Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
Substack collects your personal information whenever you use its services or subscribe to any publication, free or paid. When you subscribe to a Creator's publication, your name and email address are shared with that Creator, and Substack personnel can access your direct messages for platform enforcement and support purposes. Your direct messages are not end-to-end encrypted, and you have qualified rights to access, correct, or delete your personal information, with Substack committing to respond within one month.
The Substack Privacy Policy establishes the basis on which Substack collects and processes Personal Information across all interactions with its services, both free and paid. It defines a set of qualified user rights — including access, correction, erasure, restriction, and portability — with a one-month response commitment, while conditioning those rights on unstated eligibility criteria. The policy delineates the boundaries of Substack's role: it does not apply where Substack acts as a data processor on behalf of a Creator, placing compliance responsibility for that processing entirely on the Creator. Key operational disclosures include Substack personnel's permissive access to direct message contents for enforcement and support purposes, the absence of end-to-end encryption for direct messages, the sharing of subscriber name and email with Creators upon subscription, permissive sharing of account identifiers with child safety consortia, and an explicit acknowledgment that complete security cannot be guaranteed.
Subscribing to any Substack publication results in your name and email address being passed to the Creator, who operates outside of Substack's Privacy Policy. Direct messages you send are not end-to-end encrypted, Substack personnel may read them for operational purposes, and recipients may retain them even if you delete your account or request deletion. Your account identifiers may be shared with child safety organizations without a legal order. You have qualified rights — not guaranteed in every circumstance — to request a copy of, correction to, erasure of, or transfer of your Personal Information, and you can submit such a request and receive a response within one month.
Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.
7 important changes detected
8 versions captured · Last updated: June 2026
Substack replaced one third-party tracking vendor with another in their privacy policy. The policy previously listed AdQuick as a persistent tracking pixel for third-party analytics; this vendor reference has been …
View change record →The navigation footer of Substack's privacy policy page was updated on May 19, 2026 to include comparative product links. Specifically, 'Substack vs. beehiiv' and 'Substack vs. Patreon' navigation items were …
View change record →Substack updated its privacy policy on May 15, 2026 to disclose that it shares account identifiers with child safety industry consortia and now receives information from those consortia to detect …
View change record →Substack updated its privacy policy on May 5, 2026 to disclose that it shares account identifiers with child safety organizations to detect child sexual abuse material, added a one-month deadline …
View change record →Substack's updated privacy policy removes language describing a one-month response timeline for certain privacy rights requests and eliminates explicit disclosure about sharing account identifiers with child safety consortia. The policy …
View change record →Every distinct legal provision identified in this document. Featured provisions appear above with analysis.
Substack has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.
Cross-platform context
See how other platforms handle Account identifiers shared for child safety detection and similar clauses.
Compare across platforms →Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.