GDPR check

Is SciSpace GDPR compliant? What universities should check

SciSpace, formerly Typeset, is an AI platform for reading, searching and writing about research papers. Students in particular use it widely, which is why DPOs and librarians get asked about it. This page sets out what SciSpace publishes about data protection, where its documents differ, and what to ask before approval.

Published 7 October 2026 · Sources checked 7 October 2026

Short answer

SciSpace is run by PubGenius, Inc., based in Milpitas, California, and its privacy policy says the service is hosted and operated in the United States. It sells individual Premium, Advanced and Max plans, plus SciSpace Enterprise for institutions and teams. SciSpace states that it does not use customer data to train LLMs, shows a SOC 2 Type II report in its trust centre, and its API documentation offers EU processing and storage on Enterprise plans. We found no public DPA, subprocessor list or Data Privacy Framework certification. Whether you can use it depends on whether you buy Enterprise with a negotiated DPA and on what users will upload.

Prefer a tool built in the EU? Kahubi, from Avidemic AB in Sweden, covers AI research assistance with EU hosting and, for institutions, only European subprocessors. See how Kahubi handles research data

What SciSpace documents publicly

All sources were read on 7 October 2026. Some statements below come from SciSpace's API documentation, which may describe the API product rather than the web app; we mark those. "Not found publicly" means we did not find it in the sources listed; it does not mean the safeguard does not exist.

TopicWhat the vendor statesSource
Company and establishmentDocumented PubGenius, Inc., Milpitas, California, United States. The terms are governed by California law. The privacy policy says SciSpace is controller for its own users and processor when serving a customer's end users. Contacts: support@scispace.com and compliance@scispace.com. Not found publicly An EU representative under GDPR Article 27 or a named DPO.[1], [2], [4], [5]
Where data is stored and processedPlan-dependent "The Services are hosted and operated in the United States." Documents are stored in isolated, encrypted AWS environments. API documentation: requests are served from us-east by default, and eu-central processing and storage "is available on Enterprise plans".[1], [3], [6]
Data processing agreementOn request API documentation lists "DPA available on request" via the sales team. No public or self-serve DPA found, and none among the trust centre's documents.[7], [5]
SubprocessorsNot found publicly The trust centre says SciSpace "has not published any subprocessor information". Named providers elsewhere: AWS, Stripe, and for Enterprise LLM processing AWS Bedrock, Google Vertex AI and Azure AI Foundry. No count or locations given.[5], [1], [3]
International transfersPartly documented The privacy policy says personal data may in some circumstances be transferred to the US under a data processing agreement incorporating standard data protection clauses. No entry for PubGenius, SciSpace or Typeset on the official DPF list, active or inactive.[1], [8]
AI model training on customer contentDocumented Enterprise FAQ: "SciSpace does not use customer data for LLM training", and LLM provider agreements exclude customer data from training. The terms say private materials will not train a general-purpose model "unless separately disclosed to you". The privacy policy separately reserves use of avatar audio and video recordings to develop its AI models. No per-plan opt-out described.[3], [2], [1]
Retention and deletionPartly documented Privacy policy: data kept "for as long as necessary"; avatar recordings up to 3 years after last interaction. API documentation: chats and searches kept 90 days, documents until deleted (within 24 hours), backups purged within 30 days, and Enterprise can set chat and search retention from 0 to 365 days. The terms note content may not be completely deletable from records after account deletion.[1], [6], [2]
Security certificationsDocumented Trust centre: SOC 2 Type II, with a 2025 SOC 2 Type 2 report available on request (scope not public). API documentation: ISO 27001 "in progress".[5], [7]
Institution and enterprise controlsPlan-dependent Enterprise offers admin-managed access, shared credit pools, SSO and SAML, SCIM, RBAC and consolidated billing. The terms allow a separate written institutional agreement to take precedence over the standard terms.[4], [3], [2]

What this means for a university

Validemic's analysis

What personal data is involved. Reading and summarising published papers rarely involves personal data beyond the account and the questions. SciSpace is also used for literature reviews and writing, so drafts, theses and unpublished manuscripts may be uploaded. Those can contain participant data or other people's personal data. The privacy policy also covers audio and video recordings for an avatar feature; if anyone plans to use that feature, assess it separately from routine research use.

Two very different products. The individual plans run on the public terms and privacy policy, with US hosting and no public DPA. Enterprise, as described on SciSpace's enterprise page and API documentation, adds SSO, SCIM, configurable retention, EU processing and a DPA on request. For institutional approval, Enterprise with a signed DPA is the realistic route; approving individual subscriptions for work with personal data would be hard to justify on the public documents alone.

Documents that need reconciling. The privacy policy (effective 10 April 2024) still contains bracketed template placeholders and is written largely around US state privacy laws. It also describes advertising partners and the possible "sale or sharing" of personal data in the US-law sense, mainly through cookies. The clearest commitments (no training, retention periods, EU region) are in the enterprise page and API documentation. A DPO will want the contract to state which document prevails, and the terms do allow a separate institutional agreement to take precedence.

Transfers. SciSpace is not on the DPF list, so for US processing the basis would be SCCs in the DPA. If the EU region is contracted, ask whether any processing (support, logging, LLM inference) still happens outside the EU.

DPIA and students. A screening is sensible; a DPIA is likely if the tool is licensed broadly to students or if unpublished research data is uploaded. SciSpace's stated age threshold is 16, which suits university use.

Credit where due. A clear no-training statement, a SOC 2 Type II report, configurable retention including zero retention, and an EU processing option are meaningful safeguards that many comparable tools do not publish.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

Questions to ask SciSpace before approving it

  1. Please share your DPA. Does it apply to the web app as well as the API, and does it include the EU SCCs?
  2. Can you provide a complete subprocessor list with locations, and a way to be notified of changes?
  3. Does the eu-central option cover the web app and all its features, including LLM inference, logs and support access?
  4. Does the no-training commitment apply on all plans, and is it in the contract rather than only on the website?
  5. Do the API retention periods (90 days for chats and searches, 30 days for backups) also apply to the web app?
  6. Which LLM providers process data for non-Enterprise plans, and on what retention terms?
  7. What is the scope of your SOC 2 Type 2 report, and when do you expect ISO 27001 certification?
  8. Can advertising cookies and session replay be disabled for institutional users?
  9. Will you publish an updated privacy policy without template placeholders, and name an EU representative under Article 27?

The EU AI Act angle

Using SciSpace to read, search and summarise literature is normally not a high-risk use under the AI Act, Regulation (EU) 2024/1689. Annex III, point 3 lists the education uses that are high-risk: AI used to decide admission or access, to evaluate learning outcomes, to assess the level of education a person will receive, or to monitor students for prohibited behaviour during tests. Using any tool for those purposes would change the assessment.

A university that uses an AI system under its authority is a deployer (Article 3(4)). Article 4 on AI literacy has applied since 2 February 2025. Regulation (EU) 2026/1744 (the Digital Omnibus on AI), in force since 27 July 2026, replaced that article: deployers must now "take measures to support the development of AI literacy" of their staff and others using AI on their behalf, without having to guarantee a specific level for each person. The same regulation moved the application date for Annex III high-risk obligations to 2 December 2027.

Obligations for general-purpose AI models (Article 53, applying since 2 August 2025) fall on the model providers, not on the university.

Sources

  1. SciSpace, "Privacy Policy - SciSpace - Live" (effective 10 April 2024; published document embedded at scispace.com/privacy), retrieved 7 October 2026
  2. SciSpace, Terms of Use (effective 10 April 2024; published document embedded at scispace.com/terms), retrieved 7 October 2026
  3. SciSpace Enterprise, "AI-Powered Research Platform for Institutions & R&D Teams", retrieved 7 October 2026
  4. SciSpace, Pricing, retrieved 7 October 2026
  5. SciSpace Trust Center (including its subprocessors and resources pages), retrieved 7 October 2026
  6. SciSpace API documentation, "Data privacy and retention", retrieved 7 October 2026
  7. SciSpace API documentation, "Security and compliance", retrieved 7 October 2026
  8. Data Privacy Framework List (searched for "PubGenius", "SciSpace" and "Typeset", active and inactive participants), retrieved 7 October 2026
  9. Regulation (EU) 2024/1689 (Artificial Intelligence Act), Articles 3(4), 4, 53, 113 and Annex III, Official Journal text read via the Publications Office, retrieved 7 October 2026
  10. Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal text read via the Publications Office, retrieved 7 October 2026

About this page

We read SciSpace's privacy policy, terms, enterprise and pricing pages, trust centre and API documentation, and searched the official Data Privacy Framework list, on 7 October 2026. This page describes public documentation only. It is not legal advice and not a verdict on whether SciSpace complies with the GDPR; that depends on your contract, your plan and your use. Vendors update their documents often, so check the sources before relying on them.

If you work at SciSpace and something here is out of date or incomplete, please contact us and we will review it promptly.

Frequently asked questions

Does SciSpace train AI models on my data?

SciSpace's enterprise page says it does not use customer data for LLM training and that its LLM providers' agreements exclude customer data from training. Its terms say private materials will not be used to train a general-purpose model unless separately disclosed. We found no per-plan opt-out setting described.

Where does SciSpace store data?

The privacy policy says the services are hosted and operated in the United States. The enterprise page mentions AWS storage, and SciSpace's API documentation says EU (eu-central) processing and storage is available on Enterprise plans.

Does SciSpace sign a DPA?

SciSpace's API documentation lists a DPA as available on request from its sales team. We found no public or self-serve DPA (checked 7 October 2026).

Is SciSpace SOC 2 compliant?

SciSpace's trust centre shows SOC 2 Type II and offers a 2025 SOC 2 Type 2 report on request. Its API documentation describes ISO 27001 as in progress.

Can students use SciSpace under GDPR?

SciSpace says it does not knowingly collect data from children under 16. Whether a university can recommend or license it for students depends on a DPA, the transfer basis and the data students upload, which should be settled first.