Skip to main content
Substack logo

Substack

Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 26 Feb 2026

C-
AITS IA

AI Trust Summary

AI Training
Possibly (generic mention of service improvement)
Data Retention
Not specified in documentation
Opt-out
Only generic controls (cookies, ads)
AIPrivacy
C-
BasePrivacy
A+
  • In AI: it does not document retention periods for AI interaction data, which can create uncertainties about information management.
  • In Core Privacy: it omits additional safeguards for sensitive data, increasing risks of inappropriate processing.

Safer Alternatives

Higher-rated software in the same category

See Full Alternative Comparison

Attention Points in AI (2)

AI criteria that require attention. Buy the Premium Analysis to see all 2 criteria.

  • Substack
  • does not specify retention periods for AI inputs/outputs, which creates uncertainties about data management.
  • does not document additional safeguards for sensitive data, increasing risks of inappropriate processing.
  • it is advisable to require contractual clauses that address these points.

AI data retention (prompts and responses) is not disclosed

The policy does not specify retention periods for AI interaction data, which can create uncertainties about the management of emails and interactions.

Ethical AI principles and anti-bias measures not documented

The policy does not address ethical AI principles or anti-bias measures, which can raise concerns about fairness in the processing of emails and interactions.

Source: vendor public documents

Compliances in AI (3)

AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.

  • Substack
  • clearly identifies the company as a data controller, ensuring accountability in information management.
  • lists data processing purposes by category, promoting transparency.
  • these practices strengthen due diligence when contracting email marketing services.

Contestation and human review of AI decisions available

The policy ensures that no final content moderation decision is made without human review, ensuring oversight of interactions.

Use of artificial intelligence clearly disclosed in policies

The policy declares the use of automated systems, important for transparency about how emails and interactions are managed.

AI features clearly identified with their purposes

The policy describes functionalities that use automation and their purposes, essential for understanding the use of emails and interactions.

Source: vendor public documents

Highlights in Privacy (3)

Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.

Sensitive data processing without additional documented safeguards

The policy mentions that providing certain data is optional, but does not present additional safeguards for sensitive data.

Data controller and processor roles clearly defined

Substack is clearly identified as a data controller, which is crucial for accountability in managing emails and reader interactions.

Data controller identity and contact clearly disclosed

The policy provides clear information about Substack and a contact channel for privacy questions, facilitating communication.

Source: vendor public documents

Critical Alerts

  • Tratamento de dados sensíveis sem salvaguardas adicionais documentadas: Crucial para proteger dados sensíveis dos usuários..
  • Princípios de IA ética e medidas anti-viés não documentados: Importante para garantir que sistemas automatizados não causem discriminação.

Conformance analysis (20)

Premium Feature
AITS Criterion 8
Compliant

Human review and contestation of AI decisions available

Reference: ISO/IEC 42001 (8.3)

AITS Criterion 9
Compliant

Clearly defined data controller and processor roles

Reference: ISO/IEC 27701 (7.3)

AITS Criterion 10
Compliant

Identity and contact of the data controller clearly informed

Reference: ISO/IEC 27701 (7.3)

Source: vendor public documents

Follow this company and access all 20 criteria

Track score changes, get alerts on policy updates, and view the full conformance analysis

Sign up free

Don't miss any update

Sign up to follow this company and track changes in privacy and AI scores

Sign up free

Why trust the AITS Index: Open Community Audit

Public transparency, peer review and open evidence trails — all verifiable by the community

Trust guarantees

Peer review

users, professionals and experts confirm or contest items online.

Public history

vendor and index changes are versioned and accessible.

Participate

Evidence, confirmations and contestations

participate in the collaborative validation of AITS criteria

Contact us

Substack Email Marketing: Privacy Strengths and Weaknesses You Should Know

Clear Data Controller Roles

Substack excels in defining clear roles for data controllers and processors. This transparency is crucial for users who want to understand who is responsible for their data. With an AITS Privacy Score of 92%, Substack ensures that users are informed about how their data is managed. This clarity helps users feel more secure, as they know who to contact regarding their data rights under regulations like GDPR and LGPD. By clearly delineating these roles, Substack minimizes the risk of data mishandling, which is a significant strength for any email marketing platform.

Transparent Data Processing Purposes

Another strength of Substack is its clear listing of data processing purposes categorized by data type. This means that users can easily see how their data will be used, which is essential for compliance with privacy laws. Knowing that Substack has a well-defined purpose for each category of data can help users feel more confident about their data being used appropriately. This transparency is a strong point, especially for those concerned about their privacy rights and how their information may be utilized in marketing campaigns.

Undefined AI Data Retention Periods

Despite its strengths, Substack has notable weaknesses, particularly concerning its handling of AI data. One significant issue is the lack of defined retention periods for prompts and responses generated by AI. This absence of clarity can create uncertainty for users regarding how long their data is stored and potentially used. Without a defined retention policy, users may find it challenging to exercise their rights under GDPR or LGPD, as they cannot be sure when their data will be deleted or if it will be retained indefinitely. Users should be cautious and consider limiting their use of AI features until more transparency is provided.

Lack of Safeguards for Sensitive Data

Another critical weakness is Substack's omission of additional safeguards for sensitive data processing. While the platform has a high privacy score, the absence of documented protections for sensitive information raises concerns. Users should be aware that without these safeguards, their sensitive data could be at risk of misuse. To mitigate this risk, users should avoid sharing highly sensitive information through the platform and regularly review their data settings to ensure they are only sharing necessary information.

Ethical AI Principles Not Documented

Substack also falls short in documenting its ethical AI principles and anti-bias measures. This lack of documentation can be problematic, especially for users who prioritize ethical considerations in their marketing strategies. Users should be aware that without clear guidelines, there may be risks associated with bias in AI-generated content. To navigate this, users can opt to manually review AI-generated suggestions and ensure they align with their ethical standards before using them in their communications.

Practical Guidance for Users

To enhance their experience with Substack while addressing potential risks, users should take proactive steps. First, review the platform's privacy settings to ensure that you are comfortable with the data being collected and how it is used. Consider disabling AI features if you are concerned about data retention. Additionally, familiarize yourself with your rights under GDPR and LGPD, and don’t hesitate to reach out to Substack for clarification on any privacy concerns. Lastly, explore alternative email marketing platforms that may offer more robust safeguards for sensitive data if these weaknesses are significant for your needs.

Other Email Marketing software

Dive into in-depth research and analysis of each player

Source: vendor public documents

Analyzed Sources

Public documents used in the audit of Substack:

Evidence, confirmations and contestations

participate in the collaborative validation of AITS criteria

Contact us

Scope & Limitations

TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).

The content is indicative in nature, intended for screening and comparison, not replacing internal audits.

TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.

Source: vendor public documents