Grok-AI.app
grokThe supplied documents are generic website terms and a boilerplate privacy notice that do not describe any AI functionality, model behavior, or handling of user prompts/outputs, despite the tool's name suggesting an AI product. The privacy policy is internally inconsistent — it self-identifies as belonging to 'ChatGPT Online' rather than Grok-AI.app, and contains contradictions between its 'no sensitive information' and 'no third-party data' summary claims and later sections that disclose collecting geolocation data and sharing with ad networks. The documents are over 2.5 years old relative to the analysis date, disclose targeted advertising and sharing with ad networks/social networks, and provide no security certifications, no AI-specific disclosures, no training-use terms, and broad vendor-favorable liability and IP language. This is not recommended for professional, enterprise, or regulated-industry use without contractual protections.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
The Terms assert broad vendor ownership of intellectual property on the website but do not clearly address ownership of user-submitted prompts, files, or data. Under the 'Idea submission' clause, any ideas or content disclosed without a prior agreement grant the vendor a broad irrevocable license. There is no clear statement that users retain ownership of the data they input.
Output Data Ownership
The documents are entirely silent on ownership of AI-generated output. No clause allocates rights in generated content to the user, and the broad IP-reservation language could be read to claim all website content for the vendor. Silence on this topic is a significant risk for anyone relying on generated outputs commercially.
Training Data Usage
The documents never mention AI models, model training, or use of user inputs to improve models. The privacy policy states information is processed to 'provide, improve, and administer our Services' and reserves use for 'internal research for technological development,' but there is no clarity on whether user inputs feed model training. This silence, in a purportedly AI product, is a material risk.
Data Retention & Deletion
Retention is tied loosely to the length of time a user has an account, with no specific schedule or deletion SLA (and a visibly broken/blank clause). Users can request deletion via a contact page, but the vendor reserves broad rights to retain data for fraud prevention, investigations, and legal compliance. There are no security-related retention obligations disclosed.
Third-Party Data Sharing
Despite a summary claim that the vendor does not receive information from third parties, the policy discloses sharing personal information with ad networks, affiliate marketing programs, data analytics services, and social networks, and processing data to deliver targeted advertising. This sharing with advertising-related third parties goes beyond what a core service would require and is not integral to any disclosed marketplace or referral function. The disclosure exists but the sharing is broad and advertising-driven.
Opt-Out Rights
The policy provides several opt-out mechanisms: unsubscribing from marketing, opting out of location collection, opting out of interest-based advertising, withdrawing consent, and (for US state residents) opting out of sale/sharing and targeted advertising. However, opt-outs are exercised largely through a generic contact page and some are limited in scope. The mechanisms exist but are diffuse and partially procedural.
Compliance & Certifications
The tool_sector is unknown, so compliance is assessed against the universal baseline only. The documents reference GDPR/UK GDPR and several US state privacy laws (CCPA, CPA, VCDPA, CTDPA, UCPA) as applicable legal frameworks, but claim no certifications or third-party attestations (no SOC 2, ISO 27001, ISO 42001, NIST CSF, or EU AI Act). No audit reports or trust center are named, and the privacy notice appears mislabeled as belonging to 'ChatGPT Online,' undermining confidence in its accuracy.
Model Explainability & Auditability
The documents provide no transparency into any model behavior, no enterprise auditing capability, and no mention of automated decision-making mechanics beyond a general EU/UK right 'not to be subject to automated decision-making.' There is no explainability commitment whatsoever.
Security Practices & Breach History
Security is described only in vague, generic terms — 'organizational and technical security measures' — with an explicit disclaimer that data cannot be guaranteed secure and that transmission is at the user's own risk. No specific controls (encryption at rest/in transit, access controls, penetration testing, bug bounty, incident response) are disclosed, no breach history is addressed, and no security page or trust center is referenced.
Enterprise vs. Consumer Risk Delta
The documents describe only a single, general set of website terms with no distinction between free and paid tiers, and no enterprise data-handling commitments. There is no evidence of any differentiated protections for paying or business customers.
Human Review of User Inputs
The Terms reserve a broad right to review and monitor all content and activity on the website in the vendor's sole discretion. This is framed around open communication tools rather than AI prompts, and there is no AI-specific human-review disclosure, but the reserved right is broad.
Regulatory & Litigation Exposure
The policy discloses that the vendor may cooperate with law enforcement and disclose information in litigation, and that data may be transferred in business transactions. No specific litigation, government-request statistics, or transparency reporting is provided. These are standard clauses but broad in scope.
PII & SPI Data Inventory
The policy contains a direct contradiction on data collection: the summary claims no sensitive information is processed, yet the collection sections disclose IP addresses, device identifiers, and precise or imprecise geolocation (GPS), and the state-law table marks geolocation and internet activity as collected. Precise geolocation is a category of sensitive personal information, and it is disclosed alongside targeted-advertising sharing. The inconsistency and the collection of location data with broad ad-network sharing warrant a high-risk rating.
Policy–Product Currency
Both documents are dated 'December 10, 2023,' making them roughly 2.5 years stale as of the 2026-08-06 analysis date — beyond the 24-month threshold. No PRODUCT SURFACE was supplied, so coverage cannot be independently verified, but the recency evidence alone justifies RED. Compounding this, the privacy notice self-identifies as belonging to 'ChatGPT Online' rather than Grok-AI.app and never mentions any AI/ML processing despite the product name, indicating a mismatched/templated policy.
Cross-Document Consistency
Two documents were supplied (Terms and Privacy Policy), enabling a cross-document check. A material inconsistency exists: the Terms link to a 'Privacy Statement' that points at the Terms-and-Conditions URL rather than the privacy policy, and the privacy notice is branded for a different entity ('ChatGPT Online') than the Terms ('Grok-AI.app'). Within the privacy policy itself the 'no sensitive information / no third-party information' summary conflicts with later disclosures of geolocation collection and ad-network sharing. The branding mismatch and conflicting data-collection claims are material.
You've read all 15 risk ratings for Grok-AI.app. Create a free account to see the exact policy wording behind each rating.