Quick security facts (2026 scan)
| Chrome extension | Grammarly |
|---|---|
| Permission profile | Broader than typical |
| All-sites access | Yes — can access every site you visit when enabled |
| Permissions beyond typical | cookies, nativeMessaging, clipboardRead |
| Privacy policy score | 7.3/10 (2 red flags) |
| Scan date / version | 2026-07-31 / 14.1316.0 |
What permissions does Grammarly request?
The following permissions were declared in Chrome extension version 14.1316.0 as of the 2026-07-31 scan. If you are asking is Grammarly for Chrome safe, this table is the primary evidence: it shows what the extension is allowed to do when installed.
Requests access to all websites you visit.
| Permission | Risk | What it can do |
|---|---|---|
scripting | medium | Can inject and run scripts on pages it has access to. |
sidePanel | low | Can display content in the browser side panel. |
tabs | medium | Can see the URLs, titles, and open/close state of your browser tabs. |
notifications | low | Can show desktop notifications. |
cookies | high | Can read and modify cookies, which often include login sessions. |
identity | medium | Can get an OAuth token tied to your signed-in account. |
storage | low | Can store data locally in the browser. |
nativeMessaging | high | Can exchange messages with programs installed on your computer. |
clipboardRead | medium | Can read the contents of your clipboard. |
Permissions beyond the typical writing assistant set
Compared with the permissions a typical writing assistant extension needs, Grammarly also requests the following as of the 2026-07-31 scan. Extra permissions are not inherently a problem — each can support legitimate features. We list what each one can enable so you can weigh it for yourself.
cookies(high) — can support reading or setting site cookies, which can let it act inside web apps where you are already signed in.nativeMessaging(high) — can support exchanging messages with a companion app installed on your computer.clipboardRead(medium) — can support reading clipboard contents, which can support pasting text into the tool.
As of the 2026-07-31 scan, this extension requests permissions beyond the typical set for a writing assistant. The cookies permission can support reading or setting site cookies, which can let it act inside web apps where you are already signed in. Additionally, the nativeMessaging permission can support exchanging messages with a companion app installed on your computer, while clipboardRead can support reading clipboard contents to paste text into the tool.
Where can Grammarly data flow?
Domains below are extracted by static analysis and represent a lower bound — an extension may contact additional endpoints at runtime that this method does not capture.
amazonaws.comthird-partyapple.comthird-partycloudfront.netthird-partycoda.iothird-partycodahosted.iothird-partydoi.orgthird-partyexample.comthird-partyfacebook.comthird-partygithub.comthird-partygoogle.comthird-partygrammarly.comfirst-partygrammarly.iofirst-partyi18next.comthird-partyimgix.netthird-partyiterable.comthird-partyjsdelivr.netthird-partyjson-schema.orgthird-partylocize.comthird-partymicrosoftonline.comthird-partymozilla.orgthird-partyoutlook.comthird-partypp-sh.iothird-partyppgr.iothird-partyqa-sh.iothird-partyqagr.iothird-partyreactjs.orgthird-partyreactrouter.comthird-partysentry.iothird-partyslack.comthird-partystatsig.comthird-partysuperhuman.comthird-partysuperhuman.iothird-partyvercel-storage.comthird-partyw3.orgthird-party
As of the 2026-07-31 scan, data can flow to first-party vendor domains like grammarly.com and grammarly.io, along with numerous third-party domains including amazonaws.com, google.com, and slack.com. This external-domain list is a static-analysis lower bound, meaning it may miss dynamically loaded endpoints.
Policy claims vs observed: the vendor publishes a privacy policy; the domains above reflect what static analysis observed as of the 2026-07-31 scan, which may differ from the policy's stated data handling.
Privacy policy findings
Policy score: 7.3/10 (as of the 2026-07-31 scan, reviewed against 11 fixed criteria — a measure of policy quality, not a safety verdict).
| Criterion | Score | Flag |
|---|---|---|
| collects only what the feature needs | 2/2 | — |
| sharing with third parties disclosed and limited | 2/2 | — |
| does not sell user data | 1/2 | — |
| retention period specified | 1/2 | — |
| user can request deletion | 0/2 | red flag |
| anonymization/pseudonymization practices stated | 2/2 | — |
| readable, specific, not boilerplate | 2/2 | — |
| GDPR/CCPA handling stated | 2/2 | — |
| notifies users of policy changes | 2/2 | — |
| children's data addressed | 0/2 | — |
| states whether user content trains AI models | 2/2 | red flag |
- No clear way to request deletion of your data
- May train AI models on user content
As of the 2026-07-31 scan, the privacy policy has a score of 7.3 out of 10 based on how well it addresses 11 fixed criteria, which is not a safety verdict. The review found red flags, noting there is no clear way to request deletion of your data and that it may train AI models on user content.
Editor's analysis: is Grammarly safe?
Grammarly has one of the most extensively certified security postures in the AI tool space. As of the 2026-07-31 scan, here is what the public record shows.
Security certifications: Grammarly holds SOC 2 Type 2 (covering security, privacy, availability, and confidentiality), ISO 27001:2022, ISO 27701:2019 (privacy information management), ISO 27017:2015 (cloud security), ISO 27018:2019 (PII in the cloud), ISO 42001:2023 (AI management system), and PCI DSS. This is one of the broadest compliance portfolios among AI writing tools. Grammarly also runs a public bug bounty program through HackerOne and is a corporate member of OWASP and IAPP.
GDPR and data handling: Grammarly is GDPR-compliant and HIPAA-compliant (with a signed Business Associate Agreement). Data is stored on AWS servers in US-based data centers. Grammarly's privacy policy explicitly states how data is collected and used, and users can control whether their content trains AI models through account settings.
AI training: Grammarly's privacy policy states it uses information collected to train AI models, but provides user controls to opt out. This is a more transparent approach than extensions that do not disclose training practices at all.
For business use: Grammarly offers enterprise-grade security including SOC 2 Type 2 reports available on request, HIPAA compliance with BAA, and a dedicated trust center. These make it suitable for regulated industries.
Bottom line: Grammarly's security and compliance posture is best-in-class for AI writing assistants. The SOC 2 Type 2 + ISO 27001 + ISO 42001 combination covers security operations, information management, and responsible AI. The main trade-off is AI training on user content, but opt-out controls are available.
Is Grammarly safe to use on Chrome? The short answer for most personal users is that Grammarly has one of the strongest publicly documented security programs among AI writing extensions — SOC 2 Type 2, ISO 27001, and ISO 42001 among them — while still requesting broader-than-typical permissions (all-sites access, cookies, nativeMessaging, clipboardRead). Those permissions support real product features (desktop app bridge, signed-in web apps, clipboard suggestions) and are not by themselves proof of malice. If your threat model is "will this exfiltrate my company secrets without controls," use Grammarly Business/Enterprise with DPA/BAA where required and review admin policies.
Is Grammarly for Chrome safe for students and freelancers? For everyday essays and client emails, the main practical decision is AI training opt-out and whether you paste confidential client material into the free tier. Grammarly documents training practices and offers account-level controls; still treat highly confidential drafts as off-limits on free consumer plans unless your org has approved the product.
Evaluate Grammarly on security and controls: certifications are published; privacy policy scored 7.3/10 on our 11-criteria rubric as of the 2026-07-31 scan, with red flags for deletion-request clarity and AI training on user content. Compare this disclosure with other AI Chrome extensions on our is-it-safe index.
FAQ: is Grammarly safe to use?
Is Grammarly safe?
Grammarly holds SOC 2 Type 2, ISO 27001, ISO 42001, and HIPAA compliance — one of the broadest security portfolios among AI writing tools. Users can opt out of AI training on their content. The extension requests broader permissions than typical, supporting desktop app integration and signed-in web app access.
Is Grammarly safe to use?
Grammarly holds SOC 2 Type 2, ISO 27001, ISO 42001, and HIPAA compliance — one of the broadest security portfolios among AI writing tools. Users can opt out of AI training on their content. The extension requests broader permissions than typical, supporting desktop app integration and signed-in web app access.
Is Grammarly for Chrome safe?
The Grammarly Chrome extension was scanned on 2026-07-31 (version 14.1316.0). Requests broader permissions than typical for a writing assistant. It can access all sites you visit when enabled. Privacy policy quality score: 7.3/10 across 11 criteria.
Is Grammarly secure for business use?
Security certifications: Grammarly holds SOC 2 Type 2 (covering security, privacy, availability, and confidentiality), ISO 27001:2022, ISO 27701:2019 (privacy information management), ISO 27017:2015 (cloud security), ISO 27018:2019 (PII in the cloud), ISO 42001:2023 (AI management system), and PCI DSS. This is one of the broadest compliance portfolios among AI writing tools. Grammarly also runs a public bug bounty program through HackerOne and is a corporate member of OWASP and IAPP.
Does Grammarly use your data for AI training?
The privacy policy states: "We also use information we collect to train our AI models. You can decide whether Superhuman can use your user content to train our AI models by adjusting the available training control(s) in your account settings."
What permissions does the Grammarly Chrome extension request?
Grammarly version 14.1316.0 declares: scripting, sidePanel, tabs, notifications, cookies, identity, storage, nativeMessaging, clipboardRead as of the 2026-07-31 scan. Profile: Broader than typical.
Similar extensions
DeepL Translate
Translation-focused extension with stronger EU data-residency story; different job, similar compliance bar.
Monica
AI sidebar alternative — compare all-sites access and weaker policy score vs Grammarly certifications.
Compare other AI extensions we scanned
Still deciding? Read independent disclosures for other AI Chrome extensions — same methodology, same scan date window.
Is DeepL Translate safe?
DeepL is ISO 27001 certified and GDPR-compliant. Free-tier translations may train AI models; paid plans do not. The browser extension requests broader permissions than typical for translation tools, but they serve legitimate translation functionality.
Broader than typical · scanned 2026-07-31
Is Merlin AI Assistant safe?
Claims SOC 2/GDPR/ISO compliance for paid users only — not independently verified. Privacy policy scored 5.0/10 with three red flags: no data deletion rights, unclear GDPR handling, and AI training on user content.
Broader than typical · scanned 2026-07-31
Is Monica safe?
No ISO or SOC 2 certifications found. Privacy policy scored 4.1/10 with four red flags: no data deletion rights, no policy change notification, no children's data policy, and AI training on user content with no disclosed opt-out.
Typical for its category · scanned 2026-07-31
Is Sider safe?
No security certifications found and privacy policy could not be assessed by our scanner. The extension routes queries to multiple AI providers (ChatGPT, Claude, Gemini) and requests broad permissions including custom script execution and tab capture.
Broader than typical · scanned 2026-07-31
Compare with every extension we have reviewed on theextension security index, or read our full product comparison for Grammarly in the Grammarly review, or see how this disclosure is produced on our security methodology page. Looking for a tool by job-to-be-done? Try the AI Tool Finder.