Grok Bot
- The documents do not say whether your data trains AI.
- Your data is used for personalized ads, including by third-party ad companies.
- The documents do not say whether your data is sold or shared.
- Staff may review your content; the policy does not describe an opt-out.
You give Grok a forever right to your chats, staff may read them, and you cannot join a group lawsuit.
Agent Trust Hub uses AI and may make mistakes. Review reports and confirm their contents before relying on them.
Collected
Account info, birthday, chats, files, voice and images, device details, and sometimes your X history.
Read the exact line
Privacy policy
“You may provide personal information in prompts and other content you input, such as files, images, audio, voice, video, and other material (“Input”).”
Training
If you use Grok without logging in, they can use what you send to build and train their models.
Read the exact line
Terms of service
“when doing so, where permitted, you grant us full rights to use any data you provide to or obtain from our Service for product development and model training purposes.”
Sharing
Staff may read your chats to improve the product, check misuse, and follow the law.
Read the exact line
Terms of service
“Our authorized personnel may review how you use the Service and your User Content for specific business purposes, including improving product features, investigating security incidents and potential misuse of our Service, and complying with our legal obligations.”
Kept
Deleted chats and accounts are wiped within 30 days, unless law or safety means they keep them longer.
Read the exact line
Privacy policy
“if you choose to delete any or all of your conversations or if you choose to delete your account, we will delete the data within 30 days unless it is necessary to retain the data for legal, compliance, or safety purposes.”
Controls
When logged in, you can choose if your chats train their models, and you can delete chats or your account.
Read the exact line
Terms of service
“When logged into our Service, you can select whether or not you want us to use your User Content to improve our products and services and train our models.”
Fine print
They keep a forever right to what you submit, can close your account without warning, and paid plans do not refund.
Read the exact line
Terms of service
“you grant an , , transferable, , , and worldwide right to SpaceXAI to use, copy, store, modify, process, adapt, transmit, distribute, reproduce, publish, upload, download, display in public forums”
Expand “Read the exact line” to see the source alongside the explanation.
What you can turn off
The controls and opt-outs their own documents describe, and where they say to find them.
Choose whether your chats train their models
When logged into the Service, select whether your User Content is used to improve products and train models
Turn on Private Chat for chats you do not want in history
In the Service, turn on Private Chat; those chats are deleted within 30 days unless kept for legal, compliance, or safety reasons
Delete chats or your account
In the Service, delete conversations or your account; other privacy requests go to https://x.ai/privacy-portal/
Cancel a paid plan before the next charge
Cancel the subscription in the Service; payment questions go to support@x.ai
If a switch is not where they say, the deletion request above still applies.
Line by line
The lines that matter most, worst first.
They can keep using, changing, and passing on what you type and what Grok makes, even after you leave, and for reasons beyond just running the chat.
Read the exact line
Terms of service
“you grant an , , transferable, , , and worldwide right to SpaceXAI to use, copy, store, modify, process, adapt, transmit, distribute, reproduce, publish, upload, download, display in public forums”
For example, a private story or photo you upload could be copied, changed, and shown in a public place under this permission.
If someone sues them because of how you used Grok or what you sent, you may have to pay their legal costs. People in Europe are left out of this rule.
Read the exact line
Terms of service
“you will , and hold SpaceXAI and our parents, subsidiaries and affiliates, and our and their respective agents, suppliers, licensors, employees, contractors, officers, and directors (collectively the “SpaceXAI Indemnitees”) harmless from and against any and all claims”
For example, if a chat reply you shared gets the company sued, they can ask you to pay the lawyers.
If something goes wrong, the most they say they will pay is what you paid them, or $100 if that is more, except for serious wrongdoing.
Read the exact line
Terms of service
“IN NO EVENT WILL SPACEXAI OR ANY SPACEXAI INDEMNITEE BE TO YOU FOR ANY CLAIMS, PROCEEDINGS, LIABILITIES, OBLIGATIONS, DAMAGES, LOSSES, OR COSTS IN AN AMOUNT EXCEEDING THE AMOUNT YOU PAID TO US HEREUNDER OR ONE HUNDRED U.S. DOLLARS ($100.00), WHICHEVER IS GREATER”
For example, if a bad reply causes you a big loss, they may only owe you $100 if you never paid for Grok.
You give up a jury and cannot join a group case with other users. Most fights go to courts in two Texas counties.
Read the exact line
Terms of service
“YOU AND SPACEXAI ARE EACH WAIVING THE RIGHT TO A TRIAL BY JURY OR TO BRING, JOIN, OR PARTICIPATE IN ANY PURPORTED , , PRIVATE ATTORNEY GENERAL ACTION, OR OTHER REPRESENTATIVE PROCEEDING”
For example, if many people have the same billing problem, you would have to fight yours alone.
They can shut your account or cancel a paid plan without telling you first if they decide you broke the rules, the law requires it, your use could cause harm, or you have been inactive for more than 120 days.
Read the exact line
Terms of service
“We may terminate or suspend your access to our Service, cancel your subscription or account, or delete your account at any time without notice to you if we determine, at our sole discretion, that:”
For example, you could open the app and find your chats and paid plan gone, with no warning email.
Paid plans keep charging until you cancel, and money already taken is not given back unless the law says so. People in Europe can withdraw within 14 days and get that payment back.
Read the exact line
Terms of service
“You can cancel your paid subscription at any time; however, payments already made are non-refundable, except where required by law.”
For example, if you cancel the day after a renewal, you may still lose that month’s fee.
If you use Grok without an account, they say they can use what you send to improve products and train models. The documents do not say whether training is already on for logged-in users.
Read the exact line
Terms of service
“when doing so, where permitted, you grant us full rights to use any data you provide to or obtain from our Service for product development and model training purposes.”
For example, a question you type before signing in could be used to teach the next version of Grok.
People who work for them may read your chats, not only when there is abuse or a legal demand, but also to improve the product. No switch to stop that review is described.
Read the exact line
Terms of service
“Our authorized personnel may review how you use the Service and your User Content for specific business purposes, including improving product features, investigating security incidents and potential misuse of our Service, and complying with our legal obligations.”
For example, a personal chat about your health could be opened by a staff member working on a new feature.
Cookies and similar tools may be used to show you targeted ads and to study traffic on their sites and on other sites. They also say they do not change anything when your browser sends Do Not Track.
Read the exact line
Privacy policy
“Deliver relevant content and targeted advertising;”
For example, sites you visit could be used to pick ads you see around Grok.
If you sign in with X, they may copy posts you can see, including protected ones, plus your X usage and old Grok chats on X, into your SpaceXAI account.
Read the exact line
Terms of service
“X post history (your X posts viewable on your X account including posts to and from all accounts (public or protected) that you can view), X usage data, and your Grok on X conversation history”
For example, a protected post from a friend that you can see on X could be brought into your Grok account.
You can delete chats or your account, and they say the data is gone within 30 days, unless they need it for the law, rules, or safety.
Read the exact line
Privacy policy
“if you choose to delete any or all of your conversations or if you choose to delete your account, we will delete the data within 30 days unless it is necessary to retain the data for legal, compliance, or safety purposes.”
For example, after you delete a chat, it should be removed within a month unless a safety review keeps it.
Words to know
Legal words from the lines above, in plain English.
- personal data
- Any information that is about you or can be linked to you, from your name to your phone's ID. For example, your email, your IP address and the list of apps on your phone are all personal data.
- prompt
- What you type or say to an AI to get a response. For example, asking a chatbot to write a birthday message is a prompt, and it may be stored.
- inputs and outputs
- Inputs are what you type, say or upload to an AI; outputs are what it gives back to you. For example, the question you ask a chatbot is an input and its answer is an output, and both may be stored.
- model training
- Using your content and conversations as examples to teach an AI system, which can then echo them in future answers. For example, a story you write in a chatbot may be studied by the company to make the next version of the bot.
- irrevocable
- Cannot be taken back or cancelled once given, even if you change your mind or delete your account. For example, an irrevocable licence to your photos means you cannot withdraw it later.
- perpetual
- Lasting forever, with no end date. For example, a perpetual licence means the company can keep using your video years after you leave.
- sublicensable
- The company can pass its rights over your content on to other companies without asking you. For example, an app can let an advertiser or a partner reuse your video under the licence you gave.
- royalty-free
- The company can use your content without ever paying you for it. For example, your photo can appear in the app's ads and you get nothing.
- indemnify
- You promise to pay the company's legal costs and losses if your use of the service gets it sued. For example, if you post a song you do not own and the label sues the app, you owe the app's lawyer bills.
- affiliates
- Other companies owned by or connected to the same parent company. For example, if you use one app, its sister apps under the same owner may also get your data.
- service providers
- Outside companies that handle your data on the app's instructions, such as a cloud host or an email sender. For example, the company that stores the app's files in the cloud sees your data but only does what the app tells it.
- limitation of liability
- A cap on what the company will ever pay you if something goes wrong, often only what you paid in the last year. For example, if a leak of your data costs you thousands, the most you may get back is a month's subscription fee.
How we got here · grade D · score 39/100 · 15 of 15 policy answers backed by a verified quote · 3 not stated
What does the app collect beyond what it needs to work?
They collect account details, birthday, chats, files, images, audio, and voice, plus device, usage, and cookie data. With your OK they can take precise location, and an X login can bring in posts you can see, including protected ones.
Does it record your voice, face or body, and what happens to that?
You can send audio, voice, video, and images, and those stay with your content. They also take the same broad rights over a person’s image, likeness, or voice that you include. They say they do not aim to collect biometric scans and do not use uploaded images to identify people.
Are your chats and uploads used to train AI models, and is that off by default?
Not stated in the documents.
Can employees or contractors read your conversations, and when?
Authorized staff may read how you use the service and your content to improve features, check security and misuse, and follow the law. No way to opt out of that review is described.
Are you profiled or tracked for advertising?
Cookies and similar tools may be used for targeted ads and to study traffic on their sites and on other sites. They say they do not change their practices when a browser sends Do Not Track.
Do they sell or share your data, and can you opt out?
Not stated in the documents.
What rights do they take over what you type and what the AI makes?
You keep ownership of what you submit and what Grok makes, but you also give them a forever, transferable right to use, change, share, and publicly display that content for any purpose. That right is not limited to running the service.
How long do they keep your data after you delete it, and can you delete it in the app?
If you delete chats or your account, they say the data is deleted within 30 days, unless they must keep it for legal, compliance, or safety reasons. Private Chat is also deleted within 30 days, with the same exception.
Does it build a lasting memory or profile of you, and can you see, edit or turn it off?
Not stated in the documents.
Do they commit to basic security, and have they leaked data?
They describe ordinary technical, administrative, and organizational protections, and they say no method is fully safe. They do not describe an outside audit or a program for reporting security flaws.
Is there a real age gate, and are teens protected?
You must be at least 13 and confirm that. Teens 13 to 17 need a parent or guardian who agrees to the terms. In Australia they also use age checks before 18+ content.
Will they tell you when the rules change, and is the policy specific?
Both documents show a date, and they post a new version when rules change. Keeping using the service means you accept the new rules. They do not promise advance notice for everyone, though people in Europe may get an in-app or email notice of a material change.
Can they close your account without warning, and can you get your data out first?
They can suspend access for any reason, or no reason where the law allows. They can also cancel or delete your account at any time without notice for a broken rule, the law, risk of harm, or more than 120 days of inactivity. No way to download your data first is described.
If something goes wrong, who pays?
The service is offered as-is, and what they pay is capped at what you paid or $100, whichever is more. You may also have to cover their legal costs for claims tied to your use, your input, or a broken rule. That cost-shifting rule does not apply to European consumers.
Do subscriptions renew on their own, and can you get a refund?
Paid plans charge your payment method again each period until you cancel. Money already paid is not refunded except where the law requires it. Price increases get reasonable notice before the next renewal. European consumers can withdraw within 14 days and get that subscription payment back.
The privacy policy is 2,360 words at a college graduate level (Flesch reading ease 37.6); the terms are 7,758 words at a college level.