Is Paperpile GDPR compliant? What universities should check
Paperpile is a reference manager built around Google sign-in, Google Docs and Google Drive. This page sets out what Paperpile publicly documents about hosting, contracts, transfers, certifications and its AI integration, and what that means for a university that wants to license it or approve it for staff.
Short answer
Paperpile LLC is a US company in Cambridge, Massachusetts, with an EU contact point in Austria. It stores data with Amazon Web Services in data centres in the US and the EU, offers a data processing agreement to organisations on request, and refers to the Standard Contractual Clauses for transfers from the EU. It connects to the user's Google Drive, where it can access only files uploaded through Paperpile. Its Ask AI integration sends PDFs, when the user chooses, to an AI assistant under the user's own account, and Enterprise licences add SAML single sign-on and admin controls. SOC 2 Type II is described as in progress. What a university needs to check depends mostly on the plan and on whose Google account holds the files.
Prefer a tool built in the EU? Kahubi, from Avidemic AB in Sweden, covers reference management and a research library with EU hosting and, for institutions, only European subprocessors. See how Kahubi handles research data
What Paperpile documents publicly
Everything in this table comes from Paperpile's own pages or the official Data Privacy Framework list, read on 7 October 2026. Numbers in brackets refer to the sources at the end of the page.
| Topic | What the vendor states | Source |
|---|---|---|
| Company and establishment | Paperpile LLC, 245 First Street, Cambridge, MA, USA. The privacy policy (updated 21 September 2026) gives an "EU representation" contact: Paperpile LLC & Co OG in Bad Leonfelden, Austria. The terms are governed by Massachusetts law. | [1] [2] |
| Where data is stored | US and EU Information is stored and processed "in data centers in the US and EU" on Amazon Web Services. Logs of the Google Docs add-on are kept in Google Cloud. Paperpile connects to the user's Google Drive and can access only files uploaded through Paperpile. Not found publicly A customer choice of region. | [1] [3] [4] |
| Data processing agreement | On request The help centre says organisations that need a DPA should contact support. A standard DPA was not published on the website (checked 7 October 2026). The privacy policy does not use the terms controller or processor. | [1] [5] |
| Subprocessors | Named in the privacy policy: AWS (hosting), Google Cloud (add-on logs), Intercom (support), Stripe (payments), Bugsnag (error reporting), Mixpanel and Statsig (analytics and feature management), Google reCAPTCHA, Google Analytics and Google Ads, and Meta (advertising). A separate subprocessor list with change notices was not found. | [1] |
| International transfers | SCCs The policy says Paperpile transfers data from the EU "in accordance with" the Commission-approved Standard Contractual Clauses in certain cases and that AWS is certified under the EU-US Data Privacy Framework. Paperpile itself did not appear on the official DPF list when we searched on 7 October 2026. | [1] [6] |
| AI features | User-initiated Ask AI (beta since May 2026) sends "your full-text PDF and selected prompt" to the AI assistant the user picks, under the user's own subscription. Users can switch off all AI features; group and enterprise admins can control access and restrict assistants. Google Docs content is not used to train generalised AI models. | [1] [7] |
| Retention and deletion | Self-service account deletion removes data from active systems; a GDPR erasure request also covers backups and logs. Logs are deleted after six months. Shared items may be kept where deletion would break a collaborator's bibliography. | [1] [5] |
| Security and certifications | In progress Data encrypted at rest and in transit, annual penetration tests and a Vanta trust centre. SOC 2 Type II and HIPAA are listed as goals for 2026, although the pricing page lists HIPAA among Enterprise features. ISO 27001 was not found in public documentation (checked 7 October 2026). | [3] [5] [8] [9] |
| Institution controls | Plan-dependent Enterprise and institution licences add SAML single sign-on, "advanced security and privacy settings", a custom MSA and SLA, and vendor security reviews. Admins can limit member visibility and internal and external sharing. | [9] [10] |
Paperpile deserves credit for several things a reviewer looks for: plain-language help articles on GDPR and security, an erasure route that explicitly reaches backups and logs, a clear statement that the Google Docs add-on never sends document text to its servers, and an AI integration that users can switch off and that administrators can restrict.
What this means for a university
Validemic's analysisLow-risk content, mostly. A reference library is largely published literature, and for most users the personal data involved is account details, notes and annotations. The picture changes when researchers store unpublished manuscripts, peer review files, ethics paperwork or supplementary material that contains participant data, all of which Paperpile can hold.
Whose Google account? Because Paperpile connects to Google Drive and sign-in runs through Google, the storage location and contract for the files depend partly on the Google account used. A file in a university-managed Google Workspace account falls under the university's Google agreement; a file in a personal Gmail account does not. Universities that use Microsoft 365 rather than Google should decide whether staff may create Google accounts for this purpose.
Controller or processor. The privacy policy describes Paperpile's own handling of user information and does not address controller and processor roles. For institutional licences, a university will usually want a DPA under Article 28 GDPR [11] that makes Paperpile a processor for content, with a list of subprocessors and a way to object to changes. Paperpile offers a DPA on request, so ask for it before signing.
Transfers. Data centres in both the US and the EU are used, and a company based in the US remains subject to US law wherever data sits. Paperpile relies on the Standard Contractual Clauses, so a university should keep a transfer impact assessment on file. Our transfer mechanism tool walks through the options.
Ask AI shifts the question to another vendor. When a researcher sends PDFs through Ask AI, the content goes to ChatGPT, Gemini, Claude, Copilot or NotebookLM under that researcher's account. Training and retention then follow the AI provider's terms for that account. Routing it to an institutional AI subscription is very different from routing it to a personal free account, and Enterprise admins can enforce which assistant is allowed.
Advertising tools. The privacy policy lists Google Ads and Meta for advertising. That mainly affects the marketing website and sign-up flows rather than library content, but it belongs in the cookie and privacy information given to staff.
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
Questions to ask Paperpile before approving it
- Can you send your Data Processing Agreement, and does it make Paperpile a processor for library content on an institution licence?
- Which data is stored in the EU and which in the US, and can our institution's data be kept in the EU only?
- Which subprocessors handle library content (as opposed to website analytics), and how will we be told about changes?
- Which transfer mechanism covers data that reaches the US, and do you have a transfer impact assessment we can review?
- Can our admins turn off Ask AI for everyone, or restrict it to our institutional AI service?
- What is the current status of the SOC 2 Type II audit, and can we see the trust centre documents under NDA?
- If our staff use university Google Workspace accounts, do any files or metadata leave that tenant besides what is held on Paperpile's own servers?
- What happens to licensed users' libraries when someone leaves the university or the licence ends?
The EU AI Act angle
Core reference management is not an AI use listed in Annex III of the AI Act, Regulation (EU) 2024/1689. The education entries there cover admission, evaluating learning outcomes, assessing the appropriate level of education and monitoring students during tests [12]. Ask AI connects a library to general-purpose assistants supplied by other companies, so the main obligation for a university is AI literacy. Article 4, as amended by the Digital Omnibus on AI, Regulation (EU) 2026/1744, requires deployers to take measures to support the AI literacy of staff using AI systems [13]. Researchers who summarise papers with AI should understand that outputs can be wrong and should check quotations against the PDF. Annex III high-risk obligations now apply from 2 December 2027 [14].
Sources
- Paperpile Privacy Policy, updated 21 September 2026, retrieved 7 October 2026
- Paperpile Terms of Service, retrieved 7 October 2026
- Security at Paperpile, Paperpile Help Center, updated 18 August 2026, retrieved 7 October 2026
- Paperpile home page and sign-in panel, retrieved 7 October 2026
- Paperpile and GDPR, Paperpile Help Center, updated 18 August 2026, retrieved 7 October 2026
- Data Privacy Framework List, searched for "Paperpile" (active and inactive participants), retrieved 7 October 2026
- New integration: bring your research library to any AI assistant, Paperpile blog, 6 May 2026, retrieved 7 October 2026
- SOC 2 and HIPAA certifications, Paperpile Help Center, updated 18 August 2026, retrieved 7 October 2026
- Paperpile Pricing, retrieved 7 October 2026
- Limit data sharing in your organization, Paperpile Help Center, retrieved 7 October 2026
- Regulation (EU) 2016/679 (General Data Protection Regulation), Article 28, retrieved 7 October 2026
- AI Act Annex III: High-risk AI systems, AI Act Service Desk, retrieved 7 October 2026
- AI Act Article 4: AI literacy (as amended), AI Act Service Desk, retrieved 7 October 2026
- AI Act Article 113: Entry into force and application (as amended), AI Act Service Desk, retrieved 7 October 2026
About this page
We read Paperpile's privacy policy, terms, pricing page, blog and help centre on 7 October 2026, and searched the official Data Privacy Framework list on the same day. "Not found" means we could not find the information in public documentation; it does not mean the vendor lacks it. Plans, terms and features change, so confirm the current position with Paperpile before relying on it.
This page describes public documentation and gives our own analysis. It is not legal advice and it is not a statement that the tool is or is not GDPR compliant, which depends on your contract, configuration and use. If you work for Paperpile and see an error, please contact us and we will correct it.
Frequently asked questions
Is Paperpile GDPR compliant?
No tool is GDPR compliant on its own. Paperpile describes how it applies GDPR principles, offers a data processing agreement to organisations on request and says it uses Standard Contractual Clauses for transfers from the EU. Whether a university's use complies depends on the plan, the contract it signs and how staff use features such as Ask AI.
Where does Paperpile store data?
Paperpile's privacy policy says it stores and processes information in data centres in the US and the EU using Amazon Web Services. Its sign-in page says it connects to the user's Google Drive and can access only files uploaded through Paperpile. A customer choice of storage region was not found in public documentation (checked 7 October 2026).
Does Paperpile have a data processing agreement?
Paperpile's help centre says organisations that need a Data Processing Agreement should contact support@paperpile.com. A standard DPA was not published on its website when we checked on 7 October 2026.
Does Paperpile send my PDFs to AI tools?
Only if Ask AI is used. Paperpile says Ask AI sends the full-text PDF and the selected prompt to the AI assistant the user chooses (such as ChatGPT, Gemini, Claude, Copilot or NotebookLM) under the user's own account. Users can turn off all AI features, and administrators of group and enterprise licences can control access.
Is Paperpile on the EU-US Data Privacy Framework list?
We did not find Paperpile on the official Data Privacy Framework list on 7 October 2026. Its privacy policy says Amazon Web Services is certified under the framework and that Paperpile uses Standard Contractual Clauses for certain transfers from the EU.