77 Total
23 High severity
46 Medium severity
8 Low severity

Key Facts

Who does Substack share account identifiers with?
Substack shares account identifiers with trusted industry child safety consortia for the detection and prevention of online child sexual exploitation and abuse.
What account identifiers may Substack share with trusted industry child safety organizations?
Substack may share account identifiers such as email addresses and usernames with trusted industry child safety organizations for the purpose of detecting and preventing online child sexual exploitation and abuse.
What is the purpose of sharing account identifiers with trusted industry child safety organizations?
Substack may share account identifiers such as email addresses and usernames with trusted industry child safety organizations for the purpose of detecting and preventing online child sexual exploitation and abuse.
Who is solely responsible for privacy compliance?
Creators using Substack's services are solely responsible for their own privacy compliance, and Substack's Privacy Policy does not apply to Substack's processing of Personal Information as a data processor on behalf of any Creator.
Does Substack's Privacy Policy apply to Substack's processing of Personal Information as a data processor on behalf of any Creator?
Creators using Substack's services are solely responsible for their own privacy compliance, and Substack's Privacy Policy does not apply to Substack's processing of Personal Information as a data processor on behalf of any Creator.
Are direct messages end-to-end encrypted?
Substack discloses that direct messages are not end-to-end encrypted and are not a substitute for secure messaging services.
Does Substack make final content moderation decisions without human review of automated decisions?
At this time, Substack makes no final content moderation decisions without human review of any automated decisions.
May recipients of direct messages retain those messages if the sender requests their deletion?
Recipients of Substack direct messages may retain those messages even if the sender requests their deletion or deletes their Substack account.
May recipients retain direct messages if the sender deletes their Substack account?
Recipients of Substack direct messages may retain those messages even if the sender requests their deletion or deletes their Substack account.
May users ask Substack for a copy of their Personal Information?
Substack states that users may be entitled to ask Substack for a copy of their Personal Information, to correct it, erase or restrict its processing, or to ask Substack to transfer some of that information to other organizations.
Stay ahead of the changes
Track Substack and get the diff the day its terms change.
Summary

Substack collects your personal information whenever you use its services or subscribe to any publication, free or paid. When you subscribe to a Creator's publication, your name and email address are shared with that Creator, and Substack personnel can access your direct messages for platform enforcement and support purposes. Your direct messages are not end-to-end encrypted, and you have qualified rights to access, correct, or delete your personal information, with Substack committing to respond within one month.

Analysis

The Substack Privacy Policy establishes the basis on which Substack collects and processes Personal Information across all interactions with its services, both free and paid. It defines a set of qualified user rights — including access, correction, erasure, restriction, and portability — with a one-month response commitment, while conditioning those rights on unstated eligibility criteria. The policy delineates the boundaries of Substack's role: it does not apply where Substack acts as a data processor on behalf of a Creator, placing compliance responsibility for that processing entirely on the Creator. Key operational disclosures include Substack personnel's permissive access to direct message contents for enforcement and support purposes, the absence of end-to-end encryption for direct messages, the sharing of subscriber name and email with Creators upon subscription, permissive sharing of account identifiers with child safety consortia, and an explicit acknowledgment that complete security cannot be guaranteed.

What this means for you

Subscribing to any Substack publication results in your name and email address being passed to the Creator, who operates outside of Substack's Privacy Policy. Direct messages you send are not end-to-end encrypted, Substack personnel may read them for operational purposes, and recipients may retain them even if you delete your account or request deletion. Your account identifiers may be shared with child safety organizations without a legal order. You have qualified rights — not guaranteed in every circumstance — to request a copy of, correction to, erasure of, or transfer of your Personal Information, and you can submit such a request and receive a response within one month.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

7 important changes detected

8 versions captured · Last updated: June 2026

What changed Substack's privacy policy included a navigation menu item referencing 'For media founders' in its updated version published June 28, 2026. This appears to be a navigation or product offering update rather than a substantive change to privacy practices, data handling, or user rights. The change does not materially alter what data Substack collects, how it uses user information, or what privacy protections apply.
Why this matters This change does not materially affect consumer privacy rights or data handling practices. The updated policy adds a navigation menu item referencing 'For media founders' in its landing page structure, but this is a menu or product categorization change rather than a modification to privacy disclosures, data collection practices, or user protections. Privacy terms and practices remain substantively unchanged.
View full change record →
What changed Substack updated its privacy policy footer on June 16, 2026 to add a reference to 'Brand Partnerships' in the navigation section. The change adds a link to a new resource or section called 'Brand Partnerships' where previously this link did not appear in the footer menu. This appears to be a navigation and resource disclosure change rather than a substantive modification to privacy terms or data practices.
Why this matters This change introduces a navigation link to 'Brand Partnerships' information in the privacy policy footer. The change does not modify privacy practices, data collection, retention, or user rights. Users who encounter the privacy policy will see an additional footer link available.
View full change record →

June 5, 2026 low

Substack replaced one third-party tracking vendor with another in their privacy policy. The policy previously listed AdQuick as a persistent tracking pixel for third-party analytics; this vendor reference has been …

View change record →
May 19, 2026 low

The navigation footer of Substack's privacy policy page was updated on May 19, 2026 to include comparative product links. Specifically, 'Substack vs. beehiiv' and 'Substack vs. Patreon' navigation items were …

View change record →
May 15, 2026 low

Substack updated its privacy policy on May 15, 2026 to disclose that it shares account identifiers with child safety industry consortia and now receives information from those consortia to detect …

View change record →
May 5, 2026 medium

Substack updated its privacy policy on May 5, 2026 to disclose that it shares account identifiers with child safety organizations to detect child sexual abuse material, added a one-month deadline …

View change record →
April 19, 2026 medium

Substack's updated privacy policy removes language describing a one-month response timeline for certain privacy rights requests and eliminates explicit disclosure about sharing account identifiers with child safety consortia. The policy …

View change record →
Featured, High severity
Featured, Medium severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

77 provisions
12 featured
15 clause types
23 high severity
Stay ahead of the changes

Monitoring

Substack has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle Account identifiers shared for child safety detection and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
UK GDPR
United Kingdom
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
VPPA
United States Federal
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured June 28, 2026 00:24 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000178
Version ID CA-V-004273
SHA-256 71ddc259e5c57fb2e20d0374b0d56f85464085af02f0c9571bdde6b9270b442a
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans