Which productivity apps train AI on your data?
Of the 19 productivity apps on file, 18 are graded: 7 train on your data by default and 11 don't. One more has a policy that doesn't say either way. The best graded is Standard Notes (A) and the worst is Jasper (F).
Do they train on your drafts, notes and meetings?
A meeting recorder holds other people’s speech. A writing assistant holds the unfinished draft. A notes app holds what you never meant to publish. The apps here are graded on one narrow question: does any of that train a model, and how hard is it to stop. Read together, they run from a server that can’t read your notes at all to terms that license your drafts for training and give most people no way out.
The ones that hold what you write
Gamma’s privacy policy puts training at the end of a list of development purposes and offers only an objection by request. Its terms and help centre say more, and Gamma’s privacy team pointed to both. On Free, Plus, Pro and Ultra, “Data is allowed to be used to train AI models” until you switch it off under Settings, then Data Controls. The terms make training the rule wherever the privacy control isn’t “turned on”. A switch whose default is stated is a C. Team and Business run the other way: “If you are on a Team or Business plan, we do not train on Your Content.” This entry first read the privacy policy alone, and the reply corrected it.
QuillBot claims all the data it collects, “including your personal data”, to train its models, and carves Team Plan text inputs out of it. The policy says its services “may offer” controls and names none. The help centre does, for the browser extension only: two switches in the Data and Privacy menu, one for storing text inputs and one for training on them. Website users have no switch. Learneo told this site they can email privacy@quillbot.com, which is published nowhere. A way out that is an email, under a default that is only bought off with a Team Plan, is a D.
Grammarly’s policy is now published by Superhuman Platform Inc., formerly Grammarly. It names a control: “You can decide whether Superhuman can use your user content to train our AI models by adjusting the available training control(s) in your account settings”. It never says which way that control ships. The word default doesn’t appear. A support article names the toggle, Product Improvement and Training, and says it’s on for individual accounts. That the policy doesn’t is the difference between a D and a C here.
Wispr Flow’s setting used to be called Privacy Mode. The name is gone. What survives, under Settings, then Data and Privacy, is a toggle framed for the benefit of leaving it on: “Improve the model for everyone”. It “lets you choose whether Wispr may use your Dictation data-audio, transcripts, and edits-to evaluate, train, or improve AI models”. The promise that no third party would train on your dictation went with the old name. Nothing states which way the switch ships.
Jasper’s privacy policy never uses the word train. Its terms of service do: Creator and Pro customers license their inputs and outputs for “modifying, improving, and enhancing artificial intelligence models”, and only users in the EU or UK are offered an objection, by email. Nobody else gets a way out, which is an F. Business plans are excluded by contract, a B.
Ellipsus says three times in its privacy policy that your writing never trains a model, and covers models “whether internal or passed to a third-party provider”. Its terms carve training out of the licence you grant, and its stance page says it will never use generative AI. B and not A because these are promises.
Evernote’s policy of 1 October 2026 says it doesn’t use your Input or Output “to train our artificial intelligence models or tools, or those of third-party AI model providers”. Until then it was the rare opt-in, with the words “unless you direct us to do so”. That exception is gone, and the policy now defines an AI feature itself, so nothing rests on a document the monitor doesn’t archive.
Standard Notes’ answer is an inability, not a promise. Its policy says the server “cannot read the content of your notes”. What it stores is metadata such as creation and modification dates. The same document says it can’t decrypt end-to-end encrypted content and so can’t hand over decrypted copies when asked, a statement against its own interest. A company that can’t reach the content can’t train on it, and that’s what an A is.
The ones that record your meetings
Fathom trains its own models on de-identified meeting content, says so, and says where the switch is: “You can opt out from this use of your data in your account settings”. OpenAI, Anthropic and Google are named and refused the same data. What keeps it at a C is the default: the opt-out exists because the training is on until you use it.
Granola’s clause is one sentence: “We only use de-identified data to train AI models, which you can opt-out of within your Granola account settings”. The policy is frank about what opting out can’t undo: data points already “incorporated into aggregate model weights and parameters during the training process”. Its own list puts material flagged for safety review, and feedback you give explicitly, outside the switch. OpenAI and Anthropic are barred from training on your data.
tl;dv’s section on AI model training names the content, not a category: “meeting recordings, transcripts, notes, files”. It rules out training “for the benefit of tldx Solutions GmbH or any third party”, so a model built for somebody else is caught too. It follows the data to the providers that deliver its features. B and not A because tl;dv plainly holds the recordings. This is an undertaking it could revoke by editing the page.
Side by side
7 pairs of productivity apps people choose between, with both verdicts on one page.