Wednesday, September 2, 2026
NewsWhite
PSA: Anyone with a link can view your Granola notes by default
TECHNOLOGY

PSA: Anyone with a link can view your Granola notes by default

By Emma RothApril 2, 2026·Source: The Verge·58 views

The Verge is reporting that Granola, an AI-powered note-taking application, has a significant gap between its stated privacy practices and how it actually handles user data by default. Specifically, any note created in the app can apparently be viewed by anyone who obtains a link to it, and the company also uses those notes to train its AI systems unless users actively opt out of that arrangement.

To understand why this matters, it helps to understand what Granola is and who uses it. The app sits in a crowded but fast-growing category of AI meeting and note-taking tools — software that listens to conversations, transcribes them, and generates structured summaries. The appeal is obvious: professionals, particularly in technology and business environments, are drowning in meetings, and anything that automates the documentation burden has found a willing audience. That audience, however, tends to discuss sensitive things. Sales calls contain competitive intelligence. Executive meetings surface unannounced product plans. Investor conversations include non-public financial thinking. The entire value proposition of these tools rests on an implicit promise that the captured content stays controlled.

The phrase "private by default" is doing a great deal of work in Granola's marketing, and The Verge's reporting suggests it is doing that work deceptively. In most reasonable interpretations, "private by default" means that access is restricted unless a user chooses to share something. What Granola appears to have implemented is something closer to the opposite: notes are technically accessible to any person who holds the link, which makes the privacy model more like an unlocked door in a quiet street than a genuinely restricted space. The fact that someone needs the specific link to find a note does not make that note private in any meaningful sense. Links get forwarded. They appear in browser histories on shared machines. They can leak through referrer headers when users click out to another website.

The AI training dimension compounds the concern in a distinct way. There is a well-established and reasonable expectation among users of productivity software that their work product — their words, their client names, their internal deliberations — is not being harvested to improve a vendor's commercial model. The industry has navigated this badly before. Several major AI companies faced serious backlash when it emerged that user data was flowing into training pipelines in ways users had not clearly understood or consented to. The opt-out framing Granola reportedly uses puts the burden on users to discover a setting and take action, rather than requiring them to affirmatively choose participation. That is a meaningful ethical and, in some jurisdictions, potentially legal distinction, particularly under frameworks like GDPR in Europe, which generally favor opt-in models for data uses that go beyond what is strictly necessary to deliver a service.

The consequences here fall on several groups. Granola's existing users face the most immediate exposure. Anyone who has used the app to capture meetings involving confidential business information, personal conversations, or legally sensitive material should audit what has been shared and what settings are currently active. The risk is not theoretical — the combination of accessible links and AI ingestion means sensitive content could have already traveled further than users intended. For Granola as a company, this is a trust problem that arrives at a particularly fragile moment. Enterprise software adoption depends heavily on IT departments and legal teams signing off on data handling practices, and reporting like this tends to trigger exactly the kind of scrutiny that slows or stops procurement decisions. Competitors in the space — and there are many — will not be slow to use this in sales conversations.

More broadly, the episode is another data point in an ongoing pattern that the AI productivity software sector has not resolved. Companies in this space move fast, acquire users through consumer channels, and then discover that their casual defaults are incompatible with the environments where professionals actually want to use them. The gap between consumer-grade privacy assumptions and enterprise-grade requirements keeps producing these moments, and the industry keeps being surprised by them even though the pattern is entirely predictable.

What to watch for next is whether Granola changes its defaults in response to the coverage, or simply updates its documentation and waits for the attention to pass. A genuine change would mean making notes private in a real sense from the moment of creation, and switching AI training to an explicit opt-in. If the company moves quickly and transparently on both fronts, the damage is containable. If it does not, the story is likely to find a second life as enterprise procurement teams begin asking pointed questions. Regulatory attention is also worth monitoring, particularly in European markets where data protection authorities have shown a willingness to investigate exactly these kinds of gaps between stated policy and actual practice.

Originally reported by The Verge. Read the original article

Related Articles