The Data Ownership Test Every Publisher Should Run

Every subscription business is running on somebody else’s platform. What most publishers don’t examine closely is what that means for the subscribers themselves. The list, the payment history, the engagement data, the relationships between subscribers and content, some of it sits on your infrastructure, some of it sits on somebody else’s, and the split matters more than the marketing pages let on.

Publishers have understood “own your email list” as gospel for twenty years. The instinct is right. The scope was always too narrow. Your subscriber list is a small part of the data your subscription business generates. The rest is scattered across paywall software, ESPs, WordPress hosts, payment processors, and CRMs, each holding a slice of the picture, each on its own roadmap, each with its own definition of what “your data” actually means, and each renewing on its own cadence.

That definition is worth checking. Because the platforms you’re renting subscriber access from can and do change what they’re allowed to do with the data you thought was yours.

Data ownership on a hosted platform has several dimensions. This piece isolates three of them and asks you to check each on the platforms you’re on.

The premise: what “your data” means depends on the platform

You can watch this playing out right now. On July 27, 2026, Patreon’s new memberships become public by default. Existing memberships stay private. New ones show up on member profiles unless the subscriber flips a toggle they may not know exists.

Reframe what actually changed. On July 26, the fact that someone subscribed to your Patreon was private data held on Patreon’s servers. On July 27, that same fact becomes public data displayed on Patreon’s platform. Nothing about the underlying data record changed. What changed was what Patreon decided it was allowed to do with it, without asking the subscriber and without asking you.

That’s the pattern to notice. Data ownership on a hosted platform is a series of decisions made by the platform owner, updated at the platform’s pace, applied to your subscribers.

Memberful, owned by Patreon since 2018, isn’t affected on July 27. But if you’re a Memberful publisher, you just watched the parent company demonstrate what it thinks its rights are to member data. The demonstration was on Patreon.com. The precedent applies broadly.

Question 1: Who has physical custody of your subscriber data?

Data ownership starts with possession. Custody means direct database access. Export permission is separate, and often more permissive than actual data ownership.

Every platform will tell you your data is yours. That claim is doing a lot of work. On a hosted platform, your subscriber records live in the platform’s database. You get an interface to view them, a dashboard to manage them, an export function to download them, and terms of service that describe what happens next.

Looking to grow your publication?

Sign up for expert advice straight to your inbox.
This field is for validation purposes and should be left unchanged.

What you don’t get is the database itself.

That distinction matters when the platform decides to change what it’s doing with the data it holds. Public-by-default profiles. Home feed activity displays. Cross-platform discovery features. Model training on member behavior. Every one of those is a decision the custodian gets to make, and none of them requires asking the person whose data it is.

For historical context, look at what Patreon said when they acquired Memberful in 2018. Patreon’s VP of product wrote that Memberful served creators who wanted to “own the relationship with their fans, not relinquish control” to platforms with ulterior motives to please advertisers. Both statements were true when they were made. Eight years is enough time for a roadmap to move well beyond its founding promises.

The practical check: for every platform in your stack, know where the data physically sits and who has direct database access. Your paywall platform: your infrastructure or theirs? Your ESP: hosted by them or self-hosted? Your CRM: their cloud or your install? Your payment processor: which system holds the customer records? “We’re the custodian” and “you’re the owner” are two claims that can be true at once. The gap between them is what changes when the platform updates its defaults.

Question 2: What can the platform do with your subscriber data without your permission?

This is the one publishers miss. Beyond possession, data ownership is about rights: what the custodian is allowed to do with what they hold, without asking you.

Read the terms of service you accepted five years ago. Every hosted platform reserves the right to change what it does with the data it holds. Add features that display it differently. Aggregate it across accounts for analytics. Train models on behavior patterns. Share it with partners in the parent company’s ecosystem. Change the default visibility of fields you thought were private.

Patreon’s public-by-default change makes this concrete. A subscription record that was private is now public unless the subscriber opts out. Neither the subscriber nor you authorized the change. Patreon decided it was allowed, and it was.

The practical check: audit what your platform’s terms allow, not what its current product does. Current behavior is the floor. Future behavior is bounded by the terms, and the terms are more permissive than most publishers realize. Look specifically for: rights to modify default privacy settings, rights to display member data in new product surfaces, rights to use aggregated behavior data for platform improvements, and rights to share data with the parent company or affiliated services.

Question 3: If you left tomorrow, what would you actually get to take with you?

The third dimension of data ownership is exit: what survives when you try to leave. The technical reality is often narrower than the marketing pages suggest.

Every platform advertises data portability. The advertising is almost always true and almost always incomplete. What you export is not what you had.

Look at what happens when a publisher tries to leave a hosted subscription platform. The email list exports as a CSV. That’s real, and it matters. What doesn’t export cleanly: subscription history in a format your new platform can ingest without reconstruction. Payment method tokens, which is why you have to re-authenticate every subscriber’s payment on migration. Engagement history tied to specific content items. Custom fields the platform structured differently than your next platform does. The web of relationships between subscribers and content that made your retention model work.

Intuit’s Mailchimp trajectory shows what happens when the platform you’re on stops matching your business. Publicly documented pricing history since Intuit acquired Mailchimp in November 2021 for roughly $12 billion shows a consistent direction. The free plan went from 2,000 contacts to 500 in 2023 to 250 in January 2026. Paid plan prices rose more than 30 percent between 2022 and 2023. Legacy accounts got hit with an 11 to 13 percent increase in April 2026.

Publishers who tried to leave during those pricing shifts discovered what portability actually looked like. The list came out. The historical send data, deliverability reputation, integration configurations, and requirements to re-verify subscribers largely did not. The switching cost was high enough that most publishers stayed and paid.

The practical check: know what leaving looks like before you’re forced to consider it. Do a mock migration this quarter for at least one platform in your stack. Export everything the platform will let you export. Look at the format. Ask your next-most-likely platform’s onboarding team what they’d need to import you cleanly. The gap between what you can take and what you’d need to reconstruct is the true switching cost. Publishers who move well already know that number. Publishers who stay stuck find out during the fire.

How to run the test on your own stack

The three questions apply to every layer of your subscription business.

Run them against your email service provider. Against your WordPress host. Against your CRM. Against your payment processor. Any layer where subscriber data lives is a platform bet worth reviewing.

The check runs quarterly because platform terms and default behaviors change more often than most publishers check. A ten-minute review each quarter is cheaper than an emergency migration.

For each platform, write down where the data sits, what the terms allow, and what you’d take if you left. If any answer is “I don’t know” or “I haven’t looked in a while,” that’s where the review starts. Most quarters, the answer will be: data custody is stable, permissions are unchanged. Occasionally the answer will be: start planning a migration while there’s no urgency.

The one platform bet you can shrink

Leaky Paywall runs as a WordPress plugin inside your own install. That means your subscriber records live in your WordPress database, on your infrastructure, in a schema you can query directly. Not a dashboard view of records held elsewhere. The actual records.

That doesn’t eliminate platform risk. You still bet on WordPress core, your host, and Stripe for payments. But it moves the subscription data layer from “hosted somewhere and exposed through an interface” to “sitting in your database.” Which changes what the answers to all three questions look like.

That trade isn’t right for every publisher. Hosted platforms are often the right call for podcasters who need private feeds without custom setup, for teams without technical resources, for creators who work best in a managed dashboard, and for anyone whose subscription platform isn’t the layer they want to think about. The question is whether you know which trade you made and whether the answers to the three questions still fit your business.

The best time to audit your data ownership was five years ago. The second-best time is this quarter.

Learn how Leaky Paywall can help grow your subscription revenue