

Buttondown
Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 26 Feb 2026
AI Trust Summary
- •In AI: it does not document ethical AI principles, which may impact trust in data use.
- •In Core Privacy: data processing purposes are clearly listed, ensuring transparency regarding the use of email addresses.
Safer Alternatives
Higher-rated software in the same category
Attention Points in AI (3)
AI criteria that require attention. Buy the Premium Analysis to see all 3 criteria.
- •Buttondown
- •Does not document ethical AI principles, which may impact trust in data use.
- •Does not mention explanations of automated decisions, limiting algorithmic transparency.
- •Requiring documentation on AI ethics and explanations of automated decisions can mitigate risks.
Ethical AI principles and anti-bias measures not documented
There is no mention of ethical AI principles, which may impact trust in the use of email addresses and user interactions.
Features using AI are not identified in the policy
The absence of a description of AI-powered functionalities may create uncertainties about the processing of email addresses.
Automated AI decisions have no explanation available
The lack of explanations for automated decisions may impact trust in the processing of email addresses.
Source: vendor public documents
Compliances in AI (2)
AI criteria the company meets. Buy the Premium Analysis to see all 2 criteria.
- •Buttondown
- •Data processing purposes are clearly listed, detailing uses such as marketing and security.
- •The identity of the data controller is clearly stated, providing users with confidence.
- •These practices facilitate due diligence and risk assessment for your company.
Policy on data use for AI training clearly stated
The policy mentions the use of information for 'internal analysis', but it is unclear whether this includes AI training.
AI training opt-out control available
The policy offers generic controls, but there is no specific opt-out for AI training, which limits options for users.
Source: vendor public documents
Highlights in Privacy (3)
Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.
Safeguards for international transfers are not mentioned
The policy does not mention specific safeguards for international transfers, which may create risks for data.
Privacy contact channel available
The privacy policy provides a specific contact channel for privacy, facilitating communication with the DPO.
Data controller and processor roles clearly defined
The policy clearly identifies the responsible company, ensuring transparency about who manages email addresses and user interactions.
Source: vendor public documents
Critical Alerts
- •Decisões automatizadas por IA não têm explicação disponível: A transparência nas decisões automatizadas é crucial para a confiança dos usuários..
- •Mecanismo de contestação de decisões de IA não disponível: Permitir contestação é fundamental para a proteção dos direitos dos usuários.
Conformance analysis (20)
Contact channel for privacy issues available
Reference: ISO/IEC 27701 (7.3)
Roles of data controller and processor clearly defined
Reference: ISO/IEC 27701 (7.3)
Identity and contact of the data controller clearly stated
Reference: ISO/IEC 27701 (7.3)
Source: vendor public documents
Follow this company and access all 20 criteria
Track score changes, get alerts on policy updates, and view the full conformance analysis
Don't miss any update
Sign up to follow this company and track changes in privacy and AI scores
Why trust the AITS Index: Open Community Audit
Public transparency, peer review and open evidence trails — all verifiable by the community
Trust guarantees
Peer review
users, professionals and experts confirm or contest items online.
Public history
vendor and index changes are versioned and accessible.
Participate
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Buttondown Email Marketing: Privacy and AI Governance Insights
Clear Data Processing Purposes
Buttondown excels in transparency regarding its data processing purposes. The platform clearly categorizes the reasons for processing email addresses, which is crucial for users who want to understand how their data is being utilized. This clarity aligns with GDPR requirements, ensuring that users are informed about the specific purposes for which their personal data is collected. For users, this means you can trust that your email address is not being used for undisclosed reasons, enhancing your overall confidence in the platform.
Defined Roles of Data Controllers and Processors
Another strength of Buttondown is its clear definition of the roles of data controllers and processors. This distinction is vital for users as it outlines who is responsible for data management and protection. Knowing that Buttondown identifies itself as the data controller helps users understand their rights under regulations like LGPD and GDPR. This transparency can empower users to hold the company accountable for data protection practices, ensuring that their information is handled responsibly.
Lack of Ethical AI Principles
Despite its strengths in privacy, Buttondown has notable weaknesses in its approach to artificial intelligence. The absence of documented ethical AI principles raises concerns about how user data may be processed and utilized by AI algorithms. For users, this means there is a lack of assurance that their data is being treated fairly and without bias. Without these principles, users may feel uncertain about the integrity of automated decisions made by the platform, which could impact their trust in its services.
Unexplained Automated Decisions
Another significant weakness is the lack of explanations for automated decisions made by Buttondown's AI. Users should be aware that when AI is involved in decision-making processes, it is crucial to understand the rationale behind those decisions. The absence of this information can lead to confusion and mistrust, especially if users feel that their email marketing strategies are being influenced by opaque algorithms. To mitigate this risk, users should consider monitoring their campaign performance closely and be prepared to question any unexpected outcomes.
No Mechanism for Contesting AI Decisions
Buttondown also lacks a mechanism for contesting decisions made by its AI systems. This absence can be problematic for users who may want to challenge automated outcomes that they believe are incorrect or unfair. Without a clear process for contestation, users may feel powerless in situations where AI decisions adversely affect their marketing efforts. As a precaution, users should maintain a manual oversight of their campaigns and be proactive in seeking support from Buttondown if they encounter issues related to AI-driven decisions.
Practical Steps for Enhanced Privacy and AI Governance
To enhance your experience with Buttondown, consider reviewing your account settings to ensure that you are aware of how your data is being used. Enable features that allow you to control your data preferences and opt out of any unnecessary data processing. Additionally, familiarize yourself with Buttondown's support resources to understand how to address any concerns regarding AI decisions. If you are particularly sensitive to AI implications, you may want to explore alternative email marketing platforms that offer more robust transparency and ethical AI practices. By taking these steps, you can better protect your data and ensure that your email marketing strategies align with your privacy expectations.
Other Email Marketing software
Dive into in-depth research and analysis of each player

Adobe Marketo Engage
Oracle Eloqua

Brevo

Customer.io

Drip

EngageBay

Zoho Marketing Automation

Constant Contact
Source: vendor public documents
Analyzed Sources
Public documents used in the audit of Buttondown:
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Scope & Limitations
TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).
The content is indicative in nature, intended for screening and comparison, not replacing internal audits.
TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.
Source: vendor public documents