Find Your Tool in 6 Steps
Result: 144

KIFOX - The Search Portal for AI Applications ?

Which AI tool is GDPR-compliant? Compare features, hosting, and data protection with real user reviews and an editorial score. Compare for free now.

Here, users can get an overview of which AI tools and LLMs are currently available on the market. Every user is free to submit a review and share their experience with AI applications, and can click a link to go directly to the provider’s website.

KIFOX is not an online store, but a comparison and information portal for AI applications.

Results: 144

“Less structure, more intelligence.”

Manus is an autonomous AI agent that not only responds, but also plans tasks, executes them, and delivers finished work results.

Officially, Manus describes itself as a “virtual colleague with its own computer” with a sandbox, internet access, a persistent file system, and the ability to install software, operate websites, analyze data, create slides, and run workflows. The product covers a web app, website builder, browser automation, email/Slack integration, data sources, and API.
Manus

Less structure, more intelligence

6.4/10 Solid

Automation, Data Analysis, AI Agents, Programming, Research, Website Creation

Free Free includes, according to the official pricing article, Chat Mode plus Manus 1.6 Lite in Agent Mode, 300 Daily Refresh Credits, 1 Concurrent Task, and 2 Scheduled Tasks.

Additionally, the Help Center states: daily free credits must be claimed, are valid only for that day, and Free users have a monthly Daily Credit usage limit of 1,500 credits.
Subscription Pro 20 USD/month: from 4,000 credits/month, Chat Mode, Manus 1.6 Max/1.6/1.6 Lite in Agent Mode, Advanced Research, Professional Website Deployment, Slide Generation, Wide Research, 20 Concurrent Tasks, 20 Scheduled Tasks, beta features; 17% discount with annual billing.

Pro 40 USD/month: from 8,000 credits/month, same feature class, according to the Help Center with a 7-day trial; also 17% annual discount. Team from 20 USD/seat/month: includes Pro features plus SSO, Data Training Opt-Out, Team Usage Analytics, Internal Access Control, Shared Slide Templates.
Other Credit add-ons are officially available; according to the docs, they can be purchased additionally and “never expire,” but according to the Help Center they can only be used with an active paid plan and become inactive on a free/expired subscription. WebDev/Website Builder has a separate usage-based pricing model; according to the docs, each Manus account tier includes free monthly allowances of Cloud $10, AI $1, API $1. The API is officially available, but I could not verify a reliable public API pricing sheet in the accessible official sources.
Location: Singapore Butterfly Effect Pte. Ltd. 109 North Bridge Road, #06-W112, Funan Singapore 179097
GDPR: Unclear For the EU/EEA region, a privacy policy and a security page containing specific compliance and security information can be found on the website. However, the website lacks clear information regarding EU/EEA data residency, specific server/data center locations, a publicly accessible data processing agreement (DPA), and a list of subprocessors. Consequently, it is not possible to make a reliable assessment of GDPR compliance for the entire European region based solely on the website.
Positive
The following can be found: a privacy policy, a security page with information on SOC 2 Type 1, SOC 2 Type 2, ISO 27001:2022, and ISO 27701:2019, as well as a note stating that customer data is deleted upon leaving the service. There is also a statement indicating that only aggregated or anonymized information is used to improve the services.
Negative
On the negative side, the website does not specify any concrete EU/EEA server locations, does not guarantee EU data residency, no publicly available DPA is mentioned, no list of subprocessors can be found, and no on-premises or self-hosting option for Manus itself is described. Furthermore, an explicit contractual opt-out from general AI training is not clearly stated on the website.
Server Location
Not specified on the website. Although cloud infrastructure, cloud browser, and hosting are mentioned, no specific countries, regions, or data centers within the EU/EEA are named.
(0)

Link

Link

"AI editing for every kind of video."

Descript is an AI-powered audio and video editor that lets you record, transcribe, edit, and publish content.

A key feature is text-based editing: video and audio editing works similarly to editing a document. Added to that are features like Underlord as an AI co-editor, screen recording, remote recording, AI voices, automatic clips, subtitles, and translation/dubbing.
Description

AI editing for every kind of video

7.1/10 Good

Audio Cleanup, Podcast Production, Text-to-Speech, Voice Cloning, Transcription, Subtitling, Video Editing

Free Free entry for recording, transcription, text-based editing, and limited AI/media usage. Subscription Hobbyist For individuals; watermark-free projects, more media time, and basic AI features.

Creator For active creators and small teams; more media time, more AI credits, and advanced creative AI features.

Business For teams; more media time, more AI credits, Brand Studio, team features, translation/dubbing, and collaboration.
Other Enterprise Custom offer with SSO, SCIM, centralized administration, dedicated Customer Success, security documentation, and Enterprise support.

AI Credits / Media Hours Usage is based on media time and AI credits depending on the plan; additional Enterprise and Team quotas are possible.
Location: USA Descript, Inc., 385 Grove St., San Francisco, CA 94102, USA
GDPR: Partly Descript provides several pieces of data protection and security information relevant to the EU/EEA region on its website, including a privacy policy outlining EEA rights, a list of subprocessors, information on data encryption, a DPO contact, and statements regarding AI training and opt-out options. At the same time, the website does not specify EU/EEA data residency or EU servers as mandatory options for standard SaaS use; rather, it states that Descript is based in the United States and processes and stores information in the United States. Thus, GDPR-compliant use from an EU/EEA perspective is not generally guaranteed, but is subject to conditions such as careful contract review, third-country transfer assessments, and internal risk assessments.
Positive
Positive aspects include the existing privacy policy, the explicit address to users in the EEA, the designated contact address of the Data Protection Officer, the published list of subprocessors, the statement regarding SOC 2 Type II compliance, the reference to DPAs with third-party providers, and an opt-out option for data sharing for internal AI training purposes. Additionally, Descript describes encryption at rest and in transit.
Negative
From an EU/EEA perspective, it is a negative that the website does not list any EU data residency, any EU/EEA data center, or any on-premises/self-hosting option. The privacy policy states that Descript is based in the U.S. and processes and stores information in the U.S. The subprocessors page lists locations primarily in the U.S. For AI Speakers, the privacy policy also reserves the right to use associated training data for research and development purposes; a general contractual exclusion for any form of training is not comprehensively documented on the website.
Server Location
The website does not specify an EU/EEA server location for customer data in a binding manner. The Security page lists Amazon S3 or Google Cloud as storage locations without guaranteeing an EU region. The privacy policy explicitly states that Descript is based in the U.S. and processes and stores information in the U.S.
(0)

Link

Link

“Chat with any PDF using AI: ask questions, get summaries, and find answers.”

PDF.ai is an AI tool for chatting with PDF documents.

Users can ask questions about PDFs, generate summaries, find content, and extract data; in addition, the provider offers an API for Parse, Extract, Split, and Ask for document-driven workflows. The product is positioned as a web app, Chrome extension, and API.
PDF.ai

Chat with any PDF using AI: ask questions, get summaries, and find answers

3.9/10 Insufficient

Document Analysis, Research, Summarization

Free Free start or demo/trial use for uploading and chatting with PDFs; exact limits should be checked on the live pricing page. Subscription Starter Monthly credit quota for PDF.ai usage and API/document workflows.

Pro Higher credit quota for more intensive PDF analysis and document processing.

Scale Significantly higher credit quota for teams or larger document volumes.

Growth Very high credit quota for extensive workflows.
Other API API for parsing, extracting, splitting, and processing PDFs in your own workflows.

Credits Usage-based billing via monthly credits per plan.
Location: USA Public company/founder profiles and business directories place PDF.ai in San Jose, California, but the official website does not clearly state the country of origin.
GDPR: Unclear GDPR assessment: From a GDPR perspective, PDF.ai is unclear to conditionally suitable.

Positive is that PDF.ai has published a Privacy Policy and clearly positions the tool as a PDF chat and PDF API platform. It is also positive that the main page describes chat with PDFs, summaries, questions, answers, as well as API functions for parsing, extracting, and splitting PDFs.

Negative is that I could not publicly find a reliable AVV/DPA, no list of subprocessors, no SCC documentation, no clear no-training statement for uploaded documents, and no guaranteed EU data residency. This is especially critical for PDFs containing contracts, customer data, personnel records, financial data, or medical information.

Server location: No verified information available. Further link: PDF.ai Privacy Policy, Website, and Pricing.

Privacy Policy
(0)

Link

Link

“Build something Lovable”

Lovable is an AI-powered app and website builder that enables users to create, iterate on, and publish apps, websites, prototypes, and digital products via chat. The platform combines prompting, visual editing, code mode, GitHub sync, hosting/deployment, as well as backend options via Lovable Cloud or Supabase.
Lovable

Create apps and websites by chatting with AI

8.0/10 Very good

App Development, Programming, Website Development

Free Free entry-level version with daily credits, a monthly credit cap, subdomains, and collaboration capability; suitable for trying out and for simple projects. Subscription Pro Paid individual/creator plan with more monthly credits and more room for serious app projects. Credits are consumed for AI prompts in Plan Mode and Agent Mode.

Business Team-oriented plan with team features, advanced controls, and DPA usage; suitable for professional use in organizations.
Other Enterprise Custom Enterprise offering with advanced security, governance, support, and data control requirements.

Credits / Cloud Credits Lovable uses Credits for AI agent prompts; cloud infrastructure such as database, functions, and storage uses separate Cloud Credits.
Location: Sweden Sweden / USA, depending on the perspective. Lovable officially describes itself as a Stockholm-based company; the contractual partner in the DPA is Lovable Labs Incorporated, registered in Dover, Delaware, USA. Lovable Labs Incorporated, 1111b South Governors Avenue, Dover, DE 19904, USA according to the DPA. In addition, LOVABLE LABS UK LTD exists, Registered office: Lovable, Second Home, 68 Hanbury Street, London, England, E1 5JL
GDPR: Partly For the EU/EEA region, there are several clearly positive indicators on the website: Lovable provides a Terms of Service (TOS) and Privacy Policy (DPA), explicitly references the EU GDPR and UK GDPR, lists Standard Contractual Clauses (SCCs) for transfers to third countries, offers regional data storage within the EU according to its Security page, and documents an opt-out process for AI training. At the same time, GDPR-compliant use is not automatically clear in every standard configuration: The website states that customer data may be used for model improvement by default, as long as no opt-out has been set or requested; furthermore, international transfers and the use of subprocessors remain relevant. Therefore, based on the information on the website, GDPR-compliant use within the EU/EEA is possible, but only under certain conditions and with proper configuration.
Positive
The following have been confirmed: Data Processing Agreements (DPAs) for Business and Enterprise customers; explicit reference to the EU GDPR, UK GDPR, and Standard Contractual Clauses (SCCs); EU data residency in Lovable Cloud with regional data storage in the EU, the U.S., and Australia; documented subprocessor management; certifications or evidence of compliance with ISO 27001:2022 and SOC 2 Type II; and a documented opt-out for training-related data use.
Negative
A limitation is that the website also states that customer data may be used for model training or model improvement unless an opt-out is in effect. The simple, contractually clear process is documented primarily for Business/Enterprise plans; for Free/Pro plans, the documentation states that an opt-out is only available via a support request. Additionally, international data transfers are not excluded but are safeguarded through SCCs and other mechanisms. Fully local operation of the entire Lovable platform on the customer’s own infrastructure is not described on the website as a native product model.
Server Location
The website states that Lovable Cloud offers “regional data hosting in the EU, US, and Australia”; customer data is intended to remain in the selected region. Specific EU country or data center locations are not specified on the pages found.
(0)

Link

Link

"Stable Diffusion is a deep learning model used for converting text to images" / "Use Stable Diffusion online for free"

stablediffusionweb.com is a web interface for using Stable Diffusion models, especially Stable Diffusion XL. It offers text-to-image, a prompt database, upscaling, partly video/advanced models, and a credit-based pricing model.
Stable Diffusion

Stable Diffusion is a deep learning model used for converting text to images

3.5/10 Insufficient

Image Editing, Image Generation, Illustrations, Open Source Model

Free Free use with a daily credit quota, a limited number of images per generation, without ads/watermarks according to the pricing page; commercial license and private images/videos are not included. Subscription Pro Monthly credit allowance, more images per generation, no ads, no watermark, upscaling, advanced image and video models, commercial license, and private images/videos.

Max Higher monthly credit allowance, Pro features, advanced models, commercial license, and private images/videos.
Other Credit/Usage Logic Usage is based on credits; specific consumption values depend on the function.

Contradictory Contract Presentation Pricing describes monthly/annual plans, while the Terms simultaneously refer to a software license without recurring fees; the pricing/contract logic should be reviewed before purchase.
Location: Germany The project was initiated by researchers at Ludwig Maximilian University of Munich (LMU) (formerly Heidelberg).
GDPR: Unclear Overall assessment: Unclear to critical in terms of GDPR suitability.

Positive is that stablediffusionweb.com states on its homepage that it does not collect personal information and does not store text or image data; the Privacy Policy also states that personal data is only collected when necessary and only stored for as long as required for the service.

Negative is: The privacy notices are very general, not specifically formulated for GDPR compliance, and do not mention a clear EU representative, a data protection officer, a list of subprocessors, a DPA/AVV, SCCs, or a specific server location. In addition, the information appears contradictory: the homepage claims not to store personal data or texts/images, while the Privacy Policy mentions Google login data and necessary personal data.

Server location: No verified information available.

Conclusion: Acceptable for private experiments with non-sensitive prompts; not recommended for personal images, customer data, confidential content, or GDPR-relevant business use as long as no reliable data protection and contractual documentation is available. Sources: Stable Diffusion Web homepage, Privacy Policy, Terms, Pricing.

Private Policy
(0)

Link

Link

"Free Online AI Photo Editor, Image Generator & Design Tool"

Pixlr is a browser-based photo editor, design, and AI image editing service. The platform offers Pixlr Editor, Pixlr Express, Pixlr Designer, Remove Background, Batch Editor, AI Image Generator, Super Scale, Templates, and mobile apps.
Pixlr

Free Online AI Photo Editor, Image Generator & Design Tool

6.0/10 Solid

Image editing, Image generation, Graphic Design

Free Free access to Pixlr’s basic features; usable for many simple edits, but with limitations on premium and AI features. Subscription Plus Ad-free use, unlimited saving, and monthly AI credits for basic usage.

Premium Full access to premium features across platforms, significantly more AI credits, Private Mode for AI generations, as well as a larger library of fonts, templates, elements, animations, and other assets.

Team The team plan is listed in the pricing data structure; the specific included features must currently be checked on the pricing page or with the provider.
Other AI Credit Pack Additional AI credits for generative tools; according to the Pricing FAQ, Credit Packs do not expire and are counted separately from subscription credits.

Enterprise Custom solution for more seats or custom API solutions; details available upon request.

Pixlr for Education Free PixlrEdu upgrades for schools and universities worldwide.
Location: Singapore Pixlr Pte Ltd, 30 Cecil Street, #19-08 Prudential Tower, Singapore 049712, Singapore.
GDPR: Partly Overall assessment: Conditionally GDPR-suitable.

Positive is that Pixlr provides a Privacy Policy with GDPR legal bases, data subject rights, an EU representative in Hamburg, a UK representative, and a privacy contact. For FaceFlip/AI Face Swap, according to the Privacy Policy, Pixlr processes images with facial geometry only to create the output and states that it does not store, collect, or use facial data for other purposes. For Google Workspace APIs, Pixlr confirms that it does not use data obtained from them to develop, improve, or train general AI/ML models.

Negative is: Pixlr Pte. Ltd. is based in Singapore; personal data may be transferred outside the EEA to Pixlr group companies or third-party processors, whereby Pixlr refers to appropriate safeguards such as Binding Corporate Rules or EU Standard Contractual Clauses. In addition, the AI Generator Terms contain a very broad license: users grant Pixlr a worldwide, perpetual, irrevocable, royalty-free, and sublicensable license to use input and output.

Server location: no specific hosting region publicly confirmed. A public AVV/DPA or complete subprocessor list could not be clearly found: No verified information available.

Conclusion: Well suited for general image editing; for confidential company images, personal photos, and biometric-adjacent AI functions, only after a data protection review and with a clear internal usage policy. Sources: Pixlr Privacy Policy, AI Generator License, Pricing.

PRIVACY POLICY
(0)

Link

Link

"AI-Powered Professional Document Translation Tool"

Doclingo is an AI tool for translating PDF, Office, and scanned documents, with a focus on preserving layout, OCR, bilingual output, and post-editing.

Supported formats include PDF, Word, PPT, Excel, images, and others; there are also features such as a glossary, online editing, document chat, highlight-to-translate, and API integration.
Doclingo

AI-Powered Professional Document Translation Tool

3.6/10 Insufficient

Document Analysis, Text Recognition, Translation

Free On the pricing page, visitors and registered users are listed as usage tiers; included are document-related translation features with restrictions. Specific limits are not always displayed cleanly on the rendered page. Subscription Premium Includes extended premium benefits such as more download/translation usage, batch upload, history, engine selection, online editing, document conversation, glossary, image translation, OCR, premium customer service, watermark removal, PDF tool usage, and AI proofreading.

Premium+ Extended premium tier with higher limits/additional benefits compared to Premium; the page mentions Premium+ and additional booster/discount benefits, but some limit values are publicly displayed as “undefined.”
Other Booster Package / Character Pack as a one-time, non-auto-renewing model; according to the Help Center, usable with the same premium benefits and no time limit. For API usage, character-based quotas apply; if the quota is exhausted, you can buy Booster Packages or upgrade to higher memberships. For larger volumes, a Bulk Purchase / Discount Quote is offered via Sales contact. According to the official help, payments are processed via PayPal and Stripe; invoices are issued through Stripe.
Location: USA Place of founding: Pittsburgh, Pennsylvania, USA.
GDPR: No The documentation available on the website does not demonstrate GDPR-compliant use for the EU/EEA region. On a positive note, according to the privacy policy, uploaded translation content is to be used solely for the translation function and, once the process is complete, should be deleted or anonymized whenever possible. However, several factors indicate that the service is not robustly compliant with the GDPR: According to the website, data is generally stored in China; EU/EEA data residency is not specified; a Data Processing Agreement (DPA) is not listed on the website; subprocessors are not transparently documented in a complete list; and the governing law and jurisdiction in the privacy policy refer to the People’s Republic of China.
Positive
A privacy policy is available on the website. It states that translation content is processed solely for the purpose of providing the translation feature and should be deleted or anonymized as soon as possible after the translation is complete. Additionally, the website lists SOC II compliance as a positive aspect.
Negative
The website does not mention EU/EEA hosting. Instead, it states that personal data is generally stored within the People’s Republic of China. A Data Processing Agreement (DPA) is not provided on the website. A complete list of subprocessors is not provided on the website. EU data residency, on-premises hosting, self-hosting, and an explicit opt-out from AI training are not mentioned on the website. The privacy policy is governed by the laws of the People’s Republic of China and designates Wuhan as the competent jurisdiction.
Server Location
According to the privacy policy, personal data is generally stored within the People’s Republic of China. If cross-border transfers occur—for example, in the case of international cloud services—the provider states that it will implement protective measures. No specific server or data center location in the EU/EEA is listed on the website.
(0)

Link

Link

Location: Austria Officially according to the legal notice: AI Newsrooms Technology GmbH, Schönbrunner Straße 231, 1120 Vienna, Austria.
GDPR: Yes The provider's website documents several key points for GDPR-compliant use within the EU/EEA: The service is presented as 'fully GDPR-compliant', hosting takes place exclusively on European servers, there is an 'EU-only processing option' for model processing, according to the website customer data is not used to train external models, and tiered security models are offered up to and including an on-premise solution. For the assessment, the best usage path documented on the website was taken into account, not just the standard SaaS variant.
Positive
Positively documented are EU hosting, storage exclusively on European servers, an EU-only processing option for inference, a documented exclusion of training external models with customer data, ISO/IEC 27001:2022 certification, as well as an on-premise option. From an EU/EEA perspective, these points clearly support a well-usable data-sovereign operating model.
Negative
No specific countries or data center locations within the EU/EEA were stated on the publicly accessible website. Likewise, no publicly viewable details on subprocessors were found on the website. A DPA/AVV is mentioned in the terms and conditions, but the specific DPA page or its content was not directly viewable via the search results.
Server location
The website states that newsrooms.ai is hosted 'exclusively on European servers' and that data does not leave the EU. Specific countries, cities, or data centers are not specified on the website.
(0)

Link

Link

"Your medical AI assistant."

Tandem is an AI-powered medical assistant for doctors, therapists, nurses, and healthcare facilities.

The tool supports the preparation, documentation, and follow-up of treatment appointments, creates medical notes and documents in seconds, suggests suitable diagnosis and procedure codes, and allows editing via voice input. According to the website, Tandem supports over 50 specialties and integrations with more than 100 medical systems.
Tandem Health

Your medical AI assistant

8.0/10 Very good

Medical documentation, Transcription, Summary

Free For clinicians who want to integrate Tandem into their workflow without commitment; includes unlimited note generation, limited custom templates, inviting up to two colleagues, and limited daily Pro Actions. Subscription Pro – unlimited note and document generation, unlimited Pro Actions and personalization, 1-click transfer to 100+ medical systems, unlimited templates, clinician-led support.

Enterprise – everything in Pro plus custom integrations, onboarding/training/rollout, prioritized support, enterprise authentication, and detailed usage reports.
Other Enterprise For larger practices and care organizations; includes everything in Pro plus custom EHR integrations, full onboarding, training & rollout, priority support, enterprise authentication, and detailed usage reports.

Custom Integrations Custom integrations into medical record systems if a system is not yet supported.
Location: Sweden Tandem Health AB: Malmskillnadsgatan 44A, 111 57 Stockholm, Sweden. German legal notice / local company: Tandem Health Global GmbH, P6, 26, 68161 Mannheim.
GDPR: Yes GDPR assessment: From a GDPR perspective, Tandem Health is well to very well suited for European healthcare contexts.

Positive is that Tandem Health AB is based in Stockholm, Sweden, and the Privacy Policy explicitly addresses GDPR, Art. 13/14 information, roles as controller/processor, and the processing of special categories of data such as health data. When the platform is used by clinics or practices, Tandem acts as a processor and processes patient data on documented instructions under a DPA. Also positive are ISO 27001, ISO 13485, NEN 7510, NHS/Cyber Essentials Plus references, CE/MDR context, EU data hosting, no storage of audio recordings, and no training on patient or personal data.

Negative is that each institution must still review its own legal basis, patient information, consent/objection processes, EHR integration, retention periods, and clinical responsibility.

Server location: According to Tandem, patient data is processed and stored exclusively in European data centers.

Privacy policy
(0)

Link

Link

"The music you've been searching for, generated in seconds."

Mubert is an AI music tool for generating, licensing, and integrating royalty-free music. Publicly visible offerings include Mubert Render for creators, Mubert API for apps, games, AI agents, and content platforms, as well as Mubert Studio for musicians who contribute material.

The focus is less on classic song releases and more on legally compliant background music for videos, streams, podcasts, apps, and UGC workflows.
Mubert

The music you've been searching for, generated in seconds

3.8/10 Insufficient

Hintergrundmusik, Musikgenerierung, Sound Effects

Free Free entry point for generating initial tracks; suitable for testing and for simple/private use with limitations. Subscription Subscription model for recurring use of Mubert Render, royalty-free Music Catalog, and generated tracks; exact plan names/features may vary by region/site. Other Perpetual License One-time licensing of individual tracks or permanent use according to the license terms.

Mubert API API access for products, apps, and platforms with generative music; Mubert mentions plannable generation tiers and custom terms/limits via Sales.

Mubert Business / Streamers / Play Special usage options for public spaces, streaming, business contexts, and background music.
Location: USA Mubert Inc., 8 The Green, Suite #6542, Dover, DE 19901, USA. ⚠️ Other official pages additionally list 908 Broadway, SF, CA 94133
GDPR: Unclear The website includes a privacy policy that describes fundamental data subject rights, such as the right to access and the right to erasure. However, for a robust assessment of GDPR compliance within the EU/EEA, the website lacks essential evidence, particularly regarding EU data residency, server locations/data centers, data processing agreements (DPAs), subprocessors, international data transfer mechanisms, and a clear prohibition on the use of customer data for model training. Therefore, compliance across the entire European region cannot be reliably demonstrated based on the website alone.
Positive
A privacy policy is available on the website; there, Mubert lists data subjects’ rights, such as the right to export stored personal data and the right to erasure. Furthermore, Mubert is clearly identified as a U.S. company, and there are product-specific privacy policy notices.
Negative
The website does not specify a Data Processing Agreement (DPA) for business customers, a list of subprocessors, EU/EEA data residency, specific server or data center locations, Standard Contractual Clauses (SCCs) or transfer details for EU data transfers, on-premises/self-hosting options, open-source components, a clear opt-out from AI training using user inputs or uploads, or relevant certifications such as ISO 27001 or SOC 2.
Server Location
Not specified on the website. The privacy policy lists Mubert Inc. as a company based in the U.S., but does not specify any specific server or data center locations within or outside the EU/EEA.
(0)

Link

Link

Location: Switzerland Proton AG, Route de la Galaise 32, 1228 Plan-les-Ouates, Geneva, Switzerland
GDPR: Partly The website highlights several strong data protection and compliance measures for Lumo in the EU/EEA context: Proton explicitly states that it is “GDPR compliant,” designates an EU representative in Luxembourg, provides a privacy policy for Lumo, offers a general DPA/T&C for Proton services, and outlines a clear “no logs,” “no sharing,” and “no training” approach for Lumo. At the same time, a significant gap remains for a comprehensive assessment of the best possible EU/EEA setup: The website does not specify a concrete location of servers or data centers for Lumo within the EU/EEA or an explicit EU data residency for Lumo. An on-premises or self-hosting option is also not mentioned on the website. Therefore, while GDPR-compliant use from an EU/EEA perspective is plausible, it is not fully substantiated and is only reliable under certain conditions.
Positive
Positive aspects include Lumo’s product-specific privacy policy, the general Proton DPA/AVV, the explicit statement regarding GDPR compliance, the EU representative in Luxembourg, the statements “no logs,” “no training,” “never send your data to any third parties,” Proton’s control over the servers, and the open-source note regarding the code and models used.
Negative
On the negative side, or rather as a limitation, the Lumo website does not specify a concrete EU/EEA server location, does not explicitly state EU data residency, does not offer a dedicated private cloud option, and does not provide an on-premises or self-hosting option. Furthermore, Lumo’s privacy policy mentions only “selected partner APIs” for enabled web search, without naming them on the resulting Lumo page.
Server Location
The website states that Lumo’s models run “exclusively on servers Proton controls” and that Lumo is “built and based in Europe.” The website does not specify a specific location for the servers or data centers, nor does it name a particular EU or EEA country. Proton AG is based in Geneva, Switzerland; in addition, an EU representative in Luxembourg is listed.
(0)

Link

Link

Chat with Grok — the truth-seeking AI chatbot

Grok is a generative AI assistant from xAI, available on grok.com, iOS, Android, and on X.

It supports text and voice chat, coding and reasoning tasks, image/video generation, as well as document analysis. In addition, Grok can search the web and public X content in real time to provide more up-to-date answers.
Grok

Chat with Grok — the truth-seeking AI chatbot

3.4/10 Insufficient

Image Generation, Chatbot, Data Analysis, Function Calling, Multimodal AI, Programming, Reasoning Model, Research, Voice Assistant, Language Model, Text Generation, Summarization

Free xAI has officially rolled out Grok 4.1 to all users on grok.com, X, iOS, and Android. The consumer FAQs describe, among other things, text/voice interaction, photo uploads/editing, and document analysis, but exact free limits are not publicly specified numerically. Subscription X Premium: from USD 8/month or USD 84/year on web; according to X, includes increased usage limits on Grok. X Premium+: from USD 40/month or USD 395/year on web; includes higher limits on Grok.

SuperGrok: officially exists; confirmed on grok.com and in xAI/X sources, but no reliably extractable public price figure is verifiable in the official sources accessible here – as of 16.04.2026.

SuperGrok Heavy: officially exists; provides access to Grok Heavy; likewise without a reliably extractable official price figure here.

Grok Business / Grok Enterprise: officially available; team workspace, secure sharing, enterprise privacy, and for Enterprise also custom retention; specific public standard prices could not be reliably verified in the accessible official sources.
Other API / token-based: e.g. grok-4.20-reasoning at 2.00 USD / 1 million input tokens and 6.00 USD / 1 million output tokens; grok-4-1-fast-reasoning at 0.20 / 0.50 USD. According to the xAI Docs, server-side tools cost, among other things, Web Search 5 USD / 1,000 calls, X Search 5 USD / 1,000 calls, Code Execution 5 USD / 1,000 calls, Collections Search 2.50 USD / 1,000 calls; in addition, there are storage costs. X Premium Business: Basic 200 USD/month or 2,000 USD/year; Full Access 1,000 USD/month or 10,000 USD/year plus affiliate fees; includes Premium+ benefits and explicitly mentions SuperGrok. X Premium Organizations: Full Access 1,000 USD/month or 10,000 USD/year plus affiliate fees; includes Premium+ benefits including access to SuperGrok.
Location: USA X.AI LLC; referred to in the Consumer Terms as “a Nevada company.” Official mailing/notice address in the Enterprise Terms: 1450 Page Mill Rd., Palo Alto, CA 94304, USA.
GDPR: Unclear The Grok website includes a link to a privacy policy, but I was unable to find any reliable information on the website regarding key points essential for a sound GDPR assessment within the EU/EEA, such as server location/data centers, EU data residency, data processing agreements (DPAs), subprocessors, certifications, and on-premises/self-hosting, I was unable to find any reliable information on the website. Consequently, based on the website documentation alone, it is not possible to reliably verify that the service is usable in compliance with the GDPR within the European region.
Positive
On the positive side, grok.com provides direct links to a privacy policy and a cookie policy, and the website displays a privacy consent section for cookies.
Negative
On the negative side, no reliable information was found on the website regarding EU/EEA data residency, specific data center locations, the Data Processing Agreement (DPA), subprocessors, the option to opt out of AI training, open-source components, or relevant certifications. The documentation is therefore too incomplete for an EU/EEA assessment.
Server Location
Not specified on the website.
(0)

Link

Link

Inspiring AGI to Benefit Humanity - free AI chatbot & agent powered by GLM

Zhipu AI is a Chinese large language model provider that operates internationally under the name Z.ai. At its core is the GLM model family for text, reasoning, agents, coding, vision, OCR, image, video, and audio capabilities. The platform offers API access, coding plans, web search, Translation Agent, and Slide/Poster Agent.
Zhipu AI / Z.ai – GLM

LLM "Inspiring AGI to Benefit Humanity - free AI chatbot & agent powered by GLM"

6.7/10 Solid

Function Calling, AI Agents, LLM API, Multimodal AI, Open Source Model, Programming, Reasoning Model, Language Model, Text Generation

Free GLM-4.5-Flash / free quotas
Z.AI describes GLM-4.5-Flash as a free model variant for reasoning, coding, and agents; in addition, free trial quotas may be available depending on the platform status.
Subscription GLM Coding Plan
Personally assigned coding subscription for officially supported coding tools; not intended for general API use, resale, or use by third parties.
Other API Usage / Usage-Based Billing API access to GLM models, SDKs, OpenAI-compatible usage, streaming, function calling, structured output, context caching, and tool usage; billing is usage-based depending on the model and platform rules.

Enterprise / Individual Agreements Separate written agreements are possible; no confirmed information is available regarding standardized EU enterprise plans or EU hosting.
Location: China JINGSHENG HENGXING TECHNOLOGY PTE. LTD., 10 Anson Road, #26-03, International Plaza, Singapore 075903
GDPR: Partly Overall assessment: Conditionally GDPR-suitable. For the international GLM/Z.AI platform, the official privacy policy names JINGSHENG HENGXING TECHNOLOGY PTE. LTD. in Singapore as the responsible entity; according to the policy, personal data is generally processed in Singapore.

Positive is that Z.AI describes a Data Processing Addendum for API services in which Z.AI acts as a processor for customer data, processes customer data according to instructions, and states that it does not permanently store content from API inputs/outputs.

Negative is that the general Privacy Policy for individual users provides for the use of data to improve and train the models, and explicitly allows international transfers outside the user's country.

Server location: according to the official policy, generally Singapore; no verified information is available on EU hosting, EU data residency, a complete list of subprocessors, or specifically designated Standard Contractual Clauses for EU customers. For GDPR-relevant use, Z.AI should therefore only be used with an API DPA, a clear review of international transfers, a deletion concept, risk assessment, and without sensitive personal data. Sources: Z.AI Privacy Policy and DPA for API services.

Privacy Policy
(0)

Link

Link

"AI Meeting Assistant with #1 Noise Cancellation"

Krisp is an AI-powered voice and meeting product platform with three publicly visible product lines: AI Meeting Assistant for individuals and teams, Call Center AI for contact center environments, and AI Voice SDK for developers.

In the meeting space, Krisp offers, among other things, transcription, recording, AI notes, summaries, noise cancellation, accent adjustment, integrations, and webhooks. For call centers, additional features include Accent Conversion, Voice Translation, Agent Assist, and analytics functions.
Krisp

AI Meeting Assistant with #1 Noise Cancellation

7.7/10 Good

Audio Cleanup, Customer Support, Meeting Minutes, Transcription, Translation, Summarization

Free Test access to premium features without a credit card; includes, among other things, transcription, noise cancellation, audio/video recording, AI notes, and action items. Subscription Core For individuals and small teams; unlimited AI note-taker, bot-free transcription, audio/video recording, AI notes, action items, in-person meeting notes, noise cancellation, as well as integrations/webhooks.

Advanced For advanced teams with enhanced meeting, integration, and voice AI features.
Other Enterprise / Call Center AI Custom enterprise/call center options with security, integration, compliance, and support requirements.

AI Voice SDK Developer SDK for integrating Krisp Noise Cancellation/Voice AI into your own products; processing can take place on the customer side.
Location: USA Krisp Technologies, Inc., 2150 Shattuck Ave, Penthouse 1300, Berkeley, California 94704, United States
GDPR: Partly Krisp provides several components relevant to GDPR compliance on its website, including a privacy policy, a DPA/AVV, guidance on processing as a data processor, a list of subprocessors, and statements indicating that, where possible, data sharing and training with third-party providers are opt-out options. For the EU/EEA region, however, the situation is only partially favorable, because Krisp itself states for the enterprise/call center sector that all customer data is hosted on servers in the United States and that regional data residency outside the U.S. is not currently supported. At the same time, there are individual data-minimal or local processing methods, such as local noise suppression and, in some cases, device-based transcription. Thus, GDPR-compliant use is not guaranteed across the board, but only under specific use cases and with careful review of the data flow, the selected product line, and the contractual safeguards.
Positive
Positive aspects include the existing privacy policy, the published DPA, the identification of subprocessors, the statement regarding processing as a data processor for customers, SOC 2 Type II as the cited certification, and several references to local processing: According to the website, noise cancellation runs locally on the device, and audio is not sent to the cloud or a server; in transcription mode, transcription can take place entirely on the device, depending on the language and settings. On the security page for the AI Meeting Assistant, Krisp also explains that data sharing and training permissions are deselected for third-party providers, so that neither Krisp data nor customer data is to be used for model training.
Negative
From an EU/EEA perspective, the main concern is that Krisp explicitly states that its call center and enterprise offerings are hosted in the U.S. and, at the same time, explains that it currently does not support regional data residency outside the U.S. Additionally, the website lists several subprocessors located in the United States. Cloud processing is used for recordings and certain AI meeting assistant features; according to the help page, meeting recordings are stored in the cloud. The website does not provide evidence of clearly documented EU data residency for SaaS operations, a generally available self-hosting or on-premises option, or end-to-end EU/EEA operations for all product lines.
Server Location
For the Enterprise/Call Center segment, Krisp states that all customer data is hosted on secure servers in the United States and that regional data residency outside the U.S. is not currently supported. For the AI Meeting Assistant, the website does not specify a clear primary server location but refers to AWS infrastructure as well as subprocessors in the United States and Finland. EU/EEA data residency is not generally guaranteed on the website.
(0)

Link

Link

"Design websites faster with intelligent tools."

Framer is a visual, no-code website builder with CMS, hosting, SEO features, and real-time collaboration.

The AI features help with creating layouts, components, and translations; in addition, there is a plugin system for integrations with models like OpenAI, Anthropic, and Gemini. Framer is therefore particularly interesting for marketing websites, landing pages, portfolios, and multilingual websites.
Framer

Design websites faster with intelligent tools

7.4/10 Good

Prototyping, SEO, Text Generation, Translation, UI Design, Website Creation

Free For non-commercial use, design experiments, Framer subdomain, CMS testing, limited uploads, and collaboration with a few editors. Subscription Basic For personal, hobby, and side projects; custom domain and website publishing without free-tier limitations.

Pro For professionals, small teams, agencies, and startups; more capacity, use of team/marketing stacks, and professional website operation.

Scale For growing companies with flexible, usage-based scaling, higher limits, and add-ons.
Other Enterprise Custom contracts, SLAs, enhanced security, direct engineering support, bulk pricing, and enterprise support.

Add-ons Extensions for CMS items, collections, bandwidth, pages, events, and additional enterprise/scale features.
Location: Netherlands Framer B.V., Attn: Compliance Officer, Rozengracht 207B, 1016 LZ Amsterdam, The Netherlands
GDPR: Partly Framer documents a GDPR-compliant legal basis for data processing in the EU/EEA context via a Data Processing Addendum with SCCs and describes security measures and certifications. At the same time, the website lists AWS data centers in the United States as the hosting location for all services. The website does not specify an EU data residency or an EU/EEA hosting option. Additionally, according to the AI Notice, inputs and outputs from non-enterprise customers are used in de-identified form to train Framer’s AI models. For use within Europe, Framer cannot therefore be generally considered fully GDPR-compliant, but only under certain conditions—specifically, following a DPA/SCC review and depending on the pricing plan or the decision to opt out of certain AI features.
Positive
The website includes a privacy policy, a Data Processing Agreement (DPA) based on Article 28 with reference to Standard Contractual Clauses (SCCs) for transfers to third countries, a list of subprocessors, and security information. Framer also cites ISO 27001:2022 and SOC 2 Type 2. For enterprise customers, the AI Notice states that inputs and outputs are not used for training Framer AI models.
Negative
The website lists AWS facilities in the United States as the hosting location for all Framer services. The website does not specify an EU data residency, EU data centers, or an EU-only hosting option. For non-enterprise customers, the AI Notice permits the use of inputs and outputs in de-identified form for training Framer AI models. The website does not provide for an on-premises or true self-hosting option.
Server Location
According to the security page, all Framer services are hosted in AWS facilities in the United States. AWS is also listed in the subprocessor list with “Territories: United States.” An EU/EEA data center location for the service itself is not specified on the website.
(0)

Link

Link

“Where ideas flow into sound and songs become yours.”

Suno is an AI music platform for generating complete songs and beats from prompts as well as from uploaded or recorded audio.

Paying users get advanced features such as commercial usage rights, voice features, stem export, advanced editing, and with Suno Studio, a generative audio workstation.

With v5.5, Voices, Custom Models, and My Taste were also added.
Suno

Where ideas flow into sound and songs become yours

6.4/10 Solid

Hintergrundmusik, Musikgenerierung, Songtexte

Free Free entry with access to the free model, daily renewed credits, a limited number of songs, standard features, audio upload with a limit, a shared queue, and no commercial use. Subscription Pro Plan Paid entry-level plan with access to advanced models, monthly credits, commercial usage rights for newly created songs, Standard and Pro features, Personas, Advanced Editing, stem splitting, longer audio uploads, new vocals or instrumentals for existing songs, Early Access, add-on credits, Priority Queue, parallel songs, your own voice, and custom versions of the model with your own audio.

Premier Plan Highest regular subscription tier with Suno Studio, access to advanced models, significantly more monthly credits, commercial usage rights, Standard and Pro features, stem splitting, longer audio uploads, vocals/instrumentals for existing songs, Early Access, add-on credits, Priority Queue, parallel songs, your own voice, and custom model versions with your own audio.
Other Add-on Credits Pro and Premier users can purchase additional credits; according to Suno, purchased top-up credits do not expire, but require an active subscription to use.

Free Trial Suno may offer a trial period for paid features; the duration is determined by the respective trial confirmation.
Location: USA Suno, Inc., 17 Dunster Street, Floor 4, Cambridge, MA 02138, USA
GDPR: Partly GDPR assessment: From a GDPR perspective, Suno is unclear to critical for business use involving personal or confidential data.

Positive is that, in its Privacy Notice, Suno lists rights for EEA/UK users, including access, data portability, restriction, objection, withdrawal of consent, and the right to lodge a complaint. Also positive is that, according to its own statements, Suno does not sell to third parties and intends to contractually require service providers to use information only for the provision of services.

Negative is that, according to the Privacy Notice, Suno may collect usage data, content, prompts, uploads, music, audio, images, videos, voice recordings, and interactive chat information. Particularly critical: Suno states that it uses certain User Activity Information, Submissions, Interactive Chat Information, and Content for the development and improvement of its products as well as for training and improving its models. For voice features, voice recordings and Voice Models may be processed; depending on the jurisdiction, this may involve biometric data.

Server location: Suno is based in the USA and, according to the Privacy Notice, generally stores information on servers in the USA; data from EEA/UK users is transferred to and processed in the USA for the performance of the contract. Further link: Suno Privacy Notice and Terms of Service.

Privacy Notice
(0)

Link

Link

“Open-source orchestration for zero-human companies”

Paperclip is a self-hosted open-source platform for orchestrating teams of AI agents. The tool organizes agents as “employees” with an org chart, roles, budgets, governance, tasks/tickets, heartbeats, and audit trails.

Paperclip is explicitly a Control Plane, not an Execution Plane: the agents run externally via adapters such as Claude Code, Codex, Gemini, Cursor, OpenClaw, shell processes, or HTTP webhooks.
Paperclip AI

The human control plane for AI labor

5.8/10 Limited

Automation, AI Agents, Project Management

Free According to the official website, Paperclip is MIT-licensed, self-hosted, and usable without a Paperclip account. It includes agent orchestration, org chart, tickets, governance, cost control, and local/remote deployments. Other possible, but unclear The Terms mention services from Paperclip Labs, including a hosted platform, APIs, telemetry backend, and proprietary features; I could not reliably substantiate any specific public pricing models.
Location: USA the official Terms name Paperclip Labs, Inc. and subject the Services to the law of the U.S. state of Delaware; additionally, the Privacy Policy mentions international transfers including the USA. A precise operational headquarters is not publicly stated.
GDPR: Yes For the EU/EEA area, Paperclip can be considered usable in a GDPR-compliant manner in the best available usage form, because the website describes a clear self-hosting/local deployment path without requiring a Paperclip account. This allows a user to operate the software in their own EU/EEA infrastructure. The services operated by Paperclip Labs are significantly more critical from a GDPR perspective, because the website mentions data transfers to the USA, does not specify EU data residency, and describes the use of data for improvement and training.
Positive
Positive aspects are the explicit self-hosting approach, the MIT license, the statement 'no Paperclip account required', local execution with embedded Postgres or the user's own Postgres, as well as the possibility of local or remote deployment. For EU/EEA users, this opens a practical way to process data exclusively within their own European infrastructure.
Negative
Negative is that, for the services operated by Paperclip Labs, the website specifies neither EU data centers nor EU data residency, DPA/AVV, subprocessors, or certifications. The privacy policy also states that data may be transferred to the USA. In addition, the website describes that data may be used to improve the services and to train or improve machine-learning models and algorithms; this is explicitly mentioned for detailed telemetry.
Server location
For self-hosting, the server location can be freely chosen by the user and may be within the EU/EEA area. For the services operated by the provider, no specific server or data center location is stated on the website; the privacy policy merely states that data may be transferred to and processed in the USA, among other places.
(0)

Link

Link

"Create Videos Without Limits" / "Turn any idea into videos. Ads, explainers, stories, anything you can imagine."

invideo AI is an AI video platform for prompt-to-video, AI Video Generator, AI Avatars, image-to-video, UGC Ads, AI Animation, AI Ad Generator, Video Translator, Voice Cloning, subtitles, image generation, and classic video editing via invideo Studio.
invideo AI

Turn any idea into videos. Ads, explainers, stories, anything you can imagine.

6.3/10 Solid

Social media content, Voice output, Subtitling, Video generation, Video editing

Free Free use without a credit card; limited access to AI models, weekly reset quota, exports with the InVideo logo and stock media watermark. Subscription Plus Paid entry-level plan for exploratory use; access to paid AI/video features, credits, stock providers, and watermark removal compared to Free.

Max Expanded plan for occasional or more intensive use with a larger credit allowance than Plus and access to the paid-plan features.

Generative Plan for daily use of generative models; according to the Help Center, particularly relevant when Plus/Max credits are quickly used up through regular video generation.

Enterprise Customized enterprise offering with private/secure workflows, SOC 2/ISO alignment, GDPR compliance, Context Engine, Custom Agents, Eval & Quality, Parallel Generation, Data Isolation, Audit Trails, Access Controls, IP protection, and a no-training commitment.
Other Credits Credits are the internal currency for media clips, videos, generative models, and AI features; downloads/exports do not consume credits, and according to the Help Center, unused credits do not roll over to the next month.

redit Add-ons If credits are used up, users can, according to the Help Center, purchase one-time credit add-ons or switch to a higher plan.

Third-party models Paid Plans include access to many image, video, audio, and music models; model and agent pricing may change and is partly based on provider pricing.

invideo Studio Separate classic video editor with a timeline/template workflow; not identical to invideo AI.
Location: India India / Singapore; additionally a USA entity. Official terms name Whitesheep Technology Private Limited in India and Invideo Innovation Pte. Ltd. in Singapore.
GDPR: No For the European region, the website does not document a reliable basis for use that is fully GDPR-compliant. Although invideo states “GDPR Compliant” on its homepage and refers to “SOC 2 & ISO Aligned,” the website lacks verifiable information regarding EU data residency, specific server or data center locations within the EU/EEA, an accessible Data Processing Agreement (DPA), and a list of subprocessors. Additionally, the privacy policy permits global data transfers to third parties and to countries outside the user’s country of residence. Consequently, the website’s documentation does not demonstrate compliance for EU/EEA users.
Positive
The website includes a privacy policy, information on data subject rights, options to delete account data and certain biometric data, as well as a marketing statement indicating “GDPR Compliant” and “SOC 2 & ISO Aligned.” The website also describes the use of TLS/SSL for data transmission and encrypted backups.
Negative
The website does not specify a specific Data Processing Agreement (DPA), a list of subprocessors, an EU/EEA server location, EU data residency, on-premises or self-hosting options, or an opt-out from general AI training. The Terms of Service also state that users grant invideo the right to use AI-based output to improve AI security measures, technologies, products, and services. The Privacy Policy further provides for global transfers to third parties and to countries outside the user’s country of residence.
Server Location
Not specified on the website. The Privacy Policy mentions global transfers and processing worldwide, but does not specify a specific server or data center location in the EU/EEA.
(0)

Link

Link

Intelligent Automation & AI Agents Platform

Mazaal AI combines AI agents with workflow automation. Users can train agents using their own documents, websites, Q&A pairs, and data sources, deploy them as a website widget, in messaging channels, or via API, and connect them to automations that perform actions in third-party systems.

The current website also highlights a browser-based assistant that executes commands directly in any tab.
Mazaal

Your Browser, Now on Autopilot

3.6/10 Insufficient

Automation, Data Analysis, AI agents, Customer Support, Text recognition

Free Includes monthly AI credits and task credits; according to the homepage, no credit card required. Suitable for testing initial agents, workflows, and integrations. Subscription Basic For individuals who want to automate everyday work; includes AI Credits, Task Credits, all integrations, email support, unlimited workflows, and unlimited AI agents.

Team / Pro The official pages are inconsistent here: the homepage calls it Team, the pricing page calls it Pro. In terms of content, the middle plan is intended for teams that want to scale workflows across multiple tools; it mentions more AI Credits, more Task Credits, all integrations, Priority Support, unlimited workflows, and unlimited AI agents.

Business For organizations with Custom AI and admin control; includes more AI Credits and Task Credits, all integrations plus Custom Integrations, Dedicated Support, unlimited workflows, and unlimited AI agents.
Other Enterprise Custom offer for larger requirements; according to the pricing page with unlimited messages/credits, Dedicated Account Manager, and Premium Support.

Additional credits / API / AppSumo special models Mazaal uses AI Credits for model calls and Task Credits for integration runs. According to the documentation, additional credits can be purchased in the dashboard, but only on paid plans. AppSumo-specific plans and special conditions are also mentioned.
Location: Australia Mazaal AI Pty Ltd, 65 Durham Street, Hurstville NSW 2220, Australia. The official ABN Lookup confirms the company MAZAAL AI PTY LTD and the principal location NSW 2220.
GDPR: Unclear The website includes a privacy policy, but it explicitly refers to Australian data protection law and does not demonstrate sufficient GDPR compliance for users in the EU/EEA. No reliable information could be found on the website regarding key requirements such as EU data residency, server location, data processing agreements (DPAs), subprocessors, and EU-specific commitments regarding data processing.
Positive
General security measures such as encryption during transmission and storage, access controls, and regular security audits are clearly documented. Additionally, the website explicitly states that Google Workspace API data is not used to train or improve AI/ML models.
Negative
A negative point is that the privacy policy refers to the Australian Privacy Principles rather than the GDPR. The website does not specify a Data Processing Agreement (DPA), a list of subprocessors, a specific EU/EEA server location, EU data residency, Standard Contractual Clauses, or other explicitly EU-related guarantees. The Terms of Service also state that Mazaal may use, store, and process user data to provide and improve the solution; a general contractual prohibition on using any data for training purposes is not clearly documented on the website.
Server Location
Not specified on the website. No specific location of servers or data centers within the EU/EEA was found.
(0)

Link

Link

"Where AI agents share, discuss, and upvote. Humans welcome to observe."

Moltbook is a public social platform where AI agents can post, comment, vote, and organize themselves into communities ("Submolts").

Humans are primarily intended as observers. In addition, Moltbook positions itself as an identity layer for agents: developers can build apps in which bots authenticate with their Moltbook identity and bring their reputation with them.
Moltbook

A Social Network for AI Agents

5.3/10 Limited

AI agents

Free The website is publicly accessible; people can observe agent activity. For active use, X/Twitter login or developer access is currently relevant. Other Developer Early Access
Early Access for developers who want to build apps for AI agents; mentioned are agent authentication, identity verification, agent marketplace, customer support bots, AI assistant platform, developer tools, and social platform for agents.
Location: USA Moltbook, LLC, 1101 President Street, #1401, Brooklyn, NY 11225, USA
GDPR: Unclear Although the website includes a privacy policy with a section for UK/EEA data subjects, legal bases, and information on international data transfers, However, the website lacks key information necessary for a robust assessment of GDPR compliance throughout the EU/EEA, particularly regarding specific server and data center locations, EU data residency, data processing agreements, subprocessors, and certifications. Therefore, compliance from an EU/EEA perspective is unclear overall.
Positive
Positive aspects include a published privacy policy, an explicit reference to the rights of UK/EEA data subjects under the GDPR, specified legal bases for certain processing activities, and contact information for data protection inquiries at [email protected]. Furthermore, the policy states that applicable legal requirements will be complied with when transferring data to third countries.
Negative
A negative aspect is that the website does not specify any concrete EU/EEA server locations and explicitly provides for transfers and storage in countries outside the EEA/UK, including the U.S. and Canada. A Data Processing Agreement (DPA), a list of subprocessors, a commitment to EU data residency, an on-premises/self-hosting option, a documented opt-out from AI training, and relevant certifications are not provided on the website.
Server Location
Not specified on the website. The privacy policy only states that data may be transferred to and stored in countries other than the country of origin, including the United States, Canada, or other jurisdictions outside the EEA and the UK. No specific EU/EEA data center location is mentioned.
(0)

Link

Link

"Boost your team with AI Agents" / "Automatically record, transcribe, and summarize meetings with AI notetaker…"

Noota is a European SaaS platform for Conversation Intelligence, AI Meeting Notes, transcription, meeting summaries, email agents, telephony, knowledge search, and recruiting/sales workflows. The tool records meetings or calls, transcribes conversations, creates structured summaries, follow-up emails, reports, and makes meeting, call, and email knowledge searchable.
Noota

Boost your team with AI Agents” / “Automatically record, transcribe, and summarize meetings with AI notetaker…

7.7/10 Good

Meeting Minutes, Transcription, Translation, Summarization

Free Free entry for individuals; includes unlimited recording & transcription, monthly AI notes minutes, limited storage, email automation, Chrome extension, as well as iOS/Android app. Subscription Pro For individuals and small teams; includes everything in Free plus more AI Notes minutes, Team Workspace up to a limited team size, unlimited integrations, and AI Agents.

Business For fast-growing companies; includes everything in Pro plus unlimited recording, paid unlimited seats, unlimited AI features, Custom Templates, Zapier & API, Analytics, and AI Infrastructure.
Other Enterprise Custom offer for larger teams; includes everything from Business plus unlimited usage, payment by invoice, custom integration, SSO, dedicated support, and business telephony.

Business Telephony / Phone Add-on module for VoIP telephony, domestic calls, local numbers from multiple countries, iOS/Android calling, click-to-call in the browser, and a bring-your-phone option depending on country regulations.

API / Zapier / AI Agents Advanced automation for workflows, integrations, CRM/ATS synchronization, follow-ups, analytics, and knowledge base queries.
Location: France NOOTA, 13 Rue Sainte Ursule, 31000 Toulouse, France. Toulouse Trade and Companies Register: 888965951
GDPR: Partly Noota's website documents several building blocks relevant for the EU/EEA region: explicit GDPR references, EU data centers, a data processing agreement included in the contractual framework, as well as statements that customer data is not used to train general models. At the same time, important points remain incompletely or inconsistently documented: the exact server location is described partly as EU data centers in France, Belgium, and the Netherlands, and partly as exclusively in France; a specific list of subprocessors is not provided on the website; relevant certifications are presented partly as being in preparation and partly as already existing. From the perspective of a user in the European region, GDPR-compliant use is therefore only reliably supportable under certain conditions and after conducting one's own contractual review.
Positive
Positive are the statements regarding EU data residency, isolated environments in European data centers, encryption, customizable retention periods, an organization-wide 'text-only' option, a DPA included in the contractual framework, and the statement that data is not used to train generalized AI models. An on-premise configuration is also mentioned for companies.
Negative
Negative is that several key points are not clearly and consistently documented on the website: a specific list of subprocessors is not provided, the server locations are described inconsistently, an explicit and easily findable separate DPA download is not provided, and there are contradictory statements regarding ISO 27001 and SOC 2 between 'ongoing/in preparation' and 'certified'. This leaves documentation risk for a reliable EU/EEA assessment.
Server location
The website mentions EU/European locations. The security page refers to European data centers in France, Belgium, and the Netherlands, as well as Google Cloud Platform with Google KMS. Other subpages, however, state that all data is hosted on servers in France. This confirms EU data residency, but the exact production location is described inconsistently on the website.
(0)

Link

Link

“Build exactly what you envision with AI + no-code development.”

Bubble is a no-code platform for building web and mobile apps with visual logic, a database, workflows, API integrations, and now also AI-powered app generation.

The tool is aimed at makers, startups, agencies, and companies that want to build and operate applications without traditional full-stack development. In doing so, Bubble covers development, deployment, hosting, and scaling within its own platform ecosystem.
Bubble

Build exactly what you envision with AI + no-code development

6.6/10 Solid

App Development, Programming, Website Creation

Free Free entry point for building and testing web/mobile apps; not intended for fully productive use with your own domain. Subscription Starter For initial live apps with web app, live website, custom domain, and basic workload.

Growth For growing apps with more workload, more editor/branching options, and advanced production features.

Team For scaling teams with sub-apps, multiple app editors, more branches, more workload, and longer server logs.
Other Enterprise Custom workload, choice of hosting location, customizable server, dedicated support, and individual app/mobile limits.

Add-ons Workload tiers, additional file storage, and plugin subscriptions.
Location: USA Bubble Group, Inc., 22 W 21st Street, 2nd Floor, New York, NY 10010, USA.
GDPR: Partly Bubble documents several components relevant to GDPR compliance for the EU/EEA region: a privacy policy, a DPA/AVV, subprocessors, data transfer mechanisms for EU/EEA data, and a choice of hosting regions for isolated servers. At the same time, Bubble is a U.S.-based provider; its standard platform is cloud-based on AWS; the website does not specify a clear, general EU data residency standard for all pricing plans; and regarding the AI features, the Terms reserve the right to to use input and output for training and further developing the Bubble AI tools. Therefore, GDPR-compliant use in the EU/EEA appears plausible only under certain conditions, particularly with a sound contractual setup, an appropriate hosting region, and cautious or limited use of the AI features.
Positive
Positively noted are the company’s own DPA/AVV, the inclusion of SCCs or Data Privacy Framework mechanisms for EU/EEA-related transfers, a published list of subprocessors with update and opt-out mechanisms, as well as security certifications such as SOC 2 Type II at the Bubble level and AWS as the underlying infrastructure with ISO/IEC 27001 and SOC 2 compliance. For Enterprise, the option to select a specific AWS data center region for isolated servers is also mentioned.
Negative
A negative or limiting factor is that Bubble operates as a U.S. provider, and the website does not provide general evidence that customer data is stored or processed exclusively within the EU/EEA by default. Furthermore, the Terms explicitly state that Bubble may use input and output from the “Bubble AI Tools” for training, refinement, and further development; a clear, product-specific opt-out for AI training is not specified on the website. On-premises/self-hosting is also not described.
Server Location
Bubble lists AWS as its hosting infrastructure on the website. A specific standard server location for all customers is not specified on the website. For Enterprise, it is stated that applications can be hosted on an isolated server in a specific AWS data center region; however, the pages reviewed do not specify whether and which specific EU/EEA regions are available.
(0)

Link

Link

"Specialized language models for a sovereign Europe"

Aleph Alpha offers PhariaAI, a sovereign, customizable end-to-end AI suite for enterprises and public authorities.

The suite includes, among other things, PhariaAssistant for chat, summarization, document analysis, and translation, PhariaStudio for developing and evaluating custom AI applications, as well as PhariaOS for operation and administration. The platform is designed for sensitive, regulated, and business-critical environments and can be operated on-premises, in the cloud, or in a hybrid setup.
Aleph Alpha

Trust. Responsibility. Sovereignty

6.9/10 Solid

Data Analysis, Document Analysis, AI Agents, LLM API, Multimodal AI, Language Model, Text Generation, Summarization

Other Enterprise / Project Business Customized solutions for companies, authorities, and regulated environments with PhariaAI, specialized language models, APIs, data integration, and compliance architecture.

PhariaAI / PhariaInference API Programmatic access to Aleph Alpha functions via APIs such as PhariaInference, PhariaData, PhariaSearch, and PhariaStudio.

Government / Sovereign Deployments Sovereign deployments such as Pharia Government Assistant with EU hosting, data isolation, and specific compliance commitments.
Location: Germany Aleph Alpha GmbH, Speyerer Straße 14, 69115 Heidelberg, Germany.
GDPR: Yes From an EU/EEA perspective, GDPR-compliant use in accordance with the best practice documented on the website is plausible because Aleph Alpha explicitly positions its AI suite on European infrastructure, offers flexible deployment options—including its own data centers and infrastructure—and provides installable PhariaAI documentation for customer-side deployments. This provides a straightforward path to data-sovereign use within the EU/EEA, even though the website does not publicly disclose all detailed evidence for individual compliance points regarding the managed/SaaS variant.
Positive
Positive aspects include the clear focus on “European infrastructure,” the statement that every model runs on European infrastructure, the documented installability of PhariaAI, the explicit option for infrastructure “in the cloud and in the customer’s own data center,” the documented hybrid deployment, and the privacy policy, which references data processing agreements for website service providers.
Negative
Negative or incomplete aspects include the fact that the website does not provide a dedicated DPA for product customers, does not publish a list of subprocessors for the actual product, no explicit opt-out or contractual exclusion of model training using customer data, no clearly specified EU data residency for a standard SaaS product instance, and no certifications such as ISO 27001 or SOC 2 listed on the website.
Server Location
The website repeatedly mentions “European infrastructure.” In addition, Aleph Alpha describes its own AI data center, “alpha ONE,” in Germany and mentions a PhariaAI-as-a-Service partnership on European infrastructure with STACKIT. However, a specific, universally applicable server location for all product variants is not conclusively specified.
(0)

Link

Link

"Always the best, without switching tools."

Bolt is an AI-powered builder for websites, web apps, and mobile apps. Users describe their project via prompt, and Bolt generates a working project from it in a short time.

In addition, Bolt bundles Bolt Cloud Hosting, databases, domains, authentication, file storage, analytics, and Edge Functions directly in the interface.
Bolt.new

Always the best, without switching tools

6.4/10 Solid

App Development, Programming, Website Creation

Free Free entry point for building initial projects with limited token/usage scope. Subscription Pro / individual plans More tokens, private projects, website hosting, no Bolt branding, private sharing features, file uploads, custom domains, SEO features, databases, and AI image editing.

Teams For teams with collaborative work, higher limits, and team-oriented usage.
Other Enterprise Custom offering for organizations with advanced requirements.

bolt.diy Official open-source version for local/self-hosted use with your own LLM providers such as OpenAI, Anthropic, Ollama, Gemini, Mistral, xAI, DeepSeek, Bedrock, and others.
Location: USA StackBlitz, Inc., 2443 Fillmore St #380-7122, San Francisco, CA 94115, USA.
GDPR: Partly For the EU/EEA region, GDPR-compliant use is plausible only under certain conditions. Positive aspects include the enterprise options listed on the website for deployment in a user’s own AWS/Azure tenant with full infrastructure isolation, as well as the statement that code and prompts do not leave the user’s own infrastructure. However, for standard SaaS/Bolt Cloud usage, the website lacks essential, reliable information regarding EU data residency, specific server locations within the EU/EEA, the Data Processing Agreement (DPA), and subprocessors. Therefore, there is no verifiable, fully clear GDPR approval for standard use; the best-documented option is the Enterprise/BYOK variant.
Positive
The website mentions BYOK deployment or deployment within the user’s own AWS/Azure tenant, full infrastructure isolation without shared compute, the statement “Your code and prompts never leave your infrastructure,” and SOC 2 information. In addition, the Trust page describes client-side execution as a security feature.
Negative
The website does not specify any concrete EU/EEA server locations for the standard service. Also missing are a privacy policy, an AVV/DPA, a list of subprocessors, an explicit EU data residency for Bolt Cloud, and a clear, contractually documented no-training/opt-out rule for standard use. The support documentation also mentions external platforms such as Netlify and Supabase as the basis for Bolt Cloud.
Server Location
Not specified on the website. For Bolt Cloud, only “secure, high-performance servers” and partner platforms such as Netlify and Supabase are mentioned. A specific EU/EEA data center location or a binding EU data residency requirement is not mentioned on the pages found. For Enterprise, deployment within the customer’s own AWS/Azure tenant is described; the specific location there apparently depends on the customer’s target environment.
(0)

Link

Link

The frontier AI research lab for visual intelligence.

Black Forest Labs is the company behind the FLUX models for AI-based image generation and image editing. The platform includes Playground, API, open-weights/self-hosting licenses, and enterprise offerings for visual AI workflows. FLUX.2 is officially described as a production model for image generation and image editing with multi-reference control and up to 4MP output.
Black Forest Labs / FLUX

The frontier AI research lab for visual intelligence.

7.0/10 Good

Image Editing, Image Generation, Illustrations

Free Free or trial-based entry via the Playground; suitable for trying out FLUX.2 and image generation without your own integration. Other FLUX API / Pay-as-you-go API access to FLUX models; according to the pricing page for FLUX.2, FLUX Kontext, and additional image models with usage-based billing.

FLUX.2 [small] Fastest model variant for real-time use, prototyping, rapid iteration, and high speed; according to the model page also runnable locally and fine-tuning-ready.

FLUX.2 [pro] Production-oriented image generation and image editing with high quality and scalability.

FLUX.2 [flex] Variant for precise control, typography, small details, and finer visual control.

FLUX.2 [max] Highest-quality variant with particularly strong prompt adherence, editing consistency, professional output, and grounding features.

Self-Hosted Commercial License License for downloading, hosting, and using certain FLUX-[dev] models in your own applications; API resale or third-party API access is excluded without the corresponding rights.

Enterprise / Custom Deployment Custom enterprise options with dedicated infrastructure, custom fine-tuning, and integration support.
Location: Germany BFL GmbH, Ingeborg-Krummer-Schroth-Straße 18, 79106 Freiburg im Breisgau, Germany. Commercial Register
GDPR: Partly For the EU/EEA region, there is no clear evidence that the standard SaaS version complies with the GDPR. On the positive side, the provider describes on its website self-hosting, private cloud/on-premises operation, dedicated instances with “zero data retention” and “network isolation,” as well as GDPR-compliant data processing in an enterprise context. At the same time, according to the Terms of Service, general SaaS/website use allows for very extensive use of input and output data for further development and training. The simplest and best option for EU/EEA users is therefore the self-hosted or dedicated enterprise path, rather than the freely accessible standard SaaS usage.
Positive
The website lists self-hosted/open-source options, including “Deploy in your private cloud or on-premises with complete data isolation,” “No external calls: all inference runs inside your environment,” and “Full data sovereignty on your own infrastructure.” In addition, the Enterprise page mentions dedicated instances with “zero data retention and network isolation” as well as certifications/standards such as ISO 27001, SOC 2 Type II, and “GDPR-compliant data processing is standard.”
Negative
The website does not specify EU/EEA data residency or a specific server location for the standard services. A publicly linked page for the Terms of Service (TOS) or Data Processing Agreement (DPA), or a list of subprocessors, is also not available. Particularly critical: In the general terms, the user grants the provider a worldwide, perpetual, and irrevocable license to use input and output to “develop, train, and improve” technologies, products, and services. The website does not specify an explicit opt-out option from AI training for this standard use.
Server location
Not specified on the website. Although Enterprise, Self-Hosted, and Private Cloud options, as well as Azure AI Foundry, are mentioned, no specific EU/EEA data center, country, or binding EU data residency is specified for the standard SaaS version.
(0)

Link

Link

xAI offers Grok models via its API for text generation, reasoning, coding, tool use, document-centric workflows, and agentic research. The current docs focus primarily on Grok 4.20 as the new flagship, as well as on server-side tools such as Web Search, X Search, Code Execution, and Collections Search.

Additionally, xAI documents classic model-listing endpoints such as /v1/models and /v1/language-models.
xAI API – Grok

LLM “Build with Grok, the AI model designed to deliver truthful, insightful answers.”

7.3/10 Good

Image Generation, Function Calling, AI Agents, LLM API, Multimodal AI, Programming, Reasoning Model, Language Model

Other Token-based API usage Billing based on input, reasoning, completion, image, and cached prompt tokens per model.

Server-side Tools Additional billing for tool invocations; costs may increase with the complexity of agentic requests.

Credits / API Key API usage takes place via an xAI account, API key, and purchased credits.

Enterprise / ZDR Enterprise customers can use Zero Data Retention so that API requests and responses are not stored.

Voice / Imagine / Batch / Tools Additional product areas for real-time conversations, TTS/STT, image/video generation, batch processing, web search, and structured outputs.
Location: USA X.AI LLC, 1450 Page Mill Road, Palo Alto, CA 94304, USA
GDPR: Partly GDPR assessment: From a GDPR perspective, the xAI API is conditionally to well suited if it is used in an xAI Business/Enterprise context with a DPA and appropriate data controls.

Positive is that xAI provides a Data Processing Addendum that addresses GDPR/UK GDPR/Swiss FADP, roles as Processor, SCCs, UK Addendum, subprocessors, and deletion after the end of the contract. xAI also states that it never uses API inputs and outputs for training without explicit permission; API requests and responses are stored by default for 30 days for abuse/misuse audits and then deleted. For Enterprise, there is Zero Data Retention, under which prompts, completions, and metadata are not persisted.

Negative is that xAI allows international transfers outside Europe, including to the USA, and there is no publicly confirmed EU-only data residency as the standard for the API.

Server location: No confirmed EU-only region as standard; the DPA mentions transfers/processing outside Europe, including the USA, insofar as necessary for service provision. Further link: xAI DPA, xAI API Security FAQ, and xAI Enterprise FAQ.

xAI Data Processing Addendum
(0)

Link

Link

"The leading AI platform"

innoGPT is a German multi-model AI platform for private users, teams, and companies. Officially, it combines language models, image generation, voice integration, file/document work, a prompt library, projects, Code Interpreter, web search, academic search, Deep Research, assistants, integrations, and an API in one interface. It also includes team features, desktop apps, and a clear data protection/compliance focus with EU hosting, DPA, and Trust Center.
InnoGPT

All AI models. One tool. Permanent updates. Fully GDPR-compliant

7.6/10 Good

Chatbot, Text Generation

Free Free trial period without payment details according to the provider; suitable for evaluation. Subscription Personal According to the public OMR profile for private use with access to all models and functions except team functionality.

Business According to the OMR profile for companies with all functions, all models, no limits, up to 1000 users, as well as SSO/SCIM/SAML.
Other Enterprise Custom offer for large organizations; according to the OMR profile for 1000+ users, on-premise possible and individual support.

Shared-/Family models A shared-access/family model with EU hosting was mentioned publicly; specific functional details should be checked directly with the provider.
Location: Germany Inno KI GmbH, Osloer Str. 6, 49377 Vechta, Germany
GDPR: Yes The website clearly emphasizes compliance with the GDPR for the European market: innoGPT describes EU hosting—specifically servers in Frankfurt am Main—a directly executable data processing agreement (DPA) in accordance with Article 28 of the GDPR, a zero-training/zero-retention policy, automatic deletion schedules, and a Trust Center featuring subprocessors and compliance documents. Additionally, according to the Help Center, admin settings are available for different model hosting levels, including “EU Hosting / EU Processing.” From an EU/EEA perspective, this provides a documented path to GDPR-compliant use.
Positive
Positive aspects include EU/Germany hosting for the core infrastructure, a data processing agreement (DPA) in accordance with Article 28 of the GDPR, documented subprocessors in the Trust Center, zero training as stated on the security page and in the Help Center, ISO/IEC 27001:2022 in the Trust Center, and a clearly described data flow with storage and deletion after 180 days. Additionally, the website lists hosting options for individual models, such as “EU Hosting / EU Processing,” which is relevant for EU/EEA users.
Negative
A limitation is that the website also states that not all models are processed exclusively within the EU: The Help Center mentions “EU Hosting / Global Processing” and “Global Hosting / Global Processing” as well. As a result, actual compliance in individual cases depends on the model selected and the admin settings. The website does not consistently provide comprehensive evidence to support a claim that, without exception, all processing for all models takes place exclusively within the EU/EEA.
Server Location
The website specifies servers in Frankfurt am Main, Germany, for core data and platform hosting, as well as hosting within the EU in general. According to the Help Center, three levels are listed for individual models: “EU Hosting / EU Processing,” “EU Hosting / Global Processing,” and “Global Hosting / Global Processing.”
(0)

Link

Link

"AI-powered research assistant"

NotebookLM is an AI-powered research and knowledge assistant by Google that works with your own sources.

You can upload PDFs, Google Docs, Slides, websites, YouTube transcripts, audio, images, Office files, and text, among other things, and use them to generate questions with source references, summaries, mind maps, flashcards, quizzes, infographics, presentations, as well as audio and video overviews.
For teams and organizations, there are sharing options, analytics, higher limits, and – depending on the plan – enterprise/cloud security features.
NotebookLM

KI-Recherche-Tool & DenkpartnerWait, I need to translate FROM German TO English. But the input "AI research tool & thinking partner" is already in English.AI research tool & thinking partner

7.7/10 Good

Document Analysis, Tutoring, Podcast Production, Research, Knowledge Base, Summarization

Free NotebookLM Standard is free to use. It includes up to 100 notebooks per user, up to 50 sources per notebook, up to 500,000 words per source, chat with sources, Audio Overviews, Video Overviews, Reports, Flashcards, Quizzes, Mind Maps, limited Deep Research as well as limited Data Tables, Infographics and Slide Decks. Subscription NotebookLM in Google AI Plus: more notebooks, more sources per notebook, higher chat/audio/video limits, more reports, flashcards, quizzes, deep research, and additional NotebookLM features.

NotebookLM in Google AI Pro: higher limits than Plus, higher Gemini model access, more audio/video overviews, reports, flashcards, quizzes, deep research, data tables, infographics, and slide decks.

NotebookLM in Google AI Ultra: highest limits, highest Gemini model access, very high limits for chats, audio/video overviews, reports, flashcards, quizzes, and deep research; additionally watermark removal for infographics and slide decks.
Other NotebookLM upgrades are available not only through Google AI Plans, but also through Google Cloud or qualifying Google Workspace and Workspace for Education plans. For work and school accounts, there are additional access tiers such as Standard, More, Higher, Expanded, and Highest Level Access. When using Workspace/Education, Google notes that uploaded files, chats, and model outputs are not reviewed by human reviewers and are not used to improve generative AI models.
Location: USA Google LLC, 1600 Amphitheatre Parkway, Mountain View, California 94043, USA
GDPR: Unclear On the NotebookLM website, there is information on the handling of training data and the privacy of organizational data. However, for a reliable GDPR assessment for use in the EU/EEA, key details are missing on the NotebookLM domain, such as server locations/data center locations, EU data residency, DPA/AVV, subprocessors, and certifications. Therefore, compliance cannot be reliably demonstrated based on the information found.
Positive
It is positively documented that, according to the website, data from organizations is not used to train NotebookLM. For individual use, the website also states that data is not used for training unless feedback is shared. In addition, it is stated that an organization’s or school’s data remains private and that NotebookLM does not share data with third parties.
Negative
The website does not specify concrete server or data center locations, EU/EEA data residency, a DPA/AVV, a list of subprocessors, on-premise/self-hosting options, or relevant certifications such as ISO 27001 or SOC 2. Without these points, a reliable GDPR assessment for the entire EU/EEA area is not possible.
Server location
Not specified on the website.
(0)

Link

Link

“Projects that practically manage themselves.”

Jira is a cloud and data center platform for project, task, and work management.

In its AI-enabled form, Jira combines classic planning, tracking, and workflows with Rovo AI, for example to create work items from Slack/Teams, summarize content, break down complex work into tasks, and provide agentic assistance and search across the Teamwork Graph.
Jira / Atlassian Intelligence

Projects that practically manage themselves

7.6/10 Good

Task Management, Automation, Project Management, Text Generation, Knowledge Base

Free For small teams; unlimited goals, projects, tasks, and forms, limited number of users and limited automations. Subscription Standard More user/team capability, Standard Support, more automations, data residency, and basic scaling.

Premium Everything in Standard plus unlimited storage, 99.9% SLA, 24/7 Premium Support, Project Archiving, Admin Insights, IP Allowlisting, Sandbox, Release Tracks, more automation, and Atlassian Intelligence.
Other Enterprise Enterprise scaling, centralized administration, advanced security/compliance features, Enterprise support, and stronger data/AI control.

Marketplace / Rovo / Atlassian Intelligence Additional apps, AI features, agents, search, and automations depending on product and license scope.
Location: Australia Global HQ: Level 6, 341 George Street, Sydney, NSW 2000, Australia. Service provider according to the legal notice: Atlassian Pty Ltd, c/o Atlassian, 350 Bush St, Floor 13, San Francisco, CA 94104, USA.
GDPR: Partly For users throughout the EU/EEA, using Jira with Atlassian Intelligence in compliance with the GDPR is generally possible, but only under certain conditions. Positive aspects include the documented privacy policy, a DPA/AVV, a list of subprocessors, the explicit GDPR commitment, EU data residency for Rovo, and self-managed hosting for Jira Data Center. At the same time, the website indicates that processing for Atlassian Intelligence/Rovo features may also take place outside the EU/EEA—particularly in the U.S.—and that not all components are equally EU-resident. Therefore, to ensure compliant GDPR usage within the EU/EEA, the appropriate deployment model, data residency configuration, and a review of international data transfers are required.
Positive
Atlassian refers to its privacy policy, DPA/AVV, security measures, and list of subprocessors. For Rovo, EU data residency is documented, and Jira can also be operated as a self-managed variant via Jira Data Center on the customer’s own hardware or with IaaS providers. Rovo also mentions SOC 2 and ISO 27001, as well as the statement that LLM providers do not use inputs and outputs to improve their own services.
Negative
The website documents subprocessors and processing locations for Atlassian Intelligence and Rovo that are outside the EU/EEA, including the U.S. Furthermore, data residency is not equally available for all related components; according to the website, it is not available for Forge apps built in Studio. The website does not consistently demonstrate that AI functions operate exclusively within the EU.
Server Location
For cloud data residency, Atlassian lists the regions Europe (Frankfurt) and Europe (Dublin) for the EU. Data residency is available for Rovo. However, the list of subprocessors also includes the U.S. and, in some cases, EEA locations such as Belgium, the Netherlands, and Finland for AI-related processing, depending on the provider. For Jira Data Center, customers can choose the hosting environment themselves.
(0)

Link

Link

"AI-first coding in your natural language"

Gemini Code Assist is Google's AI-powered coding assistant for the entire software development lifecycle. It supports code completion, generation, chat, testing, debugging, and documentation in IDEs and—in the Business editions—additionally in various Google Cloud interfaces such as BigQuery, Cloud Run, Firebase, or Apigee.
Gemini Code Assist

AI-first coding in your natural language

4.6/10 Limited

App Development, AI Agents, Programming

Free No-cost tier for individual developers; suitable for code completion, chat, and coding assistance in supported development environments. Subscription Gemini Code Assist Standard Monthly or annual user licenses; includes professional coding assistance, IDE support, Gemini CLI, code completion, chat, smart actions, and enterprise data privacy framework.

Gemini Code Assist Enterprise Advanced enterprise version with enterprise features such as code customization, metrics/observability, private codebase contexts, enterprise access controls, and stronger governance.
Other Google Developer Program Gemini Code Assist is also available through the Google Developer Program; exact features depend on the respective program status.

Custom Quote / Google Cloud For larger organizations, individual Google Cloud offers, billing via Google Cloud, and the Pricing Calculator may be relevant.
Location: USA Google LLC, 1600 Amphitheatre Pkwy, Mountain View, CA 94
GDPR: Unclear On the specified website, it is clear that Gemini Code Assist addresses security and data protection concerns for business customers. Specifically mentioned are a data governance policy, a commitment not to use customer code, inputs, or generated recommendations for training shared models or for product development, as well as several certifications. However, for a robust GDPR assessment across the entire EU/EEA region, key information is missing from the website itself, such as specific EU/EEA data residency, designated server locations/data centers, a directly accessible Data Processing Agreement (DPA) on this domain, and subprocessors. Therefore, GDPR compliance cannot be conclusively verified based on this domain alone.
Positive
Positive aspects include the statements on the website regarding “Enterprise security and privacy,” the data governance policy, the exclusion of training shared models with customer data, and the mentioned certifications SOC 1/2/3 and ISO/IEC 27001, 27017, 27018, and 27701. Additionally, Gemini CLI is described on the website as open source.
Negative
On the negative side, the website does not list any specific EU/EEA server locations, does not explicitly state EU data residency for Gemini Code Assist, does not directly name a Data Processing Agreement (DPA) on this domain, and does not list any subprocessors. The website also does not specify an on-premises or self-hosting option for the complete solution.
Server Location
Not specified on the website. No specific server locations or EU/EEA data centers for Gemini Code Assist are mentioned.
(0)

Link

Link