Granola
- Your data trains their AI unless you switch it off in settings.
- Your data is used for personalized ads, including by third-party ad companies.
- Data is shared only with the providers who run the service.
- The documents do not say who can read your content.
Meeting notes and audio are stored; data trains models unless you turn that off in settings.
Agent Trust Hub uses AI and may make mistakes. Review reports and confirm their contents before relying on them.
Collected
Account info, device data, calendar details, meeting audio, transcripts, and sometimes payment and partner data.
Read the exact line
Privacy policy
“Meeting data, including but not limited to attendees, audio, and transcriptions”
Training
They use your data to run notes and may train on data unless you turn that off in settings.
Read the exact line
Privacy policy
“We only use data to train AI models, which you can opt-out of within your Granola account settings.”
Sharing
Service providers, people you share with, and your company if you use a work workspace can see data.
Read the exact line
Privacy policy
“We will only share your Personal Data as we have described in this Privacy Policy.”
Kept
They keep account data while you use the service; training data in models may stay forever.
Read the exact line
Privacy policy
“ and data, including when used in AI models, may be retained indefinitely, as it cannot reasonably be attributed to you individually.”
Controls
You can turn off model training in settings, delete meetings in the app, and email them to delete your account.
Read the exact line
Privacy policy
“You can opt-out within your Granola account settings. Enterprise users have model training turned off by default, but may opt-in through the Services.”
Fine print
The service is “as is,” they can disable your access, and they say they would pay you at most $100.
Read the exact line
Terms of service
“OUR MAXIMUM TO YOU FOR ANY BREACH OF THE USER TERMS IS ONE HUNDRED DOLLARS ($100) IN THE AGGREGATE.”
Expand “Read the exact line” to see the source alongside the explanation.
What you can turn off
The controls and opt-outs their own documents describe, and where they say to find them.
Turn off model training in account settings
Granola account settings (enterprise workspaces are off by default)
Delete a meeting from the app
Meeting list in the Granola app, then the 3 dots on the right of a meeting
Delete your account
Help Center steps, or email privacy@granola.so
Stop marketing emails
Unsubscribe link in emails, or account settings; SMS reply STOP
If a switch is not where they say, the deletion request above still applies.
Line by line
The lines that matter most, worst first.
If your notes go into a model, they say they cannot pull that data back out later.
Read the exact line
Privacy policy
“ and data that has been lawfully incorporated into AI or analytics models or other databases will not be removed from those models and datasets”
For example, even after you delete your account, patterns from old meetings may still sit inside the model.
Training on combined, data is on unless you switch it off in settings. Work accounts start with it off.
Read the exact line
Privacy policy
“We only use data to train AI models, which you can opt-out of within your Granola account settings.”
For example, open Granola settings and turn off model training if you do not want your notes used that way.
If something goes wrong for you as a user, they say they would pay at most one hundred dollars.
Read the exact line
Terms of service
“OUR MAXIMUM TO YOU FOR ANY BREACH OF THE USER TERMS IS ONE HUNDRED DOLLARS ($100) IN THE AGGREGATE.”
For example, if a bug leaks a meeting note, these user terms cap what they say they owe you at $100.
They do not promise the notes app will work or that your meeting data is error-free.
Read the exact line
Terms of service
“GRANOLA MAKES NO REPRESENTATIONS OR OF ANY KIND, WHETHER EXPRESS OR IMPLIED, TO YOU RELATING TO THE SERVICES OR ANY CUSTOMER DATA, WHICH ARE PROVIDED TO YOU ON AN “AS IS” AND “AS AVAILABLE” BASIS.”
For example, if a summary misses a key decision, they say they are not promising accuracy.
They can shut off your access if they think there is a problem, without promising a warning to you.
Read the exact line
Terms of service
“we may directly step in and take what we determine to be appropriate action (including disabling your account) if Customer does not take appropriate action or we believe there is a credible risk of harm”
For example, they could disable your login after a policy issue even if you still need old notes.
Other companies’ cookies may be used to aim ads or marketing at you.
Read the exact line
Privacy policy
“authorized third parties may use Cookies and similar technologies to enhance your experience with our Services and to deliver or target advertising and marketing.”
For example, a marketing partner could use a cookie from the site to show you ads later.
Meeting audio is kept only long enough to make a transcript, then they say it is deleted.
Read the exact line
Privacy policy
“Any recordings of communications using our Services are captured only for the purposes of providing you a transcription. We do not retain or store such recordings once the transcription is created.”
For example, after your call is turned into text, the raw audio file should not stay on their servers.
They say outside AI vendors cannot train on your personal meeting data.
Read the exact line
Privacy policy
“We do not allow third parties such as OpenAI or Anthropic to use your Personal Data to train AI models.”
For example, a transcript sent to a model provider should not be used to teach that provider’s public model.
They say they will not sell your personal data unless you agree.
Read the exact line
Privacy policy
“We will not sell your Personal Data to third parties without your consent.”
For example, they should not sell your email list to another company unless you consent.
For big privacy-policy changes they say they will try to warn you a month ahead.
Read the exact line
Privacy policy
“If we believe the changes are material, we will endeavor to provide notice of the changes thirty (30) days before the changes take effect.”
For example, if they start a new data use, they say they will post or send notice about 30 days early.
You should be at least 16. They rely on you not signing up if you are younger.
Read the exact line
Terms of service
“To the extent prohibited by applicable law, the Services are not intended for and should not be used by (a) anyone under the age of sixteen”
For example, a 15-year-old is told not to register, but there is no extra age check described.
Words to know
Legal words from the lines above, in plain English.
- de-identified
- Data with your name and obvious identifiers removed, though it can sometimes still be traced back to you. For example, your chats with names stripped out may still be kept and studied after you delete your account.
- model training
- Using your content and conversations as examples to teach an AI system, which can then echo them in future answers. For example, a story you write in a chatbot may be studied by the company to make the next version of the bot.
- opt out
- Something is on by default and stays on until you find the setting and turn it off. For example, your chats may be used for training unless you go into settings and switch it off.
- personal data
- Any information that is about you or can be linked to you, from your name to your phone's ID. For example, your email, your IP address and the list of apps on your phone are all personal data.
- opt in
- Something is off until you actively say yes to it. For example, marketing emails that only start after you tick a box are opt in.
- limitation of liability
- A cap on what the company will ever pay you if something goes wrong, often only what you paid in the last year. For example, if a leak of your data costs you thousands, the most you may get back is a month's subscription fee.
- warranty
- A promise that a product will work as described; most apps say they make no such promise at all. For example, if a paid feature never works on your phone, a no-warranty clause says that is your problem.
- as is
- You get the service in whatever state it is in, with no promise that it works or will keep working. For example, if the app deletes your photos by mistake, it is not promising to fix that or pay you back.
- third parties
- Any company or person other than you and the app, such as advertisers, partners or analytics firms. For example, an analytics company that receives a record of every screen you tap is a third party.
- cookies
- Small files a website saves on your device so it can recognise you and remember what you did. For example, a cookie keeps you logged in and can also tell an ad company which sites you visited.
- sell or share
- Under California law, selling means passing your data to others for money or other value; sharing means passing it on for targeted ads. For example, letting an ad network use your browsing history in return for ad space counts as a sale.
- consent
- Your clear agreement to something, given by an action like ticking a box or tapping Accept. For example, a pop-up asking if the app may use your location is asking for consent.
How we got here · grade B · score 50/100 · 15 of 15 policy answers backed by a verified quote · 3 not stated
What does the app collect beyond what it needs to work?
They collect more than account and notes: device IDs, IP-based location, cookies, calendar invites, meeting audio, transcripts, and sometimes social and payment details.
Does it record your voice, face or body, and what happens to that?
They capture meeting audio to make a transcript, then say they do not keep the recording. Transcripts are kept as meeting content.
Are your chats and uploads used to train AI models, and is that off by default?
De-identified data may be used to train their models unless you opt out in account settings. Enterprise workspaces start opted out. They say vendors like OpenAI cannot train on your personal data.
Can employees or contractors read your conversations, and when?
Not stated in the documents.
Are you profiled or tracked for advertising?
They mention targeted advertising and say authorized third parties may use cookies to deliver or target ads, though they also say they do not sell data for cross-context ads unless disclosed.
Do they sell or share your data, and can you opt out?
They say they will not sell personal data without consent and share it with service providers, affiliates, your company, and legal requests.
What rights do they take over what you type and what the AI makes?
The user terms say meeting content in a workspace is owned by the Customer (such as your employer or the person who invited you), not licensed away to Granola in these pages.
How long do they keep your data after you delete it, and can you delete it in the app?
They keep data while your account is active. You can delete meetings in the app; full account deletion is via Help Center or email. De-identified training data may stay in models forever.
Does it build a lasting memory or profile of you, and can you see, edit or turn it off?
Not stated in the documents.
Do they commit to basic security, and have they leaked data?
They describe encryption in AWS, firewalls, VPC, and other security measures, and point to a Trust Center. No independent audit is described here.
Is there a real age gate, and are teens protected?
They say the service is not for anyone under 16 and ask you not to sign up, with no extra age check described.
Will they tell you when the rules change, and is the policy specific?
The privacy policy is dated and they say they will try to give 30 days’ notice for material changes. The terms also promise reasonable notice for material updates.
Can they close your account without warning, and can you get your data out first?
They may disable your account if they think there is a policy or safety risk. Your workspace owner can also cut off access. No promised export-before-close for users.
If something goes wrong, who pays?
The service is offered “as is,” and their maximum payout to you under these user terms is $100.
Do subscriptions renew on their own, and can you get a refund?
Not stated in the documents.
The privacy policy is 8,722 words at a professional or legal expert level (Flesch reading ease 29.8); the terms are 2,096 words at a college graduate level.