# Open WebUI

## Kurzbeschreibung
**“The freedom AI stack.”**


**Open WebUI **is a self-hosted AI portal for teams and organizations. The platform connects local or external LLMs with team chat, RAG, document knowledge, tools, MCP, role-based permissions, and integrations.

## Claim
The freedom AI stack.

## Geeignet für
- API Integration
- Automation / Workflows
- Data Extraction / Document Analysis
- Customer Service & Chatbots
- Programming / Software Development
- Research
- Texts / Content
- Knowledge Management / Internal Search

## Kernfunktionen
- API Integration
- Chatbot
- Document analysis
- AI agents
- Research
- Text generation
- Knowledge Base
- Summary

## Preismodell
- **free:** **Community Edition**

Free self-hosted AI portal with chat, RAG, local models, cloud models, tools, and team use.
- **other:** **Enterprise** Custom enterprise support, architecture consulting, scaling, SSO, governance, and professional support.


**Self-hosting** Costs for servers, GPU, storage, databases, backups, and operations.


**External model providers** Usage costs for OpenAI, Anthropic, Azure, Bedrock, or other model providers.


**License notice **Current components are available under multiple licensing models; for larger deployments, branding requirements of the current Open-WebUI license apply.

## DSGVO und Datenschutz
**Gesamteinschätzung:** Yes

**On-Prem / local hosting: covered**

Clearly described on the website: Open WebUI can be operated 'on-premise' and self-hosted; the enterprise documentation also mentions air-gapped deployments and own data centers.

**Private cloud / data center: covered**

Explicitly described: deployment in your own cloud tenancy on AWS, Azure, or GCP with full infrastructure control.

**EU SaaS / managed: indirect / not available**

The website does not document an EU SaaS/managed service operated by the provider itself with EU data residency or an EU data center.

**Hybrid: covered**

Hybrid is explicitly named as a deployment model in the enterprise security documentation.

**DPA / data processing agreement: unclear**

A DPA/data processing agreement is not specified on the website.

**No training: partial**

The documentation demonstrates local data storage and self-control over the infrastructure, but does not mention any explicit contractual commitment that prompts, uploads, or outputs will not be used to train general models. For self-hosting, this risk can be technically limited; for externally configured model providers, it remains dependent on their settings.

**Open-source / transparency path: covered**

The website describes a publicly auditable codebase and Open WebUI as self-hostable software; this creates a clear path for transparency and sovereignty.

**Data processing**

The documentation describes Open WebUI as a self-hosted application. Data remains in your own infrastructure by default, unless external model providers are configured. Private cloud, on-premise, air-gapped, and hybrid are documented. According to the website, memories are stored locally in the Open WebUI database. For EU/EEA users, this means: data processing can be organized within their own EU/EEA infrastructure; an EU SaaS operated by the provider itself with a named data center is not specified on the website.

**Conclusion**

For a European tool directory, Open WebUI is particularly strong from a GDPR perspective via self-hosting, on-premise, or private cloud. The best available path is clear: operation in your own EU/EEA infrastructure with local or controlled model integrations. Therefore, overall 'yes'. However, for an evaluation of provider SaaS, DPA, subprocessors, or certifications, the website remains incomplete or without concrete details.

**Sources**

- [https://docs.openwebui.com/enterprise/](https://docs.openwebui.com/enterprise/)
- [https://docs.openwebui.com/enterprise/security/](https://docs.openwebui.com/enterprise/security/)
- [https://docs.openwebui.com/getting-started/advanced-topics/hardening/](https://docs.openwebui.com/getting-started/advanced-topics/hardening/)
- [https://docs.openwebui.com/features/chat-conversations/memory/](https://docs.openwebui.com/features/chat-conversations/memory/)
- [https://docs.openwebui.com/getting-started/sharing/](https://docs.openwebui.com/getting-started/sharing/)
- [https://docs.openwebui.com/security/](https://docs.openwebui.com/security/)

Open WebUI documents on its own website a clear self-hosting/on-premise path, including private cloud, air-gapped, and hybrid operation. For users in the EU/EEA, this provides a straightforward path to GDPR-compliant use, because according to the documentation, data processing can take place within their own infrastructure and the operator determines where data is physically located. At the same time, the website also makes it clear that compliance responsibility lies with the deploying company; a blanket GDPR commitment for a provider SaaS is not evident on the website.

**Positive**

Positively documented are self-hosting, on-premise, private cloud, air-gapped and hybrid deployment, as well as control over data residency. The website explicitly states that data remains in the organization's own infrastructure by default, provided no external model providers are configured, and that organizations themselves can determine where data is physically stored. In addition, a publicly auditable codebase is described.

**Negative**

Negative or limiting is that the website does not appear to provide its own privacy policy, no AVV/DPA, no subprocessor list, no specific EU data center indication for a provider-operated service, and no contractual statement excluding model training. The documentation also emphasizes that compliance certifications and regulatory obligations for the specific deployment lie with the operating organization.

**Server location**

No specific provider server location is stated on the website. Instead, the documentation for self-hosting and private cloud describes that the operator chooses the physical storage location of the data and that the data remains in the organization's own infrastructure by default. EU/EEA data residency is therefore possible via own deployment, but no provider-designated EU data center is stated on the website.

## Hosting und Daten
- **On-Prem / lokales Hosting:** abgedeckt
- **Private Cloud / Rechenzentrum:** abgedeckt
- **EU SaaS / Managed:** unknown
- **Hybrid:** abgedeckt
- **AVV / DPA:** unknown
- **Kein Training auf Kundendaten:** teilweise / indirekt
- **Open-Source / Transparenz-Pfad:** abgedeckt

## Standort
**Land:** USA

**Taxonomie:** USA

Open WebUI, Inc., 2261 Market St, #22911, San Francisco, CA 94114, USA.

## Vorteile
- Very good self-hosting and local LLM fit
- Data remains on your own server by default
- RAG, team chat, knowledge, and tools
- Support for local and cloud models
- Role permissions, SSO, LDAP/OIDC, and SCIM
- Free community use on your own infrastructure

## Nachteile
- Operation, updates, security, and backups are the responsibility of the operator
- External LLMs or web tools can transfer data out of the local environment
- No fully managed enterprise SaaS operation by the manufacturer is publicly documented
- Check licensing and branding rules for commercial resale

## Quellen
- Offizielle Website: https://docs.openwebui.com/

## Letzter Datenstand
2026-06-29

## Originalseite
https://kifox.ai/en/ki-tools/open-webui-en/
