The policy discloses that Substack shares account identifiers including email addresses and usernames with industry child safety organizations and consortia for the purpose of detecting and preventing child sexual exploitation and abuse material (CSAM/OCSEA). This provision was added in the most recent policy update (May 14, 2026).
This analysis describes what Substack's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a data sharing relationship between Substack and third-party child safety organizations for CSAM detection purposes, which represents a newly disclosed category of third-party data transfer. The provision does not identify the specific consortia involved, which limits the ability of users or compliance teams to assess the data governance practices of receiving organizations.
Substack now discloses that it shares account identifiers, such as email addresses and usernames, with trusted industry child safety organizations to detect and prevent online child sexual exploitation and abuse. The policy also establishes that Substack will respond to privacy rights requests within one month, or up to three months for complex requests, providing more certainty about response timelines. Additionally, the policy clarifies that direct message recipients may retain messages even if you request deletion or delete your account, which is now explicitly stated rather than implied.
View change record →The updated policy no longer commits to responding to privacy rights requests within one month or within three months for complex requests. This removes a procedural timeline that previously bound Substack's response obligations. Additionally, the explicit disclosure that Substack shares account identifiers with child safety consortia to detect online child sexual exploitation has been removed from the policy, though the practice itself is not stated to have ended. The direct message retention language is now framed more directly: recipients may retain messages even if you request deletion or close your account.
View change record →Severity escalated from 'low' to 'medium' and excerpt expanded to show additional context with more formal language structure.
View full change record →Under this clause, Substack may share account identifiers including email addresses and usernames with third-party child safety organizations without individual user consent, as this processing is described as a legitimate interest of the platform. The policy does not name the specific organizations with which these identifiers are shared.
How other platforms handle this
we may share data between our affiliates for the safety and security of our users and may take necessary actions if we believe you have violated these Terms, including banning you from our Services and/or our affiliates' services...
Protect us, our business, our users, and others, for example to enforce our terms of service, prevent spam or other unwanted communications, and investigate or protect against fraud
we may use, retain or share information with law enforcement or others in circumstances where a person's vital interests require protection, such as in the case of emergencies.
"to share account identifiers with trusted industry child safety consortia for the detection and prevention of online child sexual exploitation and abuse (OCSEA); ... We may share account identifiers (such as email addresses and usernames) with trusted industry child safety organizations for the purpose of detecting and preventing online child sexual exploitation and abuse (OCSEA).Excerpt from Substack's Privacy Policy
1.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
ConductAtlas detected a major restructuring of Meta’s privacy policy that removed detailed consumer rights disclosures and relocated them to separate documents.
Your genetic data may be transferred to a new owner as a business asset. Here is what the Terms of Service actually say and what you can do right now.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes a data sharing relationship between Substack and third-party child safety organizations for CSAM detection purposes, which represents a newly disclosed category of third-party data transfer. The provision does not identify the specific consortia involved, which limits the ability of users or compliance teams to assess the data governance practices of receiving organizations.
Under this clause, Substack may share account identifiers including email addresses and usernames with third-party child safety organizations without individual user consent, as this processing is described as a legitimate interest of the platform. The policy does not name the specific organizations with which these identifiers are shared.
ConductAtlas has identified this type of provision across 287 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Substack.