Is Grammarly GDPR compliant? What universities should check
Grammarly runs inside browsers, Word and learning platforms on thousands of campuses, and many students install it themselves. This page sets out what the company publicly documents for individual and institutional plans, and what a university should check before licensing it or allowing it in coursework.
Short answer
Grammarly is now part of Superhuman: the privacy policy and the data protection addendum are issued by Superhuman Platform Inc. (formerly Grammarly), a US company in San Francisco, with VeraSafe Ireland Ltd as its representative in the EEA. Plans range from Free and Premium for individuals to Pro, Business, Enterprise and Grammarly for Education. Data is hosted by Amazon Web Services in the United States, transfers rely on the EU-US Data Privacy Framework with Standard Contractual Clauses as a fallback, and AI training is on by default for individual accounts but off by default for Education and Enterprise accounts. Whether a university can use Grammarly depends on which plan it licenses, whether it signs the DPA, how it handles the move of text to the US, and which features (such as Authorship or generative AI) it enables for staff and students.
Prefer a tool built in the EU? Kahubi, from Avidemic AB in Sweden, covers AI writing support with EU hosting and, for institutions, only European subprocessors. See how Kahubi handles research data
What Grammarly documents publicly
Everything below comes from Grammarly's and Superhuman's own pages and the official Data Privacy Framework List, all read on 7 October 2026. Several Grammarly URLs now redirect to superhuman.com.
| Topic | What the vendor states | Source |
|---|---|---|
| Company and establishment | Documented The privacy policy (effective 6 July 2026) covers Superhuman Platform Inc. (formerly Grammarly) and subsidiaries including Grammarly Inc. The controller is Superhuman Platform Inc., San Francisco. VeraSafe Ireland Ltd (Cork) is appointed as representative in the EEA. No EU-established contracting entity is named. | [1] |
| Where data is stored and processed | Documented Data is stored on Amazon Web Services servers in US-based data centres, in the US East region, with native backup tools. Not found publicly An EU data residency option: not found in public documentation (checked 7 October 2026). | [3], [4], [5] |
| Data processing agreement | Documented The Superhuman Data Privacy Addendum (effective 8 July 2026) is published and incorporated into agreements between the customer and Superhuman Platform Inc., which acts as processor. It covers breach notification without undue delay, assistance with DPIAs, audit report summaries and return or destruction of data at the end of the agreement. For organisational accounts, the privacy policy does not apply to content; Superhuman processes it under the organisation's contract. | [1], [6] |
| Subprocessors | Documented A public list covers products offered as Grammarly, Docs, Superhuman Go and Superhuman Mail. Every third-party subprocessor listed is shown with the USA as country, including Anthropic, OpenAI, Microsoft Azure and Baseten as generative AI providers, AWS for hosting, and Deepgram and Soniox for transcription. Customers who opt in get 30 days' notice of new subprocessors and may object. | [6], [7] |
| International transfers | Documented Superhuman states that it complies with the EU-U.S. Data Privacy Framework, the UK Extension and the Swiss-U.S. framework. The official DPF List shows "Superhuman Platform Inc. (formerly Grammarly, Inc.)" as active, with Grammarly Inc. among covered entities. The DPA incorporates the 2021 EU SCCs where the framework does not cover a transfer. | [1], [6], [8] |
| AI model training on customer content | Plan-dependent Free, Premium and single-user Pro: training on by default, user can switch it off. Multi-user Pro bought on the website: on by default, admins can switch it off. Grammarly for Education, Enterprise, and Business or Pro bought through sales: off by default. With training off, non-content data such as writing statistics may still be used. Superhuman says it restricts its AI service providers from training on customer content. | [1], [2] |
| Retention and deletion | Plan-dependent Documents saved in the Grammarly Editor are kept until the user deletes them or the account. Personal data is kept as long as necessary for the stated purposes. For customers, the DPA provides for return or destruction on written request at the end of the agreement. A fixed retention period for text processed by the extension: not found in public documentation (checked 7 October 2026). | [1], [3], [6] |
| Security certifications | Documented SOC 2 Type 2 and SOC 3 reports; ISO/IEC 27001, 27017, 27018, 27701 and 42001. Audit reports are available on request through sales. | [4], [5] |
| Institution and enterprise controls | Documented SAML single sign-on, team administration, multi-factor authentication and custom session controls. For Grammarly for Education, admins can choose which AI features to turn on and who has access. The Authorship feature gives instructors a replay of where text in a student's document came from. | [5], [9] |
What this means for a university
Validemic's analysisIndividual and institutional accounts are different set-ups. A student or researcher on a free or Premium account is a customer of Superhuman under its privacy policy, with training on unless they switch it off [1], [2]. When a university licenses Grammarly for Education or Enterprise, content is processed under the organisation's contract and the DPA, training is off by default, and admins control features [1], [2], [9]. Article 28 GDPR requires a binding contract with a processor [10], so institutional use should run on the institutional plan with the DPA in place. Credit where it is due: the DPA is published rather than available only on request, the training defaults for education and enterprise are clearly documented, and the certification set is broad.
The text goes to the United States. Grammarly states its data is hosted in the AWS US East region and every listed third-party subprocessor is in the USA [5], [7]. The transfer basis is the EU-US Data Privacy Framework, which the European Commission recognises as providing adequate protection for participating organisations [11], with SCCs as a fallback [6]. That is a recognised route, but a DPO should record it, and note that a change to the framework would shift the transfer onto the SCCs and a transfer impact assessment.
The browser extension widens what is processed. Grammarly says it only reads text while the product is active and skips sensitive fields such as passwords on a best-efforts basis [3]. In practice, an active extension can process whatever a staff member types into webmail, the student information system or a peer review portal. A university licence should come with guidance on where the extension may be used, or with deployment settings that limit it.
Authorship is a monitoring feature. Authorship records how a student's document was written and lets instructors replay it [9]. Processing that tracks how individual students work, possibly at scale, is the kind of activity where many DPOs will want a DPIA under Article 35 GDPR [10], a clear legal basis, and transparent information for students. It also brings in the AI Act, discussed below, if used to judge academic integrity or learning outcomes.
Generative AI goes through third parties. The subprocessor list names Anthropic, OpenAI, Azure and Baseten as generative AI providers [7]. The DPA requires subprocessors to provide at least the same level of protection [6], but the university's records should still show these providers as part of the processing chain.
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
Questions to ask Grammarly before approving it
- Which Superhuman entity will sign our Grammarly for Education agreement, and is the published Data Privacy Addendum incorporated as is?
- Is any EU or EEA hosting option available for education customers, now or on a published roadmap?
- Can you confirm in writing that Product Improvement and Training is off for every user in our licence, including students who joined with an existing personal account?
- Which subprocessors process the text of our users (not only account data), and for which features?
- How long is text processed by the browser extension and the desktop app retained if the user never saves a document?
- Can admins restrict where the extension runs, for example by blocking it on specific university domains?
- What personal data does Authorship collect, how long is it kept, who can see the replay, and can we turn it off for some courses?
- What happens to our transfers if the EU-US Data Privacy Framework is suspended or invalidated?
- Can we receive the SOC 2 Type 2 report and the ISO/IEC 27701 and 42001 certificates before contract signature?
The EU AI Act angle
Regulation (EU) 2024/1689, the AI Act, has applied in stages [12]. Article 4 on AI literacy has applied to deployers since 2 February 2025. The Digital Omnibus on AI, Regulation (EU) 2026/1744, which entered into force on 27 July 2026, replaced Article 4: providers and deployers must take measures to support the AI literacy of their staff, without guaranteeing a specific level for any individual [13], [14]. A university that licenses Grammarly is a deployer.
Writing suggestions on their own are normally not a high-risk use. Annex III point 3 lists AI systems intended to evaluate learning outcomes and to monitor and detect prohibited behaviour of students during tests [12]. If a university uses Grammarly features such as Authorship to decide on grades or academic misconduct, it should assess whether that use falls under Annex III. After the Omnibus, the Annex III high-risk rules apply from 2 December 2027 [13], [14]. Chapter V obligations for general-purpose AI models have applied since 2 August 2025 and sit with the model providers [12]. Of the generative AI subprocessors Grammarly lists, Anthropic, OpenAI, Microsoft and Google appear on the European Commission's list of signatories of the General-Purpose AI Code of Practice [15]; Grammarly and Superhuman do not appear on that list.
Sources
- Superhuman, Privacy Policy (effective 6 July 2026; grammarly.com/privacy-policy redirects here), retrieved 7 October 2026.
- Grammarly Support, Product Improvement and Training Control, retrieved 7 October 2026.
- Grammarly, How We Protect Your Privacy, retrieved 7 October 2026.
- Grammarly, Security Compliances, Certifications, and Validations, retrieved 7 October 2026.
- Grammarly, Security at Grammarly, retrieved 7 October 2026.
- Superhuman, Superhuman Data Privacy Addendum (effective 8 July 2026), retrieved 7 October 2026.
- Superhuman, Superhuman Subprocessors, retrieved 7 October 2026.
- U.S. Department of Commerce, Data Privacy Framework List (entry for Superhuman Platform Inc., formerly Grammarly, Inc.), retrieved 7 October 2026.
- Grammarly, Grammarly for Education, retrieved 7 October 2026.
- Regulation (EU) 2016/679 (General Data Protection Regulation), Articles 28 and 35, retrieved 7 October 2026.
- European Commission, Data protection adequacy for non-EU countries, retrieved 7 October 2026.
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal L, 12 July 2024, Articles 4 and 113 and Annex III, retrieved 7 October 2026.
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal L, 24 July 2026, retrieved 7 October 2026.
- European Commission, AI Act (application timeline), retrieved 7 October 2026.
- European Commission, The General-Purpose AI Code of Practice (signatories), retrieved 7 October 2026.
About this page
We read Grammarly's and Superhuman's public privacy, security, compliance, support, DPA and subprocessor pages, the official Data Privacy Framework List and the EU legal texts on 7 October 2026. We did not test the product or review any institution's contract. Grammarly's legal pages are moving to the Superhuman brand, so check the linked pages before relying on them. This page is not legal advice and is not a verdict on whether any organisation's use of Grammarly complies with the GDPR. If you work at Grammarly or Superhuman or spot an error, please contact us and we will correct it.
Frequently asked questions
Does Grammarly train on my data?
It depends on the account. For Grammarly Free, Premium and single-user Pro accounts, and multi-user Pro accounts bought on the website, Product Improvement and Training is on by default and can be switched off. For Grammarly for Education, Enterprise, and Business or Pro accounts bought through the sales team, it is off by default (checked 7 October 2026).
Where does Grammarly store data?
Grammarly says it stores data on Amazon Web Services servers in US-based data centres, in the US East region. We did not find an EU data residency option in its public documentation (checked 7 October 2026).
Does Grammarly sign a DPA?
Yes, a Superhuman Data Privacy Addendum is published online and is incorporated into agreements between customers and Superhuman Platform Inc., with Superhuman acting as processor. Individual users are covered by the privacy policy instead, with Superhuman as controller.
Is Grammarly covered by the EU-US Data Privacy Framework?
Yes. The official Data Privacy Framework List shows Superhuman Platform Inc. (formerly Grammarly, Inc.) as an active participant, with Grammarly Inc. as a covered entity. The DPA uses the Standard Contractual Clauses as a fallback if the framework does not cover a transfer.
Can students use Grammarly under GDPR?
Students may use a personal account under Grammarly's own privacy policy. If the university licenses Grammarly for Education or requires it for coursework, the university becomes the controller for that use and should rely on the institutional contract and DPA, keep training off and assess features such as Authorship that record the writing process.