← All pages

1. What the document is: xAI's consumer Privacy Policy for Grok (mobile app/grok.com). The same capture bundles in a separate "Europe Privacy Policy Addendum" section for EEA/UK/Switzerland users.

What this wiki found — complete, every page

AI trainingRoyalty-freeSublicensablePerpetual / irrevocableTransferableDerivative works

Presence facts, not verdicts — each flagged term links to its definition and the exact clause on this page. Absence of a badge means the term isn't currently flagged here, not that the page is risk-free.

xAI – Privacy Policy

Dataset: GenGA (Generative AI Governance Archive) — 11 AI services, 2025–present

GenGA (Generative AI Governance Archive) is this wiki’s Generative-AI dataset: raw policy snapshots captured by the Open Terms Archive genai-eu project across 11 GenAI providers (ChatGPT, Claude.ai, DeepSeek, Google Generative AI Services, Le Chat, Llama API, Meta AI, Microsoft Copilot, Perplexity, Qwen Chat, xAI). Unlike PGAv2, GenGA has no pre-tagged risk scores — all risk scoring and keyword tagging on these pages is LLM-assigned by direct reading, spanning 2025–present.

Note: This page contains documented policy clauses. Risk assessment is qualitative and context-dependent. For analysis of patterns across platforms, see:

Source: sources/GenGA/xAI/Privacy Policy/ (raw Markdown captures, Open Terms Archive genai-eu dataset — no pre-tagged JSONL exists for this source) Last updated: 2025-12-11

Note on methodology: No pre-computed risk_score/keyword fields exist for this source. Keyword tags and clause analysis on this page are LLM-assigned, using the same rubric/vocabulary as the PGAv2 pages plus new GenAI-specific tags (train AI/models, feedback). Treat as first-pass analysis, not externally verified ground truth. This wiki’s risk-scoring system was retired project-wide on 2026-06-21 (see methodology.md §4) — no page, GenGA included, computes or displays a numeric risk score.


Overview

1. What the document is: xAI’s consumer Privacy Policy for Grok (mobile app/grok.com). The same capture bundles in a separate “Europe Privacy Policy Addendum” section for EEA/UK/Switzerland users.

2. Input rights: Training rests on a legitimate-interests legal basis, not consent, explicitly covering “Publicly available data, User Content, X Public posts for over 18 year olds and Feedback Data… necessary for our legitimate interests in improving the accuracy and performance of our models… and to train more advanced models.” Unlike Qwen Chat’s similar legitimate-interests clause, xAI pairs this with a described opt-out: “you can object to our use of your information to train our models in your settings.”

3. Output restrictions: Not addressed here, beyond a disclaimer that Output may inaccurately reproduce personal information, and that correction requests “may not be feasible… due to the technical complexity of our models.”

4. Non-explicit predatory clauses: xAI confirms it scrapes and uses public X (Twitter) posts to train Grok, despite xAI being legally “a separate company from X Corp.” — a notable cross-company data flow. There’s also a third-party data-sharing disclosure: “We share parts of Input Data with Brave Software, Inc., so we can include Brave’s search results in the Service.” One genuinely protective carve-out: “xAI does not process training data for the purposes of inferring or deriving any sensitive or special category data about individuals.”

5. Regulatory references: No explicit GDPR citation appears anywhere in this document, even though it runs a full GDPR-style legal-basis framework — legitimate interests, consent, data controller designation, supervisory-authority complaint rights, a “balancing test” for legitimate-interest processing — and cites the EU-US/Swiss-US/UK Data Privacy Framework and Standard Contractual Clauses Modules 1/2 by mechanism, just never by the name “GDPR” or its EU regulation number. One genuine compliance change: on 2025-11-24, the named third-party DPO vendor (“Taceo Limited,” London) was replaced with an internal xAI contact (privacy@x.ai), bringing the Data Protection Officer function in-house.

6. Regional variation: A dedicated Europe Addendum (EEA/UK/Switzerland) with its own legal-basis table and third-party EU/UK/Switzerland privacy representatives (Lionheart Squared entities, one per jurisdiction) — a different vendor than the Prighter pattern used elsewhere in this dataset (DeepSeek, Perplexity).

7. Key risk to users: Moderate. The legitimate-interests training basis is the standard risk pattern in this dataset, mitigated here by a genuinely described opt-out. The cross-company X-posts data flow and third-party Brave Software sharing are secondary transparency considerations, not necessarily predatory on their own.

Flagged Keywords & Risks (LLM-assigned)

Regulatory & Research Context

xAI is one of the five providers Davidson et al. (2026) directly studied, and their broader concern with jurisdictional and regulatory-gray-area clauses is reflected on this page in the fact that no GDPR citation appears anywhere in the document despite a full GDPR-style legal-basis framework (legitimate interests, controller designation, balancing test) being run throughout — a naming gap consistent with the unattributed-regulation pattern their framework targets. Pandit et al. (2026) did not study xAI directly, but their finding that GenAI providers commonly use inputs/outputs “for other purposes beyond” the immediate service applies by analogy to the train AI/models clause’s legitimate-interests basis for training on “Publicly available data, User Content, X Public posts… and Feedback Data,” even though this page’s described opt-out is more user-protective than the no-opt-out pattern Pandit et al. found typical elsewhere.


Changes Summary

DateWhat changed
2025-11-11Baseline version (“Effective: July 10, 2025”).
2025-11-24 (15:54)Genuine compliance-structure change: the named third-party DPO vendor (Taceo Limited) was replaced with an internal xAI privacy contact.
2025-11-24 (23:34)Cosmetic only: DPO contact reformatted from a raw mailto link to a clean email link.
2025-12-02Cosmetic only: trailing-slash flicker on the top-of-page legal-hub link.
2025-12-10Cosmetic/typo fix: “data we use train out models” corrected to “data we use to train our models.”
2025-12-11Cosmetic only: trailing-slash flicker reverted.

Version History

2025-11-11

Clause: train AI/models

To train and improve our models | We process Publicly available data, User Content, X Public posts for over 18 year olds and Feedback Data | This is necessary for our legitimate interests in improving the accuracy and performance of our models used to power the Services and to train more advanced models.

You can object to our use of your information to train our models in your settings. See Consumer FAQs.

Clause: feedback

Feedback Data: Where applicable, we will collect your Feedback (as defined in our Terms of Service). This might arise if, for example, in a given conversation with Grok, you rate an Output using the thumbs-up/thumbs-down icons.

Clause: sensitive-data training carve-out (not separately concept-tagged — user-protective)

in relation to Grok’s training, xAI does not process training data for the purposes of inferring or deriving any sensitive or special category data about individuals, and we do not actively seek out data sources that include sensitive or special category data.


2025-12-11

train AI/models/feedback unchanged from 2025-11-11. The only genuine change across all intervening dates was the 2025-11-24 DPO-contact in-housing noted above.