PSA: Anyone with a link can view your Granola notes by default

👁 0 views

If you utilize the AI-powered note-taking app Granola, you may need to double-check your privateness settings. Though Granola says your notes are “private by default,” it makes them viewable to anybody with a link, and likewise makes use of them for inside AI coaching except you choose out.

Granola describes itself as an “AI notepad for people in back-to-back meetings.” It integrates with your calendar to seize audio from your conferences, after which makes use of AI to generate a bulleted listing of what you’ve heard, which it calls a “note.” You can edit the AI-generated notes, invite different collaborators to view them, and use Granola’s AI assistant to ask questions on your notes and evaluation the assembly transcript they’re primarily based on.

But within the app’s settings menu, Granola says, “By default, your notes are viewable to anyone with the link.” That means anybody on the internet can see your notes if you happen to by accident share a link — probably a main situation if you happen to’re recording delicate conferences. After testing this out for myself, I discovered that I may entry my very own be aware from a non-public window in my browser, all with out signing into my Granola account. The web site even tells you who the be aware belongs to and when it was created.

You can make links to your notes private or only allow members of your company to view them.

You can make hyperlinks to your notes non-public or solely permit members of your firm to view them.
Screenshot: The Verge

While I couldn’t view the complete transcript linked to the be aware, I may nonetheless view components of it. Selecting one of many bullet factors generated by Granola pulls up a quote from the transcript that the be aware is referring to, alongside with an AI-generated abstract with further context concerning the dialog.

On its web site, Granola says “full transcript access is available to collaborators who open the same folder or note inside the Granola desktop app.” It’s not clear whether or not anybody with a Granola account can entry your transcript, or if it’s simply folks you’ve shared your workspace with. Granola didn’t reply to a request for extra info by the time of publication.

You can change who can view your hyperlinks by opening Granola, deciding on your profile within the bottom-left nook of the display screen, after which selecting “Settings.” From there, navigate to the “Default link sharing” possibility, and alter “Anyone with the link” to both “Only my company” or “Private.” If you delete your be aware, folks with the link will now not be capable of entry it.

One person on LinkedIn referred to as consideration to the general public notes setting final yr, saying, “these links aren’t indexed, but if you share or leak one – even accidentally – it’s public to whoever finds it.” And at the least one main firm has denied use of the software to a senior government as a consequence of safety considerations, a supply tells The Verge.

I got access to my notes using a public link — no account required.

I obtained entry to my notes utilizing a public link — no account required.
Screenshot: The Verge

Additionally, Granola “may use anonymized data” to enhance its AI fashions, in keeping with the app’s assist web page. Enterprise prospects are opted out of AI coaching by default, however folks on all different plans aren’t. You can disable AI coaching by going to the settings menu and toggling off the “Use my data to improve models for everyone” possibility. The firm says it doesn’t permit third-party firms, like OpenAI or Anthropic, to make use of your information for AI coaching if the setting is enabled.

Granola’s safety web page says the corporate shops your notes in a US-hosted Amazon Web Services non-public cloud, and says they’re “encrypted at rest and in transit.” The firm doesn’t retailer audio from conferences, both. It solely saves assembly notes and transcripts, each of which it processes within the cloud.

Follow subjects and authors from this story to see extra like this in your personalised homepage feed and to obtain e-mail updates.


Scroll to Top