

Substack
Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 26 Feb 2026
AI Trust Summary
- •In AI: it does not document retention periods for AI interaction data, which can create uncertainties about information management.
- •In Core Privacy: it omits additional safeguards for sensitive data, increasing risks of inappropriate processing.
Safer Alternatives
Higher-rated software in the same category
Attention Points in AI (2)
AI criteria that require attention. Buy the Premium Analysis to see all 2 criteria.
- •Substack
- •does not specify retention periods for AI inputs/outputs, which creates uncertainties about data management.
- •does not document additional safeguards for sensitive data, increasing risks of inappropriate processing.
- •it is advisable to require contractual clauses that address these points.
AI data retention (prompts and responses) is not disclosed
The policy does not specify retention periods for AI interaction data, which can create uncertainties about the management of emails and interactions.
Ethical AI principles and anti-bias measures not documented
The policy does not address ethical AI principles or anti-bias measures, which can raise concerns about fairness in the processing of emails and interactions.
Source: vendor public documents
Compliances in AI (3)
AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.
- •Substack
- •clearly identifies the company as a data controller, ensuring accountability in information management.
- •lists data processing purposes by category, promoting transparency.
- •these practices strengthen due diligence when contracting email marketing services.
Contestation and human review of AI decisions available
The policy ensures that no final content moderation decision is made without human review, ensuring oversight of interactions.
Use of artificial intelligence clearly disclosed in policies
The policy declares the use of automated systems, important for transparency about how emails and interactions are managed.
AI features clearly identified with their purposes
The policy describes functionalities that use automation and their purposes, essential for understanding the use of emails and interactions.
Source: vendor public documents
Highlights in Privacy (3)
Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.
Sensitive data processing without additional documented safeguards
The policy mentions that providing certain data is optional, but does not present additional safeguards for sensitive data.
Data controller and processor roles clearly defined
Substack is clearly identified as a data controller, which is crucial for accountability in managing emails and reader interactions.
Data controller identity and contact clearly disclosed
The policy provides clear information about Substack and a contact channel for privacy questions, facilitating communication.
Source: vendor public documents
Critical Alerts
- •Tratamento de dados sensíveis sem salvaguardas adicionais documentadas: Crucial para proteger dados sensíveis dos usuários..
- •Princípios de IA ética e medidas anti-viés não documentados: Importante para garantir que sistemas automatizados não causem discriminação.
Conformance analysis (20)
Human review and contestation of AI decisions available
Reference: ISO/IEC 42001 (8.3)
Clearly defined data controller and processor roles
Reference: ISO/IEC 27701 (7.3)
Identity and contact of the data controller clearly informed
Reference: ISO/IEC 27701 (7.3)
Source: vendor public documents
Follow this company and access all 20 criteria
Track score changes, get alerts on policy updates, and view the full conformance analysis
Don't miss any update
Sign up to follow this company and track changes in privacy and AI scores
Why trust the AITS Index: Open Community Audit
Public transparency, peer review and open evidence trails — all verifiable by the community
Trust guarantees
Peer review
users, professionals and experts confirm or contest items online.
Public history
vendor and index changes are versioned and accessible.
Participate
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Substack Email Marketing: Privacy Strengths and Weaknesses You Should Know
Clear Data Controller Roles
Substack excels in defining clear roles for data controllers and processors. This transparency is crucial for users who want to understand who is responsible for their data. With an AITS Privacy Score of 92%, Substack ensures that users are informed about how their data is managed. This clarity helps users feel more secure, as they know who to contact regarding their data rights under regulations like GDPR and LGPD. By clearly delineating these roles, Substack minimizes the risk of data mishandling, which is a significant strength for any email marketing platform.
Transparent Data Processing Purposes
Another strength of Substack is its clear listing of data processing purposes categorized by data type. This means that users can easily see how their data will be used, which is essential for compliance with privacy laws. Knowing that Substack has a well-defined purpose for each category of data can help users feel more confident about their data being used appropriately. This transparency is a strong point, especially for those concerned about their privacy rights and how their information may be utilized in marketing campaigns.
Undefined AI Data Retention Periods
Despite its strengths, Substack has notable weaknesses, particularly concerning its handling of AI data. One significant issue is the lack of defined retention periods for prompts and responses generated by AI. This absence of clarity can create uncertainty for users regarding how long their data is stored and potentially used. Without a defined retention policy, users may find it challenging to exercise their rights under GDPR or LGPD, as they cannot be sure when their data will be deleted or if it will be retained indefinitely. Users should be cautious and consider limiting their use of AI features until more transparency is provided.
Lack of Safeguards for Sensitive Data
Another critical weakness is Substack's omission of additional safeguards for sensitive data processing. While the platform has a high privacy score, the absence of documented protections for sensitive information raises concerns. Users should be aware that without these safeguards, their sensitive data could be at risk of misuse. To mitigate this risk, users should avoid sharing highly sensitive information through the platform and regularly review their data settings to ensure they are only sharing necessary information.
Ethical AI Principles Not Documented
Substack also falls short in documenting its ethical AI principles and anti-bias measures. This lack of documentation can be problematic, especially for users who prioritize ethical considerations in their marketing strategies. Users should be aware that without clear guidelines, there may be risks associated with bias in AI-generated content. To navigate this, users can opt to manually review AI-generated suggestions and ensure they align with their ethical standards before using them in their communications.
Practical Guidance for Users
To enhance their experience with Substack while addressing potential risks, users should take proactive steps. First, review the platform's privacy settings to ensure that you are comfortable with the data being collected and how it is used. Consider disabling AI features if you are concerned about data retention. Additionally, familiarize yourself with your rights under GDPR and LGPD, and don’t hesitate to reach out to Substack for clarification on any privacy concerns. Lastly, explore alternative email marketing platforms that may offer more robust safeguards for sensitive data if these weaknesses are significant for your needs.
Other Email Marketing software
Dive into in-depth research and analysis of each player

Adobe Marketo Engage
Oracle Eloqua

Brevo

Customer.io

Drip

EngageBay

Zoho Marketing Automation

Constant Contact
Source: vendor public documents
Analyzed Sources
Public documents used in the audit of Substack:
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Scope & Limitations
TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).
The content is indicative in nature, intended for screening and comparison, not replacing internal audits.
TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.
Source: vendor public documents