| Average privacy policy length | 2,500 words or more |
| US state-level privacy laws in effect | More than 15 states (As of 2025) |
| Common opt-out mechanism | "Do Not Sell My Personal Information" link (Required under California CCPA/CPRA) |
| Typical data deletion response window | 45 days (extendable to 90) (Under California CPRA) |
Why the language in privacy policies matters
When you create an account, download an app, or buy something online, you agree to a privacy policy. Few people read them. Researchers at Carnegie Mellon University estimated years ago that reading every privacy policy a typical American encounters in a year would take roughly 76 work days. The language is designed by legal teams, not readers.
That does not mean you are powerless. A working vocabulary of the most common terms lets you scan a policy quickly and spot the parts that affect you most. This reference covers the phrases that appear most often and explains what they mean in practice. For a broader look at what companies do with collected data, see our explainer on data brokers.
PII (personally identifiable information)
Any data point that can identify a specific individual, such as a name, email address, phone number, or device ID. Companies handle PII under stricter obligations than anonymous data.
Aggregate data
Information combined across many users and reported as statistics rather than individual records. It carries lower privacy risk than PII, but is not always fully anonymous.
Third-party sharing
The practice of passing user data to outside organizations, which may include advertisers, analytics vendors, affiliates, or data brokers. The breadth of who qualifies as a 'third party' varies by policy.
Opt-out
A model where a data practice happens by default unless you take action to stop it. Most US commercial data practices use opt-out rather than opt-in consent.
Opt-in
A model where a company must receive your explicit consent before using your data for a specific purpose. Required under stricter privacy laws for sensitive data categories.
Data retention
The length of time a company stores your data. Policies may specify a fixed period or use open-ended language such as 'as long as necessary for business purposes.'
First-party cookie
A small tracking file set by the website you are directly visiting, typically used to remember login sessions or preferences.
Third-party cookie
A tracking file set by an external service (such as an ad network or analytics provider) loaded on the page you are visiting. Many browsers now restrict or block these by default.
Right to deletion
A consumer right, recognized under several US state privacy laws, that lets you request a company erase the personal data it holds about you, subject to certain legal exceptions.
Data controller
The entity that determines how and why personal data is collected and used. Under frameworks like GDPR, the controller bears primary responsibility for compliance.
Terms about what gets collected
Personally identifiable information (PII) is the category that matters most to most people. It covers any data point that can identify you as an individual: your name, email address, phone number, IP address, and device identifiers all qualify. A policy that says "we do not collect PII" is making a meaningful promise. One that says "we may collect PII" is telling you to keep reading.
Aggregate data sounds harmless because it is presented as statistics rather than individual records. A company might say it shares "aggregate usage data" with partners. This is generally lower risk, but aggregation is not always a complete shield. When data sets are small or contain enough indirect signals, researchers have shown that individuals can sometimes be re-identified from supposedly anonymous records.
Cookies and tracking technologies often appear in their own section. First-party cookies are set by the site you are visiting. Third-party cookies are set by external ad networks or analytics services loaded on that page. Most browsers now give you some control over third-party cookies. For a closer look at what app-level data collection looks like on your phone, our guide to app permissions breaks it down by category.
Terms about sharing and your rights
Third-party sharing means the company passes your data to outside organizations. The word "third party" covers a wide range: advertising partners, analytics vendors, data brokers, affiliates, and subsidiaries can all qualify. Some policies limit this to "service providers" who are contractually restricted in how they use the data. Others are broader. The distinction matters.
Opt-out means you can tell a company to stop a particular use of your data, but you have to take the action yourself. It is the default for most US commercial data practices. Opt-in is the opposite: the company must get your explicit consent before doing something with your data. Opt-in is the standard under stricter privacy frameworks, including the European Union's GDPR and California's CPRA for certain data categories.
Data retention describes how long a company keeps your information. A policy might say data is held "as long as necessary to provide services" or for a specific number of years. A vague retention clause is worth noticing. After deletion, some policies say data may remain in backup systems for an additional period.
Right to access and right to deletion are consumer rights written into several US state privacy laws. If a company's policy lists these rights, it is obligated (under applicable law) to respond to verified requests. The process typically involves submitting a form or emailing a designated privacy contact. For practical steps to reduce your data footprint, see our piece on common privacy myths and the social media privacy settings walkthrough.
