← All categories
Productivity
The tools you use for work see everything you create. Microsoft reads your documents for AI. Google scans your spreadsheets. Notion stores your second brain on someone else's server.
18 devices analyzed. Set your privacy comfort level to filter.
What we found
Truecaller: DYou have never installed Truecaller.
Truecaller builds its database by uploading the entire contact list of every user who installs the app. If your friend installs Truecaller, your name, phone number, and any other contact details they stored are uploaded to Truecaller's servers — without your knowledge or consent. An estimated 4 billion phone numbers are in Truecaller's database. You do not need to be a user to be in it.
GitHub: DGitHub promised not to train on your private code.
On March 25, 2026, GitHub announced that from April 24, all Copilot Free/Pro/Pro+ interaction data — inputs, outputs, code snippets, surrounding context — would train AI models by default. Users must actively opt out. The GitHub Community Discussion received 232 downvotes. If one collaborator on a private repo uses Copilot without opting out, code context from that repo enters the training dataset regardless of other collaborators' preferences.
Microsoft 365: DMicrosoft told European schools its software was GDPR-compliant.
Austria's DSB found Microsoft violated GDPR Article 15 by refusing student data access. Then found Microsoft placed advertising tracking cookies on a minor's school device. The school and Austrian Ministry didn't know. noyb's Max Schrems noted the same terms apply to millions of students across EU/EEA. France and Germany already banned 365 from schools.
Grammarly: DGrammarly boasts SOC 2 certification and "industry-leading security." In February 2018, Google's Tavis Ormandy found that any website could read everything y...
In February 2018, Google Project Zero researcher Tavis Ormandy discovered a critical vulnerability in the Grammarly browser extension that exposed all user documents to any website. Any malicious webpage could access a user's complete Grammarly document history -- every email drafted, every document edited, every message composed while the extension was active. The vulnerability affected approximately 22 million users. Grammarly patched it within hours of Ormandy's report, but the duration of the vulnerability's existence was unknown -- it may have been exploitable since the extension's launch. A single bug in a browser extension with universal page access created a window where every word 22 million people had ever typed through Grammarly was accessible to any website they visited.
Adobe Creative Cloud: DAdobe is not just a creative tools company.
Adobe Analytics processes over 1 trillion visits to U.S. retail sites annually -- more web tracking data than any other technology company or research organization, by Adobe's own claim. Over 135,000 companies use Adobe Analytics globally, including Amazon, Walmart, and Apple. Adobe's Experience Cloud division -- which includes Analytics, Target (A/B testing), Audience Manager (data management platform), and Campaign (marketing automation) -- is a surveillance infrastructure company that happens to also sell Photoshop. The company that hosts your creative work and processes your subscription payments also operates one of the world's largest cross-site tracking platforms. Adobe's dual identity -- creative tool maker and advertising technology company -- creates a conflict of interest that most Creative Cloud subscribers are unaware of.
Cursor: DA researcher created a booby-trapped GitHub repo.
Straiker researchers discovered NomShub — a vulnerability chain where indirect prompt injection in a malicious repository tricks Cursor's AI agent into escaping the sandbox via shell builtins (export, cd, source, eval) that the command parser is completely blind to. A single chained command breaks out of workspace confinement, overwrites ~/.zshenv for persistence, and hijacks GitHub OAuth to give attackers full remote shell access via Cursor's own signed tunnel binary. The attack requires only that a developer asks the agent to "setup this repository."
Canva: DCanva promises robust security on its trust center.
On May 24, 2019, GnosticPlayers breached Canva and stole 139 million user records — names, emails, 61 million bcrypt passwords. In 2020, Canva revealed 4 million passwords had been decrypted. GnosticPlayers sold the data on the dark web. The breach was intercepted in progress but only after 139 million accounts were compromised.
Google Workspace: DGoogle told the world it stopped reading your emails in 2017.
Smart Features still scans every email, attachment, chat, and calendar event using AI — on by default. In the EU/UK these features ship off by default, an implicit admission of the risk. Full opt-out requires disabling two separate buried settings. Miss one and scanning continues.
How audits work in this category
Common standard: SOC 2 Type II
What it covers: Verifies security controls around data storage and access.
What it misses: Does not verify what the product does with your content. Grammarly holds SOC 2 while processing every keystroke through cloud servers. Does not cover AI training on user documents.
Product Auditor Standard Trust signals
Grammarly DUnknownSOC 2 Type II
Microsoft 365 DEY, EYSOC 2 Type II, ISO 27001Big Four
Gold standard for this category:
  • Local-first processing
  • End-to-end encryption
  • No AI training on user content
  • Open-source alternatives
For the auditors' own track record, see Who Audits the Auditors?

Your privacy tolerance