Is Jenni AI GDPR compliant? What universities should check
Jenni AI is an AI writing assistant for academic papers, with autocomplete, chat and citation tools. It is marketed largely to students, so DPOs, librarians and teaching staff are often asked whether it is allowed. This page sets out what Jenni publishes about data protection, what we could not find, and what to ask.
Short answer
Jenni AI is run by Jenni AI, Inc., registered in Delaware, and its terms say the service is hosted in the United States (on Google's Firebase and Cloud Storage). It offers Free, Plus and Pro plans for individuals and team plans with an admin dashboard. Jenni states clearly that it does not train models on user content and gives specific deletion periods, but we found no DPA, subprocessor list, security certification or GDPR transfer mechanism, and transfers rely on user consent. Its privacy policy also discloses that chat messages and autocomplete context are logged in its analytics tool unless analytics cookies are refused. Whether you can use it depends on what Jenni will agree in an institutional contract and what students and staff will write in it.
Prefer a tool built in the EU? Kahubi, from Avidemic AB in Sweden, covers AI writing support with EU hosting and, for institutions, only European subprocessors. See how Kahubi handles research data
What Jenni AI documents publicly
All sources were read on 7 October 2026. "Not found publicly" means we did not find it in the sources listed; it does not mean the safeguard does not exist.
| Topic | What the vendor states | Source |
|---|---|---|
| Company and establishment | Documented Jenni AI, Inc., registered in Delaware, United States; Delaware law and binding arbitration. Contact: support@jenni.ai. Not found publicly An EU representative under GDPR Article 27, a DPO, or a GDPR legal basis. | [2], [1] |
| Where data is stored and processed | Documented "The Services are hosted in the United States." Library data is stored via Firebase Firestore and Google Cloud Storage; no region named. No EU hosting option found. | [2], [1] |
| Data processing agreement | Not found publicly No public DPA and no reference to one in the terms or privacy policy. | [1], [2] |
| Subprocessors | Partly documented No public subprocessor list. The privacy policy names Firebase (Google), PostHog (analytics), the NIH PMC API and Slack (issue reports). The help centre names "third-party Large Language Model (LLM) providers such as OpenAI's ChatGPT". Other model providers and locations are not stated. | [1], [4] |
| International transfers | Not found publicly Users outside the US consent to transfer and processing in the US. No mention of SCCs or the EU-US Data Privacy Framework. No entry for Jenni on the official DPF list, active or inactive. | [2], [1], [7] |
| AI model training on customer content | Documented "We do not use any user data, including your text, prompts, citations, or uploaded files ... to train or fine-tune any language models", and Jenni ensures third-party LLM providers do not train on it either. The team plans page repeats this. The privacy policy and terms do not contain this commitment. | [4], [3] |
| Retention and deletion | Documented Deleted data is inaccessible immediately, purged from active systems within 30 days and from encrypted backups within 60 days (90 days in total). Support records are kept for 24 months. Account deletion removes all data. No retention period is stated for analytics events. | [1], [5] |
| Analytics and logging | Documented Some PostHog events "carry content you provide": chat messages and the surrounding document text sent for autocomplete. Jenni employees with PostHog access can see them. Users can refuse analytics cookies in settings to stop this content analytics and session replay. | [1] |
| Security certifications | Not found publicly No ISO 27001 or SOC 2 claim on jenni.ai or its help centre. Uploads are "encrypted in transit and securely stored". | [4] |
| Institution and enterprise controls | Plan-dependent Team plans offer an admin dashboard for seats and users, single invoicing, volume discounts and dedicated support. SSO: not found publicly. | [3], [6] |
What this means for a university
Validemic's analysis
What personal data is involved. A writing assistant sees whatever the user writes. For students that is coursework, theses and personal reflections; for researchers it can include drafts with participant quotes or other unpublished findings. Uploaded published papers are rarely personal data. The account itself, the writing and especially the analytics events that carry chat and document text are personal data.
Controller or processor. On an individual account, Jenni is the controller. If the university buys team seats, it will normally become controller for that use and needs a processor agreement under GDPR Article 28. Because no DPA is published, that has to be negotiated, along with a list of subprocessors including the model providers.
Transfers. Hosting is in the US and the public documents rely on user consent for transfers. For a university contract, you would normally expect SCCs (Jenni is not on the DPF list) and a transfer impact assessment that covers Google, PostHog and the LLM providers.
Analytics. Jenni is unusually transparent that chat messages and autocomplete context go into product analytics, and that users can switch this off through cookie settings. For institutional use, ask whether this can be disabled for all team members by default rather than per browser.
DPIA and students. A tool marketed to students, used on coursework and theses, at scale, with US transfers and no DPA, would usually warrant a DPIA before the university recommends or licenses it. Academic integrity policy is a separate question your teaching staff will also want answered. The terms set the minimum age at 13 with parental permission for minors.
Credit where due. A plain no-training statement covering both Jenni and its LLM providers, specific deletion periods including backups, and open disclosure of content analytics with an opt-out are clearer than many writing tools publish.
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
Questions to ask Jenni AI before approving it
- Will you sign a data processing agreement under GDPR Article 28 for team or institutional plans?
- Can you provide a full subprocessor list, including every LLM provider, with locations?
- What transfer mechanism (SCCs or other) will you use for EU personal data?
- Can the no-training commitment from your help centre be written into the contract and privacy policy?
- What retention and zero-data-retention terms apply with OpenAI and any other model providers?
- Can content analytics and session replay be switched off for all institutional users by default? How long are PostHog events kept, and where is PostHog hosted?
- Do you hold, or plan, SOC 2 Type II or ISO 27001? If not, can you complete a security questionnaire such as the HECVAT?
- Do team plans support SSO, and can admins delete a departing user's data?
- Who is your EU representative under Article 27, and how do EU users exercise their GDPR rights?
The EU AI Act angle
Using Jenni to draft and edit text is normally not a high-risk use under the AI Act, Regulation (EU) 2024/1689. Annex III, point 3 lists the education uses that are high-risk: AI used to decide admission or access, to evaluate learning outcomes, to assess the level of education a person will receive, or to monitor students for prohibited behaviour during tests. A writing assistant used by students does none of these by default.
A university that uses an AI system under its authority is a deployer (Article 3(4)). Article 4 on AI literacy has applied since 2 February 2025. Regulation (EU) 2026/1744 (the Digital Omnibus on AI), in force since 27 July 2026, replaced that article: deployers must now "take measures to support the development of AI literacy" of their staff and others using AI on their behalf, without having to guarantee a specific level for each person. The same regulation moved the application date for Annex III high-risk obligations to 2 December 2027.
Obligations for general-purpose AI models (Article 53, applying since 2 August 2025) fall on the model providers, such as OpenAI, not on the university.
Sources
- Jenni AI, Privacy Policy (last updated 4 October 2026), retrieved 7 October 2026
- Jenni AI, Terms of Service (last updated 27 April 2024), retrieved 7 October 2026
- Jenni AI, "Team Plans", retrieved 7 October 2026
- Jenni AI Help Center, "Data Protection & Privacy For Uploaded Papers" (updated 24 April 2025), retrieved 7 October 2026
- Jenni AI Help Center, "What Is Jenni? Quick overview", retrieved 7 October 2026
- Jenni AI, Pricing, retrieved 7 October 2026
- Data Privacy Framework List (searched for "Jenni", active and inactive participants, via the list's search service), retrieved 7 October 2026
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), Articles 3(4), 4, 53, 113 and Annex III, Official Journal text read via the Publications Office, retrieved 7 October 2026
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal text read via the Publications Office, retrieved 7 October 2026
About this page
We read Jenni AI's privacy policy, terms, team and pricing pages and help centre, checked the usual addresses for a DPA, subprocessor list and trust centre (none found), and searched the official Data Privacy Framework list, on 7 October 2026. This page describes public documentation only. It is not legal advice and not a verdict on whether Jenni AI complies with the GDPR; that depends on your contract and your use.
If you work at Jenni AI and something here is out of date or incomplete, please contact us and we will review it promptly.
Frequently asked questions
Does Jenni AI train on my writing?
Jenni's help centre and team plans page say it does not use user text, prompts, citations or uploaded files to train or fine-tune any language models, and that third-party providers such as OpenAI do not train on the data either. The privacy policy itself does not repeat this commitment.
Where does Jenni AI store data?
Jenni's terms say the services are hosted in the United States, and its privacy policy names Firebase Firestore and Google Cloud Storage. No EU hosting option was found (checked 7 October 2026).
Does Jenni AI sign a DPA?
We found no public DPA and no mention of one in Jenni's terms or privacy policy (checked 7 October 2026). Institutions should ask Jenni's team sales directly.
How long does Jenni AI keep deleted data?
The privacy policy says deleted data becomes inaccessible immediately, is purged from active systems within 30 days and from encrypted backups within 60 days, or 90 days in total.
Can students use Jenni AI under GDPR?
Jenni's terms allow users from age 13, with parental permission for minors. For a university that licenses or recommends it, the missing DPA and the consent-based US transfer are the main points to resolve first.