AuthorAZ

How the Rights & Privacy Index is assessed

What is evaluated, what is deliberately not, and how conclusions are reached — so you can judge the judgements.

What is evaluated

One question, asked of each service: what happens to an author’s work and data when they use it? That resolves into a small set of things that can be read out of the service’s own documents.

  • Content licence. What rights you grant, to whom, for how long, whether it can be sublicensed or transferred, and whether it ends when you leave.
  • AI and model training. Whether the terms permit, exclude, or simply do not address training on your work.
  • Manuscript handling. Whether uploading is required, whether the service is cloud-dependent, and whether an account is needed at all.
  • Deletion. Whether titles can be withdrawn and whether the account and its files can be removed.
  • Export and portability. How hard it is to leave and take your distribution elsewhere.
  • Policy transparency. How legible the service’s own documents are, which is itself a finding.

What is not evaluated

This is not a security assessment, an audit, or legal advice. Nothing here is based on inspecting a service’s infrastructure, testing its systems, or reviewing code.

It also does not assess quality, value for money, royalty competitiveness or customer service. Those belong to the Publishing Database, which is built from the same records.

Most importantly, it does not assess what a company does — only what its documents permit and require. Those are different things, and only the second is checkable from outside.

Source hierarchy

Findings come from primary documents wherever they exist. Where two sources conflict, the higher one wins — a binding agreement outranks a help article describing current practice, because only one of them is what the company is held to.

  1. The service’s own terms of service or author agreement
  2. The service’s own published policies
  3. The service’s own privacy policy
  4. The service’s own pricing pages
  5. The service’s own help centre and documentation
  6. Announcements published by the service
  7. Regulators, courts and enforcement bodies
  8. High-quality secondary reporting

Every factual claim on a service page carries its source, with the date an editor opened it. A sensitive conclusion is not drawn from a single weak secondary source when primary documentation exists.

How “unknown” is handled

This is the part that matters most, and the part most often got wrong elsewhere.

Absence of evidence is not evidence of absence. If an agreement says nothing about training AI models on uploaded manuscripts, that is recorded as the terms are silent — never as “does not train on your work”. Silence leaves the question to a general licence grant and to policies that can change without amending the agreement. It is not a commitment, and presenting it as one would be the single most misleading thing this index could do.

Three states are therefore kept distinct, and are shown differently:

  • A stated answer — the documents address it, and the entry says what they say.
  • Not determined — an editor looked and the documents did not settle it.
  • Not assessed — nobody has researched it yet.

A service is listed in the index only once it has an assessment. An unresearched service is absent, rather than published as a page of blanks that would read like findings.

Why there is no score

Each assessed service carries an overall posture rather than a number. A 0–100 privacy score would imply a precision the evidence does not support, and would invite comparisons between figures that were never measured on the same scale.

Strong
The terms actively protect the author: narrow, revocable licences and explicit limits on reuse.
Generally protective
The terms are scoped to what the service needs to operate, with clear routes to withdraw.
Mixed
Some terms protect the author and others do not, or an important question is left unanswered.
Concerning
The terms grant more than the service needs, or make withdrawal difficult.
Unclear
The documentation does not establish the position well enough to characterise it.

The posture is a human editorial judgement. It is never computed from the other fields — deriving it arithmetically would smuggle the same false precision back in through a different door. Every service page states the reasoning behind its own posture, and separates what the documents say from what we conclude from them.

Update schedule

Each record carries the date its policies were last read, and a review cadence: 30–60 days for platforms whose terms change often, 90–180 days for more stable ones. Records past their cadence are flagged to editors, and a record that is substantially overdue says so on the page rather than quietly presenting old findings as current.

Pages are never hidden for being old. A dated finding you can weigh is more useful than no finding at all.

Corrections

Terms change without announcement, and a summary can be wrong. If something here no longer matches a service’s own documentation, or never did, send the current source and it will be corrected.

Please include the page, the specific claim, and a link to the document that contradicts it. There is no public editing.

Send a correction

This is not legal advice

AuthorAZ is providing informational analysis of published documents. It is not a law firm, these summaries are not legal advice, and no reading here substitutes for advice on your own situation. Contracts are interpreted in context and jurisdiction matters. Before signing something that concerns you, get advice from a lawyer or an authors’ organisation.

Back to the Rights & Privacy Index