Compliance & Security

Researchers trust Kahubi with unpublished work and participant data. Here is exactly how we handle it — in plain language.

A European company, under European law

Kahubi is built and operated by Avidemic AB, a company registered in Sweden and supervised by the Swedish data protection authority (IMY). That means your relationship with us is governed by EU law from end to end: the GDPR applies not as a policy we adopted, but as the law we are incorporated under.

Kahubi runs on servers located in the European Union, and we select subprocessors that are GDPR-compliant and European: AI models run in Ireland and Sweden on EU-owned infrastructure, transcription runs in France and Germany, transactional email in the Netherlands on EU-only infrastructure, and our analytics is self-hosted on our own EU servers. Avidemic builds AI software for research and clinical work, and its products are used at universities, research institutes, and hospitals across Europe, environments where confidentiality and ethics-board scrutiny are the norm, not the exception. We build to that standard for every account.

Never used to train models

Your papers, unpublished manuscripts, datasets, and interview recordings are used exclusively to fulfill your requests. We do not train AI models on your content, and our AI subprocessors are used via API agreements that exclude training on customer data.

GDPR-compliant by design

Kahubi is operated by Avidemic AB, a Swedish company subject to the GDPR. We collect only what the service needs, document our subprocessors below, and act on data-subject requests — access, correction, export, and erasure.

EU processing for transcription

Interview audio and video are transcribed by European providers — Gladia (France) and Lemonfox (Germany, EU endpoint) — so recordings of research participants are processed within the European Union — a hard requirement for many ethics approvals, and a default in Kahubi.

Encrypted credentials at rest

Integration tokens (Zotero, Mendeley, GitHub) are encrypted at rest with application-level encryption and displayed only in masked form after you save them.

Private by default

Everything you put into Kahubi is private to your account unless you explicitly share a project with your team. There are no public profiles, no ads, and we never sell data — the subscription is the business model.

Deletion on request

You can export your library (BibTeX, RIS, CSL-JSON) and your manuscripts (.tex, .docx, PDF) at any time. Request account deletion and we remove your account and associated content from our systems, confirming when it is done.

Subprocessors

We use a small, documented set of GDPR-compliant subprocessors, each limited to a single purpose and bound by a data processing agreement. Your content is shared with them only to the extent required to deliver the feature you are using.

For institutional customers (invoice billing), every subprocessor is a European company processing data in the EU.

ProviderPurposeNotes
AI models
🇪🇺TensorX (Ireland)AI text generation and analysis (chat, writing, statistics interpretation), vision, and semantic search embeddingsEU company on EU-owned infrastructure; API traffic excluded from model training under provider terms
🇪🇺Inceptron (Sweden) / Berget AI (Sweden)Backup AI capacity when the primary provider is unavailable, and optional alternative modelsEuropean companies; processed within the EU/EEA. Same no-training API terms
Transcription
🇪🇺Gladia (France) / Lemonfox (Germany)Speech-to-text transcription of interview audio/video (speaker labels, optional PII redaction) and voice notesEuropean companies; processed in the European Union
Web search
🇪🇺Staan (France)Web search when the assistant searches the web on your request — receives the search query onlyEuropean search index (Qwant/Ecosia joint venture); EU jurisdiction and data centres
BillingOne or the other, never both: institutions are invoiced through Visma, self-serve accounts pay by card through Stripe. Which one applies depends on how you buy.
🇪🇺Visma (Sweden)Invoicing for universities and institutional buyersSwedish provider. Institutional purchases are billed by invoice through Visma; card networks are never involved for institutional buyers
StripePayment processing for credit card purchases (self-serve accounts only; not applicable to institutional buyers)Card details go directly to Stripe (PCI-DSS Level 1) and never touch our servers; we contract with Stripe Payments Europe Ltd (Ireland)
Email
🇪🇺Lettermint (Netherlands)Transactional email (verification, invitations, support replies)European company; EU-only infrastructure. Email metadata only — no research content is sent by email
Analytics
🇪🇺OpenPanel (self-hosted)Product analytics — feature-usage events so we can improve KahubiOpen-source analytics running on our own EU servers — no third party receives usage data. On the public website it runs only with your consent.

Security contact

Found a vulnerability, or need a Data Processing Agreement, subprocessor notifications, or answers for your institution's ethics board? Write to us at team@kahubi.com and we will respond promptly. Please include enough detail for us to reproduce or assess the issue.

Compliance questions answered, work to do

Start on the free plan — your data is handled the same way on every tier.