Reading a privacy policy in ten minutes
Nobody reads these, and they are readable
The usual estimate is that reading every privacy policy you agree to in a year would take several working weeks. That figure is quoted to prove the exercise is hopeless. It proves something narrower: reading them end to end is hopeless. Reading the six clauses that carry the meaning takes about ten minutes per service, and you only do it for services that matter.
The technique is search, not reading. Open the policy, use your browser's find function, and go straight to the terms below. Everything else in the document is either legally required boilerplate or marketing.
The six searches
1. "retain" or "retention". How long they keep it. You are looking for a number. "As long as necessary for the purposes described" is not a number and should be read as indefinite. Note that different categories often have different periods, and abuse-monitoring copies commonly outlive the conversation you deleted.
2. "train", "improve our services", "model development". Whether your content updates their models. The phrase "to improve our services" is the one to watch: it is broad enough to cover training and is chosen precisely because it does not say so plainly. Look for whether an opt-out exists and whether it is on by default.
3. "subprocessor", "service provider", "third part". Who else gets a copy. Serious providers publish a subprocessor list as a separate page — cloud hosts, analytics, error tracking, payment, support desk. That list is often more informative than the policy.
4. "transfer", "located", "region". Where the processing happens, which decides whose law applies. Look for whether you can choose a region, and for the mechanism used for international transfers.
5. "human", "review", "monitor". Whether staff can read your content, and under what conditions. Almost every service permits this for abuse investigation. The question is whether it is limited to flagged content and whether access is logged.
6. "deidentif", "anonymi", "aggregate". The escape hatch. Data described as de-identified or aggregated is typically carved out of every other promise in the document — it can be retained forever, shared, sold, or used for training. Given how weak de-identification usually is, this clause frequently does more work than the rest of the policy combined. The next lesson is about why.
Two more places to look
The terms of service rather than the privacy policy is where you find who owns the output, what you may do with it, and the liability cap. These are different documents with different jobs, and the interesting clause is often in the one you did not open.
The settings page is where the defaults live, and defaults beat policies. A service that says it trains on your data "where you have not opted out" is telling you the switch exists and is on. Find it. It is usually under Data Controls, Privacy, or Improve the model for everyone.
Reading with a model, carefully
You can paste a policy into an AI tool and ask for the six answers, and it is a reasonable use — the document is public, so there is no disclosure problem, and the task is extraction from supplied text, which is what these systems are best at.
Two cautions. Ask for the quoted clause supporting each answer, not a summary, and check that the quote appears in the document. And remember from the previous module that summarisation strips hedges, which in a legal document are the entire content. "We may share data with partners" and "we share data with partners" are not the same sentence, and only one of them is what the company wrote.
What good looks like
After a few of these you develop a feel. Good policies state retention in days, list subprocessors by name, separate consumer and business terms clearly, and describe the opt-out and where it is. Weak ones use "may", "including but not limited to" and "as necessary" in place of every specific.
And note what a policy is not: it is a statement of current intent, changeable with notice. The commitments that survive a change of ownership or a change of strategy are the ones in a contract you signed, which is why organisations handling other people's data negotiate a data processing agreement rather than relying on a web page.
The one thing to keep
Search a privacy policy for six terms — retention, training, subprocessors, transfers, human review and de-identification — and read the settings page, because defaults decide more than the document does.
Before you move on
A policy promises to delete conversations after 30 days, but also says aggregated and de-identified data may be retained indefinitely and used to improve the service. What does the second clause do to the first?
Pick the one you would defend. Nobody sees your answer.