# Bolt.new

## Kurzbeschreibung
**"Always the best, without switching tools."**


**Bolt **is an AI-powered builder for websites, web apps, and mobile apps. Users describe their project via prompt, and Bolt generates a working project from it in a short time. 


In addition, Bolt bundles Bolt Cloud Hosting, databases, domains, authentication, file storage, analytics, and Edge Functions directly in the interface.

## Claim
Always the best, without switching tools

## Geeignet für
- API Integration
- no Code App
- Programming / Software Development
- SEO / GEO Optimization
- Websites / Landing Pages

## Kernfunktionen
- App Development
- Programming
- Website Creation

## Preismodell
- **free:** Free entry point for building initial projects with limited token/usage scope.
- **subscription:** **Pro / individual plans** More tokens, private projects, website hosting, no Bolt branding, private sharing features, file uploads, custom domains, SEO features, databases, and AI image editing.


**Teams **For teams with collaborative work, higher limits, and team-oriented usage.
- **other:** **Enterprise** Custom offering for organizations with advanced requirements.


**bolt.diy** Official open-source version for local/self-hosted use with your own LLM providers such as OpenAI, Anthropic, Ollama, Gemini, Mistral, xAI, DeepSeek, Bedrock, and others.

## DSGVO und Datenschutz
**Gesamteinschätzung:** Conditional

**On-premises / local hosting: partially**

No classic on-premises solution running on the customer’s own hardware was explicitly found. However, there is a documented Enterprise/BYOK option for deployment in the customer’s own AWS/Azure tenant with full isolation; this is closer to a customer-owned cloud than to an on-premises data center.

**Private Cloud / Data Center: Covered**

The website describes deployment in the customer’s own AWS/Azure tenant with “full infrastructure isolation and no shared compute.” This covers a dedicated private cloud/tenant variant.

**EU SaaS / Managed: Partially**

A managed SaaS/cloud service is clearly available. However, the website does not specify explicit EU/EEA data residency or a requirement for the service to be hosted in an EU data center for this standard service.

**Hybrid: Indirect / Not Available**

An explicit hybrid operating model combining internal/on-premises with external SaaS was not described on the website. While integrations and BYOK deployment are available, there is no clearly documented hybrid offering in the required sense.

**AVV / DPA: unclear**

No AVV/DPA was found on the website. Nor are any specific data processing agreements or Data Processing Agreements linked to or described on the trust/support pages found.

**No Training: Partially**

The Enterprise page states that code and prompts “never leave your tenant” or, in the case of BYOK, “never leave your infrastructure.” A general, contractually enforced “no training” rule or an explicit opt-out for standard SaaS usage was not found on the website.

**Open Source / Transparency Path: Partial**

There is a transparency/sovereignty path via project downloads, GitHub integration, alternative use of custom Supabase projects, and references to open-source components in blog content. However, a clearly documented open-source product base or self-hostable core solution was not found.

**Data Processing**

The pages found describe two main operational models: First, Bolt Cloud as a provider-managed service for hosting, databases, domains, file storage, and edge functions. The website mentions Netlify and Supabase as the underlying platforms, without specifying EU/EEA data residency or exact server locations. Second, an Enterprise/BYOK option, in which deployment occurs within the user’s own AWS/Azure tenant, with full isolation and the assurance that code and prompts do not leave the user’s own infrastructure. For EU/EEA users, the second option is significantly better documented in terms of data protection.

**Conclusion**

For an EU/EEA directory, Bolt.new is not documented as a clearly and fully substantiated standard SaaS offering with EU data residency. **The most viable option is the Enterprise/BYOK model**, particularly if the customer selects an EU/EEA location in AWS or Azure and receives the contractual data protection documents separately during the sales process. Without these additional requirements, the GDPR compliance status for the standard cloud service, as presented on the website, remains too incomplete.

**Sources**

- [https://bolt.new/get-started/](https://bolt.new/get-started/)
- [https://support.bolt.new/cloud/bolt-cloud](https://support.bolt.new/cloud/bolt-cloud)
- [https://support.bolt.new/integrations/supabase](https://support.bolt.new/integrations/supabase)
- [https://support.bolt.new/account-and-subscription/account-management](https://support.bolt.new/account-and-subscription/account-management)
- [https://trust.bolt.new/](https://trust.bolt.new/)

For the EU/EEA region, GDPR-compliant use is plausible *only under certain conditions*. Positive aspects include the enterprise options listed on the website for deployment in a user’s own AWS/Azure tenant with full infrastructure isolation, as well as the statement that code and prompts do not leave the user’s own infrastructure. However, for standard SaaS/Bolt Cloud usage, the website lacks essential, reliable information regarding EU data residency, specific server locations within the EU/EEA, the Data Processing Agreement (DPA), and subprocessors. Therefore, there is no verifiable, fully clear GDPR approval for standard use; the best-documented option is the Enterprise/BYOK variant.

**Positive**

The website mentions **BYOK deployment** or deployment within the user’s own AWS/Azure tenant, **full infrastructure isolation without shared compute**, the statement *“Your code and prompts never leave your infrastructure,”* and SOC 2 information. In addition, the Trust page describes client-side execution as a security feature.

**Negative**

The website does **not** specify **any concrete EU/EEA server locations** for the standard service. Also missing are **a privacy policy**, **an AVV/DPA**, **a list of subprocessors**, an explicit **EU data residency** for Bolt Cloud, and a clear, contractually documented **no-training/opt-out rule** for standard use. The support documentation also mentions external platforms such as Netlify and Supabase as the basis for Bolt Cloud.

**Server Location**

Not specified on the website. For Bolt Cloud, only “secure, high-performance servers” and partner platforms such as Netlify and Supabase are mentioned. A specific EU/EEA data center location or a binding EU data residency requirement is not mentioned on the pages found. For Enterprise, deployment within the customer’s own AWS/Azure tenant is described; the specific location there apparently depends on the customer’s target environment.

## Hosting und Daten
- **On-Prem / lokales Hosting:** teilweise / indirekt
- **Private Cloud / Rechenzentrum:** abgedeckt
- **EU SaaS / Managed:** teilweise / indirekt
- **Hybrid:** unknown
- **AVV / DPA:** unknown
- **Kein Training auf Kundendaten:** teilweise / indirekt
- **Open-Source / Transparenz-Pfad:** teilweise / indirekt

## Standort
**Land:** USA

**Taxonomie:** USA

StackBlitz, Inc., 2443 Fillmore St #380-7122, San Francisco, CA 94115, USA.

## Vorteile
- Very fast path from idea to a working prototype or MVP.
- Integrated cloud features instead of a zoo of tools: hosting, DB, domains, auth, file storage, analytics, edge functions.
- Good integrations for Figma, Expo, GitHub, Stripe, Supabase, and MCP.
- Also suitable for commercial use; according to the official docs, the code generated with Bolt/StackBlitz belongs to the user.
- Private publishing and team/admin features for collaborative workflows.

## Nachteile
- Public privacy/compliance documentation appears thin from an EU perspective; the publicly found StackBlitz Privacy Policy is very old and refers to US hosting/transfers.
- No verified public information is available about a freely accessible AVV/DPA page specifically for Bolt — as of April 27, 2026.
- According to the official documentation, Bolt only supports JavaScript-based backends; PHP or Python are explicitly listed there as incompatible.
- Mobile browsers are not yet fully supported; desktop and Chromium-based browsers are recommended.
- Token consumption increases with project size because a large share of usage comes from reading and synchronizing the project files.

## Quellen
- Offizielle Website: https://bolt.new/

## Letzter Datenstand
2026-04-27

## Originalseite
https://kifox.ai/en/ki-tools/bolt-new-en/
