CA-C-001927
Substack — Substack Privacy Policy
Entity
Date detected
April 19, 2026
Effective date
April 19, 2026
Severity
Direction
Negative
Affected users
all users EU users UK users California residents
Taxonomy
Transparency removal
Changes
−9 sentences removed · 5 sentences modified
Share 𝕏 Share in Share 🔒 PDF
Watch Substack Get alerts when this policy changes.
Watch — Free

Event Summary

Substack's updated privacy policy removes language describing a one-month response timeline for certain privacy rights requests and eliminates explicit disclosure about sharing account identifiers with child safety consortia. The policy now states recipients of direct messages may keep those messages even if deleted or the account is removed, without the prior qualifying language that noted this despite platform functionality. The updated terms no longer specify response deadlines or detail the child safety data sharing practice.

MEDIUM

Consumer Impact

The updated policy no longer commits to responding to privacy rights requests within one month or within three months for complex requests. This removes a procedural timeline that previously bound Substack's response obligations. Additionally, the explicit disclosure that Substack shares account identifiers with child safety consortia to detect online child sexual exploitation has been removed from the policy, though the practice itself is not stated to have ended. The direct message retention language is now framed more directly: recipients may retain messages even if you request deletion or close your account.

Governance Analysis

The removal of response timelines for privacy rights requests eliminates a compliance commitment that operationalized GDPR and UK DPA obligations, creating ambiguity about what timeline now applies when users exercise data subject rights. The removal of explicit child safety consortium disclosure eliminates transparency about a data processing practice, which may affect users' ability to understand what data is shared and for what purpose, and may create compliance questions under transparency-focused regulations like GDPR Article 14.

Available Actions

Request clarification from Substack support on response timelines for privacy requests (access, correction, deletion, objection)

If No Action Is Taken

Substack is no longer bound by its stated one-month response commitment, and response timelines will be determined by applicable law or Substack's discretion

Users will no longer have explicit disclosure within Substack's privacy policy describing whether or how account identifiers are shared with child safety organizations

Key Clauses Affected

privacy request response timeline

Removed commitment to respond within one month, or three months for complex requests with notification of delay

child safety data sharing disclosure

Removed explicit description of sharing account identifiers with child safety consortia for OCSEA detection

direct message retention

Clarified that recipients may retain messages even if sender requests deletion or closes account

Full clause-by-clause analysis available with Professional.
These clauses may change again. Get alerted when they do. Watch Substack — Free

This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology

Evidence Verification

✓ Verified
Previous Version
f4eeb3c4853c2e7b5cc7afd42afc628de37a9db9e433c4efa1c5b78e35271628
May 6, 2026 05:48 UTC
✓ Verified
Current Version
30dacb2f5c2daea0eee194830d934496ec1685219992cb84fb4d4dad988dba70
April 19, 2026 06:13 UTC
✓ Verified
Change Detected
April 19, 2026 06:13 UTC
Analysis Methodology
✓ Verified
Source Document
https://substack.com/privacy
Citation Record
Entity: Substack
Document: Substack Privacy Policy
Record ID: CA-C-001927
Captured: 2026-04-19 06:13:46 UTC
URL: https://conductatlas.com/change/2026-04-19-substack-substack-privacy-policy-1927/
Accessed: May 20, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.

Impact Summary

2
Protections removed
Consumers Removed

Substack no longer commits to a specific timeframe for responding when you ask to access, correct, or delete your data.

Consumers Removed

The policy no longer explicitly describes the practice of sharing identifiers with child safety organizations.

For legal and compliance teams

Institutional Analysis

Assessment

This change removes compliance commitments that appeared to operationalize GDPR and UK DPA response obligations (Articles 12(3), 12(4); Data Protection Act 2018 Section 45) and eliminates explicit disclosure of a data processing practice tied to child safety. EU and UK organizations relying on Substack services should evaluate whether removal of stated response timelines creates gaps in their own data subject rights fulfillment obligations or vendor accountability structures. The removal of child safety consortium disclosure may also engage regulatory scrutiny under GDPR Article 14 (information to be provided where personal data have not been obtained from the data subject) and UK Data Protection Act transparency requirements, depending on how regulators interpret the relationship between disclosed practices and legal obligations to disclose them.

Regulatory Exposure

GDPR (Articles 12, 14, 32), UK Data Protection Act 2018 (Sections 45, 57), CCPA (California Consumer Privacy Act, disclosure and response time provisions), FTC Act Section 5 (unfair or deceptive practices)

Full compliance analysis

Obligation analysis, escalation trigger, board language, and recommended action.

Watcher $9.99/mo Professional $149/mo

Watcher: regulatory citations + obligations. Professional: full compliance memo.

ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-001927.

Full Changes

See the full side-by-side comparison of every sentence added, removed, and modified.

🔒 Full diff — Watcher

Document Context

Version history → Policy drift analysis → Document page →
Document
Substack Privacy Policy
Entity
Substack
Captured
April 19, 2026
Source URL
https://substack.com/privacy
Other changes to Substack Privacy Policy
Next change May 5, 2026
Substack updated its privacy policy on May 5, 2026 to disclose that it shares account identifiers with child safety organizations …
Medium Neutral
View full version history →
More from Substack
May 19, 2026 Low
Substack Privacy Policy

The navigation footer of Substack's privacy policy page was updated on May 19, 2026 to include comparative product links. Specifically, …

May 19, 2026 Low
Substack Terms of Use

Substack's Terms of Use footer navigation was updated on May 19, 2026 to add comparative product links. The footer now …

May 15, 2026 Low
Substack Privacy Policy

Substack updated its privacy policy on May 15, 2026 to disclose that it shares account identifiers with child safety industry …

Track Substack policy changes

Get alerted when this policy changes again — including what changed and why it matters.

Prefer a weekly summary instead?

Get the biggest policy changes across 320+ platforms every Sunday.