This is a print-friendly report. Click Print and choose “Save as PDF” in the destination dropdown to download.

SaaSGuard Risk Report

Substack

substack.com

Generated May 4, 2026

Grade C

Score: 58 / 100

Executive summary

We analyzed Substack’s Terms of Service across 8 risk dimensions and found 8 flagged clauses across 6 categories.

Flagged clauses by category

Auto-renewal traps (1)

  • Severity 3 · notable

    Your subscription will automatically renew at the end of each term for successive terms of the same duration unless you cancel your subscription prior to the end of the then-current term through your account settings.

    Substack automatically renews your subscription for the same duration unless you cancel it through your account settings before the term ends.

    You'll be charged for another subscription term if you forget to cancel, even if you no longer need the service.

    Matches FTC v. Amazon (Iliad Flow / Prime Enrollment) (2023)

Surprise price hikes (1)

  • Severity 3 · notable

    We reserve the right to change the fees for our Services at any time. If we change our pricing, we will notify you in advance by posting the changes on our website or by sending you an email.

    Substack can increase the price of its services at any time and will notify you beforehand.

    You might find yourself paying more for the service than you expected after receiving a notification.

    Matches Netflix Price Hike Class Action (2023)

Termination friction (1)

  • Severity 3 · notable

    You may cancel your subscription at any time, but you will not receive a refund for any unused portion of your current subscription term. Upon cancellation, you will continue to have access to the Services until the end of your then-current subscription term.

    You can cancel your Substack subscription anytime, but you won't get a refund for the current term and will still have access until it ends.

    If you stop using the service mid-term, you forfeit any remaining value and can't get your money back.

    Matches FTC v. Match Group (Match.com) (2019)

Liability caps (2)

  • Severity 4 · material

    IN NO EVENT SHALL OUR AGGREGATE LIABILITY EXCEED THE GREATER OF ONE HUNDRED U.S. DOLLARS (U.S. $100.00) OR THE AMOUNT YOU PAID US IN THE PAST SIX MONTHS FOR THE SERVICES GIVING RISE TO THE CLAIM.

    Substack's total liability to you is capped at $100 or the amount you paid them in the last six months, whichever is greater.

    If Substack causes a major issue, your compensation is severely limited, potentially leaving you out of pocket.

    Matches Capital One Data Breach Class Action — settled for $190M (2022)

  • Severity 4 · material

    TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT WILL WE BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL OR PUNITIVE DAMAGES, OR ANY LOSS OF PROFITS OR REVENUES, WHETHER INCURRED DIRECTLY OR INDIRECTLY, OR ANY LOSS OF DATA, USE, GOODWILL, OR OTHER INTANGIBLE LOSSES, RESULTING FROM (A) YOUR ACCESS TO OR USE OF OR INABILITY TO ACCESS OR USE THE SERVICES; (B) ANY CONDUCT OR CONTENT OF ANY THIRD PARTY ON THE SERVICES, INCLUDING WITHOUT LIMITATION, ANY DEFAMATORY, OFFENSIVE OR ILLEGAL CONDUCT OF OTHER USERS OR THIRD PARTIES; OR (C) UNAUTHORIZED ACCESS, USE OR ALTERATION OF YOUR TRANSMISSIONS OR CONTENT.

    Substack won't be liable for any indirect, special, or consequential damages, including lost profits or data, from using their service.

    If Substack's service causes you significant financial loss, they are not responsible for covering it.

    Matches Capital One Data Breach Class Action — settled for $190M (2022)

Indemnification (1)

  • Severity 3 · notable

    You agree to defend, indemnify and hold harmless Substack and its licensors and suppliers, and their respective officers, directors, employees and agents, from and against any claims, liabilities, damages, losses and expenses, including reasonable attorneys’ fees, arising out of or in connection with (a) your violation of these Terms; (b) your violation of any rights of any third party, including any intellectual property right; or (c) your violation of any applicable laws.

    You must defend Substack against any claims or losses arising from your violation of their terms, third-party rights, or applicable laws.

    You could be responsible for paying legal fees and damages if your actions lead to a lawsuit against Substack.

    Matches T-Mobile Data Breach Settlement — settled for $350M (2022)

Right to silently change terms (2)

  • Severity 4 · material

    We reserve the right to modify these Terms at any time in our sole discretion. If we make changes that we believe are material, we will notify you by posting the updated Terms on our website or through other communication channels.

    Substack can change these terms whenever they want, and they'll tell you if they think the changes are major.

    You could be subject to new rules without realizing it until Substack decides to inform you.

    Matches Italian DPA (Garante) v. WhatsApp — settled for $6M (2022)

  • Severity 4 · material

    Your continued use of the Services after the effective date of the revised Terms constitutes your binding acceptance of the revised Terms. If you do not agree to the revised Terms, you may not continue to use the Services.

    If Substack updates its terms, continuing to use the service means you accept the new terms, even if you don't agree.

    You might be forced to accept new terms you disagree with just to keep using the service.

    Matches Italian DPA (Garante) v. WhatsApp — settled for $6M (2022)

Methodology

SaaSGuard uses an automated pipeline: a daily Playwright crawler captures each vendor’s public Terms of Service, Privacy Policy, and DPA. Google’s Gemini 2.5 Flash classifies each clause into one of 8 risk categories with a severity score (1–5). Clauses are cross-referenced against a curated database of real lawsuits and FTC actions via embedding-based similarity matching. Grades are computed from per-category max severity; full source code is available on request.

Built for educational and informational purposes. Not legal advice. Always have your own counsel review SaaS contracts before signing.

View live page →