitive information.

What privacy choices may be available

There is no single privacy-rights checklist for every U.S. consumer. State laws cover different businesses and different information, and some industries have separate rules.

California is a useful example, not a nationwide template. The CCPA and its amendments give eligible California consumers rights that can include learning about information collected, requesting deletion, correcting certain information, and opting out of the sale or sharing of personal information. The official California CCPA page explains that the law gives consumers more control over information businesses collect.

California consumers can also use a user-enabled Global Privacy Control, or GPC, as an opt-out signal in situations covered by the law. The California Attorney General says a business must wait at least 12 months before asking a consumer to opt back in to the sale or sharing of personal information after an opt-out.

If you live elsewhere, don't assume California's process applies to you. Read your state's current privacy guidance and the company's state-specific notice. Some companies offer a voluntary opt-out even when a particular statutory right doesn't apply.

How to make a privacy request

If you want to access, correct, delete, or opt out of a data practice:

  1. Use the privacy email address, web form, account setting, or toll-free number listed in the policy.
  2. Identify the account and state the request: access, deletion, correction, or an opt-out. Vague complaints are easier to misroute.
  3. Follow verification instructions. The company may need to confirm you control the account. Use its secure method and don't send identification documents it didn't ask for.
  4. Keep a copy of the policy, its effective date, your request, confirmation numbers, and the response.
  5. If the request is refused, read the explanation. The company may identify a legal or operational reason for keeping certain records. Ask which part of the policy or which rule supports that decision.
  6. Escalate only after you've documented that first step. If the issue remains unresolved, contact your state attorney general or privacy regulator. California consumers can use the official CCPA information as a starting point.

A complaint to a regulator and a privacy request are different. A regulator may review a business practice without deleting your individual account or settling a particular dispute. The FTC contact page provides official routes for reporting an illegal business practice and explains how to contact the agency.

Common privacy policy questions

Does a privacy policy mean a company cannot sell my information?

No. The policy may permit disclosure, sale, or sharing, or it may say the company doesn't engage in certain practices. Check the definitions, recipient categories, and opt-out instructions. In California, use the CCPA-specific language rather than assuming "sale" has its ordinary meaning.

Does opting out of marketing stop all data collection?

Usually not. An email opt-out may stop promotional messages while still allowing account, payment, security, or service communications. An advertising opt-out can also be separate from information needed to operate your account.

Can deleting my account delete all my information?

Not necessarily. Review the retention section for transaction records, fraud prevention, legal obligations, backups, or information held by another company. Ask the business what deletion covers and what it must retain.

What if the privacy policy doesn't mention AI?

The omission doesn't tell you how the company handles your information. Search for related terms such as profiling, automated decisions, or machine learning. If the answer affects your decision, ask the company in writing before uploading sensitive content.

Should I save a copy of the policy?

Yes. Save the page or a screenshot with its effective date before you sign up or submit a request. If the policy changes later, the earlier copy helps you identify what information and purposes were disclosed at the time.

This is general consumer information, not legal advice. If a privacy issue involves sensitive data, identity theft, a major financial loss, or a formal legal claim, consider getting advice specific to your state and situation.

Before you create the next account or tap agree, open that service's privacy policy, search for collection, sharing, retention, and choices, and save a dated copy. If a category, purpose, or recipient is still unclear, use the contact method in the notice and wait for a written answer before you submit sensitive details.