Grammarly · Grammarly Privacy Policy · View original document ↗

Organizational User Privacy Policy Carve-Out

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Grammarly changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Grammarly Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy states it does not apply to content uploaded to or output from products used under organizational account management; such content is processed under the data processing agreement between Superhuman and the managing organization, not under this policy.

This analysis describes what Grammarly's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that individual employees or institutional users who access Superhuman products through employer or institution-managed accounts cannot exercise data rights under this policy for their work-related content; those rights must be directed to the managing organization.

Recent Activity

This document changed recently

Medium Jul 7, 2026

The updated policy now discloses that Grammarly collects voice data if you use transcription or Notetaker features, including recordings of other participants, and expands its list of collected content to explicitly include screen content and web pages. For users whose accounts are managed by an organization (employer, school, or other entity), the policy clarifies that Grammarly's privacy terms do not apply to the content you upload or output—your organization's privacy terms govern that data instead. This means organizational account users should review their organization's privacy policies rather than relying on Grammarly's policy to understand how their work or educational data is handled.

View change record →

Consumer impact (what this means for users)

Under this clause, users who access Superhuman products through an employer, school, or other organizational account are not covered by this privacy policy with respect to their uploaded content and outputs. The agreement directs such users to contact their organization to exercise data rights related to that content.

Cross-platform context

See how other platforms handle Organizational User Privacy Policy Carve-Out and similar clauses.

Compare across platforms →

Monitoring

Grammarly has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
If you use our products under the management of a company, organization, educational institution, or other legal entity (such as if your employer gives you access to our inbox assistant tools for work or if you open an account on behalf of an entity), this Privacy Policy won't apply to the information you upload to or output from our products. Please see more info below.

Excerpt from Grammarly's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: This provision establishes Superhuman as a data processor rather than data controller for organizational account content, engaging GDPR Articles 28 and 29 regarding processor obligations and the requirement for a data processing agreement between controller (the organization) and processor (Superhuman). Under CCPA/CPRA, the B2B exemption and service provider framework similarly distinguish between consumer-facing and business-to-business data processing. 2) GOVERNANCE EXPOSURE: High for organizational deployers. The carve-out means that employee data rights under GDPR, CCPA, and equivalent state laws must be operationalized through the organization's own data processing agreement with Superhuman, which is not reproduced or summarized in this policy. Organizations that have not reviewed or updated that agreement face exposure if it does not adequately reflect current processing activities or data subject rights procedures. 3) JURISDICTION FLAGS: EEA and UK organizations must ensure a GDPR-compliant data processing agreement is in place as a legal requirement, not merely a contractual preference. Educational institutions in the US should assess FERPA applicability depending on the nature of content processed through organizational accounts. 4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams at organizations deploying Superhuman should obtain, review, and maintain a current copy of the data processing agreement with Superhuman Platform Inc. The policy states Superhuman will refer individual data rights requests to the managing organization, meaning the organization must have an operational process to receive and respond to such requests. 5) COMPLIANCE CONSIDERATIONS: Organizations should audit whether their internal privacy notices adequately disclose Superhuman's role as a data processor for employee-generated content, and whether employee consent mechanisms or legitimate interests assessments cover the specific processing activities Superhuman performs on organizational account content.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Applicable agencies

  • FTC
    The FTC has jurisdiction over consumer protection and data practices; organizational data processing arrangements that affect employee personal data may engage FTC oversight of unfair or deceptive practices.
    File a complaint →

Provision details

Document information
Document
Grammarly Privacy Policy
Entity
Grammarly
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-015874
Document ID
CA-D-00456
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
7c74cfd243c4d415033b559955787624b7005dd4395d828c2e66590e2225ee5f
Analysis generated
July 9, 2026 09:01 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Grammarly
Document: Grammarly Privacy Policy
Record ID: CA-P-015874
Captured: 2026-07-09 09:01:20 UTC
SHA-256: 7c74cfd243c4d415…
URL: https://conductatlas.com/platform/grammarly/grammarly-privacy-policy/provision/CA-P-015874/organizational-user-privacy-policy-carve-out/
Accessed: July 24, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does Grammarly's Organizational User Privacy Policy Carve-Out clause do?

This provision establishes that individual employees or institutional users who access Superhuman products through employer or institution-managed accounts cannot exercise data rights under this policy for their work-related content; those rights must be directed to the managing organization.

How does this clause affect you?

Under this clause, users who access Superhuman products through an employer, school, or other organizational account are not covered by this privacy policy with respect to their uploaded content and outputs. The agreement directs such users to contact their organization to exercise data rights related to that content.

Is ConductAtlas affiliated with Grammarly?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Grammarly.