This analysis describes what Substack's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
Substack now discloses that it shares account identifiers, such as email addresses and usernames, with trusted industry child safety organizations to detect and prevent online child sexual exploitation and abuse. The policy also establishes that Substack will respond to privacy rights requests within one month, or up to three months for complex requests, providing more certainty about response timelines. Additionally, the policy clarifies that direct message recipients may retain messages even if you request deletion or delete your account, which is now explicitly stated rather than implied.
View change record →The updated policy no longer commits to responding to privacy rights requests within one month or within three months for complex requests. This removes a procedural timeline that previously bound Substack's response obligations. Additionally, the explicit disclosure that Substack shares account identifiers with child safety consortia to detect online child sexual exploitation has been removed from the policy, though the practice itself is not stated to have ended. The direct message retention language is now framed more directly: recipients may retain messages even if you request deletion or close your account.
View change record →How other platforms handle this
Whenever we transfer personal data internationally, we use tools and transfer agreements to: make sure the data transfer complies with applicable law; and help to give your data the same level of protection as it has in the EU...
For countries without an adequacy decision, we transfer, in accordance with Article 46 of the GDPR, personal information to recipients that have entered into the approved form of transfer contract (SCCs)...
we may share data between our affiliates for the safety and security of our users and may take necessary actions if we believe you have violated these Terms, including banning you from our Services and/or our affiliates' services...
"Under any DPF, we are accountable for the onward transfer of Personal Information, and only transfer Personal Information received pursuant to a DPF under agreements that provide the same protections as the DPF.Excerpt from Substack's Privacy Policy
ConductAtlas detected a major restructuring of Meta’s privacy policy that removed detailed consumer rights disclosures and relocated them to separate documents.
Your genetic data may be transferred to a new owner as a business asset. Here is what the Terms of Service actually say and what you can do right now.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The clause states: “Under any DPF, we are accountable for the onward transfer of Personal Information, and only transfer Personal Information received pursuant to a DPF under agreements that provide the same protections as the DPF.”
ConductAtlas has identified this type of provision across 287 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Substack.