privacydeep-dive

What Grammarly, Notion AI, and Writing Tools Do With Your Text

AI writing assistants process your text on external servers. Here's what Grammarly, Notion AI, and similar tools collect, how long they retain it, and your options.

When you paste text into Grammarly or ask Notion AI to improve a paragraph, the natural mental model is that you’re using a tool. In a strict technical sense, you’re not. You’re sending your text to an external server, where it is processed by software you don’t control, under terms you probably haven’t read, by a company whose business model may or may not align with what you’d want for your most private writing.

For a casual email draft, this is likely fine. For a personal journal entry, a sensitive work document, a private letter, or anything you’d be uncomfortable seeing quoted back to you — it’s worth understanding what actually happens.


The Core Privacy Trade-Off

AI writing tools work by sending your text to their servers for processing. This is not a bug or a privacy shortcut — it is the only way these tools can function. The AI models that check grammar, rephrase sentences, and generate text live in data centers, not on your device. Every piece of text you run through them makes a network request.

The question isn’t whether your text leaves your device — it does. The question is what happens to it afterward:

  • Is it retained on the provider’s servers, and for how long?
  • Can it be used to train or improve the AI model?
  • Who within the company can access your documents?
  • Under what legal circumstances can it be handed to a third party?
  • If you delete your account, does the text get deleted?

The answers vary by service, change over time, and are sometimes buried in policy language that requires careful reading to interpret accurately.


Grammarly: What Gets Sent and Stored

Grammarly is the most widely used AI writing assistant, with hundreds of millions of users across its browser extension, desktop app, and enterprise product. The browser extension, in particular, operates across virtually every website you visit where you type — email clients, social platforms, productivity tools, CMS editors, personal websites.

Grammarly’s privacy policy states that the company collects the text you write, your usage data, and device information. Critically, this includes text you draft in private applications if the Grammarly extension is active and has permission to access those fields.

On the question of training: Grammarly’s policy distinguishes between its free and paid tiers. Free-tier users’ text is subject to use for improving Grammarly’s AI models. Business and Enterprise users can opt out of having their text used for training purposes. This is a meaningful distinction if you’re using the free product and writing anything you’d consider private.

The extension itself is broad in its permissions. When you install Grammarly in Chrome or Firefox, it requests access to “read and change all your data on the websites you visit.” This is not a red flag unique to Grammarly — it’s a necessary permission for any tool that modifies text in browser fields — but it means Grammarly can technically process text entered on banking sites, healthcare portals, legal services, and any other website you visit while the extension is active.

Grammarly does not sell your text to third parties, according to its published policy. It stores data on servers with encryption at rest and in transit. The company is based in the United States and subject to US legal process, which means your text could be produced in response to a valid legal demand.


Notion AI: When Your Notes Become Prompts

Notion has grown into one of the most popular personal knowledge management and productivity tools, and its AI features are now tightly integrated into the core product. When you ask Notion AI to summarize a page, complete a sentence, or generate content based on your notes, those inputs are sent to the AI provider processing the request.

Notion’s AI features are built on third-party foundation models. The company uses providers including OpenAI for some AI processing. This means that when you use Notion AI, your page content may pass through OpenAI’s systems in addition to Notion’s own infrastructure.

Notion’s privacy policy states that AI prompts — which include the text of pages you ask the AI to act on — are not used to train the underlying AI models. However, they are processed on external servers and subject to Notion’s standard data retention practices.

The more relevant concern for Notion users is the breadth of content Notion AI can access. If your Notion workspace contains personal journal entries, financial notes, health records, or private correspondence — and you or a collaborator uses the AI features anywhere in that workspace — the AI processing inherently involves that content being sent to external servers.


Other AI Writing Tools Worth Examining

Jasper and Copy.ai are AI writing tools aimed primarily at marketing and content creation. Both send prompts to external model providers. Jasper’s enterprise tier includes data processing agreements and options for stricter data handling. The standard subscription tier offers fewer controls.

Microsoft Copilot integrates into Word, Outlook, and the rest of the Microsoft 365 ecosystem. Microsoft’s data processing commitments for enterprise users are detailed in its data protection addendum, which provides stronger guarantees than consumer accounts. If you’re using Microsoft 365 through work, your organization may have negotiated specific data handling terms. If you’re a personal subscriber using Copilot in Word to polish a private document, the consumer privacy policy applies, which is less restrictive.

Google Docs’ AI features (Gemini integration) process your document content through Google’s infrastructure. Google’s privacy policy for Google One and Workspace distinguishes between using content to improve its products — which personal account users may be opted into by default — and selling data to advertisers, which it does not do with document content.

Apple Writing Tools (available in macOS Sequoia and iOS 18+) take a different architecture. Many writing assistance features run on-device for shorter text, without a network request. Apple’s Private Cloud Compute handles more complex requests, routing them to Apple’s servers with a stated commitment to not retain the processed data. Apple’s model is meaningfully more privacy-protective than most competitors for this specific use case, though it’s limited to Apple devices.


What “Not Used for Training” Actually Means

Many AI writing services now include language in their privacy policies stating that user content is not used for training their AI models. It’s worth understanding what this does and doesn’t mean.

“Not trained on your data” typically means the company doesn’t use your specific text to fine-tune or update the AI model in a way that could cause your content to surface in someone else’s AI output. This is a meaningful commitment.

It does not mean:

  • Your text isn’t stored on their servers
  • Your text isn’t reviewed by human staff for safety or quality review purposes
  • Your text isn’t subject to legal process
  • Your text is deleted when you close the document or end the session

The retention period is often the more important variable. Text processed on a server may be kept in logs, caches, or infrastructure backups for days, weeks, or months even after you delete the content from your account. Some services are explicit about this; others are not.


Protecting Your Most Personal Writing

The practical hierarchy for protecting your private writing comes down to where you do it.

Highest risk: Typing directly into Grammarly’s web editor or browser extension with sensitive content. The text is sent and stored under commercial terms you don’t control, with training implications that depend on your subscription tier.

Moderate risk: Using AI writing features in Notion, Google Docs, or Microsoft Word with an active AI subscription. Your content is processed externally when AI features are invoked, though the core document storage is separate from AI processing.

Lower risk: Using Apple Writing Tools with on-device processing for shorter tasks, or using locally-run AI writing tools (several open-source options can run entirely on your device with no network component).

Lowest risk for sensitive content: Writing in a local application that has no cloud sync and no AI features enabled. A plain text editor, a local markdown app, or an app specifically designed to store content only on your device or in a private cloud you control.

If you want AI assistance on a document that contains personal content — medical information, financial details, private correspondence, a journal — consider making a sanitized version for AI review, with names, identifying details, and sensitive specifics removed. Edit with the AI’s output, then reconstruct the personal version locally.

The convenience of always-available AI writing tools is real. The trade-off is that every document you run through them becomes, to some degree, part of their infrastructure. For professional and creative writing, that’s often an acceptable exchange. For your most private thoughts, it’s worth pausing before you paste.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts