Inside the third right — and the contradiction the platforms signed themselves into
“This one is a deep read, friend. Question: if I back up everything I want to keep, is there a way to remove everything I’ve ever posted or discussed so it can not continue to be used? Or, should I ask, if it’s already been used, well that’s done, but if I delete my own account, does it still exist? Just a question 🙂”
— a reader, in the comments on the last piece
That is the question everyone circles and no one finishes. I won’t leave it hanging. But the honest answer isn’t yes and isn’t no. It’s the difference between a door and a room.
A door, not a room
Deleting the account closes a door — your way in. It does not empty the room behind it. There are two locks on deletion, and they hung both before you arrived.
The first lock: their own policy reserves the right to keep your data while a complaint is live or a dispute is reasonably foreseeable — even after consent is withdrawn, even after the account is gone. While the matter is alive, the right to be forgotten breaks against that one clause. They loaded it in advance.
The second lock: what has already been taken. The graph — who reads whom, who follows whom — was extracted and used. Deleting the account does not recall it. You shut the door. The room stays full.
I tested this myself
A year ago I signed up to Substack and spent almost a month drifting — politics, AI, business, philosophy. For a long stretch the platform couldn’t place me. It didn’t know who my audience was.
In May I was banned. I came back: a new account, a fresh anti-detect browser, clean proxies, none of the old traces. I set the same broad categories — AI, business, politics, philosophy. And in the very first session the feed handed me writers I knew. Not writers from those categories — writers from mine. People I had been connected to before, surfaced fast.
A year ago it took them a month to find my audience by what I wrote. This time it took one session — because this time they were not reading my writing. They were reading my graph. The fresh browser didn’t matter. The clean proxies didn’t matter. The new account didn’t matter. The graph survived all of it, because the graph is the asset.
Could I be wrong? I could. I am not even fully certain the browser itself didn’t leak me — an anti-detect setup is no guarantee, clean proxies are not enough. But even then, nothing changes. If they knew me by the graph, privacy failed. If my own browser — the thing meant to hide me — gave me away, privacy failed harder. Whichever way it cuts, the verdict is one: confidentiality did not hold.
That is the answer to if it has already been used, is it too late. The thing they keep is not your text. It is the map of who you know. A ban takes the account. It does not take the map.
So if deletion is the weak weapon here, where is the strong one? It is in the right next to it. The one they wrote down themselves.
The third right — and they wrote it themselves
The last piece took apart two rights: portability and erasure. Those are not the whole set. Beside them stands a third — privacy. Who sees your data, who it is handed to, on what ground it is held. And here the American platforms get interesting.
Substack and Stripe are U.S. companies, under state law. Yet their own published policies say, in plain text, what they pass on and to whom — and they carry both regimes at once, European and American. No one forced them to write it out loud. They wrote it. After that the work is simple: read it back to them.
Substack calls itself the controller
Here is the part that strengthens you personally, even from outside Europe. Substack names a representative — the law firm Bird & Bird — but reserves that door for people in the EEA or the UK. Everyone else — the rest of the world — is left outside it by their own wording.
But in the same policy, for your own data as a user — account, email, payments, profile — Substack calls itself not a processor but a controller. A controller is the party that decides how and why your data is used, and answers for it; a processor only handles it on someone else’s instruction. By naming itself the controller, Substack took on the full liability, with no representative in between and no geographic condition written into that clause. That narrows their favourite deflection — you’re not in the EU. It does not, on its own, settle whether a regulator can reach a complaint filed from outside the Union; that turns on where the GDPR actually bites, which is a separate question. For readers inside the EU and the UK, the door is direct. For everyone else it is a lever, not yet a key — and further down there is a key.
(Notice the blade facing the other way, too. Your subscribers’ data they pushed onto you in advance — you were named the controller, they made themselves your processor, acting “on your instruction.” A third-party shield, loaded into the text you accepted at sign-up.)
What they disclosed on their own
From their own policy, without a word from you:
They move money and card data through Stripe — and they name it in plain text in their Privacy Policy: they use Stripe “to receive and process your credit card transactions for us.”
They profile you “in their legitimate interests” to shape recommendations — legitimate interests being a legal basis that lets a company process your data because it claims a business need, without asking your consent. And in the same breath they concede: you may object to that processing at any time, on grounds relating to your situation, and they must stop — unless they can show an overriding ground. The phrasing — we will cease such processing unless — puts the burden on them, not on you. A ban “at their discretion” does not meet that standard.
And the clock: they will respond to any rights request within one month of receipt. Complex or repeated requests can be extended by two more — but only with notice, given inside that first month, stating why. Silence past a month, with no such notice, is a documented breach of their own published policy.
The channel to Stripe: data leaves for the US
The second half is Stripe. The money runs through it by their own arrangement, and it holds its own slice of data under its own policy. That is a transfer to the United States. And this is not theory — a European regulator has already read this exact mechanism out loud, by name.
In 2021 the digital-rights group noyb — founded by Max Schrems, whose name the “Schrems II” ruling carries (the EU court decision that made sending Europeans’ personal data to the US unlawful unless it is specially protected) — filed a complaint on behalf of six Members of the European Parliament. The trigger: the Parliament’s internal COVID testing site carried cookies from Google Analytics and Stripe, two U.S. companies. In January 2022 the EU’s own supervisor, the EDPS, reprimanded the Parliament. Not a fine — a reprimand and an order to fix it within a month (the supervisor could not levy a fine in this case under its powers; the finding is no softer for it). What it held lands straight on our axis:
— Google’s and Stripe’s cookies collect identifiers — that is personal data, and it went to the United States;
— a transfer to the U.S. is lawful only with real supplementary safeguards; the Parliament showed none — a breach under “Schrems II”;
— the privacy notice had been copied from another site, and its language versions contradicted each other — a transparency breach;
— and the nerve of nerves: a complainant asked whether his data had gone to the U.S. The Parliament knew it had — and did not answer in substance. The regulator called that silence itself a breach of the right of access. Silence is not a neutral posture. Silence is already the offense.
This is not one case. It is the norm.
You might think: one case, one site, a fluke. It isn’t. It was measured. In a 2022 study (Bowyer and colleagues, “Human–GDPR Interaction”), ten people each filed four or five requests to access their own data — and met the same wall: non-compliance and low-quality responses. They never managed to understand what the platforms were doing with their data. The study’s verdict is blunt: the right exists on paper, but in practice it breeds distrust while delivering no real control. And regulators are starting to see it — in France, the CNIL made the right of access a priority in 2024, and failures on it became one of the most-sanctioned breaches of the year.
The lesson is simple. A request for access will almost certainly be met with silence or with garbage. That is not a reason to skip it. It is the reason to file it properly — so that their silence, or their garbage, becomes a documented breach of their own deadline. The platform’s weak answer is your strong record.
Their own ladder
They drew the route themselves — the one you can march them down:
- directly — privacy@substackinc.com;
- if they go silent or refuse — the independent TrustArc Watchdog mechanism;
- your own data protection authority;
- binding arbitration under the applicable Data Privacy Framework — the EU–US arrangement that lets American companies receive Europeans’ data, policed by the U.S. Federal Trade Commission.
And above all of it: their adherence to that Framework is subject to the investigatory power of the FTC. They signed up to this voluntarily. You can fall out of the Framework, too — with everything that costs a company doing business in Europe. For readers in the EU and the UK, the door to the Bird & Bird representative is open directly, each for their own data.
The way around, for those outside the EU
If you are outside the EU and the UK — which is to say, most of the world — the European door is narrowed by their own wording. But there is a Californian one. The CCPA — California’s privacy law, which reaches companies like Substack — gives the right to request the full picture: what was collected about you, how it was used, who it was disclosed to over the prior twelve months — and to receive it in a machine-readable form. Substack hands back HTML; on your specific request, that is already a defect.
And here is the key to the door: the CCPA lets you appoint an authorized agent. The agent can be a representative inside the United States, with written permission. The right that “isn’t for you” by geography walks in through an agent who, by geography, is.
Where to write
I have moved the practical part — the exact addresses, the words, the shape of the request — to the foot of this piece, so the argument here stays unbroken. When you are ready to actually write, scroll to the appendix at the end.
This is not only Substack
And it is not only Substack. Walking the other platforms — already knowing where to look, what to read out of their policies — I saw more than enough. Almost all of them run on Stripe. Substack uses it as the only option, with no alternative at all. Others keep a choice — PayPal, say — but Stripe still sits underneath a vast share of them.
And here is the part that reaches past writers, past active users, past anyone who assumes this isn’t about them. If you ever typed your payment details into a Substack field — just that, nothing more — be certain: your data has already moved into Stripe, and out of your hands. You did not have to publish. You did not have to be banned. You did not even have to pay — you only had to try. Even if the writer never connected payments at all, the attempt is enough, because Substack does not show you which writers run Stripe and which do not. You enter your card blind, and the data moves before you ever learn whether the door at the other end was open.
And once it has moved, no one tells you where it goes next. Stripe’s own policy admits it passes personal data to third-party partners — advertisers, analytics providers, social networks. How far it travels after that, and to whom, you neither control nor see. Ask the users of Reddit, who learned after the fact that years of their posts had been sold off to train someone else’s AI. Data handed over for one purpose does not stay tied to that purpose. It becomes inventory.
And this is not my reading of it — it is theirs. Stripe’s own Privacy Policy says it transfers your data “to countries other than your own, including the United States.” Its Data Privacy Framework policy adds that it may be required to “disclose personal information” to “meet national security or law enforcement requirements.” Their words, on their own pages.
Now hold those two pages against the European law. In the same breath they promise EU-grade protection and admit they will hand your data to U.S. authorities on demand. That tension is not new — it is the same one that twice brought the whole structure down. The EU court struck down the Safe Harbour arrangement in 2015, and Privacy Shield in 2020 — the “Schrems II” ruling — each time for one reason: a paper promise cannot shield you from a surveillance law that overrides it. The current patch is the 2023 Data Privacy Framework, which both Substack and Stripe certify under. It is the third attempt at the same fix. It is already under appeal before the EU’s highest court, and it rests on a U.S. executive order that any president can revoke, over a surveillance statute that was renewed in 2024 untouched. Two of these frameworks are already dead. They certify compliance under the third, and on the same page describe the very thing that killed the other two. The contradiction is theirs, in writing — and the ground under it has given way twice before.
In the Stripe dashboard you are shown a few fields on the surface — an email, a card, an amount. But who knows what stands behind the closed ones? What is on display is never the measure of what is held. The dashboard is the label on the door. The room behind it is theirs, and you have never seen it.
“Nothing to worry about”
I thought I understood this. I had read about it, followed it, taken an interest — on the surface. I knew the words: data, transfer, privacy. I did not know the thing until I saw it here, on Substack, working on me.
And I am not new to leaks — though back then I did not even have the word for it. In the 2000s I found my own data spread across hundreds of those data sites. I did not know to call it a breach. “Personal data” was not a phrase I owned. I did not even grasp that what I was staring at had leaked out of a tax office at all.
In my plain naivety I assumed the tax office must somehow be required to publish it — that this was simply how things worked, that the state laid your records out in the open and that was normal. It never crossed my mind that I was looking at something stolen. Nor did I connect that leak to the scam calls that started coming around then — back when almost no one was getting them yet, and the people around me only wondered why I, of all people, was receiving them at all. The symptom was visible. The cause had no name — so no one, least of all me, drew the line between the two. I had no name for the thing, so I made the thing innocent. That is the deepest form of “nothing to worry about” — not shrugging at the danger, but lacking the language to see it as danger at all. And without the language, I let it pass for normal, and went on for twenty years.
The reassurance was not exactly false. There was no fire — no one drained my accounts. That is the low end of this, and it stays low: a card you can reissue. But the absence of a fire is not safety. Your email is not a card; it is the key that stitches you together across every service, the handle by which you are found in every breach after. And the graph — who you know, who knows you — you cannot reissue at all. It is not even only yours; it belongs to other people too. The danger here was never a thief at your account. It is that you are aggregated, not robbed — a row in someone’s dataset, not a target. Quieter than theft, and you do not get it back.
That is what “nothing to worry about” gets wrong. Not that nothing burned — that something soaked in. Twenty years ago I had no name for it, and let it pass for normal. Now I can see where it soaked.
And I can see the exact word that put me to sleep. Back then it was the tax office: it’s the state, so it must be lawful, so it must be fine. Today it is the same reflex, one word swapped: it’s Stripe, it’s under the law, it’s certified, so it must be fine. The label of lawfulness works as an anaesthetic. It tells you to stop looking, because an institution stands behind it. But everything above shows what that word is worth here — their “lawfulness,” the Standard Contractual Clauses, the Data Privacy Framework, collapsed in court twice and stands under appeal a third time. Lawful is not the same as safe. Twenty years ago I mistook the one for the other. That mistake is the exact trap the platforms are built on. I was the person it caught. Now I am the person naming it.
Deletion closes a door. It does not bring back what was carried out of the room. But privacy was never about deletion. It is about forcing them to show you the room — what is in it, who it opens to, on what ground it is locked.
They already wrote the answer. In their own policy, for their own convenience, to look compliant. They did not plan for someone to read it back out loud and demand it line by line.
The reader asked whether the account goes on living without them. It does. The point was never to make it vanish. The point is to make it stop being only theirs.
Appendix — where to write, and what to say
The concrete part. Not to support, which bans. To privacy@substackinc.com, and for the agent route, by letter to their CCPA address. Keep the request short, itemized, with the clock running inside it.
A minimum spine for the letter:
— who is writing and in what capacity (data subject; if through a representative in the US: “via an authorized agent, written permission attached”);
— what you demand: (1) a copy of all personal data in a machine-readable format — access and portability together; (2) a full list of who the data was disclosed to over the last twelve months; (3) an objection to processing under “legitimate interests,” including profiling for recommendations, with a demand that it stop;
— a reference to their own one-month deadline, and a request to confirm receipt;
— on the record: if no answer comes in time, you proceed down their own ladder — TrustArc, then your data protection authority or the FTC.
No explaining why. Only the right, the format, the clock.
Sources: Substack Privacy Policy — substack.com/privacy · Stripe Privacy Policy — stripe.com/privacy · Stripe Data Privacy Framework policy — stripe.com/legal/data-privacy-framework · noyb on the European Parliament case — noyb.eu · EDPS decision 2020-1013 — gdprhub.eu · Latombe v Commission (DPF upheld 3 Sept 2025; on appeal to the CJEU, Case C-703/25 P) — iapp.org · Bowyer et al., 2022, “Human–GDPR Interaction” — arxiv.org/abs/2203.05037
Write to me
Discover more from Lintara
Subscribe to get the latest posts sent to your email.
In case the first answer didn’t come through. I am resending 🙂
Ok, this one is a slow read. But a few times, I think! I get the overall message, but I am going to re-read and parse closely. What I am wondering now, is that one phrase: “The first lock: their own policy reserves the right to keep your data while a complaint is live or a dispute is reasonably foreseeable — even after consent is withdrawn, even after the account is gone.”
That is most important, I think. “reasonably foreseeable” is a statement that is 100% objective — depends on who is judging what is reasonable and what is foreseeable. That is really absurd. Even if people have been banned, and there could never be any complaints made against the intellectual property they’ve posted — they’ve left the door wide open to keep everything forever.
That one really sticks in my craw (a U.S. slang word). It is untranslatable to other languages, I expect. In Spanish, the translation is “Eso me molesta” and all that means is “that upsets me”. Not even close!
In English, loosely translated, it means “to irritate, nag at, or obsess me” and those are close, but one never uses “sticks in my craw” unless it’s really bad.
Russian? Google Translate: Это не застряло у меня
And I doubt that would work either. Anyway, fabulous answer, and thank you. I’ll be keeping this one until I figure out what to do.
Super informative!