The policy discloses that Substack may collect email addresses and phone numbers of individuals who have not created Substack accounts if a Substack user syncs their address book through the app. Collected contact information is stored as hashed values and is used to facilitate contact syncing between opted-in users.
This analysis describes what Substack's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision discloses data collection about non-Substack users through address book syncing, which may occur without the knowledge of the individuals whose contact information is collected. The policy limits collection to email addresses and phone numbers stored as hashes, and limits use to contact syncing purposes.
Substack now discloses that it shares account identifiers, such as email addresses and usernames, with trusted industry child safety organizations to detect and prevent online child sexual exploitation and abuse. The policy also establishes that Substack will respond to privacy rights requests within one month, or up to three months for complex requests, providing more certainty about response timelines. Additionally, the policy clarifies that direct message recipients may retain messages even if you request deletion or delete your account, which is now explicitly stated rather than implied.
View change record →The updated policy no longer commits to responding to privacy rights requests within one month or within three months for complex requests. This removes a procedural timeline that previously bound Substack's response obligations. Additionally, the explicit disclosure that Substack shares account identifiers with child safety consortia to detect online child sexual exploitation has been removed from the policy, though the practice itself is not stated to have ended. The direct message retention language is now framed more directly: recipients may retain messages even if you request deletion or close your account.
View change record →Severity upgraded from 'medium' to 'medium' (unchanged), but cookie/tracking language was removed and separated into distinct provision; title changed from generic to address-book-specific.
View full change record →Under this clause, Substack may collect and store hashed versions of email addresses and phone numbers from address book uploads by other users, even for individuals who do not have Substack accounts. The policy states this data is used solely for contact syncing and is stored in hashed form.
How other platforms handle this
You can always contact your local data protection authority if you have concerns regarding your rights under local law.
If you are an end user in a Workspace not owned by you and wish to update, delete, or receive any information we have about you, you may do so by contacting the organization who owns your ClickUp Workspace.
to request that your data be transferred to a third party (data portability)
"We may also collect information about you when one of our users syncs their address book information with our app for contact syncing purposes. This information collection is strictly limited to email addresses and phone numbers, and any information collected in this manner is securely stored only as hashed values.Excerpt from Substack's Privacy Policy
1.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision discloses data collection about non-Substack users through address book syncing, which may occur without the knowledge of the individuals whose contact information is collected. The policy limits collection to email addresses and phone numbers stored as hashes, and limits use to contact syncing purposes.
Under this clause, Substack may collect and store hashed versions of email addresses and phone numbers from address book uploads by other users, even for individuals who do not have Substack accounts. The policy states this data is used solely for contact syncing and is stored in hashed form.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Substack.