
Litmus
Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 26 Feb 2026
AI Trust Summary
- •In AI: it does not document ethical AI principles, which may raise concerns about bias and discrimination.
- •In Core Privacy: it does not specify retention periods for interaction data, leading to uncertainties about user information management.
Safer Alternatives
Higher-rated software in the same category
Attention Points in AI (3)
AI criteria that require attention. Buy the Premium Analysis to see all 3 criteria.
- •Litmus
- •Does not specify retention periods for interaction data, which may lead to uncertainties.
- •Does not mention ethical AI principles, exposing risks of bias.
- •It is advisable to require contractual clauses that address data retention and ethical AI use.
AI data retention (prompts and responses) is not disclosed
The policy does not specify retention periods for email interaction and user behavior data, which may lead to uncertainties.
Ethical AI principles and anti-bias measures not documented
Litmus does not mention commitments to the ethical use of AI, which may raise concerns about bias and discrimination.
AI decision contestation mechanism not available
The policy does not offer a clear mechanism to contest automated decisions, which may impact user trust.
Source: vendor public documents
Compliances in AI (3)
AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.
- •Litmus
- •Clearly defines data controller and processor roles, ensuring transparency.
- •Provides a Data Processing Agreement (DPA) for business customers, ensuring protection under privacy standards.
- •These practices strengthen trust and security in the business relationship.
AI features clearly identified with their purposes
The policy mentions services that use AI, but does not detail how each functionality contributes to the user experience.
AI training opt-out control available
Litmus offers privacy control options, but not a specific opt-out for the use of data in AI training.
Policy on data use for AI training clearly stated
The policy mentions the use of email interaction and user behavior data to improve services, but in a generic way.
Source: vendor public documents
Highlights in Privacy (3)
Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.
Data controller and processor roles clearly defined
The policy clearly identifies Litmus as responsible for email interaction and user behavior data, ensuring transparency.
Personal data recipients clearly identified in the policy
The policy details who receives email interaction and user behavior data, increasing customer trust.
Data Processing Agreement (DPA) available for business customers
Litmus offers a DPA, ensuring that business customers are protected under privacy standards.
Source: vendor public documents
Critical Alerts
- •Princípios de IA ética e medidas anti-viés não documentados: Importante para a responsabilidade e ética no uso de IA em marketing..
- •Mecanismo de contestação de decisões de IA não disponível: Crucial para a transparência e confiança em decisões automatizadas.
Conformance analysis (20)
Clearly defined data controller and processor roles
Reference: ISO/IEC 27701 (7.3)
Recipients of personal data clearly identified in the policy
Reference: ISO/IEC 27701 (7.3)
Data Processing Agreement (DPA) available for business customers
Reference: ISO/IEC 27701 (8.2) + LGPD Art. 39 + GDPR Art. 28
Source: vendor public documents
Follow this company and access all 20 criteria
Track score changes, get alerts on policy updates, and view the full conformance analysis
Don't miss any update
Sign up to follow this company and track changes in privacy and AI scores
Why trust the AITS Index: Open Community Audit
Public transparency, peer review and open evidence trails — all verifiable by the community
Trust guarantees
Peer review
users, professionals and experts confirm or contest items online.
Public history
vendor and index changes are versioned and accessible.
Participate
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Litmus Email Marketing: Privacy and AI Governance Insights
Clear Data Roles Enhance User Trust
Litmus excels in defining the roles of data controller and data processor, which is crucial for transparency in email marketing practices. With an OPTI Base Privacy Score of 83%, users can feel reassured that their data is being handled responsibly. This clarity means that users know who is accountable for their data, which is vital for compliance with regulations like GDPR and LGPD. For businesses, this transparency can enhance customer trust and improve engagement rates, as clients are more likely to interact with brands that respect their privacy.
Identified Data Recipients Strengthen Compliance
Another strength of Litmus is its clear identification of data recipients in its privacy policy. This aspect is essential for users who want to understand how their personal information is shared and used. Knowing who has access to their data allows users to make informed decisions about their engagement with the platform. This practice not only aligns with GDPR requirements but also helps users mitigate risks associated with unauthorized data sharing.
Undefined Data Retention Periods Raise Concerns
Despite its strengths, Litmus has notable weaknesses, particularly regarding the retention of AI prompts and responses. The absence of defined retention periods can lead to uncertainty about how long user data is stored. This lack of clarity may raise concerns for users who prioritize data privacy and compliance with regulations like GDPR. Users should be aware that indefinite data retention could expose them to risks, including potential data breaches or misuse of their information.
Lack of Ethical AI Principles
Another significant weakness is the absence of documented ethical AI principles and anti-bias measures. With an OPTI IA Score of 29%, this indicates that users should approach Litmus's AI features with caution. The lack of transparency in AI governance can lead to biases in email targeting and content generation, which may affect user experience and brand reputation. Users should consider this when utilizing AI-driven features and remain vigilant about the outputs generated by the software.
Practical Steps for Enhanced Privacy Protection
To mitigate the risks associated with undefined data retention and AI governance, users can take proactive steps. First, regularly review the privacy settings within Litmus to ensure that data sharing preferences align with your privacy expectations. Additionally, consider limiting the use of AI features until more robust ethical guidelines are established. Users can also reach out to Litmus support for clarification on data retention policies and express their concerns regarding AI governance, encouraging the company to prioritize these issues.
Exploring Alternatives for Comprehensive Governance
If the weaknesses in Litmus's privacy and AI governance are concerning, users might explore alternative email marketing platforms that offer clearer data retention policies and documented ethical AI practices. Look for platforms that provide detailed information about their compliance with GDPR, LGPD, and ISO 27701 standards. These alternatives may offer better transparency and risk management, ensuring that your email marketing efforts are both effective and compliant with privacy regulations.
Other Email Marketing software
Dive into in-depth research and analysis of each player

Adobe Marketo Engage
Oracle Eloqua

Brevo

Customer.io

Drip

EngageBay

Zoho Marketing Automation

Constant Contact
Source: vendor public documents
Analyzed Sources
Public documents used in the audit of Litmus:
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Scope & Limitations
TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).
The content is indicative in nature, intended for screening and comparison, not replacing internal audits.
TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.
Source: vendor public documents