Skip to main content
Litmus logo

Litmus

Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 26 Feb 2026

D-
AITS IA

AI Trust Summary

AI Training
Possibly (generic mention of service improvement)
Data Retention
Not specified in documentation
Opt-out
Only generic controls (cookies, ads)
AIPrivacy
D-
BasePrivacy
A-
  • In AI: it does not document ethical AI principles, which may raise concerns about bias and discrimination.
  • In Core Privacy: it does not specify retention periods for interaction data, leading to uncertainties about user information management.

Safer Alternatives

Higher-rated software in the same category

See Full Alternative Comparison

Attention Points in AI (3)

AI criteria that require attention. Buy the Premium Analysis to see all 3 criteria.

  • Litmus
  • Does not specify retention periods for interaction data, which may lead to uncertainties.
  • Does not mention ethical AI principles, exposing risks of bias.
  • It is advisable to require contractual clauses that address data retention and ethical AI use.

AI data retention (prompts and responses) is not disclosed

The policy does not specify retention periods for email interaction and user behavior data, which may lead to uncertainties.

Ethical AI principles and anti-bias measures not documented

Litmus does not mention commitments to the ethical use of AI, which may raise concerns about bias and discrimination.

AI decision contestation mechanism not available

The policy does not offer a clear mechanism to contest automated decisions, which may impact user trust.

Source: vendor public documents

Compliances in AI (3)

AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.

  • Litmus
  • Clearly defines data controller and processor roles, ensuring transparency.
  • Provides a Data Processing Agreement (DPA) for business customers, ensuring protection under privacy standards.
  • These practices strengthen trust and security in the business relationship.

AI features clearly identified with their purposes

The policy mentions services that use AI, but does not detail how each functionality contributes to the user experience.

AI training opt-out control available

Litmus offers privacy control options, but not a specific opt-out for the use of data in AI training.

Policy on data use for AI training clearly stated

The policy mentions the use of email interaction and user behavior data to improve services, but in a generic way.

Source: vendor public documents

Highlights in Privacy (3)

Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.

Data controller and processor roles clearly defined

The policy clearly identifies Litmus as responsible for email interaction and user behavior data, ensuring transparency.

Personal data recipients clearly identified in the policy

The policy details who receives email interaction and user behavior data, increasing customer trust.

Data Processing Agreement (DPA) available for business customers

Litmus offers a DPA, ensuring that business customers are protected under privacy standards.

Source: vendor public documents

Critical Alerts

  • Princípios de IA ética e medidas anti-viés não documentados: Importante para a responsabilidade e ética no uso de IA em marketing..
  • Mecanismo de contestação de decisões de IA não disponível: Crucial para a transparência e confiança em decisões automatizadas.

Conformance analysis (20)

Premium Feature
AITS Criterion 9
Compliant

Clearly defined data controller and processor roles

Reference: ISO/IEC 27701 (7.3)

AITS Criterion 14
Compliant

Recipients of personal data clearly identified in the policy

Reference: ISO/IEC 27701 (7.3)

AITS Criterion 20
Compliant

Data Processing Agreement (DPA) available for business customers

Reference: ISO/IEC 27701 (8.2) + LGPD Art. 39 + GDPR Art. 28

Source: vendor public documents

Follow this company and access all 20 criteria

Track score changes, get alerts on policy updates, and view the full conformance analysis

Sign up free

Don't miss any update

Sign up to follow this company and track changes in privacy and AI scores

Sign up free

Why trust the AITS Index: Open Community Audit

Public transparency, peer review and open evidence trails — all verifiable by the community

Trust guarantees

Peer review

users, professionals and experts confirm or contest items online.

Public history

vendor and index changes are versioned and accessible.

Participate

Evidence, confirmations and contestations

participate in the collaborative validation of AITS criteria

Contact us

Litmus Email Marketing: Privacy and AI Governance Insights

Clear Data Roles Enhance User Trust

Litmus excels in defining the roles of data controller and data processor, which is crucial for transparency in email marketing practices. With an OPTI Base Privacy Score of 83%, users can feel reassured that their data is being handled responsibly. This clarity means that users know who is accountable for their data, which is vital for compliance with regulations like GDPR and LGPD. For businesses, this transparency can enhance customer trust and improve engagement rates, as clients are more likely to interact with brands that respect their privacy.

Identified Data Recipients Strengthen Compliance

Another strength of Litmus is its clear identification of data recipients in its privacy policy. This aspect is essential for users who want to understand how their personal information is shared and used. Knowing who has access to their data allows users to make informed decisions about their engagement with the platform. This practice not only aligns with GDPR requirements but also helps users mitigate risks associated with unauthorized data sharing.

Undefined Data Retention Periods Raise Concerns

Despite its strengths, Litmus has notable weaknesses, particularly regarding the retention of AI prompts and responses. The absence of defined retention periods can lead to uncertainty about how long user data is stored. This lack of clarity may raise concerns for users who prioritize data privacy and compliance with regulations like GDPR. Users should be aware that indefinite data retention could expose them to risks, including potential data breaches or misuse of their information.

Lack of Ethical AI Principles

Another significant weakness is the absence of documented ethical AI principles and anti-bias measures. With an OPTI IA Score of 29%, this indicates that users should approach Litmus's AI features with caution. The lack of transparency in AI governance can lead to biases in email targeting and content generation, which may affect user experience and brand reputation. Users should consider this when utilizing AI-driven features and remain vigilant about the outputs generated by the software.

Practical Steps for Enhanced Privacy Protection

To mitigate the risks associated with undefined data retention and AI governance, users can take proactive steps. First, regularly review the privacy settings within Litmus to ensure that data sharing preferences align with your privacy expectations. Additionally, consider limiting the use of AI features until more robust ethical guidelines are established. Users can also reach out to Litmus support for clarification on data retention policies and express their concerns regarding AI governance, encouraging the company to prioritize these issues.

Exploring Alternatives for Comprehensive Governance

If the weaknesses in Litmus's privacy and AI governance are concerning, users might explore alternative email marketing platforms that offer clearer data retention policies and documented ethical AI practices. Look for platforms that provide detailed information about their compliance with GDPR, LGPD, and ISO 27701 standards. These alternatives may offer better transparency and risk management, ensuring that your email marketing efforts are both effective and compliant with privacy regulations.

Other Email Marketing software

Dive into in-depth research and analysis of each player

Source: vendor public documents

Evidence, confirmations and contestations

participate in the collaborative validation of AITS criteria

Contact us

Scope & Limitations

TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).

The content is indicative in nature, intended for screening and comparison, not replacing internal audits.

TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.

Source: vendor public documents