Does Your Writing App Train on Your Book?
We read the actual privacy policies of 12 writing and AI tools, and quoted exactly what each one says.
The short answer
Of the 12 writing and AI tools we reviewed on August 6, 2026, 4 train on your writing by default and require you to find a setting to stop it — ChatGPT, Claude, Google Gemini and Grammarly. 2 do not mention model training in their privacy policy at all: Sudowrite and Jasper. 2 state plainly that they never train on your text — ProWritingAid and Notion. The remaining 4 never receive your manuscript in readable form, because it stays on your device or is encrypted before it leaves it: Obsidian, Scrivener, NovelAI and CipherWrite. Every opt-out we found is forward-looking only — text already used in a completed training run cannot be removed from the model.
I started this audit because I wanted a straight answer for my own manuscript and could not find one. Every roundup I read was quoting other roundups. So I went and read the source documents instead — the privacy policies and terms of service themselves — and pulled out the actual sentences.
What I found surprised me, and not in the direction I expected. The tools that train on your work are mostly upfront about it. The genuinely uncomfortable category is the one nobody talks about: tools whose policies say nothing at all.
The finding that matters most: silence is not a promise
Two of the most popular AI writing tools for novelists — Sudowrite and Jasper — have privacy policies that do not address model training in either direction. Not a commitment to train. Not a commitment not to.
This matters because of how widely the opposite is asserted. Search for whether Sudowrite trains on your work and you will find review sites stating confidently that it does not. We could not find that commitment in Sudowrite’s own policy. It may well be true as a matter of company practice — but a practice that is not written down is a practice that can change without notifying you, and without breaking any promise.
If you are pasting an unpublished novel into a tool, the standard worth holding is a specific written commitment, not the absence of a stated intention.
The full audit
Every row read against the primary source on August 6, 2026. Quotes marked “verbatim” are the policy’s own words.
| Tool | Verdict | What the policy says |
|---|---|---|
| ChatGPT (OpenAI) | Trains by default | Yes, on Free/Plus/Pro — opt-out available |
| Claude (Anthropic) | Trains by default | Yes, by default — opt-out in settings |
| Google Gemini / Docs | Trains by default | Yes, plus human review of a subset |
| Grammarly | Trains by default | Opt-out control in account settings |
| Sudowrite | Policy is silent | Privacy policy does not address it |
| Jasper | Policy is silent | Privacy policy does not address it |
| ProWritingAid | Says it never trains | States it never trains on your writing |
| Notion | Says it never trains | AI subprocessors contractually barred |
| NovelAI | Never receives your text | Encrypted at rest, you hold the key |
| Obsidian | Never receives your text | Notes never leave your device |
| Scrivener | Never receives your text | Desktop app — files stay on your disk |
| CipherWrite | Never receives your text | Zero-knowledge — encrypted before it leaves your browser |
Tool by tool, with sources
ChatGPT (OpenAI)
Trains by defaultModel training is on by default for ChatGPT Free, Plus and Pro personal accounts. You can turn it off in Settings → Data Controls → “Improve the model for everyone.” API and Business (Team/Enterprise) data is not used for training by default.
Opting out is forward-looking only. Text already absorbed into a completed training run cannot be removed from the model.
Our finding, from reading OpenAI — How your data is used to improve model performance · checked August 6, 2026
Claude (Anthropic)
Trains by defaultWe may use Materials to provide, maintain, and improve the Services and to develop other products and services, including training our models, unless you opt out of training through your account settings.
The same terms state that feedback you submit and content flagged for safety review are used for training even if you have opted out.
Verbatim from Anthropic Consumer Terms of Service · checked August 6, 2026
Google Gemini / Docs
Trains by defaultA subset of chats are reviewed by human reviewers (including Google’s trained service providers) to help improve Google services. […] Google uses your activity to provide, develop, and improve its services (including training generative AI models).
Turning off “Keep Activity” stops future chats being reviewed, but Google states it still uses chats to respond to you and for safety, including with human reviewers.
Verbatim from Google — Gemini Apps Privacy Hub · checked August 6, 2026
Grammarly
Trains by defaultYou can decide whether Superhuman can use your user content to train our AI models by adjusting the available training control(s) in your account settings.
Worth knowing on its own: Grammarly’s privacy-policy URL now 301-redirects to superhuman.com. A corporate rebrand can change which entity governs your text without you being told.
Verbatim from Superhuman Privacy Policy (grammarly.com/privacy-policy now redirects here) · checked August 6, 2026
Sudowrite
Policy is silentWe read the full privacy policy and found no statement about whether customer manuscripts are used to train AI models. The policy covers data sharing with “trusted third parties” but does not name AI providers or describe how manuscripts are handled by them.
Several third-party reviews assert Sudowrite does not train on user writing. We could not find that commitment in the policy itself. Ask them directly and get it in writing.
Our finding, from reading Sudowrite Privacy Policy · checked August 6, 2026
Jasper
Policy is silentWe read the full privacy policy and found no explicit statement about whether customer content is used to train AI models.
Jasper is marketed to enterprise teams, where training commitments usually live in a separate DPA rather than the public policy. Individual users are unlikely to have one.
Our finding, from reading Jasper Privacy Policy · checked August 6, 2026
ProWritingAid
Says it never trainsWe will never use your writing to train our algorithms. […] All of our features uphold our privacy promise to never access your text or use it to train our algorithms.
One of the few unambiguous public commitments we found. Stated as an absolute, with no opt-in carve-out.
Verbatim from ProWritingAid — Our Approach to AI · checked August 6, 2026
Notion
Says it never trainsYour data is yours. Our AI Subprocessors are prohibited from using Customer Data to train models.
This binds the third-party model providers Notion routes your text through. Note it is a contractual promise, not a technical guarantee — Notion can still read your pages.
Verbatim from Notion Security · checked August 6, 2026
NovelAI
Never receives your textContent stored on our servers is encrypted and you bear the decryption key in the form of your password and email address.
The same terms note that anything you voluntarily submit for model training cannot be deleted once training has begun. Lose your password and you lose your stored stories.
Verbatim from NovelAI Terms of Service · checked August 6, 2026
Obsidian
Never receives your textAll data is saved locally on your device and is never sent to our servers. […] Obsidian does not receive or store personal content saved to your local device while using Obsidian.
The strongest structural position on this list: they cannot train on what they never receive. Third-party AI plugins you install are a separate question with separate terms.
Verbatim from Obsidian Privacy Policy · checked August 6, 2026
Scrivener
Never receives your textThe privacy policy does not address document storage or transmission, because the application does not send your documents anywhere. It covers billing, licence activation, update checks and support.
Silence here means something different from Sudowrite’s silence: there is no cloud service to make a promise about. If you sync the folder via Dropbox or iCloud, that provider’s terms apply instead.
Our finding, from reading Literature & Latte Privacy Policy · checked August 6, 2026
CipherWrite
Never receives your textDrafts are encrypted on your device with a key we never receive, so the stored ciphertext is not readable by us and cannot be used as training data by us or anyone we work with.
Disclosure: this is our product, so weigh this row accordingly. The trade-off is real — lose your key and we cannot recover your manuscript, because we genuinely cannot read it.
Our finding, from reading CipherWrite Security · checked August 6, 2026
Three things worth knowing before you change any settings
1. Opting out does not un-train a model
Every opt-out in this audit is forward-looking. Turning off training today stops future text being used; it cannot pull your earlier drafts back out of a model that has already been trained on them. The decision that actually matters is where you paste the manuscript in the first place.
2. A rebrand can move your data’s governing policy
Grammarly’s privacy-policy URL now redirects to superhuman.com, and the policy that governs your text is written in Superhuman’s name. Nothing was hidden — but nobody emails you when the legal entity holding your writing changes. It is worth re-checking the policy of any tool you have used for years.
3. Contractual promises and technical guarantees are different things
Notion’s commitment that its AI subprocessors are “prohibited from using Customer Data to train models” is a genuinely strong contractual position. It is still a promise about behaviour, not a constraint on capability — Notion can read your pages. Obsidian and Scrivener are in a different category, because there is no server holding your text at all. Neither approach is universally better: local files do not sync and cannot be recovered if your laptop dies, and encrypted storage means a lost key is a lost manuscript. Pick the failure mode you can live with.
What we would actually recommend
If privacy is your first concern and you do not need AI assistance, Obsidian or Scrivener are the strongest positions on this list, and neither is ours. Nothing beats a tool that never receives your text.
If you want AI help while drafting, ProWritingAid has the clearest written no-training commitment of any assistive tool we checked. If zero-knowledge encryption specifically is what you are after — the manuscript unreadable even to the company storing it — that is the category CipherWrite and NovelAI occupy, and you should weigh our entry knowing it is ours.
Whatever you choose, keep an offline copy. Read our 3-2-1 backup rule for novelists — no privacy policy protects you from losing the file.
Related reading
- Can you copyright a book you wrote with AI? — the other half of this question, answered from the Copyright Office and the courts
- AI writing tools that don’t train on your work — the recommendation list that grew into this audit
- Is OpenAI reading your novel?
- Are ChatGPT conversations private in 2026?
- How to protect your book idea from being stolen
Methodology
We read each tool’s public privacy policy, terms of service, or dedicated AI/security page on August 6, 2026 and recorded what it said about using customer content to train models. Where a policy states a position, we quote it verbatim and link the source. Where a policy is silent, we say so rather than inferring a commitment in either direction.
We reviewed only publicly available documents. Enterprise customers frequently have separate data processing agreements with stronger terms than the public policy, so a company’s treatment of an enterprise account may differ from what is described here.
Conflict of interest: CipherWrite is our own product and appears in this table. We have tried to apply the same standard to our row as to everyone else’s, and to name competitors — Obsidian, Scrivener, ProWritingAid — where their position is genuinely stronger than ours. Weigh our entry accordingly.
Policies change. If you find a row that is out of date, tell us at contact and we will re-check and update the date.
Frequently asked questions
Does ChatGPT train on my writing?
Yes, by default on the Free, Plus and Pro consumer plans. OpenAI uses those conversations to improve its models unless you turn off "Improve the model for everyone" in Settings → Data Controls. API and Business plans are excluded from training by default. Opting out only affects future conversations — text already used in a completed training run cannot be withdrawn.
Does Sudowrite train on your work?
Sudowrite's published privacy policy does not say. We read it in full on August 6, 2026 and found no statement about whether customer manuscripts are used to train AI models, in either direction. Several third-party reviews claim Sudowrite does not train on user writing, but we could not locate that commitment in the policy itself. If it matters to you, ask their support team for it in writing.
Is a privacy policy that says nothing about training the same as a promise not to train?
No. Silence is not a commitment. A policy that does not mention model training leaves the company free to start, or to permit a third-party AI provider to do so, without breaking any stated promise. A specific, written commitment is the minimum worth relying on.
Can I stop an AI company from training on writing I already submitted?
Generally no. Every opt-out we reviewed is forward-looking. Once text has been incorporated into a completed training run it cannot be extracted from the resulting model. This is why the decision about which tool to paste an unpublished manuscript into matters more than any setting you change afterwards.
Which writing tools cannot train on my manuscript at all?
Tools that never receive your text in readable form. Obsidian and Scrivener store files locally and never transmit them. NovelAI and CipherWrite encrypt content so the provider holds only ciphertext. This is a structural guarantee rather than a policy promise — the company cannot use what it cannot read.
Does an AI company owning my writing mean it owns my copyright?
No. Training on text and owning its copyright are different things. Every tool reviewed here leaves copyright with you. The concern is not ownership transfer but that your unpublished prose becomes part of a model that other people then write with.