GDPR check

Is Elicit GDPR compliant? What universities should check

Elicit is an AI research assistant for finding papers, extracting data and running systematic-review style workflows. It is popular with researchers and often lands on a DPO's desk. This page sets out what Elicit publishes about data protection, where the plans differ, and what to ask before approval.

Published 7 October 2026 · Sources checked 7 October 2026

Short answer

Elicit is run by Elicit Research, PBC, a US public benefit corporation in California, and its privacy policy says its servers are in the United States (on AWS). Plans run from Basic (free) through Pro and Scale to Enterprise, which is offered to companies and schools. Elicit publishes more than many tools of its size: a DPA with the EU Standard Contractual Clauses, a public subprocessor list (including OpenAI and Anthropic) and a SOC 2 Type 2 report. The written commitment not to train on customer data is tied to the Enterprise plan. Whether you can use it depends on which plan you buy, whether the DPA is part of your contract and what data researchers will put in.

Prefer a tool built in the EU? Kahubi, from Avidemic AB in Sweden, covers AI research assistance with EU hosting and, for institutions, only European subprocessors. See how Kahubi handles research data

What Elicit documents publicly

All sources were read on 7 October 2026. "Not found publicly" means we did not find it in the sources listed below; it does not mean the safeguard does not exist.

TopicWhat the vendor statesSource
Company and establishmentDocumented Elicit Research, PBC, Covina, California, United States. The privacy policy (dated 12 September 2023) gives dpo@elicit.com as the contact for EEA users. Not found publicly An EU representative under GDPR Article 27.[1]
Where data is stored and processedDocumented "Our servers are located in the United States." Customer data resides in AWS with multi-zone replication. Enterprise customers can have single-tenant, logically isolated AWS clusters. No EU region found.[1], [6]
Data processing agreementPlan-dependent A public Data Processing Addendum (last updated 1 April 2025) covers EU GDPR, UK GDPR and Swiss law, with Elicit as processor and breach notice within 72 hours. It forms part of Elicit's Master Services Agreement, so it applies to contracted customers. We found no click-through route for individual Basic or Pro users.[3]
SubprocessorsDocumented A public list in Elicit's trust centre with 16 entries, all located in the US. They include AWS, OpenAI and Anthropic (AI responses), CoreWeave (hosting custom ML models), Datadog, MongoDB, Stripe and Intercom. A change notice dated 16 September 2026 adds a file storage provider from 15 October 2026. Customers can subscribe to updates.[4], [3]
International transfersDocumented The DPA incorporates the EU SCCs (Modules 2 and 3), the UK Addendum and Swiss adjustments. Not found publicly EU-US Data Privacy Framework certification: no entry for Elicit on the official DPF list, active or inactive.[3], [11]
AI model training on customer contentPlan-dependent The pricing page lists "No training on your data by default" under Enterprise. The SOC 2 announcement says Elicit does not train on Enterprise user data and has agreements preventing providers such as OpenAI from doing so. We found no statement on training for Basic, Pro or Scale. The terms allow Elicit to use aggregated usage data that does not identify users.[7], [6], [2]
Retention and deletionPartly documented Under the DPA, Elicit deletes or helps delete customer personal data within 30 days of a request. Users can delete their account in settings, and the deletion is permanent. The privacy policy gives no fixed periods. Uploaded PDFs "remain private to your account only, until you choose to delete them" and are not added to Elicit's search corpus.[3], [9], [1], [8]
Security certificationsDocumented The trust centre lists a SOC 2 Type 2 report, a SOC 3 report, a SOC 2 bridge letter (April 2026), Cyber Essentials, a HECVAT and a VPAT. The SOC 2 report is available on request under NDA, so its scope is not public. Not found publicly ISO 27001.[5], [6]
Institution and enterprise controlsPlan-dependent Scale adds an admin panel with usage tracking and seat management. Enterprise adds SSO and SAML, 2FA, user analytics, domain verification and custom deployments such as single tenancy. Institutional contracts go through Elicit's sales team.[7], [10]

What this means for a university

Validemic's analysis

What personal data is involved. Searching Elicit's corpus of published papers involves little personal data beyond the account and the questions asked. Uploaded PDFs are usually published articles, which are not personal data in the GDPR sense in most cases. That changes when researchers upload unpublished manuscripts with participant details, interview material or student work, or when data extraction tables are built from such documents. The answer to "may I use Elicit?" therefore depends heavily on what the researcher plans to upload.

The plan matters. Elicit's strongest safeguards sit on the Enterprise plan: the explicit no-training default, SSO, domain verification and single-tenant options. The DPA forms part of the Master Services Agreement, which in practice means an institutional contract. A researcher on a personal Basic, Pro or Scale subscription is covered by the consumer terms and privacy policy, and the public documentation does not say whether that content may be used for training. For institutional approval, Enterprise (or a negotiated institutional contract that includes the DPA and a no-training clause) is the realistic route.

Transfers. Data is hosted in the US, and every listed subprocessor is US-based. Elicit is not on the DPF list, so transfers would rest on the SCCs in the DPA. Your institution will normally want a transfer impact assessment that also covers the onward flow to OpenAI and Anthropic.

DPIA. For literature searching with published papers, a screening is usually enough. A DPIA becomes likely if staff will upload material containing personal data, especially health or special category data, or if the tool is rolled out widely to students.

Students. The terms set a minimum age of 13, but the privacy policy asks users to represent that they are at least 18 or a parent or guardian. The privacy policy and terms both date from September 2023, earlier than the DPA and the subprocessor list, so ask Elicit which document governs institutional student accounts.

Credit where due. A public DPA with SCCs, a dated subprocessor list with change notices, a SOC 2 Type 2 report and a ready HECVAT make Elicit easier to assess than many research AI tools.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

Questions to ask Elicit before approving it

  1. Does your no-training commitment apply to Pro and Scale customers, or only to Enterprise? Can it be written into our contract?
  2. Can the Data Processing Addendum be signed for an institutional Pro or Scale purchase, or only with an Enterprise MSA?
  3. What retention and zero-data-retention terms apply to the content you send to OpenAI and Anthropic?
  4. Can you offer EU hosting or EU-only processing, now or on your roadmap?
  5. What is the scope and audit period of your SOC 2 Type 2 report, and does it cover the AI pipeline and uploaded documents?
  6. How long do uploaded PDFs, extraction tables and chat histories persist after deletion, including backups? The DPA says the services do not include backup services for customer personal data, while your SOC 2 post mentions daily backups: how do these fit together?
  7. Which minimum age applies to student accounts: 13 (terms) or 18 (privacy policy)?
  8. Will you update the September 2023 privacy policy and terms to match the 2025 DPA and the current subprocessor list?
  9. Do you support SSO through eduGAIN or our national research and education federation?

The EU AI Act angle

Using Elicit to find, screen and extract data from literature is normally not a high-risk use under the AI Act, Regulation (EU) 2024/1689. Annex III, point 3 lists the education uses that are high-risk: AI used to decide admission or access, to evaluate learning outcomes, to assess the level of education a person will receive, or to monitor students for prohibited behaviour during tests. Using any tool for those purposes would change the assessment.

A university that uses an AI system under its authority is a deployer (Article 3(4)). Article 4 on AI literacy has applied since 2 February 2025. Regulation (EU) 2026/1744 (the Digital Omnibus on AI), in force since 27 July 2026, replaced that article: deployers must now "take measures to support the development of AI literacy" of their staff and others using AI on their behalf, without having to guarantee a specific level for each person. The same regulation moved the application date for Annex III high-risk obligations to 2 December 2027.

Obligations for general-purpose AI models (Article 53, applying since 2 August 2025) fall on the model providers, such as OpenAI and Anthropic, not on the university or on Elicit as a downstream user of those models.

Sources

  1. Elicit, Privacy Policy (dated 12 September 2023), retrieved 7 October 2026
  2. Elicit, Terms of Service (last updated 12 September 2023), retrieved 7 October 2026
  3. Elicit, Data Processing Addendum (last updated 1 April 2025), retrieved 7 October 2026
  4. Elicit Trust Center, Subprocessors, retrieved 7 October 2026
  5. Elicit Trust Center, retrieved 7 October 2026
  6. Elicit blog, "Elicit Achieves SOC 2" (30 October 2025), retrieved 7 October 2026
  7. Elicit, Pricing, retrieved 7 October 2026
  8. Elicit Help Center, "Privacy for uploaded papers", retrieved 7 October 2026
  9. Elicit Help Center, "Cancel your subscription or delete your account", retrieved 7 October 2026
  10. Elicit Help Center, "Elicit's Scale plan for teams", retrieved 7 October 2026
  11. Data Privacy Framework List (searched for "Elicit", active and inactive participants), retrieved 7 October 2026
  12. Regulation (EU) 2024/1689 (Artificial Intelligence Act), Articles 3(4), 4, 53, 113 and Annex III, Official Journal text read via the Publications Office, retrieved 7 October 2026
  13. Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal text read via the Publications Office, retrieved 7 October 2026

About this page

We read Elicit's privacy policy, terms, DPA, trust centre, pricing page and help centre, and searched the official Data Privacy Framework list, on 7 October 2026. This page describes public documentation only. It is not legal advice and not a verdict on whether Elicit complies with the GDPR; that depends on your contract, your plan and your use. Vendors update their documents often, so check the sources before relying on them.

If you work at Elicit and something here is out of date or incomplete, please contact us and we will review it promptly.

Frequently asked questions

Does Elicit train AI models on my data?

Elicit's pricing page lists "No training on your data by default" as an Enterprise feature, and its SOC 2 announcement says it does not train on Enterprise user data. We found no equivalent statement for the Basic, Pro or Scale plans (checked 7 October 2026), so ask Elicit directly if you use those plans.

Where does Elicit store data?

Elicit's privacy policy says its servers are in the United States, and its SOC 2 announcement says customer data resides in AWS. We found no EU hosting option in its public documentation.

Does Elicit have a DPA?

Yes. Elicit publishes a Data Processing Addendum (last updated 1 April 2025) that includes the EU Standard Contractual Clauses. It forms part of Elicit's Master Services Agreement, so it is aimed at contracted customers rather than individual sign-ups.

Does Elicit use OpenAI?

Yes. Elicit's public subprocessor list includes OpenAI and Anthropic as providers of AI responses, alongside AWS and other US-based services.

Is Elicit SOC 2 certified?

Elicit's trust centre lists a SOC 2 Type 2 report, a SOC 3 report and a bridge letter. The SOC 2 report is available on request. We found no ISO 27001 certification.

Can students use Elicit under GDPR?

Elicit's terms set a minimum age of 13, while its privacy policy says users represent that they are at least 18 or a parent or guardian. Institutions planning student access should clarify this and agree a DPA first.