

Customer.io
Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 21 Feb 2026
AI Trust Summary
- •Regarding AI: it does not document data retention criteria for interactions, which creates uncertainties about information management.
- •Regarding Core Privacy: it details the purposes of data processing, making it easier for contractors to understand how their information is used.
Safer Alternatives
Higher-rated software in the same category
Attention Points in AI (2)
AI criteria that require attention. Buy the Premium Analysis to see all 2 criteria.
- •Customer.io
- •Retains AI prompts and responses without specifying deadlines, creating uncertainties about data deletion.
- •Does not mention ethical AI principles, which may generate bias risks.
- •It is advisable to require contractual clauses that define retention periods and clear ethical commitments.
AI data retention (prompts and responses) is not disclosed
The policy mentions retention criteria, but does not specify exact periods for customer data and marketing interactions, creating uncertainties.
Ethical AI principles and anti-bias measures not documented
The policy mentions compliance with privacy principles, but does not address specific commitments regarding the ethical use of AI.
Source: vendor public documents
Compliances in AI (3)
AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.
- •Customer.io
- •Clearly identifies the data controller, facilitating privacy communication.
- •Documents international data transfers, informing about movement to the United States.
- •These practices ensure greater security and clarity in the relationship with clients during due diligence.
Policy on data use for AI training clearly stated
The policy mentions the use of data for 'research and development', but does not clearly specify its use for AI training, generating ambiguity.
AI training opt-out control available
The policy offers opt-out options, but there is no specific control for AI training, limiting customer choice.
Use of artificial intelligence clearly disclosed in policies
The document explicitly lists 'AI' as one of the platform's functionalities, confirming its use in marketing automation.
Source: vendor public documents
Highlights in Privacy (3)
Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.
Data controller and processor roles clearly defined
The policy clearly identifies the responsible company and distinguishes between data collection for its own purposes and as a data processor, essential for transparency.
Data controller identity and contact clearly disclosed
The policy provides clear information about the company's identity and a contact channel, facilitating privacy communication.
Privacy contact channel available
The privacy policy offers a specific channel for privacy issues, allowing customers to effectively exercise their rights.
Source: vendor public documents
Critical Alerts
- •Princípios de IA ética e medidas anti-viés não documentados: A falta de compromisso com a ética na IA pode impactar a confiança dos clientes na automação de marketing..
- •Aspecto de privacidade não mencionado na documentação do fornecedor: Ausência de informação pública
Conformance analysis (20)
Roles of data controller and processor clearly defined
Reference: ISO/IEC 27701 (7.3)
Identity and contact of the data controller clearly informed
Reference: ISO/IEC 27701 (7.3)
Contact channel for privacy issues available
Reference: ISO/IEC 27701 (7.3)
Source: vendor public documents
Follow this company and access all 20 criteria
Track score changes, get alerts on policy updates, and view the full conformance analysis
Don't miss any update
Sign up to follow this company and track changes in privacy and AI scores
Why trust the AITS Index: Open Community Audit
Public transparency, peer review and open evidence trails — all verifiable by the community
Trust guarantees
Peer review
users, professionals and experts confirm or contest items online.
Public history
vendor and index changes are versioned and accessible.
Participate
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Customer.io Marketing Automation: Privacy and Security Insights
Privacy Strength: Clear Data Controller Identification
Customer.io excels in providing transparency regarding the identity and contact information of its data controller. This is crucial for users as it ensures that they know exactly who is responsible for their data. A clear identification of the data controller allows users to reach out for inquiries or concerns regarding their data, fostering trust and accountability. This transparency is particularly important under regulations like the GDPR and LGPD, which emphasize the need for organizations to be clear about data handling practices. With an OPTI Base Privacy Score of 94%, users can feel confident that Customer.io prioritizes their privacy rights.
Privacy Strength: Detailed Purposes of Data Processing
Another significant strength of Customer.io is its clear listing of data processing purposes categorized by data type. This clarity helps users understand how their information is being utilized, which is essential for informed consent under privacy laws such as GDPR. Users can review these purposes and assess whether they align with their expectations and needs. By knowing exactly how their data will be used, users can make more informed decisions about their engagement with the platform, ensuring that they are comfortable with the data practices in place.
Privacy Weakness: Undefined Retention Periods for AI Interactions
Despite its strengths, Customer.io has notable weaknesses, particularly concerning the retention of prompts and responses generated by its AI features. The absence of a defined retention period raises concerns about how long user interactions are stored and potentially used for future AI training or analysis. This lack of clarity could lead to compliance issues with privacy regulations, as users may not be aware of how long their data is kept. To mitigate this risk, users should inquire directly with Customer.io about their data retention policies and consider limiting the use of AI features if they are uncomfortable with the potential for indefinite data storage.
Privacy Weakness: Lack of Documentation on Ethical AI Principles
Another area of concern is the absence of documented ethical AI principles and anti-bias measures within Customer.io. This gap can lead to uncertainties regarding how the platform ensures fair and unbiased treatment of user data. Users should be aware that without these safeguards, there may be risks of biased outcomes in marketing automation processes. To address this, users are encouraged to actively seek information from Customer.io about their commitment to ethical AI practices and consider implementing additional checks or balances in their marketing strategies to ensure fairness and transparency.
Practical Guidance: Settings to Check for Enhanced Privacy
For users looking to enhance their privacy while using Customer.io, it is advisable to review the settings related to data sharing and AI features. Ensure that any options for data sharing with third parties are disabled unless absolutely necessary. Additionally, consider adjusting settings that pertain to the use of AI-generated content, particularly if you have concerns about data retention. Regularly reviewing these settings can help users maintain control over their data and ensure compliance with privacy regulations such as GDPR and LGPD.
Practical Guidance: Alternatives and Precautions
If the weaknesses in Customer.io's AI documentation and data retention policies are significant concerns, users might want to explore alternative marketing automation platforms that offer clearer guidelines and stronger commitments to ethical AI practices. Platforms that provide comprehensive documentation on data retention, ethical AI principles, and anti-bias measures can offer greater peace of mind. Users should also consider implementing regular audits of their marketing practices to ensure compliance with privacy regulations and to safeguard user data effectively.
Other Marketing Automation software
Dive into in-depth research and analysis of each player
Source: vendor public documents
Analyzed Sources
Public documents used in the audit of Customer.io:
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Scope & Limitations
TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).
The content is indicative in nature, intended for screening and comparison, not replacing internal audits.
TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.
Source: vendor public documents





