Grok on the consumer app and website
The consumer FAQ says content and interactions may be used to train the models and that the person controls it through an Improve the model setting. Private Chat conversations are deleted within 30 days and are never used for training. Authorised personnel may review conversations. Grok used inside X is governed by X's own policies, not this one.
The verdict
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Key facts
What the sources say
- Record ID
- AVD-2026-0016
- Kind
- Consumer tier
- Jurisdiction
- United States
- Last verified
- Added
- The consumer FAQ states the vendor may use your content and interactions with Grok, along with Grok's responses, to train its models, and that you control whether it does.
- Private Chat conversations do not appear in history and are deleted from the vendor's systems within 30 days.
- Deleting conversations or the account triggers deletion within 30 days unless retention is needed for legal, compliance or safety purposes.
- Unauthenticated use is different. In some regions outside the European Union and the United Kingdom there is no option to opt out when signed out.
Dimension by dimension
10 dimensions, each one stated, silent or open
Used for training by default, Retention period, Deletion on request, Storage region and residency, Subprocessor list published, Human review of content, Opt out available, DPA available, Persistent memory across sessions, Last change to the terms. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- Used for training by defaultStated
- Yes by default for signed in users, with a setting to turn it off. Content, interactions and Grok's responses may be used to train the models.SpaceXAI consumer FAQs, published at x.ai, primary source, 12 May 2025.
- Retention periodStated
- No general period. Retention runs on an ongoing legitimate business need, and the only fixed clocks are the 30 days for Private Chat and for deletion requests.SpaceXAI privacy policy, published at x.ai, primary source, 24 August 2026.
- Deletion on requestStated
- Conversations or the whole account can be deleted, and the data is deleted within 30 days unless retention is needed for legal, compliance or safety purposes.SpaceXAI privacy policy, published at x.ai, primary source, 24 August 2026.
- Storage region and residencySilent
- No storage region is printed. The policy identifies a United States company and routes European questions to a separate Europe addendum.SpaceXAI privacy policy, published at x.ai, primary source, 24 August 2026.
- Subprocessor list publishedStated
- Categories only. Service providers for hosting, cloud, analytics, content delivery, support and safety monitoring and payments are described but not named in a list.SpaceXAI privacy policy, published at x.ai, primary source, 24 August 2026.
- Human review of contentStated
- Yes. A limited number of authorised personnel may review conversations for improving model performance, investigating security incidents and misuse, and legal obligations.SpaceXAI consumer FAQs, published at x.ai, primary source, 12 May 2025.
- Opt out availableStated
- Yes, under Settings and Data Controls as Improve the model, or by using Private Chat. Feedback you volunteer may still be used for training after you opt out.SpaceXAI consumer FAQs, published at x.ai, primary source, 12 May 2025.
- DPA availableSilent
- None on this tier. The privacy policy states it does not apply to data processed on behalf of customers of the business offerings such as the API.SpaceXAI privacy policy, published at x.ai, primary source, 24 August 2026.
- Persistent memory across sessionsSilent
- No memory feature is described. Personalisation is offered separately, using X data, and conversation history is recorded as technical data.SpaceXAI privacy policy, published at x.ai, primary source, 24 August 2026.
- Last change to the termsStated
- The privacy policy prints Effective 24 August 2026 and the consumer FAQ prints 12 May 2025. The documents are published by SpaceXAI LLC at x.ai.SpaceXAI privacy policy, published at x.ai, primary source, 24 August 2026.
Figures
Every number, with who measured it and when
- 30 days
Deletion of Private Chat conversations
SpaceXAI privacy policy, published at x.ai, primary source, as of .
- 30 days
Deletion after a person deletes conversations or the account
SpaceXAI privacy policy, published at x.ai, primary source, as of .
What it changes
For a buyer or a workplace AI policy
Two traps for a policy writer. First, the assistant inside X is a different controller under different terms, so a rule written against this policy does not cover staff who use Grok on the social platform. Second, the opt out only exists for a signed in account, and in some regions an unauthenticated user has no option at all, which makes anonymous use the riskiest way to use it rather than the safest.
Sources
What this record was verified against
- SpaceXAI consumer FAQs, published at x.aiPrimary · 12 May 2025
- SpaceXAI privacy policy, published at x.aiPrimary · 24 August 2026
- SpaceXAI consumer terms of service, published at x.aiPrimary · 11 September 2026
Related
Records that sit beside this one
The Grok API and enterprise platform
United States · verified 15 September 2026
The enterprise FAQ states the vendor does not use business data, including inputs or outputs, to train its models.
Meta AI on Facebook, Instagram and WhatsApp
United States · verified 15 September 2026
The AI terms state that when information is shared with the AIs, the AIs will sometimes retain and use that information.
ChatGPT Free, Plus and Pro
United States · verified 15 September 2026
Training is on by default on the consumer plans. The help centre says OpenAI may use content from services for individuals to train its models.
Amazon Bedrock
United States · verified 15 September 2026
Amazon Bedrock uses a zero data retention security model, so by default it does not store model inputs or outputs.
GitHub Copilot Business and Enterprise
United States · verified 15 September 2026
GitHub states it does not use Copilot Business or Copilot Enterprise customer data to train AI models.
Cursor and its privacy mode
United States · verified 15 September 2026
The terms of service state that Cursor will not use content to train any AI models unless you have explicitly agreed.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AVD-2026-0016 is permanent and is never reused.
- In a sentence
- According to the GAGE AI Vendor Data Ledger (as of 15 September 2026), grok on the consumer app and website.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). Grok on the consumer app and website. AI Vendor Data Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/ai-vendor-data-ledger/records/AVD-2026-0016-grok-consumer-app
- MLA
- "Grok on the consumer app and website." AI Vendor Data Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/ai-vendor-data-ledger/records/AVD-2026-0016-grok-consumer-app.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "Grok on the consumer app and website." AI Vendor Data Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/ai-vendor-data-ledger/records/AVD-2026-0016-grok-consumer-app.
- Permalink
- https://www.gage.academy/tools/ai-vendor-data-ledger/records/AVD-2026-0016-grok-consumer-app
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any terms change a vendor announces.
Back to the full ledger, or every record for United States and every consumer tier record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.