CA-C-001590
Substack — Substack Privacy Policy
Entity
Date detected
May 5, 2026
Effective date
May 5, 2026
Severity
Direction
Neutral
Affected users
all users
Taxonomy
Data collection expansion
Changes
+9 sentences added · 5 sentences modified
Share 𝕏 Share in Share 🔒 PDF
Watch Substack Get alerts when this policy changes.
Watch — Free

Event Summary

Substack updated its privacy policy on May 5, 2026 to disclose that it shares account identifiers with child safety organizations to detect child sexual abuse material, added a one-month deadline for responding to privacy rights requests, and clarified that direct message recipients may retain messages even after deletion. The policy also now specifies that only material changes to the privacy policy will trigger user notification.

MEDIUM

Consumer Impact

Substack now discloses that it shares account identifiers, such as email addresses and usernames, with trusted industry child safety organizations to detect and prevent online child sexual exploitation and abuse. The policy also establishes that Substack will respond to privacy rights requests within one month, or up to three months for complex requests, providing more certainty about response timelines. Additionally, the policy clarifies that direct message recipients may retain messages even if you request deletion or delete your account, which is now explicitly stated rather than implied.

Governance Analysis

The policy now transparently discloses a new data sharing practice that affects all users' email addresses and usernames, and establishes formal timelines for exercising privacy rights that previously had no guaranteed deadline. This clarifies both what Substack does with user identifiers and what users can expect when requesting data or privacy rights.

Key Clauses Affected

Industry Child Safety Programs disclosure

Substack now explicitly states it shares account identifiers with child safety organizations to detect and prevent online child sexual exploitation and abuse.

Data subject rights response timeline

Substack commits to respond to privacy rights requests within one month, or up to three months for complex requests, with notification of extension.

Direct message retention clarification

Policy now clarifies that platform may restrict message access but recipients may retain messages indefinitely, regardless of user deletion or account closure.

Full clause-by-clause analysis available with Professional.
These clauses may change again. Get alerted when they do. Watch Substack — Free

This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology

Evidence Verification

✓ Verified
Previous Version
30dacb2f5c2daea0eee194830d934496ec1685219992cb84fb4d4dad988dba70
April 19, 2026 06:13 UTC
✓ Verified
Current Version
b7899fd21f6d5aa04ee2589121d23b47e86d4896e1fa797d920e873e2db1d5b5
May 5, 2026 05:44 UTC
✓ Verified
Change Detected
May 5, 2026 05:44 UTC
Analysis Methodology
✓ Verified
Source Document
https://substack.com/privacy
Citation Record
Entity: Substack
Document: Substack Privacy Policy
Record ID: CA-C-001590
Captured: 2026-05-05 05:44:17 UTC
URL: https://conductatlas.com/change/2026-05-05-substack-substack-privacy-policy-1590/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.

Impact Summary

2
New obligations
1
Expanded
Consumers Added

You are now told that Substack shares your email and username with industry groups working to prevent child abuse online.

Consumers Added

When you ask Substack for your data or to exercise a privacy right, you now have a guaranteed timeline for their response instead of an indefinite wait.

+ 1 more obligation changes. Full breakdown available with Watcher.

Track changes →
For legal and compliance teams

Institutional Analysis

Assessment

This change introduces a new disclosure about data sharing for child safety purposes and establishes formal response timelines for data subject rights requests. The child safety sharing disclosure engages GDPR Article 6 (lawful basis), CCPA disclosure requirements, and potentially COPPA considerations if minors are present. The one-month response commitment aligns with GDPR Article 12 timelines and may influence vendor contracts and privacy notices for organizations that embed Substack services. Organizations should assess whether their own privacy disclosures and data processing agreements need updating to reflect this sharing practice.

Regulatory Exposure

GDPR (Articles 6, 12, 13, 14 on lawful basis, response timelines, and transparency), CCPA (disclosure and consumer rights request timing), COPPA (if minors are present on the platform), UK Data Protection Act 2018, potential state privacy laws (VMPPA, IPDPA, etc. depending on jurisdiction)

Full compliance analysis

Obligation analysis, escalation trigger, board language, and recommended action.

Watcher $9.99/mo Professional $149/mo

Watcher: regulatory citations + obligations. Professional: full compliance memo.

ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-001590.

Full Changes

See the full side-by-side comparison of every sentence added, removed, and modified.

🔒 Full diff — Watcher

Document Context

Version history → Policy drift analysis → Document page →
Document
Substack Privacy Policy
Entity
Substack
Captured
May 5, 2026
Source URL
https://substack.com/privacy
Other changes to Substack Privacy Policy
Next change May 6, 2026
Substack's privacy policy now discloses that the company shares account identifiers with child safety industry consortia to detect child sexual …
Low Positive
View full version history →
More from Substack
May 6, 2026 Low
Substack Privacy Policy

Substack's privacy policy now discloses that the company shares account identifiers with child safety industry consortia to detect child sexual …

May 6, 2026 Low
Substack Terms of Use

Substack added one navigation link to its site architecture on May 6, 2026: a new 'For media founders' option in …

Track Substack policy changes

Get alerted when this policy changes again — including what changed and why it matters.

Prefer a weekly summary instead?

Get the biggest policy changes across 320+ platforms every Sunday.