Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that personal data may be transferred and processed outside the user's country of residence, and that the company applies the protections described in the policy and complies with applicable legal transfer frameworks including standard contractual clauses for non-DPF transfers.
This analysis describes what Grammarly's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the legal transfer mechanisms Superhuman relies upon for international data flows, including the Data Privacy Frameworks for EEA, UK, and Swiss transfers and standard contractual clauses for transfers to other third countries.
The updated policy now discloses that Grammarly collects voice data if you use transcription or Notetaker features, including recordings of other participants, and expands its list of collected content to explicitly include screen content and web pages. For users whose accounts are managed by an organization (employer, school, or other entity), the policy clarifies that Grammarly's privacy terms do not apply to the content you upload or output—your organization's privacy terms govern that data instead. This means organizational account users should review their organization's privacy policies rather than relying on Grammarly's policy to understand how their work or educational data is handled.
View change record →Under this provision, user data including account information, user content, and technical data may be transferred to and processed in the United States and potentially other countries. For EEA, UK, and Swiss users, the Data Privacy Framework certification and standard contractual clauses are identified as the applicable transfer safeguards.
Cross-platform context
See how other platforms handle Data Transfers and International Processing and similar clauses.
Compare across platforms →Monitoring
Grammarly has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"We may transfer and process your data outside of the country where you live. Countries' data protection laws vary, with some providing more protection than others. Regardless of where your information is processed, we apply the protections described in this policy and we comply with certain legal frameworks relating to the transfer of data, including ensuring that relevant safeguards are in place for the transfer of data where required by law.Excerpt from Grammarly's Privacy Policy
1) REGULATORY LANDSCAPE: This provision engages GDPR Chapter V requirements for lawful transfers of personal data to third countries, including the EU-U.S. Data Privacy Framework adequacy decision and standard contractual clauses published by the European Commission. UK GDPR imposes equivalent transfer requirements under the UK's adequacy regulations. The adequacy status of the EU-U.S. DPF is subject to periodic review and has faced legal challenges; organizations should monitor its status as a transfer mechanism. 2) GOVERNANCE EXPOSURE: Medium. Reliance on the DPF as a primary transfer mechanism is operationally straightforward while the adequacy decision remains in force, but standard contractual clauses serve as the fallback for other third-country transfers and require transfer impact assessments under applicable EDPB and ICO guidance. 3) JURISDICTION FLAGS: EEA and UK users have the strongest procedural protections given the explicit legal framework references. Swiss users are covered by the Swiss-U.S. DPF. Users in other jurisdictions outside these frameworks may have data processed in third countries without equivalent transfer safeguard disclosures in this policy. 4) CONTRACT AND VENDOR IMPLICATIONS: The policy states that standard contractual clauses are used for transfers to countries outside the DPF framework and that users may request copies of the relevant contracts. Organizational clients with GDPR obligations should request and review these SCCs as part of vendor due diligence. 5) COMPLIANCE CONSIDERATIONS: Legal teams should verify that transfer impact assessments have been conducted for all third-country transfers relying on SCCs, and that the DPF certification at dataprivacyframework.gov reflects current processing activities. If the DPF adequacy decision were to be invalidated, SCCs would need to serve as the primary transfer mechanism and should be maintained in current form.
This provision establishes the legal transfer mechanisms Superhuman relies upon for international data flows, including the Data Privacy Frameworks for EEA, UK, and Swiss transfers and standard contractual clauses for transfers to other third countries.
Under this provision, user data including account information, user content, and technical data may be transferred to and processed in the United States and potentially other countries. For EEA, UK, and Swiss users, the Data Privacy Framework certification and standard contractual clauses are identified as the applicable transfer safeguards.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Grammarly.