BACK TO HOME
granola

granola

General Servicegranola.so

Privacy Conclusion

"Granola presents a medium-high privacy risk (score: 62/100) comparable to mainstream SaaS products like Netflix, driven by extensive collection of sensitive meeting content, audio, and communications data; indefinite retention of de-identified data for AI training with no removal option; and default-enabled behavioral advertising with third-party tracking. The ability of account administrators to override user privacy preferences and the collection of data from non-consenting meeting participants represent significant control issues."

Risk Score
62
ELEVATED

granola Privacy Concerns & Scorecard

Privacy Risk Analysis
Data CollectionCRITICAL

Granola collects meeting content and communications from users and their contacts without explicit per-meeting consent. Calendar and meeting data may include sensitive information about third parties who did not consent.

Tracking & AdsHIGH

Granola uses cookies, web beacons, and pixels for cross-context behavioral advertising (targeted advertising). Targeted advertising is enabled by default with no explicit opt-out at account creation, and the policy does not clearly disclose which third-party ad networks receive data.

Retention & ControlHIGH

De-identified and aggregated data is retained indefinitely for AI model training with no deletion mechanism. Even after account closure, Granola continues using information for 'legitimate business purposes and AI model improvement.'

Transparency & RightsHIGH

Account administrators can override individual user privacy preferences, eliminating user control over their own data in organizational settings. Users cannot prevent mandatory service communications from continuing after opting out of marketing.

Third-Party SharingHIGH

Granola shares personal data with an undefined set of 'Service Providers' and 'authorized third-party integration platforms' without itemizing which companies or what safeguards apply. De-identified data is shared indefinitely for AI model training with no removal mechanism.

TransparencyMEDIUM

Policy uses ambiguous language around data control responsibilities. Granola states it is a 'limited data controller' of account information but 'processor' of user-shared data, creating confusion about which privacy rights apply.

Recommended Actions

No recommended actions at this time.

Automate your privacy

Connect your accounts to TrueTerms to automate these privacy actions and monitor policy changes.

Data Collection & Tracking

Personal Information Collected

Identity Data

Account creation, authentication, and communication

Financial Data

Payment processing and billing

Professional Data

Service provision and personalization

Location Data

Service personalization and analytics

Device & Network Data

Service delivery, analytics, and fraud prevention

Communication & Meeting Content

Service functionality, AI model training, and service improvement

Usage & Activity Data

Service analytics, improvement, and targeted advertising

Social Media Data

Account linking and authentication

Tax & Identification Data

Tax compliance and legal obligations

Cross-Platform Tracking

Granola uses cookies, web beacons, and pixels for cross-context behavioral advertising, meaning it tracks your activity for targeted advertising purposes across different websites and services where you encounter their tracking technologies. The policy does not explicitly describe tracking across unrelated websites, but states 'Cookies used for tracking across services despite claim of not tracking across different websites.'

Tracking Methods:

Cookies (First-Party & Third-Party)

Persistent and session cookies used for authentication, preferences, analytics, and targeted advertising

Web Beacons & Pixels

Tracking pixels and web beacons embedded in emails and web pages to measure engagement and enable retargeting

Advertising Identifiers

Mobile advertising IDs (AAID, IDFA) used for cross-platform behavioral advertising

Device Fingerprinting

Collection of device attributes and characteristics to create a unique device profile

AI & Data Training

granola uses your content to train AI

Below is what's used and how (if at all) you can object.

What Content Is Used

  • Meeting Transcripts

    De-identified and aggregated meeting transcripts are used for AI model training purposes and retained indefinitely without removal option.

  • Meeting Recordings & Audio

    De-identified meeting audio and related data used for AI model training; original recordings are deleted after transcription but de-identified versions retained indefinitely.

  • Calendar & Meeting Data

    De-identified calendar events and meeting metadata used for AI model training and service improvement.

  • Aggregated Usage & Analytics Data

    De-identified usage patterns, analytics, and engagement metrics used for AI model training and benchmarking.

How to Object

  1. 1

    Go to account settings and toggle off 'Allow personal data to be used for AI model training.' Enterprise Workspace Products are opted out by default; consumer users are opted in by default.

Why We Analyzed granola

TrueTerms automatically audits privacy policies and data practices using advanced machine learning to keep you informed and protected. This scorecard is based on the latest available public terms of service and privacy policies as of 2026.