We publish factual claims about New Zealand law and about what AI vendors do with data. Some of them will be wrong.

When that happens, here is what we do.

We correct it and say so. The correction appears on this page with the date, what was wrong, and what it should have said. We do not quietly edit a page and move on.

We say where it appeared. If a wrong claim went out in a newsletter or a course module, the correction names that, so anyone who read the original can tell whether it reached them.

We date everything. Every rating and every reference page carries the date it was last verified. A claim that was accurate in March may not be accurate now — particularly for vendor terms, which change without announcement.

Ratings reflect what was published when we checked. If a vendor has changed its terms since, that is a change rather than an error, and it appears in the alerts rather than here. If we read something wrong, that is an error and it appears here.

When a rating gets old, we say so on the rating. Every profile is fully re-checked at least every six months. If one passes six months without a full re-check, a notice appears on it automatically, without anyone deciding to put it there. You should expect to see those notices from time to time. They are the system working, not the system failing — a publication that never showed one would either be re-checking nothing or hiding it.

If we have a privacy breach, we will tell you. We will notify anyone affected as soon as we can, notify the Privacy Commissioner where the law requires it, and publish what happened on this page with the date — whether or not the breach meets the legal threshold for notification. We grade other organisations on how they handle data. It would be indefensible to hold ourselves to a lower standard than we hold them.

If you think something is wrong, tell us. quentin@aileakage.com. Point us at the specific wording if you can, it is faster than us guessing which part. We would rather know.

Corrections to date

This page said “none yet” until 3 September 2026. That was itself wrong. Corrections had been made on this site since 5 August 2026 — at least fourteen of them, across ten products, two of which moved a rating. Each was written onto the profile it belonged to, with a date and an explanation. None of them reached this page. By the standard set out above, that made every one of them a quiet edit, which is the exact thing this page exists to prevent. The list below is the backfill, assembled from the correction notices on the profiles themselves.

6 September 2026

  • Zoom — we over-corrected yesterday, so here is the correction to our correction. On 5 September we told you ZoomMate is “no longer included in the Zoom plan you already pay for”. Reading Zoom’s Workplace pricing page the next day — the one we had admitted was still carrying an 11 August reading — showed that too blunt. A Workplace Pro subscriber at NZ$24.99 per user per month does get substantial AI without buying anything else: unlimited meeting summaries, unlimited in-meeting questions, unlimited AI note-taking, agentic search inside Zoom. Even free Basic carries a metered amount. What the paid ZoomMate licence adds is the agent layer — credits, custom agents, deep research, reach into third-party sources. So the accurate statement is narrower than the one we published: the AI is not all behind a paywall, but the agent product is. The profile now carries both corrections rather than only the tidy final answer, and the plan table has been rebuilt with the Workplace prices we had not re-read. The rating has still not been moved.

5 September 2026

  • Zoom — we have been rating a product under a name Zoom no longer uses, and our scope note about it was wrong. Our profile is titled “Zoom AI Companion” and uses that name throughout. The page we cite as the product’s home now reads “Meet ZoomMate, your AI teammate”, and the words “AI Companion” do not appear anywhere on it. We read that page in a browser on 5 September 2026. We have also withdrawn our scope note of 3 September, which said the rated product does not exist on Zoom’s free plan: Zoom now lists ZoomMate Basic as included free with Workplace Basic, metered rather than absent — three hosted meetings of summaries a month, twenty AI queries, three uses of AI note-taking, ten workflow runs. We cannot tell you whether Zoom changed this or whether we read it wrong, and we are not going to guess. The rating has not been moved and is being re-checked. Renamed the same day. The profile is now titled “ZoomMate (Zoom)” and the new name is used throughout it and in the six other pages that referred to the product. Two things were deliberately left alone: the titles of the source documents we cite, because a citation has to say what the document actually says, and this page and the dated alert of August 2026, because a correction record that rewrites itself is not a record. The profile also carries a caution that its plan-inclusion detail has not yet been re-verified.
  • Slack — our scope note of 3 September was wrong and is withdrawn. It said this rating covered a product that does not exist on Slack’s free plan. Slack’s pricing page on 5 September lists “Basic AI” on the Free plan: conversation summaries, Slackbot, workflow generation, AI search, daily recaps and file summaries. Again we cannot say whether the page moved in two days or whether we misread it, and we would rather tell you that than pick the version that flatters us. The rating has not been moved and is being re-checked.
  • Zoom — a second, larger correction the same day: ZoomMate is not included in your Zoom plan, and we had been saying it was. Having flagged the rename, we went to Zoom’s own ZoomMate pricing page in a browser rather than trusting its marketing page, and found the profile wrong in a way that costs money. We had described the product as bundled into eligible paid plans “rather than sold as a per-seat add-on”, and drew a favourable contrast with Microsoft 365 Copilot on exactly that basis. Zoom now sells it per user: NZ$27.67 per user per month, billed annually as a single upfront charge, carrying 2,200 AI credits per user per month. Below it sits a metered free tier, ZoomMate Basic, included with Workplace Basic. For a ten-person firm that believed AI came free with its Zoom subscription, that is roughly NZ$3,300 a year it did not know it was looking at. We have corrected the summary, the deck, the plan table, the recommendations and the metadata, each with a dated note saying what the line used to claim. The rating has not been moved: price is not a privacy fact and the training and retention positions are unchanged. But the “it is already included, you may as well use it” framing ran through the whole profile, and that framing was doing work.
  • What we checked at the same time, and what held. Two of the four scope notes we added on 3 September survive the re-check. Asana stands: its pricing page still shows no AI features on the free Personal tier, with AI Studio credits beginning at Starter. HubSpot substantially stands: the free tier carries no credit allowance while Starter, Professional and Enterprise each do, and the AI agents run on those credits — though we could not find the term “Agent Hub” on the pricing page we read, so treat that particular wording as ours rather than HubSpot’s until we confirm it.

3 September 2026

  • Jasper and Shopify Magic — two ratings rested on a claim broader than the vendor’s own, and both moved. We rated both 2 of 5 partly on the basis that training on customer data was excluded across all tiers. Neither vendor publishes that. Jasper commits that data is “never used to train third-party LLMs” — a commitment about third-party model providers, not about Jasper’s own systems. Shopify commits that it “doesn’t use any merchant’s store-level data to power Shopify Magic for other merchants” — a commitment about cross-merchant use, and its Magic documentation does not address shopper data. Both ratings moved to 3 of 5. The error was ours in both cases: we wrote a broader claim than the vendor makes. Neither vendor’s conduct has changed and nothing new is alleged about either.
  • Search-result descriptions — Fathom, Perplexity and Jasper. Three profiles carried a claim in their search-result description that the page itself had already corrected. Fathom’s said its training posture was “structurally better than Otter’s” — retracted on 3 August and swept from the page body on 2 September, but left standing in the description for a month. Perplexity’s said the April 2026 lawsuit was “unresolved”, four months after it was dismissed. Jasper’s asserted a “no-training-across-tiers default” that the profile had, that same morning, declined to assert — because Jasper’s published commitment covers third-party providers rather than Jasper itself. These are the sentences shown under our pages in search results. For anyone who found us that way, they were the claim, whatever the page went on to say. They do not appear on the page, which is why every proof-read missed them. All three corrected 3 September 2026. The other twenty-six vendor descriptions were read the same day and none carried a claim its page had corrected.
  • New Zealand consent law — Granola, Fathom, Zoom AI Companion. We described New Zealand as a jurisdiction requiring the consent of all parties to record a conversation, and on the Granola profile attributed that requirement to the Privacy Act 2020. Both were wrong. New Zealand is a one-party consent jurisdiction: under section 216B(2) of the Crimes Act 1961 a person who is party to a private communication may lawfully record it. The Fathom and Zoom profiles additionally listed the EU under GDPR as an all-party consent regime; the GDPR is a lawful-basis regime, and consent is only one of its six bases. Our advice — disclose before recording — has not changed, but the reason we gave for it was wrong, and a reader who checked would have been entitled to discard the advice along with the reason. The obligations that do apply in New Zealand are information privacy principle 3 of the Privacy Act 2020, which requires you to tell people what you are collecting and why, and the employment duty of good faith.
  • Cruz v. Fireflies.AI Corp. — Otter.ai and Fathom profiles. We presented this case as a live class action and placed it in the Northern District of Illinois. It was filed in the Central District, and it was voluntarily dismissed on 11 March 2026 before any responsive pleading, so nothing was decided. We described a company as currently defending a case that had ended nearly six months earlier.
  • ChatGPT retention figures. Retention detail corrected against two contemporaneous reports, both read that day.
  • GitHub Copilot — an unsourced breach note. The profile carried a one-line note asserting a confirmed May 2026 breach affecting credential stores, with no source, and an instruction to itself to re-verify the scope later. It was vaguer than the facts and vague in a direction unfavourable to GitHub. Removed.

2 September 2026

  • Otter.ai — a court ruled and we did not know. This profile said the motion to dismiss was fully briefed and pending and that no ruling had issued. That was accurate when last checked on 3 August 2026. The order landed ten days later, on 13 August 2026, granting the motion in part and denying it in part, with federal wiretap, California Invasion of Privacy Act and Illinois biometric claims surviving. We went on publishing the old position for three weeks, in four separate places, because our monitoring watched vendors’ privacy pages and not court dockets.
  • Perplexity — a dropped lawsuit published as live, and the rating moved. We described the case as unresolved and at an early procedural stage, named it Doe v. Perplexity, and said the plaintiff was proceeding anonymously. The court had denied pseudonymity, the plaintiff was named, and the case was voluntarily dismissed on 1 May 2026 and terminated on 6 May — sixteen days before this profile’s own last-verified date. The consumer rating moved from 4 to 3 as a result.
  • Zoom AI Companion — the page contradicted itself for three weeks. One line said “standard 30-day retention applies”, contradicting a correction published in the retention section of the same page on 11 August 2026. Both claims sat on the page at once.

August 2026

  • 24 August — Fathom. An earlier correction had been written into one of the two places the claim lived and not the other, so readers of the page never saw it. Completed.
  • 22 August — Microsoft Copilot, and the correction moved the rating. We rated the consumer product 3 of 5 on the basis that training was on by default. Microsoft’s documentation states otherwise.
  • 15 August — Replit. We continued to publish a commitment to delete data within 30 days of an account-deletion request, and a clause about de-identified data, after both had been removed in the policy revision dated 3 August 2026. The vendor changing its terms is a change; our still publishing the old ones afterwards is an error, and it belongs here.
  • 13 August — Grammarly. Corrected on the availability of the training opt-out for Free, Premium and single-user Pro accounts.
  • 5 August — Replit. Source list corrected.
  • 3 August — Fathom. The profile stated that training was contractually excluded across all tiers. That was wrong: it conflated the sub-processor exclusion with Fathom’s own first-party training on meeting content. The error was ours, not a change by the vendor.

Recommendations withdrawn because a vendor was sued, or because its terms changed, are not listed here. Those are changes rather than errors, and they appear on the profile and in the alerts. This page is for the times we got something wrong.