The policy asserts legitimate interests under GDPR Article 6(1)(f) as the legal basis for using all categories of collected data, including user content, to develop and improve AI models.
This analysis describes what Grammarly's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes legitimate interests as the sole GDPR legal basis for AI development processing across all data categories, including user content such as emails and documents; users in the EEA and UK have the right to object to processing on this basis under GDPR Article 21.
Interpretive note: The adequacy of legitimate interests as a GDPR legal basis for AI training using all data categories, including user content, is subject to evolving regulatory guidance from EEA data protection authorities and has not been definitively established through enforcement decisions.
The updated policy now discloses that Grammarly collects voice data if you use transcription or Notetaker features, including recordings of other participants, and expands its list of collected content to explicitly include screen content and web pages. For users whose accounts are managed by an organization (employer, school, or other entity), the policy clarifies that Grammarly's privacy terms do not apply to the content you upload or output—your organization's privacy terms govern that data instead. This means organizational account users should review their organization's privacy policies rather than relying on Grammarly's policy to understand how their work or educational data is handled.
View change record →Under this provision, all categories of personal data including user content may be processed for AI development purposes on the basis of Superhuman's asserted legitimate interests under GDPR Article 6(1)(f). EEA and UK users have the right to object to this processing, and users globally may exercise the account-level AI training opt-out described separately in the policy.
Cross-platform context
See how other platforms handle GDPR Legal Bases for AI Development Processing and similar clauses.
Compare across platforms →"To develop and improve AI: All categories of data. We have a legitimate interest in operating and improving our services and developing new products through the use of AI (Art. 6 (1)(f) GDPR/ UK GDPR).Excerpt from Grammarly's Privacy Policy
1) REGULATORY LANDSCAPE: GDPR Article 6(1)(f) requires that processing based on legitimate interests pass a three-part test: the interest must be legitimate, processing must be necessary, and the controller's interests must not be overridden by …
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes legitimate interests as the sole GDPR legal basis for AI development processing across all data categories, including user content such as emails and documents; users in the EEA and UK have the right to object to processing on this basis under GDPR Article 21.
Under this provision, all categories of personal data including user content may be processed for AI development purposes on the basis of Superhuman's asserted legitimate interests under GDPR Article 6(1)(f). EEA and UK users have the right to object to this processing, and users globally may exercise the account-level AI training opt-out described separately in the policy.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Grammarly.