AOL Privacy Policy

This Privacy Policy (“Privacy Policy”) applies to the collection, use, and processing of personal data of users (“user” or “you”) by AOL Media LLC (“we” or “us”) in connection with your use of AOL website, available at https://www.aol.com/ (“Website”), as well as the app, services and platform (“Services”). We provide this Privacy Policy in accordance with the applicable data protection laws, including Regulation (EU) 2016/679 – General Data Protection Regulation (“GDPR” and, collectively, “Applicable Privacy Laws”).

Additional Information for U.S. Consumers

Residents of certain U.S. States may have different privacy rights under their applicable U.S. State Privacy Laws. If you are a U.S. Consumer, in addition to this Privacy Policy, please also refer to the relevant U.S. State Laws page for additional information and a detailed description of your rights and how to exercise them.

  1. Data Controller

    The Data Controller is AOL Media LLC, based in 770 Broadway, New York, NY 10003, United States of America.

  2. Categories of Personal Data that We Collect, Purposes and Legal Bases for Our Processing

    Below is a list of the categories of personal data that we collect and process, along with the purposes and the legal grounds for processing it. Please be aware that not all information listed may be considered as personal data in your jurisdiction under Applicable Privacy Laws.

    Purpose Legal Basis Categories of Processed Data

    a) To enable you to use our Services (“Service Delivery”).

    For example, we may process your data to enable you to perform the following activities:

    • Navigating our Website
    • Using the AOL Mail
    • Subscribe to any of our plans or bundles

    Our contractual relationship provides the legal basis for processing this data for this purpose.

    Username, password, log-in activity and the unique identifiers we create for your account (“Account Data”).

    Information about your approximate location (for example, the country or city you are in) (“Approximate Geolocation Information”). This does not include precise geolocation information.

    Name, email address, phone number, postal address, IDs (“Identity and Contact Data”).

    Information about your interaction with our Services, such as your browsing history and search history, and information about your interaction with our ads (“Online activity information”).

    Comments, photos and videos that you upload to our consumer services and make available to other people (“User-generated Content”).

    Technical data such as your IP address, your login data, browser type and version, hardware information, time zone setting and location, browser plug-in types and versions, operating system and website, and other technology on the devices you use to access the Services or originating from another platform you use to access the Services (“Technical Data”).

    Details about the payments made and the products and services purchased (“Transaction data”). We do not store card details on our servers.

    b) To provide you with some specific, smart features, such as the smart email features (​​e.g., to automatically identify travel-related emails, including those relating to flight and hotel bookings, and allowing one-tap unsubscribing from emails you no longer want to receive) (“Smart Features”).

    Depending on the applicable jurisdiction, your consent or our legitimate interest is the legal basis to process your data to offer you the Smart Features.

    As for the collection of personal data by means of tracking technologies, please see our Cookie Policy.

    Account Data.

    Information about the emails you send and receive, such as the subject line, the content of incoming and outgoing emails and attachments, and metadata about your emails, such as the times they are sent (“Email Information”).

    c) To improve and develop our products and services (“Service Improvement”). For example, we may process your data by conducting statistical analysis or other research activities to optimize our features and provide you with new ones.

    Our legitimate interest to improve our products and services provides the legal basis for processing this data for this purpose.

    As for the collection of personal data by means of tracking technologies, please see our Cookie Policy.

    Account Data.

    Age, gender, marital status and socioeconomic information (for example, your level of education, employment status and income range) (“Demographic Data”)

    Your comments, suggestions, and answers to our surveys (“Feedback”).

    Identity and Contact Data.

    Online activity information.

    Information that describes where you are in a precise way (e.g., the co-ordinates—latitude and longitude—of your device, which are precise enough to locate it at a specific place) (“Precise Geolocation Information”).

    User-generated Content.

    Information about your preferences that you provide us (e.g., selecting your sport team), or that we infer (e.g., assuming you are interested in sport if you visit the related section of our Website) (“User Preference Information”).

    Technical Data.

    Transaction Data.

    d) To provide tailored content to you, including to build a content interest profile (“Tailored Content”).

    Our legitimate interest to provide you with tailored content and to create content interest profiles based on your interests provides the legal basis for processing this data for this purpose.

    As for the collection of personal data by means of tracking technologies, please see our Cookie Policy.

    Account Data.

    Approximate Geolocation Information.

    Information that we may collect from the emails you receive from retailers or other organizations (“Commercial Emails”).

    Demographic Data.

    Identity and Contact Data.

    Online activity information.

    Precise Geolocation Information.

    User-generated Content.

    User Preference Information.

    Technical Data.

    Transaction Data.

    e) To ensure the quality and the proper functioning of the Services, by analyzing, preventing or correcting failures and bugs, and to prevent the illicit use or misuse of the Services (“Troubleshooting”).

    Our legitimate interest to ensure the quality and the smooth functioning of the Services provides the legal basis for processing this data for this purpose.

    Account Data.

    Identity and Contact Data.

    User-generated Content.

    Technical Data.

    f) To enforce our Terms of Service, and enhance the safety and integrity of our Services and users (“Service Integrity”).

    Our legitimate interest to enforce our Terms of Service and maintain the safety and integrity of our Services provides the legal basis for processing this data for this purpose.

    Depending on the applicable jurisdiction, your consent is the legal basis for the recording of our phone calls for security, fraud detection, prevention, quality assurance and training purposes.

    Account Data.

    Recordings of phone calls you have with us, for security, fraud detection, prevention, quality assurance and training purposes (“Call Recordings”).

    Identity and Contact Data.

    User-generated Content.

    Technical Data.

    g) To carry out marketing activities, and send you information and marketing communications about our products and services—such as tips, offers, and newsletters—to conduct user research activities, or to promote our partners’ products, through email or push notifications (“Marketing”).

    Your consent provides the legal basis for processing this data for this purpose.

    In the jurisdiction where your consent is not required, the legal basis is our legitimate interest.

    Approximate Geolocation Information.

    Demographic Data.

    Identity and Contact Data.

    User-generated Content.

    User Preference Information.

    Technical Data.

    h) To comply with our legal obligations, including requests from public authorities, and to prove that we have complied with them, such as in the event of a request from a public authority (“Compliance”).

    When this activity is required by a specific legal obligation, your personal data may be used to the extent required to comply with the legal obligation itself.

    When the applicable law leaves some discretion in assessing the appropriate way to comply with it, your personal data is used based on our legitimate interest to prove our compliance.

    Any information necessary to comply with legal obligations and requests from public authorities.

    i) To send you administrative or technical updates and to process and respond to customer support communications and any other requests or communications from you (“Customer Support”).

    Our contractual relationship provides the legal basis for processing this data for this purpose.

    Account Data.

    Call Recordings.

    Identity and Contact Data.

    User-generated Content.

    Technical Data.

    j) To establish, exercise or defend our rights and those of our employees, and to carry out corporate transactions or operations (“Defense”). For example, we may process your data in case of bankruptcy, merger, acquisition, reorganization, sale of assets or assignments, and due diligence related to any such transactions.

    Our legitimate interest or necessity to establish, exercise, or defend our rights and to carry out corporate transactions or operations provide the legal basis for processing this data for this purpose.

    Any information necessary to ensure the performance of these purposes.

    k) To show you personalized advertising, including by installing third party tracking technologies, and to measure the effectiveness of these ads (“Targeted Advertising”).

    Depending on your country of residence, your consent or our legitimate interest provides the legal basis for processing this data for this purpose.

    If you deny or withdraw your consent, we will still show you ads, which will not be tailored on these categories of information. In this case, our legitimate interest will be the legal basis for this processing activity.

    As for the collection of personal data by means of tracking technologies, please see our Cookie Policy.

    Account Data.

    Approximate Geolocation Information.

    Commercial Emails.

    Demographic Data.

    Identity and Contact Data.

    Online activity information.

    Precise Geolocation Information.

    User Preference Information.

    Technical Data.

    Transaction Data.

  3. Data Storage and Protection

    Personal data may be processed by both automated and non-automated means and may be stored at our premises and on our service providers’ servers. We adopt appropriate technical and organizational measures designed to prevent the loss, improper use and alteration of your personal data. In some cases, we may also adopt data encryption and pseudonymization measures. However, transmissions over the Internet are never 100% secure.

    Personal data processed for Service Delivery will be kept for no more than three (3) years from your last interaction with our Services, or from the expiration of your subscription. If you use the Services after your subscription has expired, the retention period starts from this most recent interaction. Upon the expiration of the mentioned retention period, unless specific legal obligations require that the data is retained for longer, your account is deleted, and your data is either deleted or anonymized.

    Personal data processed for the purposes of Smart Features, Service Improvement, Service Integrity, Tailored Content, and Marketing will be kept for no more than three (3) years from your last interaction with our Services, or from the expiration of your subscription. If you use the Services after your subscription has expired, the retention period starts from this most recent interaction.

    Personal data processed for the purposes of Troubleshooting will be kept for no more than one (1) year from your last interaction with our Services, or from the expiration of your subscription. If you use the Services after your subscription has expired, the retention period starts from this most recent interaction.

    Personal data processed for Customer Support purposes will be kept for no more than five (5) years from the closure of the request.

    Personal data processed for Compliance purposes will be kept for no more than five (5) years from your last interaction with our Services, or from the expiration of your subscription. If you use the Services after your subscription has expired, the retention period starts from this most recent interaction.

    Personal data processed for Defense purposes will be kept for no more than ten (10) years from your last interaction with our Services, or from the expiration of your subscription. If you use the Services after your subscription has expired, the retention period starts from this most recent interaction.

    Regarding personal data processed for Targeted Advertising purposes, you can find more information visiting our Cookie Policy.

    Upon the expiration of the mentioned retention periods, unless specific legal obligations require that the data is retained for longer, the data is either deleted or anonymized.

  4. Your Choices With Regard to the Use of Your Personal Data

    To access the Services, it is mandatory for you to provide your personal data for the purposes of Service Delivery, Customer Support, Compliance, and Defense. If you choose not to provide your personal data, you will not be able to enjoy our Services.

    Where we rely on your consent to process your personal data, providing your personal data is optional, and you have the right to withdraw your consent at any time. If you choose not to provide your personal data, you will still be able to enjoy our Services.

    Where we rely on our legitimate interest as the legal grounds to process your personal data you may, at any time, exercise your right to object to such processing as explained in Section 7 (Your Rights) below.

  5. Recipients of Your Personal Data

    We may disclose your personal data to the following categories of recipients:

    • Vendors carrying out activities related or instrumental to our business and operations, either as outsourced data processors appointed in writing in accordance with Applicable Privacy Laws (such as IT or storage service providers) or as autonomous data controllers (such as advertising networks and platforms)
    • If we carry out a corporate transaction or operation (for example, in case of merger, acquisition, reorganization, sale of assets or assignments, and due diligence related to any such transactions), personal data may be transferred to another owner, and disclosed to our advisers and any prospective purchaser's advisers, as part of such transaction or operation
    • Public, judicial and/or police authorities, within the limits established by applicable laws
    • Other parties as necessary, in the event we believe that your actions are inconsistent with our user agreements or policies, if we believe that you have violated the law, or if we believe it is necessary to protect our rights, property, and safety or that of our users, the public, or others
    • Professional advisors where necessary to obtain advice or otherwise protect and manage our business interests
    • Our corporate affiliates under common control and ownership

    We may transfer your data to Yahoo Inc. as an independent data controller. Yahoo Inc. will process your data for its own autonomous purposes, as described in their privacy policy. This transfer always happens in respect of the data protection rules applicable in the relevant jurisdictions, and does not affect EEA users.

    If you give your consent to install tracking technologies, you will allow third parties to collect personal data about you in order to show you customized and personalized advertising. If you want more information, please see our Cookie Policy.

    Personal data will not be disclosed for any reason other than those stated above, unless such disclosure is deemed necessary for the fulfillment of a legal obligation or if we request your consent.

  6. International Transfers

    Personal data we collect from and about you through the Services may be transferred to countries other than the one in which you reside, such as when we select a provider outside your country of residence. We will make such transfer of personal data pursuant to Applicable Privacy Laws.

    With respect to transfer of personal data from the EEA/UK, we ensure an appropriate degree of protection to EEA/UK’s users as those afforded in those areas, implementing at least one of the following safeguards:

    • Transferring personal data to third parties residing in countries that have been deemed to provide an adequate level of protection for personal data by the European Commission or UK Information Commissioner’s Office
    • Requiring third parties to sign a Data Processing Agreement which incorporates the appropriate Standard Contractual Clauses, or another legally applicable data transfer mechanism, which requires them to provide protection to EEA/UK data to the standard expected within the EEA/UK

    Please contact us to receive more information on the appropriate safeguards.

  7. Your Rights

    Depending on where you are located, you may have certain rights under Applicable Privacy Laws in relation to your personal data. At any time and free of charge, you may exercise those rights, as specified and subject to certain limitations and exceptions under Applicable Privacy Laws. These may include the following:

    • Right of access. You have the right to obtain information about the processing of your personal data and to access it.
    • Right to rectification. You have the right to ask for the update, rectification or integration of your personal data.
    • Right to erasure. You have the right to request the deletion of your personal data.
    • Right to restriction of processing. You have the right to request the restriction of the processing of your personal data.
    • Right to data portability. You have the right to obtain a portable electronic copy of your personal data.
    • Right to object. Where we rely on our legitimate interest to process your personal data, you have the right to object to such processing, wholly or partly, on grounds related to your particular situation. In particular, you are entitled to object to the processing of your personal data for direct marketing purposes, including profiling.
    • Right to withdraw your consent. Where we rely on your consent to process your personal data, you have the right to withdraw your consent, although the processing carried out before your withdrawal of consent will remain valid.

    You also have the right to lodge a complaint before the competent national Data Protection Authority, or other applicable regulator in the jurisdiction where you reside.

    To contact us and exercise your rights, please visit your privacy dashboard, which you can access here.

    We may take reasonable steps to verify your identity prior to responding to your request, such as by asking you for information that matches information we have on file about you. If you are submitting a rights request as an authorized agent, we may ask you to provide proof of your authorization to make the request, or we may contact the individual who is the subject of the request for confirmation, in accordance with Applicable Privacy Laws.

    If you are a U.S. Consumer, please also refer to the relevant U.S. State Laws page for a detailed description of your rights and how to exercise them.

    If you used products and services offered under the AOL brand by Yahoo prior to January 1st, 2026, Yahoo Inc. remained an independent data controller for your personal data in accordance with Applicable Privacy Laws. If you wish to receive additional information on the processing of personal data by Yahoo, or exercise your rights in relation to the personal data retained by Yahoo, please refer to Yahoo’s privacy policy or contact Yahoo directly via this form (or this form for European users).

  8. Links to Third Party Websites

    We may provide links to websites and other third-party content (e.g., social media platforms) that are not owned or operated by us. The websites and third-party content to which we link may have separate privacy notices or policies. If you provide any personal data to or through one of these third-party sites, your interaction and your personal data will be collected by and controlled by the privacy policy of that third party site. We recommend that you familiarize yourself with the privacy policies and practices of any such third parties, which are not governed by this Privacy Policy. We are not responsible for the privacy practices of these websites.

  9. Changes to this Privacy Policy

    We may modify, integrate or update, in whole or in part, this Privacy Policy, and we will notify users of any modification, integration or update in accordance with Applicable Privacy Laws. If we make modifications, we will notify you by revising the date at the bottom of this Privacy Policy and, under certain circumstances, we may also notify you by additional means such as pop-up or push notifications within our Website or email.

Last updated: November 24, 2025