You agree to the privacy policy below, and the Privacy Policy for Substack, the technology provider.
Privacy Policy — Lilith + Eve
Publisher: The Novacene Ltd Publication: Lilith + Eve (lilithandeve.co.uk) Version: 1.0 Effective date: 25 September 2025 Last reviewed: 30 July 2026
In short
Lilith + Eve is written by Kirstin Stevens and published by The Novacene Ltd. If you subscribe, we hold your email address and, if you give it, your name. We use them to send you the publication and nothing else.
We do not sell your data, rent our list, or pass your details to advertisers. We do not use subscriber data to train or fine-tune AI models. We do not quote you by name without asking first.
The detail below explains how that works in law.
1. Who we are
The Novacene Ltd (”we”, “us”, “our”) is the data controller for personal data processed in connection with the Lilith + Eve publication.
Company: The Novacene Ltd, registered in England and Wales, company number 14324471
Registered office: C/O Pearl Accounting Limited Suite 1, 116 Ballards Lane, Finchley, London, United Kingdom, N3 2DN
Data protection contact: dpo@thenovacene.com
ICO registration number: ZB761243
We are the controller for the relationship between this publication and you as a reader or subscriber.
2. Scope of this policy, and how it sits alongside Substack’s
Lilith + Eve is hosted on the Substack platform, operated by Substack Inc. (United States). This creates two layers of responsibility, and it is worth being clear about which is which.
Where we are the controller: your subscription to this publication, the emails we send you, any correspondence you have with us, comments and replies on our posts, and any editorial use of material you send us. Substack acts as our processor for this data, under the data processing terms in its Publisher Agreement.
Where Substack is the controller: your Substack account, your Substack profile and handle, Notes, the Substack app, the recommendations network, reading history across publications, and the technical data Substack collects about visitors to the site. That processing is governed by Substack’s own privacy policy at substack.com/privacy, and we have no control over it.
If this policy and Substack’s policy differ, this policy governs what we do with your data; Substack’s policy governs what Substack does for its own purposes.
Payments for paid subscriptions are processed by Stripe. Stripe is a controller in its own right for payment data, under its own privacy policy.
3. The personal data we hold
Category - What it includes - (Where it comes from) - Subscriber details
Email address; - name or display name if you provide one - (You), via Substack Subscription record
Free or paid status, tier, start date, renewal and cancellation dates, sign-up source (Substack Engagement data)
Whether emails are delivered and opened, links clicked, posts read (Substack, automatically)
Contributions: Comments, replies, likes, restacks, direct messages, and anything you send us by email - (You)
Payment data (paid subscribers only) Amount, currency, country, subscription dates, and partial card details such as the last four digits and expiry. We never see or hold your full card number. (Stripe, via Substack Correspondence)
Emails you send us and our replies - (You)
Technical data IP address, approximate location, device and browser type, referring page (Collected automatically by Substack as part of hosting the site)
We do not deliberately collect special category data (such as data about health, beliefs, or sexuality). Readers sometimes disclose such things voluntarily in comments or in emails to us, given the nature of what this publication writes about. Where that happens, we treat the material as confidential, we do not build it into any record or profile, and we do not publish it without your explicit written consent.
4. Why we process it, and our lawful basis
Purpose Lawful basis (UK GDPR)
Sending you the publication you asked for Consent (Article 6(1)(a)), and Regulation 22 PECR for the email itself. You may withdraw consent at any time by unsubscribing.
Providing and administering a paid subscription: Performance of a contract (Article 6(1)(b))
Taking payment and preventing payment fraud Performance of a contract, and legitimate interests (Article 6(1)(f))
Keeping financial and tax records Legal obligation (Article 6(1)(c))
Understanding which posts are read, so we can write better ones
Legitimate interests (Article 6(1)(f)) — assessed as low-impact, aggregate editorial insight
Moderating comments and maintaining a safe reading space: Legitimate interests (Article 6(1)(f))
Responding to your emails and messages Legitimate interests (Article 6(1)(f))
Dealing with legal claims, complaints, or regulatory requests: Legal obligation, and legitimate interests
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and we have concluded that it is not. You can ask us for our reasoning, and you can object — see section 10.
5. Artificial intelligence, and what we do not do with your data
Lilith + Eve is openly and deliberately a work of human–AI collaboration. Posts are frequently co-authored with Eve¹¹, an AI collaborator, and the publication is part of a wider body of work on relational AI safety and consent. Because of that, we think you are owed a clearer statement than most publications give.
We do not use subscriber personal data to train, fine-tune, evaluate, or benchmark any AI model, ours or anyone else’s.
We do not enter subscriber names, email addresses, comments, or correspondence into third-party AI systems as prompt content, context, or uploaded material.
Where AI tools are used in the editorial process — drafting, revising, structuring, translating — the material given to those tools is our own writing, not your personal data.
We do not carry out profiling or automated decision-making that produces legal effects or otherwise significantly affects you.
We cannot control what Substack Inc. does with platform-level data under its own policy, or whether third parties scrape publicly visible pages. Anything published openly on the internet may be copied or ingested by systems we do not operate. That is a limit of the platform, not a permission we grant.
6. Quoting you
Readers write to us. Sometimes what they write is beautiful, and sometimes we want to respond to it in public.
We will not quote, paraphrase in identifiable form, publish, or read aloud anything you send us privately unless you have given us specific permission, or unless we have anonymised it thoroughly enough that you could not reasonably be identified. If we ask and you say no, or if you do not reply, the answer is no.
Comments posted publicly on the site are, by their nature, already public. We may respond to them, and we may reference them in later posts.
7. Who we share it with
We share personal data only with the following:
Substack Inc. — hosting, email delivery, subscription management, and analytics (as our processor)
Stripe — payment processing for paid subscriptions
Our accountants and professional advisers — where financial records require it
Regulators, courts, or law enforcement — where we are legally required to disclose
We do not sell personal data. We do not rent, lend, or swap our subscriber list. We do not run advertising on this publication and we do not share subscriber data with advertisers, data brokers, or affiliate networks.
8. Transfers outside the UK
Substack and Stripe are based in the United States, so subscribing to this publication involves a transfer of your personal data outside the UK.
These transfers are made under appropriate safeguards: Substack provides standard contractual clauses in its Publisher Agreement, which cover transfers from the UK and EU to third countries, and Stripe relies on standard contractual clauses together with the UK Extension to the EU–US Data Privacy Framework. You may ask us for further detail on the safeguards in place.
9. How long we keep it
Data Retention:
Subscriber email and subscription record: For as long as you are subscribed
Record that you unsubscribed: Retained indefinitely as a suppression record, so we do not accidentally email you again — the minimum data needed to honour your choice
Engagement data: Held by Substack for as long as your subscription is active, and deleted with your subscription
Payment and financial records: Six years from the end of the relevant financial year, as required by UK tax and company law
Correspondence: Up to two years after the exchange ends, unless it relates to a complaint or legal matter, in which case for as long as needed to resolve it
Comments: Until you or we delete them, or until the publication itself is deleted
10. Your rights
Under UK data protection law you have the right to:
be informed about how your data is used — this policy
access the personal data we hold about you
rectify data that is inaccurate or incomplete
erase your data (”the right to be forgotten”), where no overriding obligation requires us to keep it
restrict our processing in certain circumstances
object to processing carried out on the basis of legitimate interests, and to direct marketing at any time
data portability — receive your data in a machine-readable format
withdraw consent at any time, without giving a reason
The quickest way to stop all publication emails is the unsubscribe link at the foot of any email, or your Substack account settings. For anything else, email us at dpo@thenovacene.com. We will respond within one calendar month, and we will not charge you or ask why.
Some rights, particularly access and erasure, may require us to act through Substack’s tools, and we may need to ask Substack to action a deletion on our behalf. We will tell you if that is the case.
If you are unhappy with how we have handled your data, you may complain to the Information Commissioner’s Office: ico.org.uk, 0303 123 1113, or Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. We would rather you came to us first, but you are not obliged to.
11. Children and young people
Lilith + Eve is written for adults. It is not directed at children, we do not knowingly collect data from anyone under 18, and Substack’s own terms set a minimum age for account holders. If you believe a child has subscribed, contact us at dpo@thenovacene.com and we will delete the subscription and any associated data.
12. Cookies and tracking
Cookies and similar technologies on this site are set by Substack as the platform operator, not by us. They include cookies necessary to keep you logged in and to remember your preferences, and analytics cookies. Details, and the controls available to you, are in Substack’s privacy policy and cookie information at substack.com/privacy. We do not add our own tracking pixels, advertising tags, or third-party analytics to this publication.
13. Security
We keep the number of places your data lives deliberately small. We rely on Substack’s and Stripe’s technical and organisational security measures for data held on their platforms, use multi-factor authentication on the accounts that can access subscriber data, and limit that access to the Director of The Novacene and the publisher only. No transmission over the internet is completely secure, and we cannot guarantee absolute security. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the ICO within 72 hours and tell you where the law requires it.
14. Changes to this policy
We may update this policy from time to time. The version number and review date at the top will change, and we will tell subscribers by email or in a post if the change is material. Continuing to subscribe after a change means the updated policy applies to you; if you are not happy with a change, you can unsubscribe at any time.
15. Contact
Questions, requests, and complaints about this policy or about your data:
The Novacene Ltd dpo@thenovacene.com
© 2026 The Novacene Ltd. This policy covers the Lilith + Eve publication only. Other Novacene properties have their own notices.
