Skip to main content
Customer.io logo

Customer.io

Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 21 Feb 2026

D-
AITS IA

AI Trust Summary

AI Training
Possibly (generic mention of service improvement)
Data Retention
Not specified in documentation
Opt-out
Only generic controls (cookies, ads)
AIPrivacy
D-
BasePrivacy
A+
  • Regarding AI: it does not document data retention criteria for interactions, which creates uncertainties about information management.
  • Regarding Core Privacy: it details the purposes of data processing, making it easier for contractors to understand how their information is used.

Safer Alternatives

Higher-rated software in the same category

See Full Alternative Comparison

Attention Points in AI (2)

AI criteria that require attention. Buy the Premium Analysis to see all 2 criteria.

  • Customer.io
  • Retains AI prompts and responses without specifying deadlines, creating uncertainties about data deletion.
  • Does not mention ethical AI principles, which may generate bias risks.
  • It is advisable to require contractual clauses that define retention periods and clear ethical commitments.

AI data retention (prompts and responses) is not disclosed

The policy mentions retention criteria, but does not specify exact periods for customer data and marketing interactions, creating uncertainties.

Ethical AI principles and anti-bias measures not documented

The policy mentions compliance with privacy principles, but does not address specific commitments regarding the ethical use of AI.

Source: vendor public documents

Compliances in AI (3)

AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.

  • Customer.io
  • Clearly identifies the data controller, facilitating privacy communication.
  • Documents international data transfers, informing about movement to the United States.
  • These practices ensure greater security and clarity in the relationship with clients during due diligence.

Policy on data use for AI training clearly stated

The policy mentions the use of data for 'research and development', but does not clearly specify its use for AI training, generating ambiguity.

AI training opt-out control available

The policy offers opt-out options, but there is no specific control for AI training, limiting customer choice.

Use of artificial intelligence clearly disclosed in policies

The document explicitly lists 'AI' as one of the platform's functionalities, confirming its use in marketing automation.

Source: vendor public documents

Highlights in Privacy (3)

Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.

Data controller and processor roles clearly defined

The policy clearly identifies the responsible company and distinguishes between data collection for its own purposes and as a data processor, essential for transparency.

Data controller identity and contact clearly disclosed

The policy provides clear information about the company's identity and a contact channel, facilitating privacy communication.

Privacy contact channel available

The privacy policy offers a specific channel for privacy issues, allowing customers to effectively exercise their rights.

Source: vendor public documents

Critical Alerts

  • Princípios de IA ética e medidas anti-viés não documentados: A falta de compromisso com a ética na IA pode impactar a confiança dos clientes na automação de marketing..
  • Aspecto de privacidade não mencionado na documentação do fornecedor: Ausência de informação pública

Conformance analysis (20)

Premium Feature
AITS Criterion 9
Compliant

Roles of data controller and processor clearly defined

Reference: ISO/IEC 27701 (7.3)

AITS Criterion 10
Compliant

Identity and contact of the data controller clearly informed

Reference: ISO/IEC 27701 (7.3)

AITS Criterion 11
Compliant

Contact channel for privacy issues available

Reference: ISO/IEC 27701 (7.3)

Source: vendor public documents

Follow this company and access all 20 criteria

Track score changes, get alerts on policy updates, and view the full conformance analysis

Sign up free

Don't miss any update

Sign up to follow this company and track changes in privacy and AI scores

Sign up free

Why trust the AITS Index: Open Community Audit

Public transparency, peer review and open evidence trails — all verifiable by the community

Trust guarantees

Peer review

users, professionals and experts confirm or contest items online.

Public history

vendor and index changes are versioned and accessible.

Participate

Evidence, confirmations and contestations

participate in the collaborative validation of AITS criteria

Contact us

Customer.io Marketing Automation: Privacy and Security Insights

Privacy Strength: Clear Data Controller Identification

Customer.io excels in providing transparency regarding the identity and contact information of its data controller. This is crucial for users as it ensures that they know exactly who is responsible for their data. A clear identification of the data controller allows users to reach out for inquiries or concerns regarding their data, fostering trust and accountability. This transparency is particularly important under regulations like the GDPR and LGPD, which emphasize the need for organizations to be clear about data handling practices. With an OPTI Base Privacy Score of 94%, users can feel confident that Customer.io prioritizes their privacy rights.

Privacy Strength: Detailed Purposes of Data Processing

Another significant strength of Customer.io is its clear listing of data processing purposes categorized by data type. This clarity helps users understand how their information is being utilized, which is essential for informed consent under privacy laws such as GDPR. Users can review these purposes and assess whether they align with their expectations and needs. By knowing exactly how their data will be used, users can make more informed decisions about their engagement with the platform, ensuring that they are comfortable with the data practices in place.

Privacy Weakness: Undefined Retention Periods for AI Interactions

Despite its strengths, Customer.io has notable weaknesses, particularly concerning the retention of prompts and responses generated by its AI features. The absence of a defined retention period raises concerns about how long user interactions are stored and potentially used for future AI training or analysis. This lack of clarity could lead to compliance issues with privacy regulations, as users may not be aware of how long their data is kept. To mitigate this risk, users should inquire directly with Customer.io about their data retention policies and consider limiting the use of AI features if they are uncomfortable with the potential for indefinite data storage.

Privacy Weakness: Lack of Documentation on Ethical AI Principles

Another area of concern is the absence of documented ethical AI principles and anti-bias measures within Customer.io. This gap can lead to uncertainties regarding how the platform ensures fair and unbiased treatment of user data. Users should be aware that without these safeguards, there may be risks of biased outcomes in marketing automation processes. To address this, users are encouraged to actively seek information from Customer.io about their commitment to ethical AI practices and consider implementing additional checks or balances in their marketing strategies to ensure fairness and transparency.

Practical Guidance: Settings to Check for Enhanced Privacy

For users looking to enhance their privacy while using Customer.io, it is advisable to review the settings related to data sharing and AI features. Ensure that any options for data sharing with third parties are disabled unless absolutely necessary. Additionally, consider adjusting settings that pertain to the use of AI-generated content, particularly if you have concerns about data retention. Regularly reviewing these settings can help users maintain control over their data and ensure compliance with privacy regulations such as GDPR and LGPD.

Practical Guidance: Alternatives and Precautions

If the weaknesses in Customer.io's AI documentation and data retention policies are significant concerns, users might want to explore alternative marketing automation platforms that offer clearer guidelines and stronger commitments to ethical AI practices. Platforms that provide comprehensive documentation on data retention, ethical AI principles, and anti-bias measures can offer greater peace of mind. Users should also consider implementing regular audits of their marketing practices to ensure compliance with privacy regulations and to safeguard user data effectively.

Other Marketing Automation software

Dive into in-depth research and analysis of each player

Source: vendor public documents

Analyzed Sources

Public documents used in the audit of Customer.io:

Evidence, confirmations and contestations

participate in the collaborative validation of AITS criteria

Contact us

Scope & Limitations

TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).

The content is indicative in nature, intended for screening and comparison, not replacing internal audits.

TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.

Source: vendor public documents