Elicit
elicit.comElicit is an AI-powered research assistant used to search academic literature and generate cited research reports. The consumer-facing documents (Terms of Service and Privacy Policy, both last updated September 2023) grant Elicit broad, perpetual, irrevocable licenses to user content, explicitly permit use of aggregated user data to improve and market the service, and are largely silent on named security certifications, encryption specifics, and formal data retention/deletion schedules. Users retain ownership of their content, but the license terms are heavily vendor-favorable and the Privacy Policy is stale relative to the AI-first product now shipping (research agents, API/MCP, third-party model providers such as Claude). Professional users handling proprietary or regulated research data should review carefully and rely on the enterprise DPA rather than the consumer terms.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
Users retain ownership of their content, but grant Elicit an unusually broad license — perpetual, irrevocable, worldwide, transferable, and permitting derivative works. While ownership is preserved on paper, the scope of the license materially dilutes the practical value of that ownership.
Output Data Ownership
The consumer Terms of Service treat AI-generated results as part of 'Your Content' which the user owns, but the same broad license Elicit takes over Your Content applies. The consumer documents do not distinguish outputs from inputs as clearly as the enterprise agreement does, leaving some ambiguity around generated results.
Training Data Usage
Elicit reserves broad rights to use aggregated user behavior and telemetric data to improve and market the service, both during and after membership. The license to modify and create derivative works of Your Content in order to 'improve' the service, combined with silence on any opt-out from model training, is vendor-favorable and disadvantages users concerned about their inputs feeding model development.
Data Retention & Deletion
Consumer users can delete their account and end membership at any time by emailing Elicit, and termination may involve deletion of Your Content. However, the documents provide no explicit retention schedule, no deletion SLA, and Elicit reserves the right to retain aggregated data indefinitely, so retention practices are only partially disclosed.
Third-Party Data Sharing
The Terms permit sharing Your Content as set forth in the Terms and Privacy Policy, and integrations with Third-Party Services are described. The consumer Privacy Policy provided is truncated and largely silent on the full scope of third-party sharing, and there is no statement that data is sold, but the disclosure is incomplete rather than clearly limited.
Opt-Out Rights
The consumer documents describe no mechanism to opt out of data collection, aggregated data use for service improvement, or model training use. The only user control disclosed is account deletion, which is not the same as an opt-out from data use while using the service.
Compliance & Certifications
The consumer Terms and Privacy Policy name no compliance certifications (no SOC 2, ISO, GDPR framework, FERPA, or COPPA references beyond a CAN-SPAM prohibition). For a tool used in academic and research (edtech-adjacent) contexts, the absence of any named framework in the consumer documents is a significant gap. A trust center exists but is only referenced in the enterprise DPA.
Model Explainability & Auditability
The consumer legal documents provide no transparency into model behavior, no auditability commitments, and no enterprise audit rights. The Team terms acknowledge the inherent inaccuracy of generative AI but offer no explainability guarantees.
Security Practices & Breach History
The consumer Terms and Privacy Policy disclose almost no specific security controls — no encryption at rest/in transit statements, no access-control detail, no penetration testing or bug bounty, and no breach history. The Privacy Policy states only a general aim of maintaining security of the Sites. A trust center is not referenced in the consumer documents.
Enterprise vs. Consumer Risk Delta
There is a material difference between the consumer terms and the Team/enterprise agreements. The Team Services Agreement and the DPA introduce data-protection obligations, subprocessor lists, SCCs, and breach notification that the consumer documents lack — but the consumer Privacy Policy and free-tier Terms remain broadly permissive on data use. Free/consumer users get materially weaker protections.
Human Review of User Inputs
The consumer Terms reserve the right for Elicit to review, edit, delete, modify, remove, or filter Your Content for any reason, which implies staff may access user inputs. This is disclosed but broad, and no safeguards or limitations on such access are described.
Regulatory & Litigation Exposure
The Privacy Policy indicates Elicit will respond to legal requests such as subpoenas, though the supplied text is truncated mid-sentence. The Terms impose mandatory binding arbitration, a class-action waiver, and a one-year claim limitation period, all of which limit users' litigation options against Elicit.
PII & SPI Data Inventory
The consumer Privacy Policy discloses collection of limited PII (email, password, IP address, browser/device characteristics, location, usage data) with stated purposes. It does not describe collection of SPI in the consumer context, but the research use case means users may submit sensitive content, and the truncated policy leaves some categories unaddressed.
Policy–Product Currency
The consumer Terms of Service and Privacy Policy are both dated September 12, 2023 — roughly three years before the analysis date and materially stale. Meanwhile the product surface shows an AI-first product shipping research agents, an API/MCP server, and third-party model providers (e.g., Claude Opus). The consumer Privacy Policy never addresses AI/ML model processing, model training, or third-party model providers now visibly in use, a significant coverage gap.
Cross-Document Consistency
Multiple consumer documents were supplied (Terms of Service, Team Terms, Privacy Policy), permitting a cross-document check. No hard contradictions were found, but there are minor tensions: the older consumer Terms grant a 'limited, non-exclusive' license while the newer Team Terms grant a broader 'sub-licensable' license over Content, and the documents carry different update dates and slightly different framings of the improvement license. These are reconcilable wording/scope differences rather than direct conflicts.
You've read all 15 risk ratings for Elicit. Create a free account to see the exact policy wording behind each rating.