Midjourney
high riskAI Media Generationmidjourney.comverified 2026-06-27
Data-handling profile
- Trains on input
- Yes, on the consumer tier (enterprise tier excluded)
- Retention
- May use user-submitted materials (prompts/images) to provide/improve the service and train models unless the user opts out via account settings; deletion requests are honored for future retraining but do not retroactively alter already-trained models. Chat/generation logs purged after 90 days; personal data otherwise kept as long as needed for stated purposes/legal compliance. Default operation is public (Discord-based); Stealth Mode (Pro/Mega only) hides future generations but not prior public images.
- Data region
- US
- Certifications
- none listed
- DPA available
- No
- Breach history
- none known
- EU AI Act
- Default-public image generation, opt-out (not opt-in) training model, and no identified SOC 2/ISO certification or formal DPA give Midjourney a comparatively weak enterprise data-governance posture under the EU AI Act; independent privacy scorecards rate it low (e.g., 'Privacy Score 38/100').
Sources
- https://docs.midjourney.com/hc/en-us/articles/32083472637453-Privacy-Policy
- https://docs.midjourney.com/hc/en-us/articles/32083055291277-Terms-of-Service
- https://docs.midjourney.com/hc/en-us/articles/32084462534541-Data-Deletion-and-Privacy-FAQ
- https://terms.law/Privacy-Watchdog/ai-services/midjourney/
- https://verifywise.ai/ai-trust-index/midjourney
Every fact above is drawn from the vendor's public documentation, reviewed by a human, and version-stamped. Monitored daily for changes.
Change history
No material changes recorded since monitoring began.