Undermind
undermind.aiUndermind is an AI-powered scientific literature search tool whose terms and privacy policy are heavily vendor-favorable and largely silent on AI-specific data handling concerns. The broad, irrevocable, sublicensable license over User Content, a $50 liability cap, mandatory arbitration with class-action waiver, and a privacy policy that predates the AI product (last updated August 2023) and freely reserves rights to share Non-Personal Information with advertisers create meaningful risk. There are no compliance certifications, no stated data retention or deletion SLAs, no security audit attestations, and no enterprise data protection commitments visible in the provided documents — making this unsuitable for professional, enterprise, or regulated-industry use with sensitive or proprietary data without a negotiated contract (e.g., a DPA).
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
The Terms acknowledge that users retain ownership of their User Content (it is excluded from Company IP), but users grant an irrevocable, worldwide, sublicensable license to reproduce, distribute, and prepare derivative works of that content. While nominally limited to 'including your User Content in the Site,' the breadth and irrevocability of the license weakens the user's practical control. Note the policy frames User Content around profiles/postings rather than research prompts, leaving prompt-level ownership somewhat ambiguous.
Output Data Ownership
The Terms expressly permit users to freely share, distribute, and disseminate search results they create, which implies practical user rights to outputs. However, the documents never explicitly assign ownership of AI-generated outputs to the user, and the Company asserts broad IP ownership over the Site and its content, leaving output ownership legally ambiguous.
Training Data Usage
Neither the Terms nor the Privacy Policy clearly addresses whether user inputs, prompts, or research queries are used to train or improve AI models. The broad User Content license ('otherwise use and exploit') combined with the right to use Non-Personal Information without limitation could permit model training, and the policy's silence on this AI-specific issue is itself a significant risk signal.
Data Retention & Deletion
Users can delete their account at any time, and account termination may involve deletion of User Content from live databases, but no retention schedule, deletion SLA, or backup-purge timeline is stated. There are no security-related retention obligations (e.g., HIPAA, SOC 2 audit log retention) addressed, and the Company explicitly disclaims any obligation to back up or preserve content and may delete it at any time without notice.
Third-Party Data Sharing
Personal Information is stated not to be sold, traded, or rented for marketing purposes without consent, and is shared with service vendors and in response to legal requests, which is appropriate and disclosed. However, the policy reserves an unrestricted right to disclose Non-Personal Information to 'partners, advertisers and other third parties' at the Company's discretion, and Personal Information may be transferred in a business sale, which moves this beyond what the core literature-search service requires.
Opt-Out Rights
Users can opt out of marketing communications via unsubscribe links or by emailing the Company, and an arbitration opt-out exists within 30 days. However, there is no mechanism to opt out of Non-Personal Information sharing with advertisers/partners, cookie tracking, or any model-training use, and the policy only promises a future opt-out if information practices change.
Compliance & Certifications
The documents reference no recognized privacy or security compliance frameworks or certifications — no GDPR, CCPA/CPRA, SOC 2, HIPAA, ISO 27001, NIST, or FedRAMP attestations appear. A referenced security one-pager was inaccessible, and only a COPPA-adjacent under-13 provision and a California complaint-unit disclosure are present, which is insufficient evidence of compliance posture.
Model Explainability & Auditability
The documents provide no transparency into model behavior, no explainability commitments, and no enterprise auditing rights. The Terms instead disclaim accuracy entirely and acknowledge that the AI/RAG technology may produce incomplete or inaccurate results, placing all verification burden on the user.
Security Practices & Breach History
The Privacy Policy discloses basic security measures including encryption, firewalls, and SSL/secure socket layer technology, but provides no detail on access controls, penetration testing, bug bounties, or incident response, and explicitly disclaims any guarantee against breach. No breach history is disclosed; a referenced security one-pager PDF was inaccessible, so no trust center or audit attestation could be verified.
Enterprise vs. Consumer Risk Delta
The provided Terms and Privacy Policy apply uniformly and do not describe any differentiated data handling, retention, or protection commitments for paid/enterprise tiers versus the free tier. Although an Enterprise page is linked from the site navigation, no enterprise-specific data terms (e.g., DPA, no-training commitment) are present in the analyzed documents, leaving enterprise buyers without disclosed protections.
Human Review of User Inputs
The Terms reserve the right (without obligation) for the Company to review, refuse, or remove any User Content at its sole discretion, which permits staff access to user submissions for enforcement purposes. The policy does not otherwise clarify whether prompts or outputs are routinely read by staff, leaving the scope of human review ambiguous.
Regulatory & Litigation Exposure
The Privacy Policy states the Company may disclose information to meet legal processes or governmental requests and to address fraud or security concerns, and the Terms impose binding arbitration with class-action and jury-trial waivers governed by Massachusetts law. No active litigation or government data-request history is disclosed, but the dispute-resolution structure substantially limits user remedies.
PII & SPI Data Inventory
The Company collects minimal Personal Information (primarily email address and account credentials) plus technical/usage data (browser, device, referring URL, cookies with anonymous identifiers). No sensitive personal information categories are described as collected, and purpose is reasonably limited to communication and service improvement, though the unrestricted use of Non-Personal Information and silence on what research content users may upload introduces some ambiguity.
You've read all 15 risk ratings for Undermind. Create a free account to see the exact policy wording behind each rating.