Is Grammarly safe for confidential information?
A plain reading of Grammarly's own privacy and security pages, and what to do if your text must not leave your control.
Published
The short answer
Grammarly is a reasonable choice for everyday work text if your employer allows it, but it is not built for text that must stay under your control. Everything you check is processed on Grammarly's cloud servers in the US, and on Free, Premium and single-user Pro accounts your writing can be used to train its models unless you switch that off. For client files, legal drafts, health records or anything under an NDA, use a company-approved Enterprise plan or a tool that runs on a model you control, such as a local model on your own computer.
Checked against Grammarly's own pages on 26 September 2026.
What Grammarly says it does with your text
| Question | What Grammarly says |
|---|---|
| Where is text processed? | In Grammarly's private network in its cloud platform; data is hosted on AWS in the US East region |
| Is it encrypted? | TLS 1.2 in transit, AES-256 at rest |
| Is my writing used for training? | On by default for Free, Premium and single-user Pro; off by default for Business, Enterprise and Education bought through sales |
| Is my content sold? | No, and not used for advertising or to let third parties train their models |
| Sensitive fields | Blocked from running in read-only and sensitive fields such as passwords, payment forms and addresses, "on a best-efforts basis" |
| Health data (PHI) | Only with a Business Associate Agreement, which is offered on Enterprise plans only |
| Certifications | SOC 2 Type 2, ISO 27001, 27017, 27018, 27701 and 42001, PCI DSS |
| How long documents are kept | Documents in the Grammarly Editor stay until you delete them |
Grammarly's company is now Superhuman Platform Inc. ("formerly Grammarly"). Its privacy policy (effective 6 July 2026) lists the content it can collect as "emails and drafts, text, screen content, web pages, documents, files" and "any other content you allow our products to access", and says data may be processed outside the country where you live.
Is that safe enough?
The security certifications are real and worth something. They don't change three basic facts:
- Your text leaves your device and is stored and processed by a third party in the US.
- On personal plans, training on your writing is on until you turn it off.
- Your employer's rules on confidential data apply whatever Grammarly's certifications say.
So the honest answer is: safe for a cover letter or a blog post, questionable for a client's contract, and off limits for patient data without an Enterprise agreement.
How to turn off training on your writing
Open your Grammarly privacy settings
Sign in at account.grammarly.com. On a Free or Premium account, open Security, then Privacy. On a single-user Pro account, open the admin data settings instead.
Direct links: privacy settings (Free and Premium), data settings (single-user Pro).
Turn off Product Improvement and Training
Switch the Product Improvement and Training toggle off. Grammarly then stops using your content to train its models and improve the product.
Check what your employer allows
Turning training off does not stop your text from being sent to Grammarly's servers for checking. If your organisation restricts cloud tools for confidential data, that rule still applies.
What to use for confidential text
- Your company's approved tool. If your employer has a Grammarly Enterprise or similar contract, use that. It comes with training off and a proper agreement.
- A local model. A model running on your own computer, through Ollama or LM Studio, never sends text anywhere. The trade-off is setup and a slower, smaller model.
- A provider you already trust, with your own key. If your organisation already has an agreement with OpenAI, Anthropic or Google, a bring-your-own-key tool sends text only to that provider.
Where ShroomPen fits
ShroomPen is a Chrome extension that drafts, rewrites and fixes text in the field you are typing in, using a model you connect. It has no ShroomPen server, account or analytics. With a local model, nothing leaves your computer. With a cloud key, your text goes straight from the browser to that provider and nowhere else. It asks for consent before reading anything, and it skips passwords, payment fields and one-time codes.
If that suits you, install ShroomPen on the Chrome Web Store and connect a local model or the provider your organisation already uses.
Related pages
Questions
Does Grammarly send my text to its servers?
Yes. Grammarly's privacy FAQ says all components that process your data run in its private network inside its cloud platform, hosted on Amazon Web Services in the US East region. It checks text while you are actively using it.
Does Grammarly train its AI on my writing?
On Free, Premium and single-user Pro accounts, the Product Improvement and Training setting is on by default, so your content can be used to train Grammarly's models until you switch it off. For Business, Enterprise and Education accounts bought through Grammarly's sales team, it is off by default.
Is Grammarly HIPAA compliant?
Grammarly says it complies with the HIPAA Security, Privacy and Breach Notification rules, but it signs Business Associate Agreements only for Grammarly for Business Enterprise plans. Its support article says you should not process protected health information through Grammarly without a current BAA.
Does Grammarly sell my data?
Grammarly says it does not sell the content you write or use it for advertising. The parent company's privacy policy does say some identifiers are shared with advertising networks in ways that may count as a "sale" under some US state laws, but not your content.
Is ShroomPen safer than Grammarly?
It depends on the model you connect. With a local model such as Ollama or LM Studio, your text never leaves your computer. With a cloud provider, your text goes to that provider under its terms, just as it goes to Grammarly. ShroomPen itself has no server and no account.