Reviewed Jun 2026 · policies are checked weekly for changes · stated — every cell is read from Granola's published policy; none has been tested (run by us) yet.
1Accessstated
You can view your notes in-app and self-serve a CSV of historical notes, but a copy of all your personal data is request-only by email ("email us at privacy@granola.so with the subject line: 'GDPR Request'") — no self-serve rights portal.
Granola — Privacy Policy · accessed Jun 2026 ↗
1Frictionstated
Account deletion and notes export are self-serve in-app, but full access/deletion rights run through email with no self-serve rights portal and no stated response timeline.
Granola — Privacy Policy · accessed Jun 2026 ↗
1Deletionstated
Self-serve account deletion in-app (Settings → Profile → Delete Account) and audio is not retained after transcription, but notes and transcripts are "retained indefinitely unless you or your admin configures a retention policy" and no post-deletion purge timeline is stated.
Granola — Security & Privacy FAQs · accessed Jun 2026 ↗
1Trains AIstated
Granola trains its own models on de-identified data by default with an opt-out (Settings → Preferences → Data & sharing); "we do not allow third parties such as OpenAI or Anthropic to use your Personal Data to train AI models."
Granola — Privacy Policy · accessed Jun 2026 ↗
0API access — feeds Agent Readiness, not the /12stated
Granola offers no public API for a third-party agent to connect to your account data; access is through the desktop app plus an email data request, so an autonomous or remote agent has no sanctioned programmatic path.
Granola — no public consumer API · accessed Jul 2026 ↗
Source-verified Jul 2026 from Granola’s own privacy policy and help center. All cells are "stated" (read from published policy/docs); no live export or deletion has been run to mark any cell "tested."
Events
Breaches, policy changes, and export-format changes we’ve recorded at Granola — other parties’ actions, alongside the enforcement record above. An event never changes a grade by itself. All events →
8 Sep 2026Granola published a new privacy policy, effective 8 September 2026. It adds a HIPAA program for enterprise accounts: those customers can sign a business associate agreement, and under it Granola will not use protected health information to train AI models without express consent. Enterprise training stays off by default, but enterprise users can now opt in.policy change
On the events page →
Grade history
Every change to this company’s grade since it was first published, and why. All grade changes →
No changes since this grade was first published in Jun 2026.