This analysis describes what Substack's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
Substack now discloses that it shares account identifiers, such as email addresses and usernames, with trusted industry child safety organizations to detect and prevent online child sexual exploitation and abuse. The policy also establishes that Substack will respond to privacy rights requests within one month, or up to three months for complex requests, providing more certainty about response timelines. Additionally, the policy clarifies that direct message recipients may retain messages even if you request deletion or delete your account, which is now explicitly stated rather than implied.
View change record →The updated policy no longer commits to responding to privacy rights requests within one month or within three months for complex requests. This removes a procedural timeline that previously bound Substack's response obligations. Additionally, the explicit disclosure that Substack shares account identifiers with child safety consortia to detect online child sexual exploitation has been removed from the policy, though the practice itself is not stated to have ended. The direct message retention language is now framed more directly: recipients may retain messages even if you request deletion or close your account.
View change record →How other platforms handle this
Request a review of decisions made solely based on automated processing of personal data.
Mailchimp uses a combination of automated and human detection review processes to ensure that Members are complying with our Standard Terms of Use and this Acceptable Use Policy.
We may (but are not obligated to) use automated systems and human reviewers to record, monitor, analyse, modify, disable and, store and review use of our Interactive Features...
"We may also use automated means to ensure the safety of direct messaging content, including scanning for spam, malicious content, and child abuse material.Excerpt from Substack's Privacy Policy
How Meta, TikTok, and Supabase restructured governance language across documents, jurisdictions, and consent frameworks through incremental document updates.
How 10 AI platforms describe the use of user data for model training, improvement, and development, based on archived governance provisions.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The clause states: “We may also use automated means to ensure the safety of direct messaging content, including scanning for spam, malicious content, and child abuse material.”
ConductAtlas has identified this type of provision across 216 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Substack.