Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy asserts legitimate interests under GDPR Article 6(1)(f) as the legal basis for using all categories of collected data, including user content, to develop and improve AI models.
This analysis describes what Grammarly's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes legitimate interests as the sole GDPR legal basis for AI development processing across all data categories, including user content such as emails and documents; users in the EEA and UK have the right to object to processing on this basis under GDPR Article 21.
Interpretive note: The adequacy of legitimate interests as a GDPR legal basis for AI training using all data categories, including user content, is subject to evolving regulatory guidance from EEA data protection authorities and has not been definitively established through enforcement decisions.
The updated policy now discloses that Grammarly collects voice data if you use transcription or Notetaker features, including recordings of other participants, and expands its list of collected content to explicitly include screen content and web pages. For users whose accounts are managed by an organization (employer, school, or other entity), the policy clarifies that Grammarly's privacy terms do not apply to the content you upload or output—your organization's privacy terms govern that data instead. This means organizational account users should review their organization's privacy policies rather than relying on Grammarly's policy to understand how their work or educational data is handled.
View change record →Under this provision, all categories of personal data including user content may be processed for AI development purposes on the basis of Superhuman's asserted legitimate interests under GDPR Article 6(1)(f). EEA and UK users have the right to object to this processing, and users globally may exercise the account-level AI training opt-out described separately in the policy.
Cross-platform context
See how other platforms handle GDPR Legal Bases for AI Development Processing and similar clauses.
Compare across platforms →Monitoring
Grammarly has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"To develop and improve AI: All categories of data. We have a legitimate interest in operating and improving our services and developing new products through the use of AI (Art. 6 (1)(f) GDPR/ UK GDPR).Excerpt from Grammarly's Privacy Policy
1) REGULATORY LANDSCAPE: GDPR Article 6(1)(f) requires that processing based on legitimate interests pass a three-part test: the interest must be legitimate, processing must be necessary, and the controller's interests must not be overridden by the data subject's interests or fundamental rights. EEA data protection authorities including the EDPB have issued guidance indicating that AI training using customer content requires careful legitimate interests balancing, particularly where the processing involves sensitive or confidential content categories. GDPR Article 21 provides data subjects the right to object to legitimate interests processing. 2) GOVERNANCE EXPOSURE: Medium to High. The reliance on legitimate interests for processing all data categories for AI development, without a consent alternative, may face scrutiny from EEA supervisory authorities. The policy's account-level opt-out mechanism may be assessed as equivalent to a right to object in practice, but the adequacy of this mechanism as a substitute for formal Article 21 objection procedures has not been established in this document. 3) JURISDICTION FLAGS: EEA and UK users face the most direct exposure, as GDPR and UK GDPR impose enforceable constraints on legitimate interests processing. Swiss users are similarly affected under the Swiss Federal Act on Data Protection. Users in jurisdictions without equivalent legal basis requirements are not protected by this specific provision. 4) CONTRACT AND VENDOR IMPLICATIONS: Organizations whose employee-generated content flows through Superhuman under organizational accounts should confirm whether the organizational data processing agreement restricts AI development use of that content, as the legitimate interests basis described in this policy applies to individual user accounts. 5) COMPLIANCE CONSIDERATIONS: Legal teams for EEA and UK users or organizational deployers should assess whether the legitimate interests balancing test is documented in a data protection impact assessment or legitimate interests assessment, and whether the account-level opt-out satisfies the operational requirements of GDPR Article 21's right to object. A data protection authority consultation or regulatory guidance review may be warranted for organizational deployments at scale.
This provision establishes legitimate interests as the sole GDPR legal basis for AI development processing across all data categories, including user content such as emails and documents; users in the EEA and UK have the right to object to processing on this basis under GDPR Article 21.
Under this provision, all categories of personal data including user content may be processed for AI development purposes on the basis of Superhuman's asserted legitimate interests under GDPR Article 6(1)(f). EEA and UK users have the right to object to this processing, and users globally may exercise the account-level AI training opt-out described separately in the policy.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Grammarly.