Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy discloses that cookie IDs, device identifiers, browsing activity on Superhuman marketing websites, and unique identifiers derived from email addresses or phone numbers are shared with advertising and social network partners for targeted advertising, and acknowledges these activities may constitute sale or sharing under applicable state privacy laws.
This analysis describes what Grammarly's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision operationalizes the targeted advertising disclosure requirements under CCPA/CPRA and equivalent state privacy laws by identifying the specific categories of personal information disclosed (cookie IDs, email-derived unique identifiers, browsing activity) and the recipient categories (advertising networks, social networks), and provides opt-out mechanisms for users in covered jurisdictions.
The updated policy now discloses that Grammarly collects voice data if you use transcription or Notetaker features, including recordings of other participants, and expands its list of collected content to explicitly include screen content and web pages. For users whose accounts are managed by an organization (employer, school, or other entity), the policy clarifies that Grammarly's privacy terms do not apply to the content you upload or output—your organization's privacy terms govern that data instead. This means organizational account users should review their organization's privacy policies rather than relying on Grammarly's policy to understand how their work or educational data is handled.
View change record →Under this clause, identifiers derived from a user's email address or phone number, along with cookie IDs and website browsing activity, may be disclosed to advertising and social network partners. The policy states these disclosures may constitute targeted advertising, sharing, or sale under state privacy laws, and opt-out mechanisms are available via the 'Your Privacy Choices' footer link or Global Privacy Control signal.
Cross-platform context
See how other platforms handle Targeted Advertising Data Disclosure and similar clauses.
Compare across platforms →Monitoring
Grammarly has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"We engage other companies to serve advertisements promoting our products and our company and to perform related services. We do not make user content available to these companies. These companies may use Cookies to collect limited information about your interactions with our websites, such as a cookie ID or device identifier and a link you click or page you visit on our websites. In addition, we may work with advertising partners to translate your email address or phone number into a unique identifier that such partners can then use to show ads promoting our products on other websites and online services. These activities–disclosing unique IDs and disclosing data through Cookies–may constitute "targeted advertising", "sharing", or "selling" under certain privacy laws, and depending on where you live, we may require your consent or you may be able to opt out of such activities.Excerpt from Grammarly's Privacy Policy
1) REGULATORY LANDSCAPE: This provision directly engages CCPA/CPRA definitions of sale and sharing of personal information, and equivalent provisions in Colorado, Connecticut, Virginia, and the other sixteen states named in the policy. The disclosure of email-derived unique identifiers to advertising networks may also engage FTC guidance on data broker practices and cross-context behavioral advertising. The FTC Act Section 5 prohibits unfair or deceptive practices, and the adequacy of the opt-out mechanism for each state's requirements should be evaluated separately. 2) GOVERNANCE EXPOSURE: Medium. The policy discloses the practice and provides opt-out mechanisms, which represents standard CCPA/CPRA operational compliance. However, the opt-out is browser-linked and must be renewed per device or after cookie clearing, which may not satisfy all users' expectations or all jurisdictions' requirements regarding persistent opt-out signals. 3) JURISDICTION FLAGS: California users have CPRA rights to opt out of sale and sharing; the policy's mechanism relies on a browser-linked opt-out or Global Privacy Control signal. The Global Privacy Control is recognized as a valid opt-out signal under CCPA regulations. Users in states without enacted privacy laws at the time of this policy's effective date do not have statutory opt-out rights but may still use the provided controls. 4) CONTRACT AND VENDOR IMPLICATIONS: The policy identifies advertising networks and social networks as recipient categories but does not name specific partners. Procurement and compliance teams may wish to request a list of advertising technology vendors to assess data flows and confirm that data processing agreements with those vendors satisfy applicable service provider or contractor requirements under CCPA/CPRA. 5) COMPLIANCE CONSIDERATIONS: Organizations deploying Superhuman at scale should assess whether their employees' email-derived identifiers are included in targeted advertising data flows, and whether organizational account data processing agreements restrict this practice for work-related accounts. Consumer-facing compliance teams should verify that the 'Your Privacy Choices' link and Global Privacy Control opt-out are operational and technically effective across all Superhuman product websites.
This provision operationalizes the targeted advertising disclosure requirements under CCPA/CPRA and equivalent state privacy laws by identifying the specific categories of personal information disclosed (cookie IDs, email-derived unique identifiers, browsing activity) and the recipient categories (advertising networks, social networks), and provides opt-out mechanisms for users in covered jurisdictions.
Under this clause, identifiers derived from a user's email address or phone number, along with cookie IDs and website browsing activity, may be disclosed to advertising and social network partners. The policy states these disclosures may constitute targeted advertising, sharing, or sale under state privacy laws, and opt-out mechanisms are available via the 'Your Privacy Choices' footer link or Global …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Grammarly.