Back to Home
Grammarly logo

Grammarly Privacy Summary

grammarly.comLast updated: 04/09/2026
Productivity

AI-powered productivity platform that provides email and writing assistance, inbox management, and third-party integrations to streamline work across tools.

This summary was generated using AI and may contain errors or omissions. Learn about our methodology. Always refer to the original privacy policy for legal purposes.

Quick Summary

  • What They Collect: Account details, emails/documents, contacts, payments, device and usage data, cookies, and inferred profile attributes.
  • How They Use & Share It: Used to power AI features, improve products, secure systems, and for marketing; shared with affiliates, service providers, marketplace partners, and advertising networks (opt-outs available).
  • Your Rights: Access, correct, delete, portability (region-specific), withdraw consent, opt out of targeted ads, and disable AI training via settings.

Why You Should Care About Grammarly's Privacy Practices

  • Superhuman processes highly sensitive user content (emails, documents) which can be used to build AI models and affect privacy and intellectual property.
  • Behavioral profiling and targeted advertising use identifiers and inferences, impacting ad targeting and personalization across the web.
  • International transfers and vague retention ('as long as necessary') increase legal complexity and long-term data exposure risks.
  • Mandatory arbitration and unrestricted feedback use reduce users’ legal leverage and allow the company broad rights over suggestions and improvements.

Why High Exposure?

  • Superhuman processes extensive personal data including emails, documents, files, and inferred profile details for product functionality.
  • The policy discloses sharing identifiers and activity with advertising networks and social networks for targeted advertising and promotion.
  • User content is used to develop and train AI models by default (though an opt-out is offered in settings).
  • Data transfers occur internationally under Data Privacy Frameworks or standard contractual clauses, and retention is described only as 'as long as necessary'.
Learn more about our methodology →

Privacy Highlights

What They Collect

  • Account information
  • Profile information
  • User content and files
  • Payment information
  • Demographic information

How They Share Data

  • Business affiliates and subsidiaries
  • Service providers (hosting, payments, customer support, AI providers, cloud storage)
  • Analytics and measurement partners
  • Advertising partners / Advertising networks

Data Retention

Personal data is retained 'as long as necessary' to provide services, complete transactions, comply with law, and for legitimate business purposes; retention varies by data type and some records (e.g., opt-out flags) are kept longer for compliance.

Your Rights

  • Access data
  • Rectify data
  • Erase or limit processing
  • Object to processing

Detailed Analysis

Concerning Practices

  • Uses user content and other data to develop and train AI models (users can opt out via settings)
  • Automated processing and scanning of user content for product features and AI
  • Shares identifiers and activity with advertising networks and social networks for targeted marketing
  • International data transfers (EEA/UK/Switzerland to US under Data Privacy Frameworks and SCCs)
  • Retention language is vague — data kept “as long as necessary” with varying timeframes by type
  • Feedback and suggestions may be used by the company without restriction
  • Mandatory arbitration and class-action waiver in the Terms of Service
  • Collects data about non-users (contact information included in user content and contact uploads)

Personal Data Types

Account informationProfile informationUser content and filesPayment informationDemographic informationFeedback dataSupport dataContact sync dataLinked account dataDevice and technical information (IP address, OS, browser type, device IDs)Geolocation informationService usage informationWebsite usage dataLog and event dataThird-party demographic data (from ad partners or data brokers)

Tracking Methods

CookiesPixelsLocal storage

Third Parties

Business affiliates and subsidiariesService providers (hosting, payments, customer support, AI providers, cloud storage)Analytics and measurement partnersAdvertising partners / Advertising networksThird-party app/integration developers (Marketplace participants)Government authorities and law enforcementAcquirers or successors in sale or merger scenarios

User Controls

Access dataRectify dataErase or limit processingObject to processingData portability (region-specific: EU/UK and various State laws)Withdraw consentOpt-out of marketingDelete accountRequest data copy or exportAI training control (opt out of using user content to train AI)Control cookie and similar technology preferencesAuthorized agent requests (California and other state provisions)

Frequently Asked Questions About Grammarly

Legal Disclaimer

This analysis is provided for informational purposes only and should not be used as legal advice. Privacy Exposure ratings and summaries are AI-generated assessments based on publicly available privacy policies — they are not statements of fact and may contain errors. Learn how ratings are determined. Consult with legal professionals for matters requiring legal guidance.