Last Updated: August 2026
How do you tell if an app trains on your writing?
Open the privacy policy and search for four phrases: improve our services, train, sublicensable, and retain. Content used “to improve our products” is content used for training — the softer wording permits the same thing. If the policy never mentions training at all, it has not forbidden it; silence is a gap, not a guarantee.
Grammarly's privacy FAQ is unusually direct about it: you keep every right to your text, and by using the product you give “formal permission to provide writing suggestions to you and to use your writing to improve our products.” Both halves of that are true at once, which is exactly why the sentence is easy to skim past. The point of the checker above is not to name villains — it is to put the sentence in front of you, in the company's own words, so the decision is yours.
Here is why we built this as a live tool rather than another article. When we ran Grammarly's main policy URL through the checker in August 2026, the document that came back belonged to Superhuman, which now owns the product, and it stated plainly that user content is used to train its AI models with an opt-out in account settings. Any article written before that acquisition is now describing a policy that no longer governs the account. Reading the live page is the only version of this answer that does not expire.
- — “To improve our services” is the clause that permits training. It rarely uses the word “train.”
- — “Encrypted at rest” means the company holds the keys. It stops thieves, not the company.
- — The licence you grant over your book lives in the terms of service, not the privacy policy.
- — An opt-out that defaults to ON has already used everything you wrote before you found it.
- — Policies are revised quietly. An answer from last year is not an answer about today.
The seven questions this tool answers
Every check reads the document you supply and answers these, quoting the exact sentence it relied on. A question the document never addresses is reported as unanswered rather than as a pass.
| Question | What to look for | Why it matters |
|---|---|---|
| Is it used for training? | “improve our services”, “develop new features”, “research and development” | Your unpublished novel becomes training data for a model that competes with you. |
| Can a human read it? | “employees, contractors, or agents may access” | Support and abuse review are normal. Unrestricted staff access to drafts is not. |
| What rights did I grant? | “worldwide, royalty-free, perpetual, irrevocable, sublicensable” | You keep copyright and still hand over a licence. The two are not opposites. |
| Who else receives it? | Named model providers, sub-processors, advertisers | Your text can reach companies you never chose and cannot audit. |
| What happens on delete? | Retention windows, backup persistence, “as long as necessary” | Deleting the account rarely deletes the copies. |
| Can they technically read it? | “encrypted at rest” vs “end-to-end” / “zero-knowledge” | Only the second means the provider cannot decrypt your file. |
| Is there a real opt-out? | Default state, and whether it is free-tier or paid-tier only | An opt-out defaulting to ON is consent you never gave. |
Why “your data is encrypted” usually means nothing
This is the single most misread sentence in the category, so it is worth being precise. Encryption at rest means the files on the company's disks are scrambled and the company holds the key. It defends against a stolen server, a rogue data-centre technician, and a certain class of breach. It does not, and cannot, prevent the company itself from reading your manuscript — the key is right there.
End-to-end or zero-knowledge encryption is a different claim: the key never leaves your device, so the provider stores ciphertext it cannot open. The checker above holds this line deliberately. It will not upgrade “bank-level AES-256 encryption” into a promise the company never made, because that specific confusion is how careful writers end up trusting the wrong product.
If the answer comes back “yes, they can read it”
You have three options, and switching apps is only one of them. You can opt out where a real opt-out exists, you can keep the sensitive work offline, or you can write somewhere the question cannot arise. CipherWrite encrypts your manuscript in the browser before it is ever stored, which is why our own answer to “do you train on my book” is not a promise — we hold no readable copy to train on.
Worth saying plainly: if you need Scrivener's compile engine or Google Docs' real-time co-editing, we do not replace those. Encryption costs you features that require a server to read your text.
Who actually needs to check this
For a lot of writers this is a matter of principle, and principle is a perfectly good reason. For some, it is a professional obligation with consequences attached:
- Ghostwriters. You signed an NDA covering the client's manuscript. Pasting it into a tool that trains on input is a disclosure you promised not to make, and the NDA does not care that it was a setting.
- Memoirists. Your draft names living people and describes events they would dispute. It is the most legally exposed document most writers will ever produce, and it exists in draft form for years.
- Journalists and non-fiction writers. Notes that identify a source are not yours to leak, and “the app retained it” is not a defence you can offer someone who trusted you.
- Anyone writing under a pen name. Account metadata ties the pseudonym to the person. That link is often more sensitive than the manuscript.
Frequently asked questions
Does Google Docs train AI on my novel?
Google states that it does not use the content of Workspace documents to train its generative models, and Workspace carries stronger commitments than consumer surfaces. The honest complication is that the consumer Google account many writers actually use is governed by the general Google privacy policy, not the Workspace terms, and Google can read your documents in either case — encryption there is at rest, with Google holding the key. Run the tool against the policy that covers your account type rather than the one quoted in articles.
Does ChatGPT use my writing to train its models?
On consumer tiers, content is used to improve models by default and there is a setting to turn it off; API and enterprise traffic is excluded by default. This has changed more than once, which is the whole argument for reading the live policy rather than a blog post about it. Check the current wording and the current default state of the setting in your own account.
Is a privacy policy legally binding?
It binds the company while it stands, and nearly every policy also reserves the right to amend it with notice — often notice by email or by a dated page nobody re-reads. That is the structural weakness of policy-based privacy: the promise is real, and it is also unilaterally revisable. Encryption you control is not revisable by the vendor.
Do you store the policy I paste, or the results?
No. The text is processed for one analysis and never stored on our servers, never used to train models, and never seen by our team. When you read a page from a link, that page is fetched once for the review and nothing is retained afterwards.
Why is reading a link a Pro feature?
Fetching a live page costs us money on every single check, so that part sits behind Pro. The analysis itself is free for everyone, including people who are not signed in — paste the policy text and you get the identical breakdown with every clause quoted. We gate the expensive capability rather than crippling the free answer.