Is scite GDPR compliant? What universities should check
scite (Scite, LLC, part of Research Solutions) shows how papers cite each other and offers an AI Assistant grounded in its citation index. Libraries and researchers ask whether it can be used under the GDPR. This page sets out what scite publicly documents about processing, transfers, AI training and retention, and what a university should ask before approval.
Short answer
scite is run by Scite, LLC, a Research Solutions company based in Henderson, Nevada. Its privacy policy says personal data is processed in the United States and that transfers from the EEA rely on the Standard Contractual Clauses; scite does not appear on the Data Privacy Framework list. Its terms contain a clear, plan-independent commitment not to use customer inputs, outputs, queries or uploads to train AI systems. We did not find a public DPA, subprocessor list, named AI model provider or security certification, and the public website uses advertising cookies. For institutional use, those gaps are best closed in an Enterprise agreement.
Prefer a tool built in the EU? Kahubi, from Avidemic AB in Sweden, covers AI research assistance with EU hosting and, for institutions, only European subprocessors. See how Kahubi handles research data
What scite documents publicly
All sources were read on 7 October 2026. "Not found publicly" means we did not find it in the sources listed at the end of this page; it does not mean the safeguard does not exist.
| Topic | What the vendor states | Source |
|---|---|---|
| Company and establishment | Documented Scite, LLC, "a Research Solutions Company", 10624 S. Eastern Ave., Henderson, Nevada, USA. Privacy requests go to customersupport@researchsolutions.com with the subject line "Privacy". Not found publicly An EU representative under Article 27 GDPR or a named data protection officer. | [1] |
| Where data is processed | Documented "Personal information will be processed in the United States." Not found publicly The hosting provider, data centre regions or an EU data residency option. | [1] |
| Data processing agreement | Not found publicly No public DPA. The privacy policy mentions a "written agreement with the institution" for US institutions that license the service for students under FERPA, which shows that institutional agreements exist. | [1] |
| Subprocessors | Not found publicly No public subprocessor list. The privacy policy describes categories of recipients: service providers (customer service, IT outsourcing and hosting, marketing), advertising networks, advisers and auditors. Google Analytics is named. The large language model provider behind the Assistant is not named. | [1] |
| International transfers | Partly documented For transfers from the EEA, scite says it implements the Standard Contractual Clauses, and a copy can be requested. Not found publicly Data Privacy Framework certification: no active or inactive entry for scite on the official list. A search for "Research Solutions" returned only an inactive entry for Reprints Desk, Inc. | [1] [5] |
| AI training on customer content | Documented The terms define Customer Data broadly ("inputs, outputs, queries, and usage data") and state that scite does not use it "to train, fine-tune, or improve such AI systems". The licence users grant over uploaded media also excludes model training. The privacy policy repeats the commitment. | [1] [2] |
| Retention and deletion | Partly documented Account data is kept for as long as the account exists "and for 10 years after that"; marketing data for up to 10 years from last contact. scite says it will securely delete data on request, in line with applicable law. Users can delete account information themselves, but servers "may retain previously provided information". | [1] |
| Cookies and advertising | The website uses analytics (Google Analytics) and targeting cookies shared with advertising networks. The cookie banner offers "Reject All Unnecessary Cookies", and the Global Privacy Control signal is honoured. | [1] |
| Security certifications | Not found publicly SOC 2, ISO 27001 or a trust centre on scite's or Research Solutions' sites. The privacy policy describes "reasonable technical and organizational measures". The Enterprise plan lists "Enhanced security and data confidentiality" without further detail. | [1] [3] |
| Institution controls | Plan-dependent Team (up to 15 seats) adds user analytics. Enterprise adds unlimited users, access by domain, IP address or email, SAML single sign-on and a customer success manager. Universities buy organisation-wide access through an Enterprise agreement. | [3] |
scite deserves credit for a training commitment that is written into the terms for every user rather than reserved for one plan, for a broad definition of Customer Data that covers queries and outputs as well as uploads, and for clear statements of retention periods, lawful bases and transfer mechanisms in its privacy policy.
What this means for a university
Validemic's analysis
What personal data is involved. Most scite use concerns published literature: searching citation statements, reading Smart Citation reports and asking the Assistant questions grounded in papers. The personal data is mainly the account, search history and prompts. Two features change that picture. Reference Check asks the user to upload a manuscript PDF, and the report is kept in the user's profile [4]. An unpublished manuscript can contain participant descriptions, acknowledgements or pilot data. And researchers sometimes paste unpublished findings or notes into AI prompts. Guidance for staff should say what may and may not go into uploads and prompts.
The training commitment is strong, the processing chain is not visible. The no-training clause covers queries and outputs, not only uploaded files, and applies regardless of plan. What is missing from public documentation is who else processes the data: no subprocessor list, no named hosting provider and no named AI model provider. A DPO cannot assess onward transfers or the retention practices of an AI provider without that list. Requesting it, with change notification, is the most important step in any procurement.
Transfers rest on the SCCs. Without a DPF certification, transfers to scite in the US depend on the Standard Contractual Clauses. Your institution will normally want them signed as part of a DPA, together with a transfer impact assessment that also covers any AI provider used by the Assistant.
Controller or processor. The privacy policy is written from scite's position as a controller of user data, which fits individual sign-ups. For staff and student use under a university licence, the institution will normally want scite to act as processor under Article 28 GDPR for the content its users submit [6]. That needs a DPA; the public terms alone do not provide one.
Retention of ten years. Keeping account data for ten years after an account closes is a long default by European standards, even though deletion on request is offered. An institutional agreement can set shorter periods and a deletion process for leavers.
Advertising cookies and the MCP route. The public website uses targeting cookies, which researchers can refuse in the banner. scite also offers an MCP connector that brings its data into ChatGPT, Claude, Copilot and other assistants [7]. In that set-up, the researcher's prompts are processed by the chosen AI assistant under that assistant's own terms, so the institution's approval of scite does not cover the assistant.
DPIA likelihood. Literature searching with published papers will usually need only a screening. A DPIA becomes more likely if staff upload manuscripts or notes containing personal data, or if access is rolled out to all students. Our DPIA screening tool gives a first view.
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
Questions to ask scite before approving it
- Will you sign a data processing agreement under Article 28 GDPR, including the Standard Contractual Clauses, as part of our Enterprise agreement?
- Can you provide your current subprocessor list, with locations, and notify us of changes with a right to object?
- Which large language model providers process Assistant prompts, and what are their retention and no-training terms?
- Which hosting provider and regions store our users' data and uploaded manuscripts? Is EU hosting possible?
- Can the ten-year post-closure retention of account data be shortened for our institution, and how are backups handled?
- How long are Reference Check uploads and Assistant chat histories kept, and can users delete them individually?
- Do you hold an independent security attestation such as SOC 2 Type 2 or ISO 27001, or can you complete a HECVAT or similar questionnaire?
- What does "Enhanced security and data confidentiality" on the Enterprise plan include in practice?
- Does SAML single sign-on work with eduGAIN or our national research and education federation?
- Will you name an EU representative under Article 27 GDPR?
The EU AI Act angle
Using scite to search, evaluate and summarise literature is normally not a high-risk use under the AI Act, Regulation (EU) 2024/1689 [8]. Annex III, point 3 lists the education uses that are high-risk: AI used to decide admission or access, to evaluate learning outcomes, to assess the level of education a person will receive, or to monitor students for prohibited behaviour during tests. A university that used any tool for those purposes would need a different assessment.
A university that uses an AI system under its authority is a deployer (Article 3(4)). Article 4 on AI literacy has applied since 2 February 2025. Regulation (EU) 2026/1744 (the Digital Omnibus on AI), in force since 27 July 2026, amended it so that deployers must take measures to support the AI literacy of their staff and others using AI on their behalf [9]. For scite, that means explaining that AI answers can misread sources and that citation classifications come from a model and can be wrong. The same regulation moved the application date for Annex III high-risk obligations to 2 December 2027 [9].
Sources
- scite, Privacy Policy (effective 26 March 2026), retrieved 7 October 2026
- scite, Terms of Service, retrieved 7 October 2026
- scite, Pricing and access (last updated 5 October 2026), retrieved 7 October 2026
- Research Solutions Help Center, "How to use the Scite Reference Check", retrieved 7 October 2026
- Data Privacy Framework List (searched for "Scite" and "Research Solutions", active and inactive participants), retrieved 7 October 2026
- Regulation (EU) 2016/679 (General Data Protection Regulation), Articles 27, 28 and 35, retrieved 7 October 2026
- scite, Scite MCP, retrieved 7 October 2026
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), Articles 3(4), 4 and Annex III, Official Journal text read via the Publications Office, retrieved 7 October 2026
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal text read via the Publications Office, retrieved 7 October 2026
About this page
We read scite's privacy policy, terms of service, pricing information, MCP page and help centre, looked for security and subprocessor pages on scite's and Research Solutions' websites, and searched the official Data Privacy Framework list, all on 7 October 2026. "Not found" means we could not find the information in public documentation; it does not mean scite lacks it, and much of it may be available to institutional customers on request. Plans, terms and features change, so confirm the current position with scite before relying on it.
This page describes public documentation and gives our own analysis. It is not legal advice and it is not a statement that the tool is or is not GDPR compliant, which depends on your contract, configuration and use. If you work at scite or Research Solutions and see an error, please contact us and we will correct it.
Frequently asked questions
Does scite train AI models on my data?
scite's Terms of Service say it does not use Customer Data, defined to include inputs, outputs, queries, uploads and usage data, to train, fine-tune or improve its AI systems. The privacy policy (effective 26 March 2026) repeats this commitment. Unlike several competitors, the commitment is not limited to an enterprise plan in the published terms.
Where does scite store and process data?
The privacy policy says that, as a US company, scite processes personal information in the United States and uses the European Commission's Standard Contractual Clauses for transfers from the EEA. The hosting provider and any EU data residency option were not found in public documentation (checked 7 October 2026).
Is scite certified under the EU-U.S. Data Privacy Framework?
On 7 October 2026 a search of the official Data Privacy Framework list returned no active or inactive entry for scite. scite's privacy policy names the Standard Contractual Clauses as its transfer mechanism for EEA data.
Does scite offer a data processing agreement?
A public data processing agreement or subprocessor list was not found in scite's public documentation (checked 7 October 2026). The privacy policy refers to written agreements with institutions that license the service, so universities should request a DPA as part of an Enterprise agreement.
Which AI model does the scite Assistant use?
scite's own public documentation does not name the large language model providers behind the Assistant (checked 7 October 2026). Ask scite which providers process prompts and under what retention and training terms.