

Mailchimp
Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 26 Feb 2026
AI Trust Summary
- •Regarding AI: it does not document which functionalities use AI, which can create uncertainties about data processing.
- •Regarding Core Privacy: it does not mention the use of data for AI training, raising concerns about user data privacy and security.
Safer Alternatives
Higher-rated software in the same category
Attention Points in AI (3)
AI criteria that require attention. Buy the Premium Analysis to see all 3 criteria.
- •Mailchimp
- •Does not identify specific functionalities that use AI, which creates uncertainties about data processing.
- •Does not mention the use of data for AI training, raising privacy concerns.
- •It is advisable to require contractual clauses that detail the use of AI and the processing of sensitive data.
Features using AI are not identified in the policy
Lack of clarity on which functionalities use AI can create uncertainties about the processing of email addresses and campaign interactions.
Automated AI decisions have no explanation available
The absence of explanations about automated decisions can generate distrust regarding the processing of email addresses and campaign interactions.
AI data retention (prompts and responses) is not disclosed
Lack of information about AI data retention can impact transparency in the processing of email addresses and campaign interactions.
Source: vendor public documents
Compliances in AI (3)
AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.
- •Mailchimp
- •Clearly identifies the responsible company (Intuit Inc.) and provides multiple contact channels.
- •Explicitly declares the use of artificial intelligence in its policy, highlighting a dedicated section on 'Responsible AI'.
- •These practices facilitate transparency and trust in user data management.
Use of artificial intelligence clearly disclosed in policies
The policy confirms the use of artificial intelligence, essential for understanding how email addresses and campaign interactions are processed.
AI training opt-out control available
The policy offers control over the use of email addresses and campaign interactions for AI training, promoting privacy.
Commitments to ethical AI and anti-bias measures clearly documented
The policy mentions a commitment to responsible AI, important to ensure that email addresses and campaign interactions are treated fairly.
Source: vendor public documents
Highlights in Privacy (3)
Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.
Data retention period not stated in the policy
The absence of information about the retention period for email addresses can impact compliance with data protection laws.
Data controller identity and contact clearly disclosed
The identification of the responsible company and its contacts are essential for transparency in the processing of email addresses.
Personal data recipients clearly identified in the policy
The policy mentions how email addresses and campaign interactions are shared, increasing transparency for customers.
Source: vendor public documents
Critical Alerts
- •Uso de dados para treinamento de IA não é declarado: A transparência sobre o uso de dados para treinamento é essencial para a confiança dos usuários..
- •Tratamento de dados sensíveis sem salvaguardas adicionais documentadas: A proteção de dados sensíveis é crucial para a conformidade e segurança dos usuários.
Conformance analysis (20)
Use of artificial intelligence clearly stated in policies
Reference: ISO/IEC 42001 (7.4)
Data controller's identity and contact clearly informed
Reference: ISO/IEC 27701 (7.3)
Recipients of personal data clearly identified in the policy
Reference: ISO/IEC 27701 (7.3)
Source: vendor public documents
Follow this company and access all 20 criteria
Track score changes, get alerts on policy updates, and view the full conformance analysis
Don't miss any update
Sign up to follow this company and track changes in privacy and AI scores
Why trust the AITS Index: Open Community Audit
Public transparency, peer review and open evidence trails — all verifiable by the community
Trust guarantees
Peer review
users, professionals and experts confirm or contest items online.
Public history
vendor and index changes are versioned and accessible.
Participate
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Mailchimp Email Marketing: Privacy and AI Governance Insights
Clear Data Controller Identity
Mailchimp excels in providing transparency regarding the identity of the data controller. Users can easily access contact information and understand who is responsible for their data. This clarity is crucial for users who want to know whom to contact in case of data-related inquiries or issues. With a score of undefined/3 in this area, Mailchimp demonstrates a commitment to user rights under regulations like GDPR and LGPD, which emphasize the importance of clear data governance.
Transparent AI Usage Policies
Another strength of Mailchimp is its clear declaration of AI usage within its policies. Users are informed about the purposes for which their data is processed, categorized by data type. This transparency helps users make informed decisions about their data and its usage. However, with an AITS Privacy Score of 25%, it is essential to remain vigilant about how AI functionalities may impact data privacy.
Lack of AI Functionality Disclosure
Despite its strengths, Mailchimp has notable weaknesses, particularly in the area of AI functionality. The platform does not specify which features utilize AI, leading to uncertainty about how user data is processed. This lack of clarity can be concerning, especially for users who are cautious about how their data is leveraged. Users should consider reviewing their settings to limit data exposure and ensure they are comfortable with the functionalities they are using.
Unclear AI Training Data Usage
Additionally, Mailchimp does not disclose whether user data is used for AI training purposes. This omission raises significant privacy concerns, particularly under GDPR and LGPD regulations that protect user data from being used without explicit consent. Users should be proactive in understanding how their data might be utilized and consider reaching out to Mailchimp for clarification on this matter.
Sensitive Data Handling Risks
Mailchimp's handling of sensitive data also presents a risk, as there are no documented additional safeguards for such data. This lack of protection can expose users to potential breaches or misuse of their sensitive information. Users should take precautions by avoiding the input of sensitive data into the platform and regularly reviewing their data management practices to ensure compliance with privacy regulations.
Practical Steps for Enhanced Privacy
To mitigate the risks associated with Mailchimp’s weaknesses, users should take practical steps. First, regularly check privacy settings to ensure that data sharing is minimized. Users can also explore alternatives that provide more robust privacy features or consider using Mailchimp in conjunction with additional privacy-focused tools. Staying informed about updates to Mailchimp’s policies and features can also help users maintain control over their data.
Other Email Marketing software
Dive into in-depth research and analysis of each player

Adobe Marketo Engage
Oracle Eloqua

Brevo

Customer.io

Drip

EngageBay

Zoho Marketing Automation

Constant Contact
Source: vendor public documents
Analyzed Sources
Public documents used in the audit of Mailchimp:
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Scope & Limitations
TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).
The content is indicative in nature, intended for screening and comparison, not replacing internal audits.
TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.
Source: vendor public documents