56
Privacy Score
Data Collection20%
50/100
Data Sharing25%
60/100
Tracking20%
40/100
Transparency20%
60/100
User Rights15%
70/100
AI Risk
75/100

Analysis Findings

Data Collection
-50 pts33 Types
Data Sharing
-35 pts4 Issues
Tracking
-60 pts4 Trackers
Transparency
+10 ptsFair
User Rights
+20 ptsComprehensive
AI Practices
-10 pts75/100

Top Vendors

View all 11
VendorCategoryPurpose
S
Stripe
How will Substack share the Personal Information it receives? - Our Service ProvidersThird-party payment provider to receive and process credit card transactions
G
Generic Website Hosting Provider
How will Substack share the Personal Information it receives? - Our Service ProvidersWebsite hosting
G
Generic Maintenance Services Provider
How will Substack share the Personal Information it receives? - Our Service ProvidersMaintenance services
G
Generic Email Services Provider
How will Substack share the Personal Information it receives? - Our Service ProvidersEmail services
G
Generic Security Services Provider
How will Substack share the Personal Information it receives? - Our Service ProvidersSecurity services
Collected Data Types
First Name and Last Name
identityRequired
Email Address
identityRequired
Phone Number
identity
Date of Birth
identity
Credit Card Details
financialRequired
Cookies & Tracking
No data available
Doing Well
  • Subprocessor list published
  • Privacy policy published
  • Comprehensive policy sections
  • Data processing purposes stated
  • Readable policy length
  • 3 user rights listed
Concerns
  • Tracks behavioral data
  • Collects browsing history
  • Collects location data
  • Collects financial data
  • Collects 33 data types
  • Shares data with advertisers
Privacy Summary
Substack collects personal data like your name, email, payment details, location, device information, and direct message content. This information is shared with Creators you subscribe to, third-party service providers (e.g., for payments, hosting), other users (e.g., your profile), and if legally required, with government authorities. You can delete your account and some personal information through your account settings, or contact privacy@substackinc.com to request data deletion or access.
AI-generated summary based on policy analysis dated Apr 11, 2026
Quick Facts
Legal NameSubstack Inc.
HeadquartersUS
Data DeletionModerate (4/10)
Vendors11 third parties
Data Types33 types collected
Last AnalyzedApr 11, 2026
Compliance
GDPRYes
CCPAYes
Data Request FormNo
Recent BreachNo
Data BrokerNo
AI Risk
  • High user impact from AI usage
  • Automated decision-making risk