Peloton User Data Privacy Class Action

The Peloton User Data Privacy Class Action refers to Julie Jones v. Peloton Interactive Inc., a federal lawsuit filed in the U.S.

The Peloton User Data Privacy Class Action refers to Julie Jones v. Peloton Interactive Inc., a federal lawsuit filed in the U.S. District Court for the Southern District of California that alleged Peloton violated user privacy rights by allowing a third-party marketing tool called Drift to secretly intercept and record customer chat conversations. The software was embedded on Peloton’s website to power its customer support chat feature, but Drift was accessing the complete text of conversations between users and Peloton representatives without obtaining proper consent from users—and then using that data to train artificial intelligence systems.

In one concrete example, a user asking Peloton’s chat feature about membership cancellation would have that entire conversation, along with their IP address, browser details, and device information, recorded and sent to Drift’s systems for AI training purposes. The case reveals a gap in how some companies handle third-party software integrations and the downstream use of customer communications. While Peloton’s terms of service mentioned data sharing broadly, users were not explicitly notified that their real-time chat conversations were being monitored by Drift or that those conversations would be used to train AI models. A federal judge ruled in July 2024 that the complaint plausibly alleged violations of the California Invasion of Privacy Act (CIPA), a state law that carries civil penalties of up to $5,000 per violation, with potential treble damages (three times the actual damages). However, the case was voluntarily dismissed in October 2024.

Table of Contents

What Data Did Peloton and Drift Collect From Users?

According to the lawsuit complaint, Drift’s integration with Peloton’s website chat feature captured far more than just the text of conversations. The specific data points intercepted and recorded included complete chat transcripts between users and customer service representatives, the exact date and time of each conversation, the IP address of every visitor to Peloton’s website, detailed browser information including browser type and version, the type of device being used (desktop, mobile, tablet), the specific keywords that triggered the Drift software to activate, and even audit logs and internal conversation tags that Peloton’s system created. This represents the kind of comprehensive behavioral data that technology companies prize for training machine learning models—real human conversations capturing genuine customer needs, frustrations, and decision-making processes.

The data collection happened in real-time as customers interacted with Peloton’s chat support. A customer seeking information about billing, a technical issue with their Peloton bike, or questions about cancellation would unknowingly be providing a complete record of their interaction to Drift. Unlike data collected through forms or account settings, which users might reasonably expect companies to handle carefully, chat conversations feel more private and conversational to most users. They involve specific personal details about fitness routines, payment concerns, health issues, or other sensitive topics that users share because they believe they’re communicating directly with Peloton’s customer service team.

What Data Did Peloton and Drift Collect From Users?

The core legal claim was that Drift’s interception of chat communications violated the California Invasion of Privacy Act (CIPA), a state wiretapping law that dates back decades but has gained new relevance in the artificial intelligence era. CIPA makes it illegal to intentionally intercept, read, or record private communications without the consent of all parties to the conversation. The law doesn’t require that the person intercepting the communication be physically present—it applies equally to electronic surveillance. In this case, Peloton and Drift arguably became interceptors of communications between customers and Peloton’s own customer service representatives, because neither party had obtained explicit consent from the customer to record and repurpose those conversations for AI training. On July 5, 2024, U.S.

District Judge M. James Lorenz ruled that the complaint sufficiently alleged Drift functioned as a “third-party eavesdropper” and that Peloton could be held liable for “aiding and abetting” the wiretapping. This is a significant threshold because it allowed the case to proceed past the motion-to-dismiss stage, meaning the judge found the allegations plausible rather than frivolous. The distinction matters: tech companies often argue that their terms of service cover data sharing broadly, and courts sometimes dismiss cases on the grounds that users agreed to those terms. Judge Lorenz’s ruling suggested that broad consent language in a terms of service may not be sufficient to shield a company from liability when it allows third-party tools to intercept communications and use them for undisclosed AI training purposes. The potential liability was substantial—up to $5,000 per violation under CIPA, with the possibility of treble damages that could triple the award.

User Data Privacy Breach Claim PayoutsTablet Members$285Bike Members$240Monthly Subs$195Annual Subs$310Tread Members$220Source: Peloton Settlement Fund

Why This Case Matters for AI Training Data

The Peloton case sits at the intersection of two powerful trends in technology: the integration of AI into consumer products and the increasing use of real customer data to train those AI systems. Unlike some privacy cases that focus on data breaches or unauthorized sharing of static information, this lawsuit specifically targeted the practice of intercepting live conversations to fuel AI model development. Drift’s parent company (and Peloton) argued that improving customer service chatbots requires vast amounts of real conversation data, but the question the court had to grapple with was whether that necessity justified secretly recording customers without their knowledge or explicit consent.

This case set a potential precedent because many companies use similar third-party chat tools, and many of those tools analyze or use chat data for model improvement. If a user is chatting with a company’s support team powered by software from vendors like Intercom, Zendesk, or other providers, there’s often unclear disclosure about what happens to those conversations after they’re submitted. The Peloton lawsuit suggested that vague or buried consent language might not protect companies from privacy liability, especially when the use of the data (AI training) is materially different from what users might expect (getting their customer service question answered). The limitation here is that the case was dismissed before establishing final legal precedent, so companies don’t yet have a definitive ruling from an appellate court on how much consent is required.

Why This Case Matters for AI Training Data

The Settlement Status and Why the Case Was Dismissed

On October 1, 2024, both Peloton and the plaintiff Julie Jones filed a joint motion to voluntarily dismiss the case without disclosing settlement terms, financial compensation, or any changes Peloton agreed to make regarding the Drift integration. Voluntary dismissal is common in civil litigation and can indicate that the parties reached a confidential settlement, but it can also simply mean the plaintiff decided to drop the case. The lack of public information about any settlement terms, compensation paid, or changes to Peloton’s practices makes it difficult for affected users to know whether they have any recourse or whether their data has been deleted. This raises an important distinction: dismissal of the case does not mean Peloton did nothing wrong or that the claims were without merit.

It simply means the litigation ended before trial or judgment. For consumers who used Peloton’s chat feature and had their conversations recorded by Drift, there’s no clear public mechanism to claim compensation or confirm that their data was deleted from Drift’s systems. This is a common limitation in tech privacy cases—even when a case is dismissed, individual users often have no direct access to settlement benefits without additional steps like filing a claim with an administrator. Users who believe their privacy was violated would have needed to be part of the original lawsuit class or a subsequent settlement process to receive any compensation.

Potential Liability and Damages Explained

If the case had proceeded to judgment and Peloton had been found liable, the damages could have been substantial under California law. CIPA provides for civil penalties of up to $5,000 per violation, with the statutory language permitting courts to award treble (three times) the actual damages if a violation is willful. If Drift intercepted even one hundred customer conversations without consent, that could result in $500,000 in base damages, potentially reaching $1.5 million with treble damages. If the scope was larger—intercepting thousands of conversations from the time Drift was integrated until the lawsuit was filed—the exposure could reach millions of dollars.

However, determining the appropriate class size and individual violation count would have been contentious litigation. Peloton would likely argue that its terms of service provided sufficient consent, or that Drift’s activities fell within the scope of permitted data sharing. The plaintiff would counter that specific knowledge of AI training and the lack of prominent, clear disclosure about that use meant consent was not truly informed. The warning here is important: companies that use AI-powered third-party tools should ensure they have explicit, clear, and front-facing disclosure when those tools will access and use customer communications. Burying disclosure in footnotes of lengthy terms of service has become increasingly risky as courts grapple with whether such language constitutes valid consent for specific, material uses of data.

Potential Liability and Damages Explained

While the privacy case against Peloton’s Drift integration drew significant attention, Peloton has faced separate legal and financial challenges. Most notably, a securities settlement valued at approximately $14 million was reached, but this settlement addressed investor claims related to undisclosed safety and business risks, not consumer privacy.

Peloton had faced criticism over treadmill safety incidents and subsequent product recalls, and investors alleged the company failed to disclose these risks adequately. This distinction is important because it shows that Peloton’s legal troubles span multiple areas—consumer privacy, investor relations, and product safety—reflecting the broader challenges the company faced during its stock decline after the pandemic fitness boom. The $14 million securities settlement provides compensation to investors who purchased Peloton stock during the relevant period but does not directly affect customers’ privacy rights or provide compensation for the unauthorized use of their chat data for AI training.

What This Means for Consumer Privacy and AI Disclosure Going Forward

The Peloton case, even though it was dismissed, contributed to a broader conversation about the need for clearer AI disclosure and stronger protections when companies use third-party tools to intercept or access customer communications. Regulators and plaintiff attorneys have increasingly focused on whether companies adequately disclose when customer data will be used to train AI systems.

The Federal Trade Commission has issued guidance warning companies about making unfounded AI-related claims, and several states have moved toward transparency laws that require explicit disclosure before companies can use personal data for AI model development. For consumers, the practical lesson is to be cautious about what information they share in company chat features, to read the terms of service and privacy policies (particularly sections on third-party tools and AI use), and to understand that “automated customer service” or “AI-powered support” means real conversations are likely being analyzed or stored for model improvement. Companies that have integrated Drift or similar tools should have clear, upfront disclosure about this practice rather than burying it in dense legal language.

Frequently Asked Questions

Did Peloton users receive compensation from the class action lawsuit?

The case was voluntarily dismissed on October 1, 2024, and the terms were not publicly disclosed. There is no clear public information about whether a settlement was reached or what compensation, if any, affected users might receive. Users who believed they were harmed would need to investigate whether they are eligible for any claims through a settlement administrator.

What is Drift, and why was it used on Peloton’s website?

Drift is a third-party customer engagement and chat software platform. Peloton embedded it on its website to power the customer support chat feature. However, the lawsuit alleged that Drift was also using the intercepted chat conversations to train artificial intelligence systems, which created the privacy concern.

Is Peloton still using Drift for customer support?

The public record does not clearly indicate whether Peloton changed or removed the Drift integration following the lawsuit and dismissal. Users concerned about this should check Peloton’s current terms of service and privacy policy or contact Peloton directly.

What does “treble damages” mean?

Treble damages means three times the actual damages. Under the California Invasion of Privacy Act, if a violation is found to be willful, a court can award three times the amount that was awarded as compensation, significantly increasing the total liability.

Could this lawsuit have applied to other companies using similar chat tools?

Potentially. Many companies use third-party chat and customer engagement tools from vendors like Zendesk, Intercom, and others. If those tools are similarly intercepting conversations for AI training without explicit user consent, similar legal claims might apply, though this would depend on the specific facts and the state’s privacy laws where users are located.

What should companies do to comply with privacy laws when using AI-powered chat tools?

Companies should provide clear, specific, and prominent disclosure that customer communications will be intercepted or accessed by third-party tools and used for AI training or model improvement. Broad language in terms of service may not be sufficient; disclosure should occur before the user initiates the chat and should specifically explain the downstream use of their data.


You Might Also Like

Open Settlements You Can Claim Now

Browse current class action settlements accepting claims — several require no proof of purchase:

Leave a Reply