GenAgent Trust Hub
Menu

Granola

BTier BLow risk · 50/100
  • Your data trains their AI unless you switch it off in settings.
  • Your data is used for personalized ads, including by third-party ad companies.
  • Data is shared only with the providers who run the service.
  • The documents do not say who can read your content.

Meeting notes and audio are stored; data trains models unless you turn that off in settings.

Highest riskMedium riskLow risk

Agent Trust Hub uses AI and may make mistakes. Review reports and confirm their contents before relying on them.

Privacy policy · September 15, 2026 ↗Terms · September 15, 2026 ↗38 min read · professional or legal expert level29 lines verified word for word

Collected

What is collected

Account info, device data, calendar details, meeting audio, transcripts, and sometimes payment and partner data.

Read the exact line

Privacy policy

“Meeting data, including but not limited to attendees, audio, and transcriptions”

Training

How it is used

They use your data to run notes and may train on data unless you turn that off in settings.

Read the exact line

Privacy policy

“We only use data to train AI models, which you can opt-out of within your Granola account settings.”

Sharing

Who may see it

Service providers, people you share with, and your company if you use a work workspace can see data.

Read the exact line

Privacy policy

“We will only share your Personal Data as we have described in this Privacy Policy.”

Kept

How long it is kept

They keep account data while you use the service; training data in models may stay forever.

Read the exact line

Privacy policy

“ and data, including when used in AI models, may be retained indefinitely, as it cannot reasonably be attributed to you individually.”

Controls

Your controls

You can turn off model training in settings, delete meetings in the app, and email them to delete your account.

Read the exact line

Privacy policy

“You can opt-out within your Granola account settings. Enterprise users have model training turned off by default, but may opt-in through the Services.”

Fine print

The fine print

The service is “as is,” they can disable your access, and they say they would pay you at most $100.

Read the exact line

Terms of service

“OUR MAXIMUM TO YOU FOR ANY BREACH OF THE USER TERMS IS ONE HUNDRED DOLLARS ($100) IN THE AGGREGATE.”

Expand “Read the exact line” to see the source alongside the explanation.

What you can turn off

The controls and opt-outs their own documents describe, and where they say to find them.

  1. Turn off model training in account settings

    Granola account settings (enterprise workspaces are off by default)

  2. Delete a meeting from the app

    Meeting list in the Granola app, then the 3 dots on the right of a meeting

  3. Delete your account

    Help Center steps, or email privacy@granola.so

  4. Stop marketing emails

    Unsubscribe link in emails, or account settings; SMS reply STOP

If a switch is not where they say, the deletion request above still applies.

Line by line

The lines that matter most, worst first.

1 · How it is used

If your notes go into a model, they say they cannot pull that data back out later.

Read the exact line

Privacy policy

“ and data that has been lawfully incorporated into AI or analytics models or other databases will not be removed from those models and datasets”

For example, even after you delete your account, patterns from old meetings may still sit inside the model.

2 · How it is used

Training on combined, data is on unless you switch it off in settings. Work accounts start with it off.

Read the exact line

Privacy policy

“We only use data to train AI models, which you can opt-out of within your Granola account settings.”

For example, open Granola settings and turn off model training if you do not want your notes used that way.

3 · The fine print

If something goes wrong for you as a user, they say they would pay at most one hundred dollars.

Read the exact line

Terms of service

“OUR MAXIMUM TO YOU FOR ANY BREACH OF THE USER TERMS IS ONE HUNDRED DOLLARS ($100) IN THE AGGREGATE.”

For example, if a bug leaks a meeting note, these user terms cap what they say they owe you at $100.

4 · The fine print

They do not promise the notes app will work or that your meeting data is error-free.

Read the exact line

Terms of service

“GRANOLA MAKES NO REPRESENTATIONS OR OF ANY KIND, WHETHER EXPRESS OR IMPLIED, TO YOU RELATING TO THE SERVICES OR ANY CUSTOMER DATA, WHICH ARE PROVIDED TO YOU ON AN “AS IS” AND “AS AVAILABLE” BASIS.”

For example, if a summary misses a key decision, they say they are not promising accuracy.

5 · The fine print

They can shut off your access if they think there is a problem, without promising a warning to you.

Read the exact line

Terms of service

“we may directly step in and take what we determine to be appropriate action (including disabling your account) if Customer does not take appropriate action or we believe there is a credible risk of harm”

For example, they could disable your login after a policy issue even if you still need old notes.

6 · How it is used

Other companies’ cookies may be used to aim ads or marketing at you.

Read the exact line

Privacy policy

“authorized third parties may use Cookies and similar technologies to enhance your experience with our Services and to deliver or target advertising and marketing.”

For example, a marketing partner could use a cookie from the site to show you ads later.

7 · What is collected

Meeting audio is kept only long enough to make a transcript, then they say it is deleted.

Read the exact line

Privacy policy

“Any recordings of communications using our Services are captured only for the purposes of providing you a transcription. We do not retain or store such recordings once the transcription is created.”

For example, after your call is turned into text, the raw audio file should not stay on their servers.

8 · How it is used

They say outside AI vendors cannot train on your personal meeting data.

Read the exact line

Privacy policy

“We do not allow third parties such as OpenAI or Anthropic to use your Personal Data to train AI models.”

For example, a transcript sent to a model provider should not be used to teach that provider’s public model.

9 · How it is used

They say they will not sell your personal data unless you agree.

Read the exact line

Privacy policy

“We will not sell your Personal Data to third parties without your consent.”

For example, they should not sell your email list to another company unless you consent.

10 · The fine print

For big privacy-policy changes they say they will try to warn you a month ahead.

Read the exact line

Privacy policy

“If we believe the changes are material, we will endeavor to provide notice of the changes thirty (30) days before the changes take effect.”

For example, if they start a new data use, they say they will post or send notice about 30 days early.

11 · The fine print

You should be at least 16. They rely on you not signing up if you are younger.

Read the exact line

Terms of service

“To the extent prohibited by applicable law, the Services are not intended for and should not be used by (a) anyone under the age of sixteen”

For example, a 15-year-old is told not to register, but there is no extra age check described.

Words to know

Legal words from the lines above, in plain English.

de-identified
Data with your name and obvious identifiers removed, though it can sometimes still be traced back to you. For example, your chats with names stripped out may still be kept and studied after you delete your account.
model training
Using your content and conversations as examples to teach an AI system, which can then echo them in future answers. For example, a story you write in a chatbot may be studied by the company to make the next version of the bot.
opt out
Something is on by default and stays on until you find the setting and turn it off. For example, your chats may be used for training unless you go into settings and switch it off.
personal data
Any information that is about you or can be linked to you, from your name to your phone's ID. For example, your email, your IP address and the list of apps on your phone are all personal data.
opt in
Something is off until you actively say yes to it. For example, marketing emails that only start after you tick a box are opt in.
limitation of liability
A cap on what the company will ever pay you if something goes wrong, often only what you paid in the last year. For example, if a leak of your data costs you thousands, the most you may get back is a month's subscription fee.
warranty
A promise that a product will work as described; most apps say they make no such promise at all. For example, if a paid feature never works on your phone, a no-warranty clause says that is your problem.
as is
You get the service in whatever state it is in, with no promise that it works or will keep working. For example, if the app deletes your photos by mistake, it is not promising to fix that or pay you back.
third parties
Any company or person other than you and the app, such as advertisers, partners or analytics firms. For example, an analytics company that receives a record of every screen you tap is a third party.
cookies
Small files a website saves on your device so it can recognise you and remember what you did. For example, a cookie keeps you logged in and can also tell an ad company which sites you visited.
sell or share
Under California law, selling means passing your data to others for money or other value; sharing means passing it on for targeted ads. For example, letting an ad network use your browsing history in return for ad space counts as a sale.
consent
Your clear agreement to something, given by an action like ticking a box or tapping Accept. For example, a pop-up asking if the app may use your location is asking for consent.
How we got here · grade B · score 50/100 · 15 of 15 policy answers backed by a verified quote · 3 not stated
  • What does the app collect beyond what it needs to work?

    They collect more than account and notes: device IDs, IP-based location, cookies, calendar invites, meeting audio, transcripts, and sometimes social and payment details.

  • Does it record your voice, face or body, and what happens to that?

    They capture meeting audio to make a transcript, then say they do not keep the recording. Transcripts are kept as meeting content.

  • Are your chats and uploads used to train AI models, and is that off by default?

    De-identified data may be used to train their models unless you opt out in account settings. Enterprise workspaces start opted out. They say vendors like OpenAI cannot train on your personal data.

  • Can employees or contractors read your conversations, and when?

    Not stated in the documents.

  • Are you profiled or tracked for advertising?

    They mention targeted advertising and say authorized third parties may use cookies to deliver or target ads, though they also say they do not sell data for cross-context ads unless disclosed.

  • Do they sell or share your data, and can you opt out?

    They say they will not sell personal data without consent and share it with service providers, affiliates, your company, and legal requests.

  • What rights do they take over what you type and what the AI makes?

    The user terms say meeting content in a workspace is owned by the Customer (such as your employer or the person who invited you), not licensed away to Granola in these pages.

  • How long do they keep your data after you delete it, and can you delete it in the app?

    They keep data while your account is active. You can delete meetings in the app; full account deletion is via Help Center or email. De-identified training data may stay in models forever.

  • Does it build a lasting memory or profile of you, and can you see, edit or turn it off?

    Not stated in the documents.

  • Do they commit to basic security, and have they leaked data?

    They describe encryption in AWS, firewalls, VPC, and other security measures, and point to a Trust Center. No independent audit is described here.

  • Is there a real age gate, and are teens protected?

    They say the service is not for anyone under 16 and ask you not to sign up, with no extra age check described.

  • Will they tell you when the rules change, and is the policy specific?

    The privacy policy is dated and they say they will try to give 30 days’ notice for material changes. The terms also promise reasonable notice for material updates.

  • Can they close your account without warning, and can you get your data out first?

    They may disable your account if they think there is a policy or safety risk. Your workspace owner can also cut off access. No promised export-before-close for users.

  • If something goes wrong, who pays?

    The service is offered “as is,” and their maximum payout to you under these user terms is $100.

  • Do subscriptions renew on their own, and can you get a refund?

    Not stated in the documents.

The privacy policy is 8,722 words at a professional or legal expert level (Flesch reading ease 29.8); the terms are 2,096 words at a college graduate level.

Your privacy
has an agent now

Be in control of your online privacy in the AI Era with confidence.

Gen

From Gen, the Company BehindNorton