← Productivity
D

Grammarly

Serious concerns
Grammarly · 🇺🇸 United States
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
App: com.grammarly.android.keyboard
Manufacturer: Grammarly Inc.

⚠️ The bottom line

Grammarly boasts SOC 2 certification and "industry-leading security." In February 2018, Google's Tavis Ormandy found that any website could read everything you'd ever typed through Grammarly. Every email. Every document. Every message. Twenty-two million users' complete writing history, accessible to any malicious webpage. Grammarly fixed it in hours. But nobody knows how long the hole existed. Could have been weeks. Could have been years. When your browser extension can read every webpage you visit, a single bug doesn't expose one document -- it exposes everything. SOC 2 certification didn't prevent 22 million people's writing from being an open book to the internet. You install Grammarly to fix your typos. You give it keyboard access. Now Grammarly sees every password you type. Every bank account number. Every private message to your partner. Every medical symptom you search. Every text to your lawyer. Keyboard permissions on Android and iOS are all-or-nothing -- you cannot tell Grammarly to check your emails but ignore your banking app. A "writing assistant" that reads your passwords, your bank details, your medical queries, and your most intimate messages. You wanted better grammar. You gave a $13 billion company a wiretap on your entire digital life.

Legal jurisdiction
🇺🇸 United States (headquarters)
CLOUD Act read more →
US govt can demand your data from this company even if stored overseas
FISA §702 / PRISM read more →
NSA collects stored emails, photos, messages without individual warrants
Geofence warrants read more →
Police can demand location data for everyone near a crime scene
Audited by: Unknown (SOC 2 Type II, Jan 2024)
An audit is a snapshot, not a guarantee. How reliable are these auditors?
Spying
2/4 MODERATE
Is someone spying on me?
Data Sharing
3/4 HIGH
Who gets my data?
Security
3/4 HIGH
Is it actually secure?
Honesty
2/4 MODERATE
Can I trust what they say?
CONFIGURE High-risk areas that can be partially mitigated with settings changes.
7Contradictions
1Critical
3High
3Medium
4Sources
Findings by concern
Spying 2/4 MODERATE 1 finding
⚡ highmarketing claims vs app permissions
You install Grammarly to fix your typos. You give it keyboard access. Now Grammarly sees every password you type. Every bank account number. Every private message to your partner. Every medical symptom you search. Every text to your lawyer. Keyboard permissions on Android and iOS are all-or-nothing -- you cannot tell Grammarly to check your emails but ignore your banking app. A "writing assistant" that reads your passwords, your bank details, your medical queries, and your most intimate messages. You wanted better grammar. You gave a $13 billion company a wiretap on your entire digital life.

What they claim: Grammarly markets itself as a "writing assistant" that helps users "communicate with confidence" by fixing grammar, spelling, and tone.

What we found: As a keyboard replacement on mobile devices, Grammarly receives every keystroke the user types across all apps: passwords, bank account numbers, credit card details, private messages, medical queries, legal communications, intimate conversations, and search queries. On desktop, the browser extension reads the full content of every webpage visited -- including banking portals, medical record sites, email inboxes, and corporate intranets. Android and iOS keyboard permissions are all-or-nothing: users cannot restrict Grammarly to specific apps. The keyboard permission grants access to the most comprehensive data stream on any device -- universal input monitoring. Grammarly occupies the single most privileged position any app can hold: intercepting every piece of information that enters or exits the device through text.

Data Sharing 3/4 HIGH 3 findings
⚫ mediumpolicy claims vs network analysis
Every time Grammarly fixes your grammar, your text leaves your device and travels to Grammarly's servers. One hundred billion text events per day. Thirty million users' writing. Grammarly's privacy policy says content may be used to "improve and develop products" -- which is how every AI company describes training data. Grammarly's FAQ says they don't train general AI on your content. Grammarly's legal policy says they can use content to "develop" products. The FAQ is a webpage. The policy is a contract. A company sitting on 100 billion daily text events launched an AI writing product (GrammarlyGO) and asks you to trust that your writing didn't help build it.

What they claim: Grammarly states it collects user content to "provide, improve, and develop our products and services" and processes text through its AI to deliver writing suggestions.

What we found: Every text correction, AI rewrite, and tone suggestion requires transmitting user text from the device to Grammarly's cloud servers. Grammarly processes over 100 billion text events daily across all users. The privacy policy's "improve and develop products" language is standard industry phrasing for using customer data to train AI models. Grammarly states it does not use individual user content to train general-purpose AI, but the policy language is broader than the public FAQ statements -- creating a gap between what's promised in marketing and what's permitted in legal terms. GrammarlyGO, launched in 2023, is powered by large language models that require massive training datasets. A company processing 100 billion daily text events from 30 million users sits on one of the most valuable AI training corpora in existence.

⚫ mediummarketing claims vs third party research
A Fortune 500 company deploys Grammarly Business. Now every email, every strategy document, every legal draft, every HR complaint, every M&A discussion flows through Grammarly's servers. SOC 2 certification means Grammarly protects what it collects. It doesn't address whether a third party should see your merger negotiations in the first place. Universities deploy Grammarly for Education. Students' unpublished research, thesis work, and original analysis are processed by a $13 billion commercial AI company. The student thinks the university provided a grammar tool. The university routed their intellectual property through a company that processes 100 billion text events daily. Enterprise security certifications protect the pipe. They don't question whether the pipe should exist.

What they claim: Grammarly Business markets enterprise-grade security with SOC 2 Type II compliance, GDPR compliance, and data processing agreements that protect corporate communications.

What we found: Grammarly Business and Grammarly for Education process text through Grammarly's cloud servers. Corporate deployments route internal emails, strategy documents, legal drafts, HR communications, merger and acquisition discussions, board communications, and trade secrets through a third-party service. A company using Grammarly Business sends every internal communication through servers controlled by an external company. Universities deploying Grammarly for Education process students' essays, research papers, thesis work, and academic communications through commercial servers. Students may not realize their academic work -- including unpublished research and original analysis -- is processed by a $13 billion commercial AI company. The SOC 2 certification addresses security controls, not data use -- it certifies that Grammarly protects the data it collects, not that it shouldn't collect it.

⚫ mediumpolicy claims vs third party research
Grammarly's blog says: "Your writing is your own. We will never sell it." Grammarly's privacy policy says content may be used to "provide, improve, and develop our products and services" and shared with "service providers" and "business partners" for as long as "reasonably necessary." The blog is a promise. The policy is a contract. The policy wins. "We don't sell your data" has become the tech industry's favorite meaningless pledge -- the same data flows to the same companies under labels like "service provider" and "business partner" instead of "buyer." Different words, same data flow. Grammarly keeps your content forever, shares it with unnamed partners, and calls it anything but selling.

What they claim: Grammarly's public FAQ and blog posts state: "We do not sell your data" and "Your writing is your own. We will never sell it."

What we found: Grammarly's legal privacy policy permits broader use than its public statements suggest. The policy states content may be used to "provide, improve, and develop our products and services" and allows sharing with "service providers" and "business partners." The policy permits retaining "User Content" for as long as "reasonably necessary" with no defined maximum retention period. The distinction between "selling" data and "sharing for business purposes" is legally narrow -- the same data flows to the same third parties under a different contractual label. Grammarly's public communications emphasize "we don't sell your data," but the privacy policy does not define "sell" and permits data flows that function equivalently under "business purposes," "service providers," and "product development" categories.

Security 3/4 HIGH 2 findings
⚠️ criticalpolicy claims vs third party research
Grammarly boasts SOC 2 certification and "industry-leading security." In February 2018, Google's Tavis Ormandy found that any website could read everything you'd ever typed through Grammarly. Every email. Every document. Every message. Twenty-two million users' complete writing history, accessible to any malicious webpage. Grammarly fixed it in hours. But nobody knows how long the hole existed. Could have been weeks. Could have been years. When your browser extension can read every webpage you visit, a single bug doesn't expose one document -- it exposes everything. SOC 2 certification didn't prevent 22 million people's writing from being an open book to the internet.

What they claim: Grammarly states it uses "industry-leading security practices" including SOC 2 Type II certification, 256-bit AES encryption, and enterprise-grade data protection to keep user content secure.

What we found: In February 2018, Google Project Zero researcher Tavis Ormandy discovered a critical vulnerability in the Grammarly browser extension that exposed all user documents to any website. Any malicious webpage could access a user's complete Grammarly document history -- every email drafted, every document edited, every message composed while the extension was active. The vulnerability affected approximately 22 million users. Grammarly patched it within hours of Ormandy's report, but the duration of the vulnerability's existence was unknown -- it may have been exploitable since the extension's launch. A single bug in a browser extension with universal page access created a window where every word 22 million people had ever typed through Grammarly was accessible to any website they visited.

⚡ highmarketing claims vs third party research
Grammarly asks you to trust that its keyboard only sends what it needs to. That its browser extension only reads text fields. That your content isn't training AI models. You cannot verify any of this. Grammarly is entirely closed source. The one time an independent security researcher (Google's Tavis Ormandy) actually looked inside, he found a critical vulnerability exposing 22 million users' documents. SOC 2 certification is a paid audit of security controls -- it doesn't verify what data Grammarly collects or how it uses it. No public transparency report. No warrant canary. No independent data flow audit. A company that reads everything you type asks for trust and provides no way to verify it. The only time someone checked, everything was broken.

What they claim: Grammarly promotes its SOC 2 Type II certification and security practices as evidence that user data is protected, and states its AI processes text only to provide writing assistance.

What we found: Grammarly is entirely closed source -- no independent researcher can verify what the keyboard app transmits, what the browser extension reads, or how user content is processed on Grammarly's servers. The 2018 Tavis Ormandy vulnerability was only discovered because Google's Project Zero actively audited the extension. Without that audit, 22 million users' data may have remained exposed indefinitely. SOC 2 certification is conducted by paid auditors examining security controls, not an independent review of data practices. There is no public transparency report detailing government data requests, no warrant canary, and no independent audit of what data flows between the Grammarly client and its servers. Users must trust Grammarly's claims about data handling with no ability to verify them -- and the one time an independent researcher looked closely, they found a critical vulnerability.

Honesty 2/4 MODERATE 1 finding
⚡ highmarketing claims vs app permissions
Grammarly's browser extension asks for permission to "read and change all your data on all websites." Not just the text boxes where you type -- all data on all websites. Your bank balance. Your medical records. Your tax returns. Your corporate intranet. Grammarly says it only reads text in editable fields. But the permission doesn't say that -- the permission says "all your data on all websites." Thirty million users granted one company the ability to read every webpage they visit. The permission is technically necessary for the extension to work everywhere. It's also the most invasive permission a browser extension can request. You installed a grammar checker. You gave it access to your entire online life.

What they claim: Grammarly's browser extension is marketed as helping users "write confidently across the web" with suggestions appearing wherever they type online.

What we found: The Grammarly browser extension requires permission to "read and change all your data on all websites." This is the broadest permission a browser extension can request -- full access to every webpage's content, including pages the user reads but doesn't type on. The extension can access: banking portal balances and transaction histories, medical record portals, email content (reading, not just composing), corporate intranet pages, legal documents, tax returns viewed online, and any sensitive information displayed in the browser. While Grammarly states it only processes text in editable fields, the permission grants access to all page content. The extension runs continuously in the background, maintaining persistent access to every webpage. Over 30 million users have granted a single company the ability to read every webpage they visit.

Sources