Apps ยท Analysis
Writing Tools and What They Read
A writing assistant sees everything you type, including things you never meant to share. What that means and how to limit it.
A grammar checker has to read your writing to check it. The question is where that reading happens, what is retained, and whether your particular writing should be somewhere else.
What a cloud checker sees
Everything you type into a field it monitors. Emails, documents, messages, form fields, search boxes, sometimes password fields if the tool is poorly scoped.
On the server, not your machine. The text is transmitted for analysis and a response comes back. This is inherent to how cloud-based checking works.
Potentially retained. Providers differ on how long text is kept and what it is used for. Product improvement and model training are common stated purposes.
This is not sinister โ it is the architecture. But it means the tool is a third party with sight of your writing, and whether that is acceptable depends entirely on what you write.
The browser extension question
A grammar-checking extension typically requests permission to read and change data on all websites. That permission is genuinely needed for the feature to work everywhere, and it is also one of the broadest permissions a browser grants.
An extension with that access can, in principle, see the content of every page you visit and every field you fill.
Practical mitigations:
Restrict the extension to specific sites. Both Chrome and Firefox allow per-site extension permissions. Right-click the extension icon and set it to run only on the sites where you write at length. This removes it from your banking, your health portal and your work systems.
Or use on-click activation, which runs the extension only when you invoke it.
Check what it does on password fields. Reputable tools exclude them. It is worth verifying rather than assuming.
When cloud processing is a genuine problem
Legally privileged material. Communications with counsel lose privilege in some circumstances when shared with a third party. This is a real risk, not a theoretical one, and law firms increasingly prohibit these tools.
Patient or client information covered by health, financial or professional confidentiality rules. Sending it to an unapproved processor is typically a breach regardless of the provider's own security.
Unpublished creative work. Not a legal risk so much as a rights and retention question. Read what the terms say about content you submit.
Anything under a non-disclosure agreement. The obligation usually names permitted recipients, and a grammar service is not one of them.
Regulated or classified material, where the answer is straightforwardly no.
When it does not matter much
Blog drafts, personal email, social posts, coursework, general correspondence. The overwhelming majority of writing. Treating every document as sensitive is its own kind of error.
Questions worth answering before installing
Is text retained, and for how long? The privacy policy should say.
Is it used to train models? Increasingly there is an opt-out. It is frequently off by default in business tiers and on by default in consumer ones.
Where is it processed? Jurisdiction matters for some obligations.
Is there a business or enterprise tier with different terms? These usually include data processing agreements and no training on customer content. If your employer needs the tool, this is the version to buy.
Can it be run on-premises or offline? Some tools can. This resolves the question entirely.
The safer configurations
Use the built-in checker in your word processor for sensitive documents. It runs locally in most cases and is now reasonably capable.
Use an open-source checker locally. Several can be self-hosted, so text never leaves your network. Grammar coverage is good; style suggestions are thinner.
Restrict the extension by site so it is active only where you want it.
Draft sensitive material offline and check only the parts that need it, with identifying details removed.
Turn off any always-on integration in your email client for accounts that carry confidential correspondence.
What to tell your employer
If you use one of these tools for work, the organisation may have a view. Many now block them at the network level or restrict them to approved business tiers.
Raising it before rather than after is a much better conversation. The usual outcome is either an approved enterprise licence or a documented restriction on what may be checked, and both are better than an unmonitored consumer installation across a department.
The short version
For ordinary writing, cloud grammar checking is a reasonable trade and the convenience is real.
For anything confidential, privileged or contractually restricted, use a local tool or your word processor's built-in checker. And in either case, restrict the browser extension to the sites where you actually write, because that single change removes most of the exposure at almost no cost.
Mistakes people make
Granting all-sites access and forgetting it. Restricting the extension to the sites where you actually write removes most of the exposure at almost no cost.
Using a consumer tier for work. Business tiers usually include a data processing agreement and no training on customer content. If your employer needs the tool, that is the version to buy.
Assuming the employer has no view. Many organisations block these tools or restrict them. Asking first is a much better conversation than being found out.
Treating everything as sensitive, or nothing. Most writing genuinely does not matter. Privileged, regulated and contractually restricted material genuinely does. Knowing which is which is the whole skill.
Enabling an always-on integration in an email client that carries confidential correspondence.
The short answer
For ordinary writing, cloud checking is a reasonable trade. For privileged or confidential material, use a local checker or your word processor's built-in one. In both cases, restrict the browser extension to specific sites.