
MailerLite
Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 26 Feb 2026
AI Trust Summary
- •Regarding AI: it does not document the use of data for AI training, which creates uncertainties about the use of customer information.
- •Regarding Baseline Privacy: it identifies data recipients, ensuring clarity on who accesses user information.
Safer Alternatives
Higher-rated software in the same category
Attention Points in AI (3)
AI criteria that require attention. Buy the Premium Analysis to see all 3 criteria.
- •MailerLite
- •does not mention the use of data for AI training, creating uncertainties about the application of information.
- •omits a mechanism for contesting AI decisions, limiting customer protection.
- •it is advisable to require contractual clauses that address these aspects.
AI data retention (prompts and responses) is not disclosed
The policy does not mention the retention of AI inputs and outputs, which can create uncertainties about data processing.
Use of data for AI training is not disclosed
The policy does not clarify whether customer data is used to train AI models, creating uncertainties about data use.
Ethical AI principles and anti-bias measures not documented
The policy does not mention ethical AI principles or anti-bias measures, which can raise concerns about fairness in data processing.
Source: vendor public documents
Compliances in AI (3)
AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.
- •MailerLite
- •details the purposes of email address processing, connecting data categories to specific purposes.
- •specifies data retention periods, promoting clarity and trust.
- •these practices facilitate due diligence and demonstrate a commitment to transparency.
Use of artificial intelligence clearly disclosed in policies
The policy mentions the use of automated systems for security and detection, promoting transparency in operations.
AI features clearly identified with their purposes
The policy describes functionalities that imply automation, but does not detail the use of AI, indicating room for improvement.
Automated AI decisions explained in an understandable way
The policy explains that content personalization is done based on preferences, but could be more detailed.
Source: vendor public documents
Highlights in Privacy (3)
Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.
Safeguards for international transfers are not mentioned
The policy mentions legal compliance, but does not address safeguards for international transfers, which can create risks.
Processing purposes clearly listed by data category
The privacy policy connects email address categories and campaign interactions with specific purposes, ensuring transparency.
Data retention period clearly stated
The policy specifies detailed retention periods for different types of data, including cookies, promoting clarity and trust.
Source: vendor public documents
Critical Alerts
- •Mecanismo de contestação de decisões de IA não disponível: Importante para garantir que os clientes possam contestar decisões que impactam suas interações..
- •Salvaguardas para transferência internacional não são mencionadas: Crucial para a proteção dos dados em transferências internacionais.
Conformance analysis (20)
Purposes for processing email addresses clearly listed
Reference: ISO/IEC 27701 (7.3)
Email address retention period clearly informed
Reference: ISO/IEC 27701 (7.4.6)
Recipients of email addresses clearly identified
Reference: ISO/IEC 27701 (7.3)
Source: vendor public documents
Follow this company and access all 20 criteria
Track score changes, get alerts on policy updates, and view the full conformance analysis
Don't miss any update
Sign up to follow this company and track changes in privacy and AI scores
Why trust the AITS Index: Open Community Audit
Public transparency, peer review and open evidence trails — all verifiable by the community
Trust guarantees
Peer review
users, professionals and experts confirm or contest items online.
Public history
vendor and index changes are versioned and accessible.
Participate
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
MailerLite Email Marketing: Privacy and AI Governance Insights
Transparency in Data Usage
MailerLite excels in its transparency regarding data usage, which is crucial for users concerned about their privacy. The platform clearly lists the purposes for which email addresses are processed, allowing users to understand how their data will be utilized. This transparency is reflected in its AITS Privacy Score of 64%, indicating a solid commitment to user privacy. Users can feel more secure knowing that their data is not being used for ambiguous purposes. Additionally, MailerLite specifies the retention periods for email addresses, ensuring that users are informed about how long their data will be stored. This clarity helps users manage their expectations and rights under regulations like GDPR and LGPD, which emphasize the importance of informed consent and data retention policies.
Clear Identification of Data Recipients
Another strength of MailerLite is its ability to identify the recipients of email addresses clearly. This practice is essential for users who want to know who has access to their personal information. By documenting this, MailerLite enhances user trust and aligns with privacy standards set by ISO 27701. Users can rest assured that their data is being handled responsibly, as they can easily track who is accessing their information. This level of transparency is not only a best practice but also a requirement under various data protection regulations, which aim to protect user rights and foster accountability among data processors.
Lack of Clarity on AI Data Usage
Despite its strengths, MailerLite has notable weaknesses, particularly concerning its use of data for AI training. The platform does not disclose whether user data is utilized for training AI models, which raises concerns about data privacy and user consent. This lack of clarity can lead to uncertainty for users who are wary of how their information might be used beyond its intended purpose. The absence of a clear policy on AI data usage is reflected in its low AITS AI Score of 17%, indicating significant room for improvement. Users should be cautious and consider whether they are comfortable with the potential risks associated with undisclosed AI data practices.
Absence of AI Decision Contestation Mechanisms
Another significant weakness is the lack of mechanisms for contesting AI-driven decisions. Users may find themselves at a disadvantage if they are subjected to automated decisions without the ability to challenge or appeal those decisions. This absence could lead to a lack of recourse in situations where users feel that their data has been misused or misinterpreted by AI systems. To mitigate this risk, users should remain vigilant and consider using alternative platforms that offer clearer policies and mechanisms for contesting AI decisions, especially if they are concerned about the implications of automated processing on their data.
International Data Transfer Safeguards Missing
MailerLite also does not mention any safeguards for international data transfers, which is a critical consideration for users. Under GDPR and LGPD, data protection regulations require that adequate safeguards be in place when transferring personal data outside the user's jurisdiction. The absence of such information may expose users to risks related to data privacy and security. Users should check the platform's terms of service and privacy policy for any updates regarding international data transfers. Additionally, it may be prudent to explore alternative email marketing solutions that provide clear assurances regarding data protection during international transfers.
Practical Steps for Users
To enhance their privacy while using MailerLite, users should take proactive steps. First, review the settings related to data sharing and ensure that any features allowing for data usage in AI are disabled if available. Users should also regularly check for updates on the platform's privacy policy to stay informed about any changes in data handling practices. Furthermore, consider using anonymized data or pseudonyms when signing up for services to minimize the risk of exposing personal information. If privacy is a top concern, users may want to explore other email marketing platforms that offer stronger privacy protections and clearer policies regarding AI data usage and international data transfers.
Other Email Marketing software
Dive into in-depth research and analysis of each player

Adobe Marketo Engage
Oracle Eloqua

Brevo

Customer.io

Drip

EngageBay

Zoho Marketing Automation

Constant Contact
Source: vendor public documents
Analyzed Sources
Public documents used in the audit of MailerLite:
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Scope & Limitations
TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).
The content is indicative in nature, intended for screening and comparison, not replacing internal audits.
TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.
Source: vendor public documents