Substack's updated privacy policy removes language describing a one-month response timeline for certain privacy rights requests and eliminates explicit disclosure about sharing account identifiers with child safety consortia. The policy now states recipients of direct messages may keep those messages even if deleted or the account is removed, without the prior qualifying language that noted this despite platform functionality. The updated terms no longer specify response deadlines or detail the child safety data sharing practice.
Consumers: Substack no longer commits to a specific timeframe for responding when you ask to access, correct, or delete your data.
Consumers: The policy no longer explicitly describes the practice of sharing identifiers with child safety organizations.
The updated policy no longer commits to responding to privacy rights requests within one month or within three months for complex requests. This removes a procedural timeline that previously bound Substack's response obligations. Additionally, the explicit disclosure that Substack shares account identifiers with child safety consortia to detect online child sexual exploitation has been removed from the policy, though the practice itself is not stated to have ended. The direct message retention language is now framed more directly: recipients may retain messages even if you request deletion or close your account.
→ Request clarification from Substack support on response timelines for privacy requests (access, correction, deletion, objection)
Removed commitment to respond within one month, or three months for complex requests with notification of delay
Removed explicit description of sharing account identifiers with child safety consortia for OCSEA detection
Clarified that recipients may retain messages even if sender requests deletion or closes account
This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology
This change removes compliance commitments that appeared to operationalize GDPR and UK DPA response obligations (Articles 12(3), 12(4); Data Protection Act 2018 Section 45) and eliminates explicit disclosure of a data processing practice tied to …
Regulatory exposure, obligation change, escalation trigger, board-ready language, and recommended action for legal and compliance teams.
Unlock the full institutional analysis — InsightConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-001927.
Substack's privacy policy included a navigation menu item referencing 'For media founders' in its updated version published June 28, 2026. …
Substack updated its navigation menu on June 28, 2026 by adding 'For media founders' to its list of creator categories. …
Substack updated its privacy policy footer on June 16, 2026 to add a reference to 'Brand Partnerships' in the navigation …
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Get alerted when this policy changes again, including what changed and why it matters.