Grok-AI.app logo

Grok-AI.app

grok
High Risk
Updated August 6, 2026

The supplied documents are generic website terms and a boilerplate privacy notice that do not describe any AI functionality, model behavior, or handling of user prompts/outputs, despite the tool's name suggesting an AI product. The privacy policy is internally inconsistent — it self-identifies as belonging to 'ChatGPT Online' rather than Grok-AI.app, and contains contradictions between its 'no sensitive information' and 'no third-party data' summary claims and later sections that disclose collecting geolocation data and sharing with ad networks. The documents are over 2.5 years old relative to the analysis date, disclose targeted advertising and sharing with ad networks/social networks, and provide no security certifications, no AI-specific disclosures, no training-use terms, and broad vendor-favorable liability and IP language. This is not recommended for professional, enterprise, or regulated-industry use without contractual protections.

AI Transparency Facts

Independent analysis by TermsWatchdog · © 2026 TermsWatchdog

Input Data Ownership

Moderate Risk

The Terms assert broad vendor ownership of intellectual property on the website but do not clearly address ownership of user-submitted prompts, files, or data. Under the 'Idea submission' clause, any ideas or content disclosed without a prior agreement grant the vendor a broad irrevocable license. There is no clear statement that users retain ownership of the data they input.

Confidence
45%

Output Data Ownership

High Risk

The documents are entirely silent on ownership of AI-generated output. No clause allocates rights in generated content to the user, and the broad IP-reservation language could be read to claim all website content for the vendor. Silence on this topic is a significant risk for anyone relying on generated outputs commercially.

Confidence
35%

Training Data Usage

High Risk

The documents never mention AI models, model training, or use of user inputs to improve models. The privacy policy states information is processed to 'provide, improve, and administer our Services' and reserves use for 'internal research for technological development,' but there is no clarity on whether user inputs feed model training. This silence, in a purportedly AI product, is a material risk.

Confidence
40%

Data Retention & Deletion

Moderate Risk

Retention is tied loosely to the length of time a user has an account, with no specific schedule or deletion SLA (and a visibly broken/blank clause). Users can request deletion via a contact page, but the vendor reserves broad rights to retain data for fraud prevention, investigations, and legal compliance. There are no security-related retention obligations disclosed.

Confidence
55%

Third-Party Data Sharing

High Risk

Despite a summary claim that the vendor does not receive information from third parties, the policy discloses sharing personal information with ad networks, affiliate marketing programs, data analytics services, and social networks, and processing data to deliver targeted advertising. This sharing with advertising-related third parties goes beyond what a core service would require and is not integral to any disclosed marketplace or referral function. The disclosure exists but the sharing is broad and advertising-driven.

Confidence
65%

Opt-Out Rights

Moderate Risk

The policy provides several opt-out mechanisms: unsubscribing from marketing, opting out of location collection, opting out of interest-based advertising, withdrawing consent, and (for US state residents) opting out of sale/sharing and targeted advertising. However, opt-outs are exercised largely through a generic contact page and some are limited in scope. The mechanisms exist but are diffuse and partially procedural.

Confidence
60%

Compliance & Certifications

High Risk

The tool_sector is unknown, so compliance is assessed against the universal baseline only. The documents reference GDPR/UK GDPR and several US state privacy laws (CCPA, CPA, VCDPA, CTDPA, UCPA) as applicable legal frameworks, but claim no certifications or third-party attestations (no SOC 2, ISO 27001, ISO 42001, NIST CSF, or EU AI Act). No audit reports or trust center are named, and the privacy notice appears mislabeled as belonging to 'ChatGPT Online,' undermining confidence in its accuracy.

Confidence
55%

Model Explainability & Auditability

High Risk

The documents provide no transparency into any model behavior, no enterprise auditing capability, and no mention of automated decision-making mechanics beyond a general EU/UK right 'not to be subject to automated decision-making.' There is no explainability commitment whatsoever.

Confidence
40%

Security Practices & Breach History

High Risk

Security is described only in vague, generic terms — 'organizational and technical security measures' — with an explicit disclaimer that data cannot be guaranteed secure and that transmission is at the user's own risk. No specific controls (encryption at rest/in transit, access controls, penetration testing, bug bounty, incident response) are disclosed, no breach history is addressed, and no security page or trust center is referenced.

Confidence
55%

Enterprise vs. Consumer Risk Delta

High Risk

The documents describe only a single, general set of website terms with no distinction between free and paid tiers, and no enterprise data-handling commitments. There is no evidence of any differentiated protections for paying or business customers.

Confidence
30%

Human Review of User Inputs

Moderate Risk

The Terms reserve a broad right to review and monitor all content and activity on the website in the vendor's sole discretion. This is framed around open communication tools rather than AI prompts, and there is no AI-specific human-review disclosure, but the reserved right is broad.

Confidence
45%

Regulatory & Litigation Exposure

Moderate Risk

The policy discloses that the vendor may cooperate with law enforcement and disclose information in litigation, and that data may be transferred in business transactions. No specific litigation, government-request statistics, or transparency reporting is provided. These are standard clauses but broad in scope.

Confidence
50%

PII & SPI Data Inventory

High Risk

The policy contains a direct contradiction on data collection: the summary claims no sensitive information is processed, yet the collection sections disclose IP addresses, device identifiers, and precise or imprecise geolocation (GPS), and the state-law table marks geolocation and internet activity as collected. Precise geolocation is a category of sensitive personal information, and it is disclosed alongside targeted-advertising sharing. The inconsistency and the collection of location data with broad ad-network sharing warrant a high-risk rating.

Confidence
60%

Policy–Product Currency

High Risk

Both documents are dated 'December 10, 2023,' making them roughly 2.5 years stale as of the 2026-08-06 analysis date — beyond the 24-month threshold. No PRODUCT SURFACE was supplied, so coverage cannot be independently verified, but the recency evidence alone justifies RED. Compounding this, the privacy notice self-identifies as belonging to 'ChatGPT Online' rather than Grok-AI.app and never mentions any AI/ML processing despite the product name, indicating a mismatched/templated policy.

Confidence
50%

Cross-Document Consistency

High Risk

Two documents were supplied (Terms and Privacy Policy), enabling a cross-document check. A material inconsistency exists: the Terms link to a 'Privacy Statement' that points at the Terms-and-Conditions URL rather than the privacy policy, and the privacy notice is branded for a different entity ('ChatGPT Online') than the Terms ('Grok-AI.app'). Within the privacy policy itself the 'no sensitive information / no third-party information' summary conflicts with later disclosures of geolocation collection and ad-network sharing. The branding mismatch and conflicting data-collection claims are material.

Confidence
60%

You've read all 15 risk ratings for Grok-AI.app. Create a free account to see the exact policy wording behind each rating.