← All extension security reviews

Is Grammarly Safe? 2026 Chrome Extension Security Review

Independent Chrome extension security disclosure — permissions, data flow, and privacy-policy findings. Last scanned 2026-07-31.

Broader than typical

Requests broader permissions than typical for a writing assistant.

Grammarly holds SOC 2 Type 2, ISO 27001, ISO 42001, and HIPAA compliance — one of the broadest security portfolios among AI writing tools. Users can opt out of AI training on their content. The extension requests broader permissions than typical, supporting desktop app integration and signed-in web app access.

Scanned on 2026-07-31 · scanner extscan/0.2.0 · version 14.1316.0

Is Grammarly safe to use?

Grammarly's Chrome extension requests broader permissions than typical for its writing assistant category as of the 2026-07-31 scan. It requests access to all websites you visit. Privacy policy score: 7.3/10 (2 red flags). Grammarly holds SOC 2 Type 2, ISO 27001, ISO 42001, and HIPAA compliance — one of the broadest security portfolios among AI writing tools. Users can opt out of AI training on their content. The extension requests broader permissions than typical, supporting desktop app integration and signed-in web app access.

This is a disclosure based on a static scan of the Chrome extension and public policy documents — not a pass/fail safety certification. Full methodology:security methodology.

Quick security facts (2026 scan)

Chrome extensionGrammarly
Permission profileBroader than typical
All-sites accessYes — can access every site you visit when enabled
Permissions beyond typicalcookies, nativeMessaging, clipboardRead
Privacy policy score7.3/10 (2 red flags)
Scan date / version2026-07-31 / 14.1316.0

What permissions does Grammarly request?

The following permissions were declared in Chrome extension version 14.1316.0 as of the 2026-07-31 scan. If you are asking is Grammarly for Chrome safe, this table is the primary evidence: it shows what the extension is allowed to do when installed.

Requests access to all websites you visit.

PermissionRiskWhat it can do
scriptingmediumCan inject and run scripts on pages it has access to.
sidePanellowCan display content in the browser side panel.
tabsmediumCan see the URLs, titles, and open/close state of your browser tabs.
notificationslowCan show desktop notifications.
cookieshighCan read and modify cookies, which often include login sessions.
identitymediumCan get an OAuth token tied to your signed-in account.
storagelowCan store data locally in the browser.
nativeMessaginghighCan exchange messages with programs installed on your computer.
clipboardReadmediumCan read the contents of your clipboard.

Permissions beyond the typical writing assistant set

Compared with the permissions a typical writing assistant extension needs, Grammarly also requests the following as of the 2026-07-31 scan. Extra permissions are not inherently a problem — each can support legitimate features. We list what each one can enable so you can weigh it for yourself.

  • cookies (high) — can support reading or setting site cookies, which can let it act inside web apps where you are already signed in.
  • nativeMessaging (high) — can support exchanging messages with a companion app installed on your computer.
  • clipboardRead (medium) — can support reading clipboard contents, which can support pasting text into the tool.

As of the 2026-07-31 scan, this extension requests permissions beyond the typical set for a writing assistant. The cookies permission can support reading or setting site cookies, which can let it act inside web apps where you are already signed in. Additionally, the nativeMessaging permission can support exchanging messages with a companion app installed on your computer, while clipboardRead can support reading clipboard contents to paste text into the tool.

Where can Grammarly data flow?

Domains below are extracted by static analysis and represent a lower bound — an extension may contact additional endpoints at runtime that this method does not capture.

  • amazonaws.comthird-party
  • apple.comthird-party
  • cloudfront.netthird-party
  • coda.iothird-party
  • codahosted.iothird-party
  • doi.orgthird-party
  • example.comthird-party
  • facebook.comthird-party
  • github.comthird-party
  • google.comthird-party
  • grammarly.comfirst-party
  • grammarly.iofirst-party
  • i18next.comthird-party
  • imgix.netthird-party
  • iterable.comthird-party
  • jsdelivr.netthird-party
  • json-schema.orgthird-party
  • locize.comthird-party
  • microsoftonline.comthird-party
  • mozilla.orgthird-party
  • outlook.comthird-party
  • pp-sh.iothird-party
  • ppgr.iothird-party
  • qa-sh.iothird-party
  • qagr.iothird-party
  • reactjs.orgthird-party
  • reactrouter.comthird-party
  • sentry.iothird-party
  • slack.comthird-party
  • statsig.comthird-party
  • superhuman.comthird-party
  • superhuman.iothird-party
  • vercel-storage.comthird-party
  • w3.orgthird-party

As of the 2026-07-31 scan, data can flow to first-party vendor domains like grammarly.com and grammarly.io, along with numerous third-party domains including amazonaws.com, google.com, and slack.com. This external-domain list is a static-analysis lower bound, meaning it may miss dynamically loaded endpoints.

Policy claims vs observed: the vendor publishes a privacy policy; the domains above reflect what static analysis observed as of the 2026-07-31 scan, which may differ from the policy's stated data handling.

Privacy policy findings

Policy score: 7.3/10 (as of the 2026-07-31 scan, reviewed against 11 fixed criteria — a measure of policy quality, not a safety verdict).

CriterionScoreFlag
collects only what the feature needs2/2
sharing with third parties disclosed and limited2/2
does not sell user data1/2
retention period specified1/2
user can request deletion0/2red flag
anonymization/pseudonymization practices stated2/2
readable, specific, not boilerplate2/2
GDPR/CCPA handling stated2/2
notifies users of policy changes2/2
children's data addressed0/2
states whether user content trains AI models2/2red flag
  • No clear way to request deletion of your data
  • May train AI models on user content

As of the 2026-07-31 scan, the privacy policy has a score of 7.3 out of 10 based on how well it addresses 11 fixed criteria, which is not a safety verdict. The review found red flags, noting there is no clear way to request deletion of your data and that it may train AI models on user content.

Editor's analysis: is Grammarly safe?

Grammarly has one of the most extensively certified security postures in the AI tool space. As of the 2026-07-31 scan, here is what the public record shows.

Security certifications: Grammarly holds SOC 2 Type 2 (covering security, privacy, availability, and confidentiality), ISO 27001:2022, ISO 27701:2019 (privacy information management), ISO 27017:2015 (cloud security), ISO 27018:2019 (PII in the cloud), ISO 42001:2023 (AI management system), and PCI DSS. This is one of the broadest compliance portfolios among AI writing tools. Grammarly also runs a public bug bounty program through HackerOne and is a corporate member of OWASP and IAPP.

GDPR and data handling: Grammarly is GDPR-compliant and HIPAA-compliant (with a signed Business Associate Agreement). Data is stored on AWS servers in US-based data centers. Grammarly's privacy policy explicitly states how data is collected and used, and users can control whether their content trains AI models through account settings.

AI training: Grammarly's privacy policy states it uses information collected to train AI models, but provides user controls to opt out. This is a more transparent approach than extensions that do not disclose training practices at all.

For business use: Grammarly offers enterprise-grade security including SOC 2 Type 2 reports available on request, HIPAA compliance with BAA, and a dedicated trust center. These make it suitable for regulated industries.

Bottom line: Grammarly's security and compliance posture is best-in-class for AI writing assistants. The SOC 2 Type 2 + ISO 27001 + ISO 42001 combination covers security operations, information management, and responsible AI. The main trade-off is AI training on user content, but opt-out controls are available.

Is Grammarly safe to use on Chrome? The short answer for most personal users is that Grammarly has one of the strongest publicly documented security programs among AI writing extensions — SOC 2 Type 2, ISO 27001, and ISO 42001 among them — while still requesting broader-than-typical permissions (all-sites access, cookies, nativeMessaging, clipboardRead). Those permissions support real product features (desktop app bridge, signed-in web apps, clipboard suggestions) and are not by themselves proof of malice. If your threat model is "will this exfiltrate my company secrets without controls," use Grammarly Business/Enterprise with DPA/BAA where required and review admin policies.

Is Grammarly for Chrome safe for students and freelancers? For everyday essays and client emails, the main practical decision is AI training opt-out and whether you paste confidential client material into the free tier. Grammarly documents training practices and offers account-level controls; still treat highly confidential drafts as off-limits on free consumer plans unless your org has approved the product.

Evaluate Grammarly on security and controls: certifications are published; privacy policy scored 7.3/10 on our 11-criteria rubric as of the 2026-07-31 scan, with red flags for deletion-request clarity and AI training on user content. Compare this disclosure with other AI Chrome extensions on our is-it-safe index.

FAQ: is Grammarly safe to use?

Is Grammarly safe?

Grammarly holds SOC 2 Type 2, ISO 27001, ISO 42001, and HIPAA compliance — one of the broadest security portfolios among AI writing tools. Users can opt out of AI training on their content. The extension requests broader permissions than typical, supporting desktop app integration and signed-in web app access.

Is Grammarly safe to use?

Grammarly holds SOC 2 Type 2, ISO 27001, ISO 42001, and HIPAA compliance — one of the broadest security portfolios among AI writing tools. Users can opt out of AI training on their content. The extension requests broader permissions than typical, supporting desktop app integration and signed-in web app access.

Is Grammarly for Chrome safe?

The Grammarly Chrome extension was scanned on 2026-07-31 (version 14.1316.0). Requests broader permissions than typical for a writing assistant. It can access all sites you visit when enabled. Privacy policy quality score: 7.3/10 across 11 criteria.

Is Grammarly secure for business use?

Security certifications: Grammarly holds SOC 2 Type 2 (covering security, privacy, availability, and confidentiality), ISO 27001:2022, ISO 27701:2019 (privacy information management), ISO 27017:2015 (cloud security), ISO 27018:2019 (PII in the cloud), ISO 42001:2023 (AI management system), and PCI DSS. This is one of the broadest compliance portfolios among AI writing tools. Grammarly also runs a public bug bounty program through HackerOne and is a corporate member of OWASP and IAPP.

Does Grammarly use your data for AI training?

The privacy policy states: "We also use information we collect to train our AI models. You can decide whether Superhuman can use your user content to train our AI models by adjusting the available training control(s) in your account settings."

What permissions does the Grammarly Chrome extension request?

Grammarly version 14.1316.0 declares: scripting, sidePanel, tabs, notifications, cookies, identity, storage, nativeMessaging, clipboardRead as of the 2026-07-31 scan. Profile: Broader than typical.

Similar extensions

DeepL Translate

Translation-focused extension with stronger EU data-residency story; different job, similar compliance bar.

Monica

AI sidebar alternative — compare all-sites access and weaker policy score vs Grammarly certifications.

Compare other AI extensions we scanned

Still deciding? Read independent disclosures for other AI Chrome extensions — same methodology, same scan date window.