---
title: "Security and privacy for GDPR-compliant AI | Niki"
description: "Every Niki instance is GDPR-compliant. Every service is hosted in the EU, data is never used for LLM training, and deleted data stays deleted."
canonical: "https://useniki.com/security-and-privacy/"
---

Security and privacy

# Privacy is built into every Niki instance.

Every Niki instance is GDPR-compliant. Every service is hosted in the EU, your data is never used to train LLMs, and deleted data stays deleted.

**The standard for every instance**

These privacy rules are Niki’s baseline, not an optional enterprise configuration.

## Built-in privacy guarantees

Niki protects your data while keeping the work of its AI agents visible and steerable.

### Privacy by default

-   Every service that is part of Niki is hosted in the European Union.
-   Niki data is never used to train LLMs of any kind.
-   When data is deleted in Niki, it stays deleted.

### Visible and steerable

-   Authenticated users, private chats, and shared projects create separate work contexts.
-   Assignments, status, sources, tool activity, and results remain inspectable.
-   Users can stop running work, change the brief, and redirect the next step.

## Deleted means deleted.

When you delete data in Niki, it stays deleted. No Niki data, deleted or active, is used to train LLMs of any kind.

## Use AI without giving up your privacy standards.

See how Niki combines GDPR-compliant EU hosting with visible, steerable agent work.

[Talk to a human](/#enterprise)[Explore GDPR-compliant Niki](/gdpr-ai/)
