Is Undermind GDPR compliant? What universities should check
Undermind is an AI research assistant that runs deep literature searches and writes reports on what it finds. This page sets out what Undermind publicly documents about storage, transfers, AI training, uploaded files and security, and what that means for a university whose researchers want to use it.
Short answer
Undermind AI, Inc. is a US company that says it processes and stores personal data in the United States and relies on Standard Contractual Clauses for transfers from the EEA, UK and Switzerland. On its standard terms, users grant Undermind a broad licence to their content, including use in de-identified or aggregated form to develop AI systems. Its Enterprise offer is different: Undermind says company data is never used to train AI models, its model providers do not retain or train on it, and custom terms are available. Whether a university can use it depends mostly on which plan researchers use and what they upload.
Prefer a tool built in the EU? Kahubi, from Avidemic AB in Sweden, covers AI research assistance with EU hosting and, for institutions, only European subprocessors. See how Kahubi handles research data
What Undermind documents publicly
Everything in this table comes from Undermind's own pages, read on 7 October 2026. Numbers in brackets refer to the sources at the end of the page.
| Topic | What the vendor states | Source |
|---|---|---|
| Company and establishment | Undermind AI, Inc., with an address in Dover, Delaware. Privacy policy effective and Terms of Use last revised 31 July 2026. An EU representative under Article 27 GDPR was not found in public documentation (checked 7 October 2026). | [1] [2] |
| Plans | Free, Pro and Team plans, plus Enterprise with "sitewide organizational login", an admin dashboard and "Custom terms/SLA/security review". The pricing page has separate Industry and Academic views. A library or campus-wide licence was not found publicly. | [3] |
| Data collected | Account details, search queries and prompts, "uploaded documents and files", usage logs, and device and IP information. | [1] |
| Where data is stored | "We process and store personal data in the United States." Not found publicly An EU hosting option on any plan. | [1] |
| International transfers | Documented Adequacy decisions where available and otherwise Standard Contractual Clauses and the UK Addendum for transfers from the EEA, UK and Switzerland. The DPF is not mentioned in the policy, and a search of the official DPF list for "Undermind" on 7 October 2026 returned no results. | [1] [6] |
| Subprocessors | The privacy policy refers to service providers including "AI model providers" but does not name them. Not found publicly A subprocessor list. | [1] |
| Data processing agreement | Not found publicly No DPA is referenced in the standard terms. The privacy policy says content processed on an organisation's behalf is "governed by that agreement, not by this policy". | [1] [2] |
| AI training on user content | Plan-dependent Standard terms: users grant an irrevocable, worldwide licence to their content, including for "developing and improving related technologies, including artificial intelligence and machine learning systems", in de-identified or aggregated form. Enterprise: company data "is never used to train AI models", and agreements with model providers guarantee no long-term retention and no training. | [2] [3] [4] |
| Retention and deletion | Data is kept "as long as needed to provide the Services" and for legitimate business purposes. Enterprise customers can "request complete removal" of their organisation's data. | [1] [3] |
| Security | Encryption in transit and at rest, role-based access control, multi-factor authentication for staff, daily backups and annual security training, as described for enterprise agreements. A manual penetration test by Oneleet, with a letter of attestation available under NDA. SOC 2 and ISO 27001 were not found in public documentation (checked 7 October 2026). | [4] |
Undermind deserves credit for publishing a security overview with concrete controls, naming its penetration tester, stating a clear no-training commitment for Enterprise customers and its model providers, and setting out GDPR legal bases and transfer mechanisms in a recently updated privacy policy.
What this means for research and teaching
Validemic's analysisWhat goes in matters most. A literature search question is usually not sensitive. The picture changes when researchers upload files: Undermind's privacy policy lists uploaded documents among the data it collects [1], and the Pro plan advertises unlimited files and analysis of full texts [3]. Published papers carry little personal data beyond author names. Draft manuscripts, grant applications or anything containing participant information should not be uploaded on an individual plan.
The plan decides the training question. The standard Terms of Use licence is broad and includes developing AI systems with de-identified or aggregated content [2]. For a university, that sits awkwardly with unpublished research ideas and with any personal data in uploads. The Enterprise commitments are much stronger [4], so institutional use points towards an Enterprise agreement with the no-training commitment written into the contract.
Controller or processor. On individual plans, Undermind sets the terms and acts as controller for the user's data under its privacy policy. For institutional use, a university will normally want Undermind to act as processor under Article 28 GDPR [5], with a DPA listing subprocessors and locations. Because no subprocessor list is public, ask for it during procurement.
Transfers. Data is stored in the United States and the stated transfer mechanism is the SCCs [1]. When relying on SCCs, universities normally document whether the safeguards work in practice in a transfer impact assessment. Our transfer mechanism tool can help structure that step.
DPIA likelihood. Ordinary literature searching by staff is unlikely to need a full DPIA. Uploading documents that contain personal data, or rolling the tool out to all students, are factors that point towards at least a documented screening under Article 35 GDPR [5].
Students and shared workspaces. The Free plan includes shared workspaces and connections to other AI agents [3]. If a course encourages students to sign up individually, each student accepts the standard terms on their own behalf, and the university has no contract covering that use. Course guidance should either point students to an institutional workspace or make clear that use is optional and that no personal or confidential data should be entered.
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
Questions to ask Undermind before approving it
- Will you sign a data processing agreement in which Undermind acts as our processor, and can we see your template?
- Which AI model providers and other subprocessors process our users' queries and files, and in which countries?
- Can the Enterprise no-training commitment be written into our contract, and does it cover uploaded files, queries and generated reports?
- For staff who already use Free or Pro accounts, can their content be moved into our Enterprise workspace and excluded from the standard content licence?
- Do you offer EU data hosting, or a transfer impact assessment for US storage?
- What retention periods apply to queries, reports and uploaded files, and do deletion requests cover backups?
- Which single sign-on standards does the sitewide login support?
- Can we review the penetration test attestation and any planned SOC 2 or ISO 27001 work under NDA?
The EU AI Act angle
The EU AI Act, Regulation (EU) 2024/1689, applies alongside the GDPR [7]. AI literature search for research is not one of the education uses listed as high-risk in Annex III (such as admission decisions, evaluating learning outcomes or monitoring students during tests), and the Annex III obligations now apply from 2 December 2027 under Regulation (EU) 2026/1744 [8]. The obligation that applies today is AI literacy: Article 4, as amended, requires deployers to take measures to support the AI literacy of staff and others using AI systems on their behalf [9]. Researchers should understand that an AI search report can miss papers or misstate findings, and should check claims against the sources before citing them.
Sources
- Undermind Privacy Policy, effective 31 July 2026, retrieved 7 October 2026
- Undermind Terms of Use, last revised 31 July 2026, retrieved 7 October 2026
- Undermind home page and pricing, and Undermind Enterprise, retrieved 7 October 2026
- Undermind Security Overview (PDF), retrieved 7 October 2026
- Regulation (EU) 2016/679 (General Data Protection Regulation), Articles 28, 35 and 46, retrieved 7 October 2026
- Data Privacy Framework List, searched for "Undermind" (no result), retrieved 7 October 2026
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), Annex III, retrieved 7 October 2026
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), retrieved 7 October 2026
- AI Act Article 4: AI literacy, AI Act Service Desk, retrieved 7 October 2026
About this page
We read Undermind's privacy policy, Terms of Use, pricing and enterprise pages and its security overview on 7 October 2026. We also searched the official Data Privacy Framework list on the same day. "Not found" means we could not find the information in public documentation; it does not mean the vendor lacks it. Enterprise agreements may contain terms that are not public, so confirm the current position with Undermind before relying on it.
This page describes public documentation and gives our own analysis. It is not legal advice and it is not a statement that the tool is or is not GDPR compliant, which depends on your contract, configuration and use. If you work for Undermind and see an error, please contact us and we will correct it.
Frequently asked questions
Is Undermind GDPR compliant?
No tool is GDPR compliant on its own. Undermind's privacy policy addresses EEA and UK users, lists legal bases and relies on Standard Contractual Clauses for transfers to the United States. Whether a university's use complies depends on the plan, the contract and what researchers upload.
Where does Undermind store data?
Undermind's privacy policy says it processes and stores personal data in the United States. An EU hosting option was not found in public documentation (checked 7 October 2026).
Does Undermind use my searches to train AI?
It depends on the plan. The standard Terms of Use give Undermind a licence to use user content, in de-identified or aggregated form, to develop AI and machine learning systems. For Enterprise agreements, Undermind says company data is never used to train AI models and that its model providers do not retain or train on it.
Does Undermind sign a DPA?
A data processing agreement was not found in Undermind's public documentation (checked 7 October 2026). The privacy policy says data processed on an organisation's behalf is governed by that organisation's agreement, and the Enterprise plan offers custom terms and a security review.
Is Undermind on the EU-U.S. Data Privacy Framework list?
Undermind's privacy policy relies on Standard Contractual Clauses and does not mention the Data Privacy Framework. A search of the official DPF list for Undermind on 7 October 2026 returned no results.