Granola
Granola · Meeting notes · US · www.granola.ai
services/granola.yamlVendor data-handling terms
“Before we get into the details, below are a few key points we’d like you to know: We do not allow third parties such as OpenAI or Anthropic to use your Personal Data to train AI models. / We only use de-identified data to train AI models, which you can opt-out of within your Granola account settings .”
The policy describes account deletion and message retention but sets no period for meeting notes or transcripts.
“Granola is based in and operates its Services from the United States and the United Kingdom, and we use Amazon Web Services (“AWS”) servers located primarily in the US to collect, use, process, store, transfer, and protect (with encryption) your Personal Data.”
Domains and endpoints
observed means seen in Unseen deployments; vendor-documented means listed by the vendor. Vendors do not publish complete lists.
| Host | Role | Source |
|---|---|---|
| granola.ai | app | observed |
Assessment
Reasoning: A meeting-notes tool that transcribes from the device's audio without joining the call as a bot, so other participants are less likely to know. Model providers are barred from training and Granola's own training uses de-identified data with an opt-out. Storage is US AWS with no retention period for transcripts. The consent question for other participants is the deployer's.
Flags: Recorded meetings (third-party personal data; consent required) · GDPR Chapter V (US storage) · Assessed 2026-09-16. The assessment is Unseen's; the terms above are the vendor's.
Changelog
- 2026-09-16Documented. Training and storage terms verified against the Granola privacy policy; retention period not stated.
- 2026-09-15Listed from the Unseen catalogue with observed domains.
Corrections
Pull request on GitHub, or the form below. Changes are reviewed and recorded in the changelog.