Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states it does not apply to content uploaded to or output from products used under organizational account management; such content is processed under the data processing agreement between Superhuman and the managing organization, not under this policy.
This analysis describes what Grammarly's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that individual employees or institutional users who access Superhuman products through employer or institution-managed accounts cannot exercise data rights under this policy for their work-related content; those rights must be directed to the managing organization.
The updated policy now discloses that Grammarly collects voice data if you use transcription or Notetaker features, including recordings of other participants, and expands its list of collected content to explicitly include screen content and web pages. For users whose accounts are managed by an organization (employer, school, or other entity), the policy clarifies that Grammarly's privacy terms do not apply to the content you upload or output—your organization's privacy terms govern that data instead. This means organizational account users should review their organization's privacy policies rather than relying on Grammarly's policy to understand how their work or educational data is handled.
View change record →Under this clause, users who access Superhuman products through an employer, school, or other organizational account are not covered by this privacy policy with respect to their uploaded content and outputs. The agreement directs such users to contact their organization to exercise data rights related to that content.
Cross-platform context
See how other platforms handle Organizational User Privacy Policy Carve-Out and similar clauses.
Compare across platforms →Monitoring
Grammarly has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"If you use our products under the management of a company, organization, educational institution, or other legal entity (such as if your employer gives you access to our inbox assistant tools for work or if you open an account on behalf of an entity), this Privacy Policy won't apply to the information you upload to or output from our products. Please see more info below.Excerpt from Grammarly's Privacy Policy
1) REGULATORY LANDSCAPE: This provision establishes Superhuman as a data processor rather than data controller for organizational account content, engaging GDPR Articles 28 and 29 regarding processor obligations and the requirement for a data processing agreement between controller (the organization) and processor (Superhuman). Under CCPA/CPRA, the B2B exemption and service provider framework similarly distinguish between consumer-facing and business-to-business data processing. 2) GOVERNANCE EXPOSURE: High for organizational deployers. The carve-out means that employee data rights under GDPR, CCPA, and equivalent state laws must be operationalized through the organization's own data processing agreement with Superhuman, which is not reproduced or summarized in this policy. Organizations that have not reviewed or updated that agreement face exposure if it does not adequately reflect current processing activities or data subject rights procedures. 3) JURISDICTION FLAGS: EEA and UK organizations must ensure a GDPR-compliant data processing agreement is in place as a legal requirement, not merely a contractual preference. Educational institutions in the US should assess FERPA applicability depending on the nature of content processed through organizational accounts. 4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams at organizations deploying Superhuman should obtain, review, and maintain a current copy of the data processing agreement with Superhuman Platform Inc. The policy states Superhuman will refer individual data rights requests to the managing organization, meaning the organization must have an operational process to receive and respond to such requests. 5) COMPLIANCE CONSIDERATIONS: Organizations should audit whether their internal privacy notices adequately disclose Superhuman's role as a data processor for employee-generated content, and whether employee consent mechanisms or legitimate interests assessments cover the specific processing activities Superhuman performs on organizational account content.
This provision establishes that individual employees or institutional users who access Superhuman products through employer or institution-managed accounts cannot exercise data rights under this policy for their work-related content; those rights must be directed to the managing organization.
Under this clause, users who access Superhuman products through an employer, school, or other organizational account are not covered by this privacy policy with respect to their uploaded content and outputs. The agreement directs such users to contact their organization to exercise data rights related to that content.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Grammarly.