LLM Privacy Policies Are Too Long and Hard to Read, Study Finds
A new study reveals that privacy policies for popular large language models (LLMs) are excessively long and difficult to read, raising concerns about transparency and user data protection. The findings highlight how complexity may obscure critical details about data processing and opt-out options for consumers and businesses alike.
LazyFounders

A new study reveals that privacy policies for popular large language models (LLMs) are excessively long and difficult to read, raising concerns about transparency and user data protection. The findings highlight how complexity may obscure critical details about data processing and opt-out options for consumers and businesses alike.
30 SEC SUMMARY
- A study by Bridewell found that privacy policies for top LLMs are lengthy and hard to read, averaging 20 minutes to review.
- Meta’s Muse Spark privacy policy is over 14,000 words long, requiring nearly an hour to read.
- The average Flesch Reading Ease Score for LLM privacy policies is 40.2, indicating poor readability.
- 13 of 20 LLMs assessed use user inputs and outputs to train their models, with some offering opt-out options.
- 75% of people use an AI chatbot at least once a month, raising concerns about unintended data sharing.
TABLE OF CONTENTS
- Lengthy and Complex Privacy Policies
- Poor Readability Raises Concerns
- Data Use and Opt-Out Gaps
- What this means
- Key takeaways
- FAQ
- Sources
KEY HIGHLIGHTS
- Privacy policies for leading LLMs average 20 minutes to read, with Meta’s Muse Spark policy taking nearly an hour.
- The average Flesch Reading Ease Score for LLM privacy policies is 40.2, signaling poor readability.
- 13 out of 20 LLMs assessed use user inputs and outputs to train their models.
- 75% of people use AI chatbots monthly, but many may not understand how their data is processed.
- Some LLMs offer opt-out options for training, while others do not.
Lengthy and Complex Privacy Policies
A study by cybersecurity firm Bridewell, reported by TechRadar, found that privacy policies for leading large language models (LLMs) are significantly longer and more complex than typical user agreements. The average privacy policy for an LLM takes about 20 minutes to read, with an average word count of 4,603 words.
Meta’s Muse Spark privacy policy stood out as an extreme example. At over 14,000 words, it requires nearly an hour to read—far exceeding the length of policies for other LLMs in the study. This trend of lengthy policies was consistent across the 20 LLMs assessed, raising concerns about how effectively users can understand their data rights and risks.
Poor Readability Raises Concerns
The study evaluated readability using the Flesch Reading Ease Score, a metric developed by Rudolf Flesch to assess how accessible a text is to the average reader. Scores over 60 are considered easy to read, while those below 60 are increasingly difficult. The average score for LLM privacy policies was 40.2, indicating poor readability.
According to TechRadar, this level of complexity makes it unlikely that most users will fully grasp the terms they agree to when using AI chatbots. The finding underscores a broader issue in tech: balancing legal thoroughness with user comprehension.
Data Use and Opt-Out Gaps
The research also shed light on how LLMs handle user data. Of the 20 models assessed, 13 use inputs and outputs from interactions to train their systems. While some providers offer opt-out mechanisms, others do not, leaving users with limited control over how their data is processed.
This lack of standardization is particularly concerning given the widespread adoption of AI tools. TechRadar reports that around 75% of people use an AI chatbot at least once a month. For employees, this raises the risk of accidentally sharing sensitive or confidential information that could later be used to train models.
The study did not confirm whether all providers disclose these practices clearly in their policies, but the combination of lengthy documents and poor readability suggests many users may remain unaware of the implications.
What this means
LazyFounders analysis — our interpretation, not reported fact.
For founders and operators building or integrating AI tools, this research underscores a critical gap between compliance and usability. Privacy policies are a legal necessity, but their complexity risks alienating users or creating a false sense of security—especially when employees or customers unwittingly share sensitive data.
The findings also highlight an opportunity for startups to differentiate themselves by making privacy more accessible. Whether through simplified summaries, interactive explanations, or clearer opt-out mechanisms, prioritizing transparency could build trust in an era where users are increasingly wary of how their data is used. For B2B founders, this is particularly relevant: if your product integrates with LLMs, ensure your team and customers understand the risks of feeding data into these systems.
Key takeaways
- LLM privacy policies average 20 minutes to read, with one exceeding an hour due to length and complexity.
- Readability scores for these policies are low, making them inaccessible to the average user.
- Most LLMs use user data for training, and not all provide opt-out options, raising ethical and compliance concerns.
- High usage of AI chatbots suggests many users may unknowingly expose sensitive data.
- Founders should prioritize transparent data practices to mitigate risks and build user trust.
FAQ
Why do LLM privacy policies take so long to read?
The study found that LLM privacy policies are significantly longer than average, with complex language and legal jargon. This is partly due to the need to cover intricate data processing practices, but it also makes them inaccessible to most users.
What is the Flesch Reading Ease Score, and why does it matter?
The Flesch Reading Ease Score measures how easy a text is to read. Scores over 60 are considered accessible, while lower scores indicate difficulty. The average score for LLM privacy policies was 40.2, meaning most users would struggle to understand them.
Can users opt out of having their data used to train LLMs?
Some LLMs offer opt-out options, but not all. The study found that 13 out of 20 models use user inputs and outputs for training, and the lack of standardized practices means users often lack clear control over their data.
Related on LazyFounders
Sources
- TechRadar · 2026-09-23
Privacy policies on top LLMs take over 20 minutes to read, so perhaps it no wonder people are signing their lives over to ChatGPT and others
This story is an original summary and analysis written by LazyFounders from the reporting listed above. Facts are attributed to their original publishers; sections marked as analysis are LazyFounders's opinion. Where a source is in another language, facts were machine-translated and quotations are reported, not reproduced. Read the original coverage via the links.


