Gravy Analytics, Inc.; Analysis of Proposed Consent Order to Aid Public Comment
The consent agreement in this matter settles alleged violations of Federal law prohibiting unfair or deceptive acts or practices. The attached Analysis of Proposed Consent Order to Aid Public Comment describes both the allegations in the complaint and the terms of the consent order--embodied in the consent agreement--that would settle these allegations.
What this rule actually says
The FTC sued Gravy Analytics for deceiving customers about how their data would be used and protected. Specifically, the company allegedly promised data wouldn't be shared or sold, then did exactly that—and failed to secure customer information properly. The settlement requires Gravy (and similar companies) to stop making false claims about data practices and to actually implement the security measures they promise.
Who it applies to
- If you collect user data (names, emails, health info, hiring records, etc.) and make any promises about how you'll use or protect it—this applies to you.
- If you're in the US—the FTC has jurisdiction over US-based companies and any company serving US customers.
- AI use cases that trigger this: medical scribes (HIPAA-adjacent data), hiring assistants (employment records), support chatbots (customer PII), or any tool storing personal information.
- What's in scope: Any data you collect directly from users or on their behalf, plus data you buy from third parties and re-use.
- What's out of scope: Purely anonymized, aggregated statistics (though the FTC's bar for "truly anonymous" is high).
What founders need to do
- Audit your privacy claims (2-3 days): Review your website, terms of service, and product copy. Write down every promise you make about data—what you collect, who sees it, how long you keep it. Flag anything vague or overstated.
- Match claims to reality (3-5 days): Document what you *actually* do with data. If your website says "data is never shared" but you use a third-party vendor, that's a problem. Update either the claims or the practices.
- Implement basic security (1-2 weeks, ongoing): Encryption at rest and in transit, access controls, regular backups. Document it. You don't need Fort Knox, but you need *something* and you need to prove it works.
- Create a data retention policy (1 day): Decide how long you keep user data, then stick to it. Delete old data.
- Get it in writing (1 day): Update your privacy policy and terms of service to match reality. Have a lawyer review (budget $1-2K).
Bottom line
If you're collecting any user data and making promises about it—act now. This isn't theoretical; the FTC is actively enforcing it.