Dictation and transcription
Granola privacy rating
AI notepad for meetings that captures computer audio without a bot joining the call, transcribes it through cloud providers, and turns the user's notes and the transcript into meeting summaries.
Summary
Granola scores 26 out of 100 (grade F) on the dictation and transcription criteria. It meets 1 of 10 criteria: TLS configuration. It partly meets no ads or data sales, independent audit, security headers and no training on recordings. It does not meet open source, no trackers or telemetry, transparency report, tells users about requests and runs on the device. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade B.
Score 26 out of 100. How scoring works
Criteria
- No
-
No
No trackers or telemetry Weight 3 of 3
Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?
The policy allows authorized third parties to use cookies, pixels and tags for analytics and targeted advertising.
-
Partial
No ads or data sales Weight 2 of 3
Is the product funded without advertising, ad targeting or selling user data?
Funded by subscriptions and does not sell personal data, but third-party cookies are used to target Granola's own advertising.
-
Partial
Independent audit Weight 2 of 3
Has an independent security or privacy audit been published within the last three years?
A SOC 2 Type 2 audit is claimed, but the report is not public.
-
No
Transparency report Weight 2 of 3
Does the provider regularly publish how many government and legal requests it receives and how it responds?
No transparency report or government request policy is published.
-
No
Tells users about requests Weight 1 of 3
Does the provider promise to tell users about requests for their data, unless a court forbids it?
No published policy on notifying users about data requests.
-
No
Runs on the device Weight 3 of 3
Is speech converted to text on the device, without sending audio to a server?
Audio is sent to cloud transcription providers such as Deepgram and AssemblyAI.
-
Partial
No training on recordings Weight 2 of 3
Are recordings and transcripts kept out of model training by default?
De-identified data is used for model training unless the user opts out in account settings; enterprise workspaces are opted out by default.
Automated tests
-
Yes
TLS configuration Weight 2 of 3
Does the website pass the Qualys SSL Labs test with a grade of A or better?
Grade A
-
Partial
Security headers Weight 1 of 3
Does the website pass the Mozilla HTTP Observatory test with a grade of A or better?
Grade B (75/100+)
-
Not tested yet
Modern web standards Weight 1 of 3
Does the website score 90% or higher on the Internet.nl website test?
Not tested yet.