Granola — privacy & data policy

Provider: Granola. PromptPrivacy score: 76/100. Last verified August 26, 2026.

What happens to your data?

Granola captures and processes your meeting audio, notes, and calendar information to generate transcripts and AI-powered summaries. Audio recordings are immediately deleted after transcription is complete, and your data is encrypted at rest and in transit on AWS servers. Your personal information is not sold or shared with third-party AI providers for model training.

Does it train on your data?

Third-party AI providers (such as OpenAI or Anthropic) are strictly prohibited from using personal data to train their models. Granola only uses aggregated, de-identified data to evaluate and train its internal AI models when users are opted in. Standard users can opt out via account settings, and enterprise workspace users are opted out by default.

Can you opt out?

Yes. Users can opt out of AI model training using de-identified data through their account settings. Enterprise workspace products have model training disabled by default with admin controls. Users can also unsubscribe from promotional communications.

Data retention

Audio recordings are not stored or retained once a transcription is generated. Access tokens and license keys for third-party integrations are deleted promptly when access is revoked. Personal data and transcripts are retained for as long as your account is active or needed to provide services and comply with legal requirements. De-identified and aggregated data incorporated into models may be retained indefinitely.

Encryption & security

All personal data is encrypted both in transit and at rest using Amazon Web Services (AWS) encrypted database systems. Granola also employs virtual private clouds (VPCs), firewalls, anti-virus/malware protection, and security controls on stored browser authentication credentials.

Is it safe for work?

Yes, Granola provides business-friendly protections, particularly for enterprise workspace tiers where AI model training is disabled by default. Third parties like OpenAI and Anthropic are prohibited from training on user data, audio recordings are deleted immediately after transcription, data is encrypted at rest and in transit, and Data Protection Agreements (DPAs) with Standard Contractual Clauses are available.

Source policy: https://www.granola.ai/privacy