首次追踪主流大模型隐私政策演变,揭示其长期模糊与地域差异。
A Longitudinal Measurement of Privacy Policy Evolution for Large Language Models
- 构建11家厂商74份历史政策数据集,分析超3000处逐版修改
- 政策平均需大学水平阅读能力,关键条款仍高度模糊
- 产品发布与监管动向是政策变更主因,适合关注数据合规者
大型语言模型(LLM)服务已广泛融入日常,通过持续收集大量数据运行,引发对敏感个人信息过度采集的隐私担忧。隐私政策是现代信息隐私体系中告知用户数据实践的核心机制。尽管传统网页和移动应用政策研究充分,但大模型提供商的隐私政策、其特定内容及随时间演进情况仍缺乏系统探索。本文首次开展全球主流大模型提供商隐私政策的纵向实证研究。我们整理了来自5个国家11家厂商截至2025年8月的74份历史隐私政策及115份补充文档,提取超过3,000条连续版本间的句子级修改。通过对比其他软件格式政策,提出专用于大模型的分类体系,标注政策修改并关联关键大模型生态事件时间线。结果表明,大模型隐私政策显著更长,需大学级别阅读能力,且仍高度模糊。分类分析揭示了厂商披露大模型特有实践的模式,并凸显区域覆盖差异。政策修改集中于第一方数据收集与国际/特定受众条款,且主要受产品发布与监管行动驱动,为理解大模型隐私政策现状与演化提供了洞见。
原文摘要 · Abstract (English)
Large language model (LLM) services have been rapidly integrated into people's daily lives as chatbots and agentic systems. They are nourished by collecting rich streams of data, raising privacy concerns around excessive collection of sensitive personal information. Privacy policies are the fundamental mechanism for informing users about data practices in modern information privacy paradigm. Although traditional web and mobile policies are well studied, the privacy policies of LLM providers, their LLM-specific content, and their evolution over time remain largely underexplored. In this paper, we present the first longitudinal empirical study of privacy policies for mainstream LLM providers worldwide. We curate a chronological dataset of 74 historical privacy policies and 115 supplemental privacy documents from 11 LLM providers across 5 countries up to August 2025, and extract over 3,000 sentence-level edits between consecutive policy versions. We compare LLM privacy policies to those of other software formats, propose a taxonomy tailored to LLM privacy policies, annotate policy edits and align them with a timeline of key LLM ecosystem events. Results show they are substantially longer, demand college-level reading ability, and remain highly vague. Our taxonomy analysis reveals patterns in how providers disclose LLM-specific practices and highlights regional disparities in coverage. Policy edits are concentrated in first-party data collection and international/specific-audience sections, and that product releases and regulatory actions are the primary drivers, shedding light on the status quo and the evolution of LLM privacy policies.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。