

AWeber
Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 26 Feb 2026
AI Trust Summary
- •In AI: it does not document ethical AI principles, which can create uncertainties about the responsible use of data.
- •In Basic Privacy: it does not mention safeguards for processing sensitive data, exposing financial information to risks.
Safer Alternatives
Higher-rated software in the same category
Attention Points in AI (1)
AI criteria that require attention. Buy the Premium Analysis to see all 1 criteria.
- •AWeber
- •Does not document ethical AI principles, which exposes the company to risks of irresponsible data use.
- •The processing of sensitive data is mentioned without additional safeguards, which can compromise the security of financial information.
- •It is necessary to require specific contractual clauses to mitigate these risks.
Ethical AI principles and anti-bias measures not documented
There is no mention of ethical or responsible AI principles in the analyzed documents, which may raise concerns about usage practices.
Source: vendor public documents
Compliances in AI (3)
AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.
- •AWeber
- •Clearly documents data controller and processor roles, increasing transparency.
- •Provides detailed information about the controller's identity and contact methods, enhancing customer trust.
- •These practices facilitate due diligence and trust in the commercial relationship.
Use of artificial intelligence clearly disclosed in policies
The policy informs about the use of an AI writing assistant, allowing customers to understand how this may impact their email campaigns.
AI features clearly identified with their purposes
The policy describes automation and AI functionalities, such as automatic content creation, helping customers understand their use.
AI training opt-out control available
Although opt-out mechanisms exist, there is no clear option for the use of email and interaction data in AI training.
Source: vendor public documents
Highlights in Privacy (3)
Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.
Sensitive data processing without additional documented safeguards
The policy mentions 'sensitive information' without additional safeguards, which may expose financial data and credentials to risks.
Data controller and processor roles clearly defined
AWeber clearly identifies its roles as controller of Customer data and processor of Subscriber data, ensuring transparency.
Data controller identity and contact clearly disclosed
The policy provides clear information about AWeber's identity and multiple contact methods, increasing customer trust.
Source: vendor public documents
Critical Alerts
- •Tratamento de dados sensíveis sem salvaguardas adicionais documentadas: Importante para proteger informações sensíveis dos clientes e evitar vazamentos..
- •Controle de opt-out para treinamento de IA disponível: Importante para que os clientes tenham controle sobre como seus dados são utilizados.
Conformance analysis (20)
Clearly defined data controller and processor roles
Reference: ISO/IEC 27701 (7.3)
Data controller's identity and contact clearly informed
Reference: ISO/IEC 27701 (7.3)
Purposes of processing clearly listed by data category
Reference: ISO/IEC 27701 (7.3)
Source: vendor public documents
Follow this company and access all 20 criteria
Track score changes, get alerts on policy updates, and view the full conformance analysis
Don't miss any update
Sign up to follow this company and track changes in privacy and AI scores
Why trust the AITS Index: Open Community Audit
Public transparency, peer review and open evidence trails — all verifiable by the community
Trust guarantees
Peer review
users, professionals and experts confirm or contest items online.
Public history
vendor and index changes are versioned and accessible.
Participate
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
AWeber Email Marketing: Privacy and Security Insights
Clear Data Roles and Responsibilities
AWeber excels in defining the roles of data controller and processor, which is crucial for transparency in data handling. This clarity helps users understand who is responsible for their data and how it is managed. With an OPTI Base (Privacy) Score of 69%, AWeber ensures that users are informed about the identity and contact details of the data controller. This transparency is essential for compliance with regulations like the GDPR and LGPD, which emphasize user rights regarding personal data. Users can feel more secure knowing that their data is handled by a clearly defined entity, reducing the risk of mismanagement.
Transparency in Data Processing Purposes
Another strength of AWeber is its clear listing of data processing purposes categorized by data type. This practice aligns with best practices under GDPR, which requires that users be informed about how their data will be used. By providing this information, AWeber empowers users to make informed decisions about their data. Users should regularly review these purposes to ensure they align with their expectations and preferences, and they can reach out to AWeber for clarification if needed.
Lack of Ethical AI Principles
Despite its strengths, AWeber has notable weaknesses, particularly in the area of AI governance. The platform does not document ethical AI principles or anti-bias measures, which raises concerns about how user data may be utilized in AI training processes. With an OPTI IA Score of 46%, users should be aware that their data could be used in ways that they might not fully understand or agree with. This lack of transparency can lead to potential misuse of data, especially in sensitive applications.
Insufficient Safeguards for Sensitive Data
AWeber's handling of sensitive data also presents a risk. The absence of documented safeguards for processing sensitive information means that users' financial and personal data could be exposed to vulnerabilities. This is particularly concerning for users who may be subject to regulations like the LGPD, which mandates strict protections for sensitive data. Users should consider limiting the amount of sensitive information they share through the platform and regularly audit their data settings to minimize exposure.
Practical Steps for Enhanced Privacy
To mitigate the risks associated with AWeber's weaknesses, users should take proactive steps. First, review the settings related to data sharing and opt-out options for AI training. Ensure that you have disabled any features that allow your data to be used for AI purposes unless you are comfortable with it. Additionally, consider using alternative platforms that provide clearer documentation on ethical AI practices if this is a significant concern for you.
Regular Data Audits and User Rights
Lastly, users should conduct regular audits of their data within AWeber. Familiarize yourself with your rights under GDPR and LGPD, such as the right to access, rectify, or delete your data. Make sure to utilize AWeber's contact information for the data controller to address any concerns or requests regarding your data. By staying informed and proactive, users can better protect their privacy while using AWeber's email marketing services.
Other Email Marketing software
Dive into in-depth research and analysis of each player

Adobe Marketo Engage
Oracle Eloqua

Brevo

Customer.io

Drip

EngageBay

Zoho Marketing Automation

Constant Contact
Source: vendor public documents
Analyzed Sources
Public documents used in the audit of AWeber:
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Scope & Limitations
TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).
The content is indicative in nature, intended for screening and comparison, not replacing internal audits.
TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.
Source: vendor public documents