Grammarly boasts SOC 2 certification and "industry-leading security." In February 2018, Google's Tavis Ormandy found that any website could read everything you'd ever typed through Grammarly. Every email. Every document. Every message. Twenty-two million users' complete writing history, accessible to any malicious webpage. Grammarly fixed it in hours. But nobody knows how long the hole existed. Could have been weeks. Could have been years. When your browser extension can read every webpage you visit, a single bug doesn't expose one document -- it exposes everything. SOC 2 certification didn't prevent 22 million people's writing from being an open book to the internet. You install Grammarly to fix your typos. You give it keyboard access. Now Grammarly sees every password you type. Every bank account number. Every private message to your partner. Every medical symptom you search. Every text to your lawyer. Keyboard permissions on Android and iOS are all-or-nothing -- you cannot tell Grammarly to check your emails but ignore your banking app. A "writing assistant" that reads your passwords, your bank details, your medical queries, and your most intimate messages. You wanted better grammar. You gave a $13 billion company a wiretap on your entire digital life.
What they claim: Grammarly markets itself as a "writing assistant" that helps users "communicate with confidence" by fixing grammar, spelling, and tone.
What we found: As a keyboard replacement on mobile devices, Grammarly receives every keystroke the user types across all apps: passwords, bank account numbers, credit card details, private messages, medical queries, legal communications, intimate conversations, and search queries. On desktop, the browser extension reads the full content of every webpage visited -- including banking portals, medical record sites, email inboxes, and corporate intranets. Android and iOS keyboard permissions are all-or-nothing: users cannot restrict Grammarly to specific apps. The keyboard permission grants access to the most comprehensive data stream on any device -- universal input monitoring. Grammarly occupies the single most privileged position any app can hold: intercepting every piece of information that enters or exits the device through text.
What they claim: Grammarly states it collects user content to "provide, improve, and develop our products and services" and processes text through its AI to deliver writing suggestions.
What we found: Every text correction, AI rewrite, and tone suggestion requires transmitting user text from the device to Grammarly's cloud servers. Grammarly processes over 100 billion text events daily across all users. The privacy policy's "improve and develop products" language is standard industry phrasing for using customer data to train AI models. Grammarly states it does not use individual user content to train general-purpose AI, but the policy language is broader than the public FAQ statements -- creating a gap between what's promised in marketing and what's permitted in legal terms. GrammarlyGO, launched in 2023, is powered by large language models that require massive training datasets. A company processing 100 billion daily text events from 30 million users sits on one of the most valuable AI training corpora in existence.
What they claim: Grammarly Business markets enterprise-grade security with SOC 2 Type II compliance, GDPR compliance, and data processing agreements that protect corporate communications.
What we found: Grammarly Business and Grammarly for Education process text through Grammarly's cloud servers. Corporate deployments route internal emails, strategy documents, legal drafts, HR communications, merger and acquisition discussions, board communications, and trade secrets through a third-party service. A company using Grammarly Business sends every internal communication through servers controlled by an external company. Universities deploying Grammarly for Education process students' essays, research papers, thesis work, and academic communications through commercial servers. Students may not realize their academic work -- including unpublished research and original analysis -- is processed by a $13 billion commercial AI company. The SOC 2 certification addresses security controls, not data use -- it certifies that Grammarly protects the data it collects, not that it shouldn't collect it.
What they claim: Grammarly's public FAQ and blog posts state: "We do not sell your data" and "Your writing is your own. We will never sell it."
What we found: Grammarly's legal privacy policy permits broader use than its public statements suggest. The policy states content may be used to "provide, improve, and develop our products and services" and allows sharing with "service providers" and "business partners." The policy permits retaining "User Content" for as long as "reasonably necessary" with no defined maximum retention period. The distinction between "selling" data and "sharing for business purposes" is legally narrow -- the same data flows to the same third parties under a different contractual label. Grammarly's public communications emphasize "we don't sell your data," but the privacy policy does not define "sell" and permits data flows that function equivalently under "business purposes," "service providers," and "product development" categories.
What they claim: Grammarly states it uses "industry-leading security practices" including SOC 2 Type II certification, 256-bit AES encryption, and enterprise-grade data protection to keep user content secure.
What we found: In February 2018, Google Project Zero researcher Tavis Ormandy discovered a critical vulnerability in the Grammarly browser extension that exposed all user documents to any website. Any malicious webpage could access a user's complete Grammarly document history -- every email drafted, every document edited, every message composed while the extension was active. The vulnerability affected approximately 22 million users. Grammarly patched it within hours of Ormandy's report, but the duration of the vulnerability's existence was unknown -- it may have been exploitable since the extension's launch. A single bug in a browser extension with universal page access created a window where every word 22 million people had ever typed through Grammarly was accessible to any website they visited.
What they claim: Grammarly promotes its SOC 2 Type II certification and security practices as evidence that user data is protected, and states its AI processes text only to provide writing assistance.
What we found: Grammarly is entirely closed source -- no independent researcher can verify what the keyboard app transmits, what the browser extension reads, or how user content is processed on Grammarly's servers. The 2018 Tavis Ormandy vulnerability was only discovered because Google's Project Zero actively audited the extension. Without that audit, 22 million users' data may have remained exposed indefinitely. SOC 2 certification is conducted by paid auditors examining security controls, not an independent review of data practices. There is no public transparency report detailing government data requests, no warrant canary, and no independent audit of what data flows between the Grammarly client and its servers. Users must trust Grammarly's claims about data handling with no ability to verify them -- and the one time an independent researcher looked closely, they found a critical vulnerability.
What they claim: Grammarly's browser extension is marketed as helping users "write confidently across the web" with suggestions appearing wherever they type online.
What we found: The Grammarly browser extension requires permission to "read and change all your data on all websites." This is the broadest permission a browser extension can request -- full access to every webpage's content, including pages the user reads but doesn't type on. The extension can access: banking portal balances and transaction histories, medical record portals, email content (reading, not just composing), corporate intranet pages, legal documents, tax returns viewed online, and any sensitive information displayed in the browser. While Grammarly states it only processes text in editable fields, the permission grants access to all page content. The extension runs continuously in the background, maintaining persistent access to every webpage. Over 30 million users have granted a single company the ability to read every webpage they visit.