How much of your writing does Grammarly see? More text than any other AI tool in your environment — email, drafts, chat, internal documents — which is the structural fact to weigh.
UNDER RE-VERIFICATION — 13 August 2026. The vendor has changed identity. grammarly.com now serves the privacy policy of Superhuman, effective 6 July 2026, following the company’s rebrand after the Superhuman and Coda acquisitions. Grammarly is now presented as one product within a wider Superhuman suite that also includes Mail, Docs, Databases and agents. That changes which entity you contract with and whose terms govern your text, and it may change the tier structure described below. The tier detail, pricing and the training-opt-out positions on this page were verified on 24 May 2026 against Grammarly-branded terms and have not yet been re-checked against the Superhuman policy. Treat the specifics below as provisional until this notice is removed. One part of this is already resolved. The claim that individual users on the lower tiers cannot opt out of model improvement was wrong, and is corrected below. The rating is unchanged at 3 of 5 for those tiers — but it now rests on the correct basis, set out in the next paragraph.
Plain-English risk rating: 3 of 5 (Free/Premium) / 2 of 5 (Business/Enterprise)
Why 3, on our published scale. A 3 means industry-typical: training on by default for the consumer tier, with an opt-out available. That is exactly where Grammarly Free, Premium and single-user Pro now sit. This page previously justified the same 3 by saying no opt-out existed — which, on our own scale, would have described a 4. The number was right; the reasoning underneath it was not. Both are now aligned (13 August 2026).
Why it does not drop to 2 now that the control is confirmed. A 2 is for a strong posture with structural caveats, which is where admin-enforced tiers belong. On the individual tiers the control is on by default, set per user, and invisible to anyone else — an owner cannot see whether staff have turned it off, cannot enforce it, and gets no report if a new hire never touches it. For a business, an unverifiable per-user setting is a materially weaker protection than an admin-enforced one, and that gap is what keeps these tiers at 3 while Business and Enterprise sit at 2.
Grammarly is one of the most-deployed writing AI tools in the SMB and individual professional segments, with reported user base of approximately 30 million daily active users across hundreds of millions of registered accounts. The risk picture is dominated by one structural fact: Grammarly's browser extension and desktop client read essentially all text the user types in applications where Grammarly is active, including email, document drafts, chat messages, and any other text field. The platform processes this text on Grammarly's servers (and at LLM provider servers for AI-generated suggestions and rewrites) to produce its corrections and rewrites.
The scale of text content that crosses Grammarly's systems for an active business user is substantial. The privacy posture relies on Grammarly's commitments to not process content in sensitive fields (credit card forms, passwords, URLs) and the contractual no-training commitments at Business and Enterprise tiers. The structurally important fact for SMBs: individual users on Free and Premium CAN opt out — the control is called Product Improvement and Training and it is on until they turn it off — but only a Business account administrator can switch it off for everyone and confirm it stayed off.
Recommended for
- Sole proprietor: Premium at $12/month acceptable for general writing. Switch off Product Improvement and Training at account.grammarly.com/security/privacy. It is on until you do, so until then your typed text contributes to model improvement under Grammarly's terms. Switching it off stops future use; it does not retrieve text already used.
- Small team (2-10 people): Business at $15/user/month for contractual no-training and admin controls. The training opt-out is admin-controlled at this tier (not individual-controlled), so the workspace admin needs to configure the opt-out actively.
- Regulated industry: Enterprise tier with BAA where applicable, strict allowed-applications policy, and explicit policy guidance to team members about which content classes should be excluded from Grammarly processing.
- The honest answer for most 1-10 employee businesses: Grammarly is one of the most-pervasive AI tools in your environment if even one team member uses it. The right posture is: standardise on Business tier with admin controls; have the admin actively configure the training opt-out; document which applications Grammarly is allowed to operate in; treat the breadth of text Grammarly sees as a category-level data governance question rather than a per-employee decision.
Correction: an individual training opt-out DOES exist
Earlier versions of this page said individual users on Free and Premium could not opt out of model training, and that only Business administrators held the control. That was wrong, and it was wrong against the vendor. Corrected 13 August 2026.
Grammarly’s own support documentation describes a Product Improvement and Training control that lets users of Free, Premium and single-user Pro accounts opt out of having their content — including content processed by Grammarly Go — used to train its models. Where to find it: account.grammarly.com/security/privacy, the “Product Improvement and Training” toggle.
The caution that survives, and it is still the one that matters: the toggle is ON by default for individual users. Training happens unless somebody turns it off, and nothing prompts you to. For a business, the practical instruction is not “avoid the free tier” but “have every person who uses Grammarly open that settings page and check” — which is a five-minute job across a small team and was not possible under our previous, incorrect account of the product.
Two further details worth knowing. Multi-user team accounts bought through the website start with Product Improvement and Training ON, and an admin can opt the whole organisation out. If someone leaves a team account and reverts to an individual account, the team’s setting carries over to their personal account, and the toggle remains visible and changeable — so a departing staff member does not silently revert to training-on.
Grammarly's stated mitigations: text in sensitive fields (passwords, credit card numbers, URLs) is not processed; user-generated content is anonymised before being used for training; users can manually delete content from their account. None of these mitigations changes the fundamental fact that the individual user has no toggle to opt out.
The practical implication: if any employee in your business uses Grammarly Premium for work tasks, their typed text has been incorporated into Grammarly's model improvement pipeline. The fix, cheapest first: (a) switch off Product Improvement and Training in the account settings of the person using it – free, takes a minute, and this profile previously failed to mention it; (b) move that employee to Business tier on your account with admin opt-out configured, which is the only version an administrator can enforce and audit across staff; or (c) accept that the data is in the pipeline and document it for your privacy posture. Note that (a) stops future use but does not retrieve text already used.
Data retention default
- Free, Premium: Text processed for corrections retained per Grammarly's standard data lifecycle; user-generated content may be used for model improvement (anonymised) but an individual opt-out DOES exist – it is the same control described in the training section above: Product Improvement and Training, ON by default, switched off at account.grammarly.com/security/privacy for Free and Premium, or account.grammarly.com/admin/data_settings for single-user Pro. Verified 31 August 2026 against Grammarly own support article
- Business, Enterprise: Stronger contractual retention controls; admin-configurable opt-out from model improvement use; verify current configuration per tenant
- AI-generated rewrites (GrammarlyGO): LLM provider processing under zero-retention contracts for paid tiers
- Sensitive-field exclusion: Grammarly does not process text in fields recognised as password, credit card, or sensitive URL types
Training opt-out
Free — INDIVIDUAL OPT-OUT AVAILABLE, but ON by default. Turn off “Product Improvement and Training” at account.grammarly.com/security/privacy. Until you do, your content may be used to train the models.
Premium and single-user Pro — INDIVIDUAL OPT-OUT AVAILABLE, same toggle, also ON by default. Premium is being migrated to Grammarly Pro: began March 2025, gradual, cannot be declined, billing unchanged.
Business — ADMIN-CONFIGURABLE OPT-OUT. The workspace administrator can opt the entire account out of model improvement use. This is the inflection point where Grammarly becomes appropriate for business use with client-sensitive content.
Enterprise — NO TRAINING ON CUSTOMER CONTENT BY DEFAULT per contractual terms; stronger admin controls.
Zero Data Retention availability
- Available at Business and Enterprise tiers via zero-retention LLM provider contracts for AI rewrite features
- Custom data handling terms negotiable for Enterprise customers
Plan tiers and pricing (as of early 2026)
| Tier | Price (USD) | Training default | Suitable for |
|---|---|---|---|
| Free | $0 | On by default; individual opt-out available | Personal use; light corrections only |
| Premium | $12/month | On by default; individual opt-out available | Individual professionals; consider Business for client work |
| Business | $15/user/month (3-user min) | Admin-configurable opt-out | Small teams |
| Enterprise | Custom | No training by default | Larger orgs needing SSO, audit, admin controls |
Jurisdiction
- Primary processor: Grammarly Inc., San Francisco, California, USA (with Kyiv, Ukraine engineering presence)
- Cloud infrastructure: AWS primarily
- Third-party AI subprocessors: OpenAI, Anthropic under contractual no-training arrangements for paid Business and Enterprise tiers
- SOC 2 Type II, ISO 27001 certified; HIPAA available at Enterprise with BAA
- GDPR-compliant; data stored in the United States with global access by Grammarly engineering teams per published privacy policy
Breach history (public incidents)
February 2018 — Browser extension authentication token vulnerability (Tavis Ormandy / Google Project Zero)
Google Project Zero researcher Tavis Ormandy disclosed a critical vulnerability in Grammarly's browser extension that allowed any visited website to read the user's Grammarly account contents and stored documents. The exposure affected approximately 22 million users. Grammarly patched within hours of disclosure. The vulnerability arose from how Grammarly's browser extension exposed authentication tokens to web pages on which the extension operated.
Sources: Google Project Zero disclosure (February 2018); SecurityWeek coverage
2023 — API security flaw (Salt Labs research)
Salt Labs researchers identified an OAuth-related vulnerability affecting Grammarly, Vidio, and Bukalapak that could have allowed account takeover for affected users. The vulnerability category (OAuth implementation flaw allowing token interception) is one of the most-common authentication issues for SaaS products. Grammarly patched the issue. Salt Labs researcher Yaniv Balmas noted that the issues affected more than one billion users across the three platforms combined.
Source: Infosecurity Magazine coverage of Salt Labs disclosure
No major publicly-disclosed Grammarly AI-specific breach as of May 2026.
Category-level risk: Grammarly's breadth-of-text-access combined with browser-extension architecture creates a particular risk profile — a compromised Grammarly extension or account has access to every text field on every site the user visits. The 2018 disclosure and the 2023 Salt Labs API issue are useful reminders of how this attack surface manifests. The mitigations are: keep the extension updated, use multi-factor authentication on the Grammarly account, periodically review which sites have Grammarly active.
What this means in plain English for SMB owners
Three honest takeaways:
- Grammarly sees more of your text than any other AI tool in your environment. This is the structural fact to internalise. The breadth of text classes — email, drafts, chat, code comments, search queries, internal documents — is substantial. Treat this as a data governance question, not a feature decision.
- The Free and Premium tiers do not let individual users opt out of training data use. Only Business tier accounts (with admin-configurable opt-out) provide this control. The $15/user/month upgrade from Premium is the inflection point for any team handling client work. For sole proprietors who cannot justify Business tier, the realistic mitigation is per-application control (disable Grammarly on sensitive applications) rather than training opt-out.
- App-level controls matter regardless of tier. Grammarly's extension can be disabled per-application; use this for genuinely sensitive applications (legal document drafting, financial spreadsheets, regulated data entry, anything client-confidential). The control exists; using it is operational discipline.
The tier names on this page are changing
Treat the tier table below as transitional. The parent company renamed itself from Grammarly to Superhuman in late 2025 after acquiring Superhuman and Coda — the company rebranded, not the writing product, which is still called Grammarly. Alongside that, Grammarly Premium is being migrated to Grammarly Pro (began March 2025, gradual, no opt-out, same billing), and Pro has effectively replaced the old Grammarly Business plan by absorbing its light team features. Coda is becoming Superhuman Docs. A Superhuman Pro subscription now bundles Go, Grammarly and Coda; Business and Enterprise add Mail.
Why this matters beyond naming: if you buy the suite, one subscription now spans your writing assistant, your email client and your documents — so the data-governance question stops being about a browser extension and becomes a question about the whole company’s written output. The Superhuman privacy policy also states that companies within the Superhuman corporate family may access your information for business operations, product integration and improvement. Decide about the suite deliberately rather than arriving at it through an upgrade prompt.
Sources
- Grammarly privacy and security documentation (grammarly.com/privacy, verified 2026-05-24)
- Grammarly Trust Center for current certifications
- Grammarly Business and Enterprise feature documentation
- Grammarly: Demystifying Generative AI Security Risks blog post (September 2024)
- Cybershore: Grammarly Security and Privacy Due Diligence Report (September 2024)
- Google Project Zero disclosure of browser extension vulnerability (February 2018)
- SecurityWeek: Grammarly Rushes to Patch Flaw Exposing User Data (2018)
- Infosecurity Magazine: API Security Flaw Impacted Grammarly Vidio and Bukalapak (Salt Labs research coverage)
- UpGuard: Grammarly Security Rating vendor risk report (verified 2026-05-21)
Related on AI Leakage
- Compare all 29 AI tools in the risk directory — see how Grammarly (with Grammarly AI / GrammarlyGO) stacks up against the rest, tier by tier.
- Take the 5-minute “Am I Leaking?” check — a personalised view of your business’s AI exposure.
- Check a prompt before you paste it — our free Data-Safe Prompt Rewriter.
- Shadow AI vs AI leakage — why even approved tools like Grammarly (with Grammarly AI / GrammarlyGO) can leak data.
- Get plain-English AI Leakage Alerts — we email you when an AI tool you use changes its data policy or has an incident.
- Get the free AI Acceptable Use Policy template — a plain-English policy with the tool-by-tool risk guide built in.
