9 Total
1 High severity
4 Medium severity
4 Low severity
Summary

This privacy policy establishes Substack's data collection, use, and sharing practices for readers, writers, and subscribers. The policy authorizes Substack to access the contents of direct messages, which are not end-to-end encrypted, and specifies that messages may persist with recipients following account deletion. Users may request data access, correction, or deletion by submitting a privacy rights request to privacy@substackinc.com.

Technical / Legal Breakdown

This document is Substack Inc.'s Privacy Policy (last updated May 4, 2026), governing the collection, use, storage, and sharing of personal information across Substack's website and services, with Substack acting as data controller for its own processing purposes. The policy states that Substack collects a broad range of data including names, email addresses, phone numbers, dates of birth, payment details, IP addresses, direct message contents and metadata, and social media account information linked to user profiles; the terms authorize sharing this data with affiliates, service providers (including generative AI providers), creators, third-party data controllers, industry child safety consortia, and government authorities, and reserve the right to transfer data in connection with a merger or acquisition. Two operationally distinct provisions are notable: the policy explicitly discloses that direct messages are not end-to-end encrypted and that Substack personnel may access message contents to enforce terms or provide services; and the policy permits sharing account identifiers such as email addresses and usernames with child safety industry consortia for CSAM detection, a practice newly disclosed in this update. The policy asserts compliance with the EU-U.S. Data Privacy Framework, the UK Extension, and the Swiss-U.S. DPF as mechanisms for transatlantic data transfers, engaging GDPR and UK GDPR obligations, with DPF Principles stated to govern in the event of conflict with policy terms; the policy also includes dedicated CCPA disclosures for California residents, engaging California Consumer Privacy Act obligations enforced by the California Privacy Protection Agency.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial

5 important changes detected

5 versions captured · Last updated: May 2026

What changed The navigation footer of Substack's privacy policy page was updated on May 19, 2026 to include comparative product links. Specifically, 'Substack vs. beehiiv' and 'Substack vs. Patreon' navigation items were added to the footer menu. This is a navigation and site structure change with no material impact on the privacy policy terms themselves.
Why this matters This change is a site navigation and footer update with no substantive impact on privacy policy terms, data handling practices, or user rights. The addition of comparative product links does not modify what data Substack collects, how it processes data, or what rights users have. The privacy policy terms remain unchanged.
View full change record →
What changed Substack updated its privacy policy on May 15, 2026 to disclose that it shares account identifiers with child safety industry consortia and now receives information from those consortia to detect child sexual abuse material (CSAM). The policy also added language stating that Substack may obtain additional information from third parties, combine it with platform data, and use the combined information to provide safer experiences and improve the platform and analytics.
Why this matters The updated policy discloses that Substack shares account identifiers with child safety industry consortia and receives information from those consortia to detect CSAM. The policy now also states that Substack may obtain additional information from third parties and combine it with platform data to provide safer experiences and improve platform analytics. The updated terms treat combined information from other sources in accordance with the overall privacy policy. These are disclosures of existing or new data-handling practices rather than changes that grant users new control mechanisms.
View full change record →

May 6, 2026 low

Substack's privacy policy now discloses that the company shares account identifiers with child safety industry consortia to detect child sexual abuse material (CSAM). This is a new transparency disclosure added …

View change record →
May 5, 2026 medium

Substack updated its privacy policy on May 5, 2026 to disclose that it shares account identifiers with child safety organizations to detect child sexual abuse material, added a one-month deadline …

View change record →
April 19, 2026 medium

Substack's updated privacy policy removes language describing a one-month response timeline for certain privacy rights requests and eliminates explicit disclosure about sharing account identifiers with child safety consortia. The policy …

View change record →
High — 1 provision
Medium — 4 provisions
Low — 4 provisions

Monitoring

Substack has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle Direct Messages Not End-to-End Encrypted and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
UK GDPR
United Kingdom
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
VPPA
United States Federal
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 19, 2026 00:17 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000178
Version ID CA-V-002719
SHA-256 bc3dd14b26e4b8c46be1ce9b1c100960cdfd4a0b0e63fa665fc2d51f98cc80b7
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans