Privacy Audit·Last checked August 6, 2026

Does Your Writing App Train on Your Book?

We read the actual privacy policies of 12 writing and AI tools, and quoted exactly what each one says.

The short answer

Of the 12 writing and AI tools we reviewed on August 6, 2026, 4 train on your writing by default and require you to find a setting to stop it — ChatGPT, Claude, Google Gemini and Grammarly. 2 do not mention model training in their privacy policy at all: Sudowrite and Jasper. 2 state plainly that they never train on your text — ProWritingAid and Notion. The remaining 4 never receive your manuscript in readable form, because it stays on your device or is encrypted before it leaves it: Obsidian, Scrivener, NovelAI and CipherWrite. Every opt-out we found is forward-looking only — text already used in a completed training run cannot be removed from the model.

I started this audit because I wanted a straight answer for my own manuscript and could not find one. Every roundup I read was quoting other roundups. So I went and read the source documents instead — the privacy policies and terms of service themselves — and pulled out the actual sentences.

What I found surprised me, and not in the direction I expected. The tools that train on your work are mostly upfront about it. The genuinely uncomfortable category is the one nobody talks about: tools whose policies say nothing at all.

The finding that matters most: silence is not a promise

Two of the most popular AI writing tools for novelists — Sudowrite and Jasper — have privacy policies that do not address model training in either direction. Not a commitment to train. Not a commitment not to.

This matters because of how widely the opposite is asserted. Search for whether Sudowrite trains on your work and you will find review sites stating confidently that it does not. We could not find that commitment in Sudowrite’s own policy. It may well be true as a matter of company practice — but a practice that is not written down is a practice that can change without notifying you, and without breaking any promise.

If you are pasting an unpublished novel into a tool, the standard worth holding is a specific written commitment, not the absence of a stated intention.

The full audit

Every row read against the primary source on August 6, 2026. Quotes marked “verbatim” are the policy’s own words.

ToolVerdictWhat the policy says
ChatGPT (OpenAI)Trains by defaultYes, on Free/Plus/Pro — opt-out available
Claude (Anthropic)Trains by defaultYes, by default — opt-out in settings
Google Gemini / DocsTrains by defaultYes, plus human review of a subset
GrammarlyTrains by defaultOpt-out control in account settings
SudowritePolicy is silentPrivacy policy does not address it
JasperPolicy is silentPrivacy policy does not address it
ProWritingAidSays it never trainsStates it never trains on your writing
NotionSays it never trainsAI subprocessors contractually barred
NovelAINever receives your textEncrypted at rest, you hold the key
ObsidianNever receives your textNotes never leave your device
ScrivenerNever receives your textDesktop app — files stay on your disk
CipherWriteNever receives your textZero-knowledge — encrypted before it leaves your browser

Tool by tool, with sources

ChatGPT (OpenAI)

Trains by default
Model training is on by default for ChatGPT Free, Plus and Pro personal accounts. You can turn it off in Settings → Data Controls → “Improve the model for everyone.” API and Business (Team/Enterprise) data is not used for training by default.

Opting out is forward-looking only. Text already absorbed into a completed training run cannot be removed from the model.

Our finding, from reading OpenAI — How your data is used to improve model performance · checked August 6, 2026

Claude (Anthropic)

Trains by default
We may use Materials to provide, maintain, and improve the Services and to develop other products and services, including training our models, unless you opt out of training through your account settings.

The same terms state that feedback you submit and content flagged for safety review are used for training even if you have opted out.

Verbatim from Anthropic Consumer Terms of Service · checked August 6, 2026

Google Gemini / Docs

Trains by default
A subset of chats are reviewed by human reviewers (including Google’s trained service providers) to help improve Google services. […] Google uses your activity to provide, develop, and improve its services (including training generative AI models).

Turning off “Keep Activity” stops future chats being reviewed, but Google states it still uses chats to respond to you and for safety, including with human reviewers.

Verbatim from Google — Gemini Apps Privacy Hub · checked August 6, 2026

Grammarly

Trains by default
You can decide whether Superhuman can use your user content to train our AI models by adjusting the available training control(s) in your account settings.

Worth knowing on its own: Grammarly’s privacy-policy URL now 301-redirects to superhuman.com. A corporate rebrand can change which entity governs your text without you being told.

Verbatim from Superhuman Privacy Policy (grammarly.com/privacy-policy now redirects here) · checked August 6, 2026

Sudowrite

Policy is silent
We read the full privacy policy and found no statement about whether customer manuscripts are used to train AI models. The policy covers data sharing with “trusted third parties” but does not name AI providers or describe how manuscripts are handled by them.

Several third-party reviews assert Sudowrite does not train on user writing. We could not find that commitment in the policy itself. Ask them directly and get it in writing.

Our finding, from reading Sudowrite Privacy Policy · checked August 6, 2026

Jasper

Policy is silent
We read the full privacy policy and found no explicit statement about whether customer content is used to train AI models.

Jasper is marketed to enterprise teams, where training commitments usually live in a separate DPA rather than the public policy. Individual users are unlikely to have one.

Our finding, from reading Jasper Privacy Policy · checked August 6, 2026

ProWritingAid

Says it never trains
We will never use your writing to train our algorithms. […] All of our features uphold our privacy promise to never access your text or use it to train our algorithms.

One of the few unambiguous public commitments we found. Stated as an absolute, with no opt-in carve-out.

Verbatim from ProWritingAid — Our Approach to AI · checked August 6, 2026

Notion

Says it never trains
Your data is yours. Our AI Subprocessors are prohibited from using Customer Data to train models.

This binds the third-party model providers Notion routes your text through. Note it is a contractual promise, not a technical guarantee — Notion can still read your pages.

Verbatim from Notion Security · checked August 6, 2026

NovelAI

Never receives your text
Content stored on our servers is encrypted and you bear the decryption key in the form of your password and email address.

The same terms note that anything you voluntarily submit for model training cannot be deleted once training has begun. Lose your password and you lose your stored stories.

Verbatim from NovelAI Terms of Service · checked August 6, 2026

Obsidian

Never receives your text
All data is saved locally on your device and is never sent to our servers. […] Obsidian does not receive or store personal content saved to your local device while using Obsidian.

The strongest structural position on this list: they cannot train on what they never receive. Third-party AI plugins you install are a separate question with separate terms.

Verbatim from Obsidian Privacy Policy · checked August 6, 2026

Scrivener

Never receives your text
The privacy policy does not address document storage or transmission, because the application does not send your documents anywhere. It covers billing, licence activation, update checks and support.

Silence here means something different from Sudowrite’s silence: there is no cloud service to make a promise about. If you sync the folder via Dropbox or iCloud, that provider’s terms apply instead.

Our finding, from reading Literature & Latte Privacy Policy · checked August 6, 2026

CipherWrite

Never receives your text
Drafts are encrypted on your device with a key we never receive, so the stored ciphertext is not readable by us and cannot be used as training data by us or anyone we work with.

Disclosure: this is our product, so weigh this row accordingly. The trade-off is real — lose your key and we cannot recover your manuscript, because we genuinely cannot read it.

Our finding, from reading CipherWrite Security · checked August 6, 2026

Three things worth knowing before you change any settings

1. Opting out does not un-train a model

Every opt-out in this audit is forward-looking. Turning off training today stops future text being used; it cannot pull your earlier drafts back out of a model that has already been trained on them. The decision that actually matters is where you paste the manuscript in the first place.

2. A rebrand can move your data’s governing policy

Grammarly’s privacy-policy URL now redirects to superhuman.com, and the policy that governs your text is written in Superhuman’s name. Nothing was hidden — but nobody emails you when the legal entity holding your writing changes. It is worth re-checking the policy of any tool you have used for years.

3. Contractual promises and technical guarantees are different things

Notion’s commitment that its AI subprocessors are “prohibited from using Customer Data to train models” is a genuinely strong contractual position. It is still a promise about behaviour, not a constraint on capability — Notion can read your pages. Obsidian and Scrivener are in a different category, because there is no server holding your text at all. Neither approach is universally better: local files do not sync and cannot be recovered if your laptop dies, and encrypted storage means a lost key is a lost manuscript. Pick the failure mode you can live with.

What we would actually recommend

If privacy is your first concern and you do not need AI assistance, Obsidian or Scrivener are the strongest positions on this list, and neither is ours. Nothing beats a tool that never receives your text.

If you want AI help while drafting, ProWritingAid has the clearest written no-training commitment of any assistive tool we checked. If zero-knowledge encryption specifically is what you are after — the manuscript unreadable even to the company storing it — that is the category CipherWrite and NovelAI occupy, and you should weigh our entry knowing it is ours.

Whatever you choose, keep an offline copy. Read our 3-2-1 backup rule for novelists — no privacy policy protects you from losing the file.

Related reading

Methodology

We read each tool’s public privacy policy, terms of service, or dedicated AI/security page on August 6, 2026 and recorded what it said about using customer content to train models. Where a policy states a position, we quote it verbatim and link the source. Where a policy is silent, we say so rather than inferring a commitment in either direction.

We reviewed only publicly available documents. Enterprise customers frequently have separate data processing agreements with stronger terms than the public policy, so a company’s treatment of an enterprise account may differ from what is described here.

Conflict of interest: CipherWrite is our own product and appears in this table. We have tried to apply the same standard to our row as to everyone else’s, and to name competitors — Obsidian, Scrivener, ProWritingAid — where their position is genuinely stronger than ours. Weigh our entry accordingly.

Policies change. If you find a row that is out of date, tell us at contact and we will re-check and update the date.

Frequently asked questions

Does ChatGPT train on my writing?

Yes, by default on the Free, Plus and Pro consumer plans. OpenAI uses those conversations to improve its models unless you turn off "Improve the model for everyone" in Settings → Data Controls. API and Business plans are excluded from training by default. Opting out only affects future conversations — text already used in a completed training run cannot be withdrawn.

Does Sudowrite train on your work?

Sudowrite's published privacy policy does not say. We read it in full on August 6, 2026 and found no statement about whether customer manuscripts are used to train AI models, in either direction. Several third-party reviews claim Sudowrite does not train on user writing, but we could not locate that commitment in the policy itself. If it matters to you, ask their support team for it in writing.

Is a privacy policy that says nothing about training the same as a promise not to train?

No. Silence is not a commitment. A policy that does not mention model training leaves the company free to start, or to permit a third-party AI provider to do so, without breaking any stated promise. A specific, written commitment is the minimum worth relying on.

Can I stop an AI company from training on writing I already submitted?

Generally no. Every opt-out we reviewed is forward-looking. Once text has been incorporated into a completed training run it cannot be extracted from the resulting model. This is why the decision about which tool to paste an unpublished manuscript into matters more than any setting you change afterwards.

Which writing tools cannot train on my manuscript at all?

Tools that never receive your text in readable form. Obsidian and Scrivener store files locally and never transmit them. NovelAI and CipherWrite encrypt content so the provider holds only ciphertext. This is a structural guarantee rather than a policy promise — the company cannot use what it cannot read.

Does an AI company owning my writing mean it owns my copyright?

No. Training on text and owning its copyright are different things. Every tool reviewed here leaves copyright with you. The concern is not ownership transfer but that your unpublished prose becomes part of a model that other people then write with.

Keep reading