Privacy Policy Analyzer
Enter a public privacy policy URL to get a shareable compliance-style report on data collection, sharing, model training, and EU transfer risks.
Informational tool only. This is not legal advice.
Analysed privacy policies
44 reports
app.klang.ai
62/100
Medium privacy riskKlang AI collects potentially sensitive audio and video content, shares it with multiple AI providers, and reserves the right to use your uploaded data to improve its own algorithms without offering an opt-out — though it does keep most processing in the EU and enforces zero data retention with its AI sub-processors.
View report →apple.com
72/100
Medium privacy riskApple's Messages privacy disclosure shows strong encryption and short data retention but leaves critical EU compliance gaps—no mention of international transfers, GDPR user rights, or whether message metadata trains AI models.
View report →tuta.com
87/100
Low privacy riskTuta is a highly privacy-friendly encrypted email provider that stores all user data end-to-end encrypted in Germany, collects minimal metadata, uses no cookies, and shares data with third parties only for payment processing or under court order.
View report →about.qwant.com
72/100
Medium privacy riskQwant offers strong privacy by default without tracking cookies, but creating an account or consenting to cookies shares significant data with Microsoft, and the policy lacks clarity on international transfers and AI training.
View report →gdprchat.eu
88/100
Low privacy riskGDPRchat offers exceptionally strong EU-centric privacy with no tracking and self-service data controls, but users should be aware that image prompts may be used for AI training by a third-party provider.
View report →proton.me
88/100
Low privacy riskProton offers strong privacy by default with end-to-end encryption, minimal data collection, and no ad tracking, though some user data does flow to US-based processors for support and payments.
View report →greenpt.com
82/100
Low privacy riskGreenPT offers strong EU data sovereignty and minimal tracking, but its policy is suspiciously silent on whether your chat data is used to train AI models, and it relies on a weak safeguard for US-based search transfers.
View report →hotels.com
48/100
High privacy riskHotels.com (Expedia Group) collects an unusually broad range of personal data — including sensitive data, voice recordings, and co-traveler info — shares it widely with advertisers and Expedia Group brands, and uses it for extensive AI purposes with no opt-out, making this a data-hungry policy despite decent transfer safeguards.
View report →signal.org
72/100
Medium privacy riskSignal genuinely collects almost nothing and encrypts everything, but its legal documentation is outdated and missing critical GDPR-mandated disclosures like transfer safeguards, retention periods, and user rights procedures.
View report →whatsapp.com
45/100
High privacy riskWhatsApp collects extensive metadata on your usage and device and shares it widely across Meta's family of companies, making it a concerning privacy choice despite its end-to-end encrypted messaging.
View report →trust.grindr.com
40/100
High privacy riskGrindr collects deeply sensitive data—including HIV status, precise geolocation, and biometric information—from a vulnerable community, ships it all to the US with no EU establishment, and reserves the right to keep training AI on it even after you opt out.
View report →policies.tinder.com
48/100
High privacy riskTinder collects a massive amount of highly sensitive personal data—including sexual orientation, biometric face data, and precise location—and shares it widely across Match Group companies and advertising partners, making it a concerning privacy choice despite offering standard EU rights.
View report →mastodon.social
25/100
High privacy riskMastodon GmbH's mastodon.social privacy policy page was not actually provided for analysis — only navigation chrome and marketing copy were included, making it impossible to assess compliance and leaving users without verifiable assurances.
View report →bsky.social
55/100
Medium privacy riskBluesky collects broad behavioral data and stores your direct messages unencrypted, but earns points for refusing to sell your data for targeted ads and providing solid GDPR rights infrastructure.
View report →cursor.com
62/100
Medium privacy riskCursor (Anysphere) promises not to use your code inputs for AI training by default and doesn't sell your data, but it collects a sweeping range of personal and usage data, ships it to the US with vague transfer safeguards, and leaves key details like retention periods and legal bases unspecified.
View report →scaleway.com
55/100
Medium privacy riskScaleway talks a big game on European data sovereignty, but this marketing page provides zero actual privacy policy substance to back those claims up.
View report →eustella.com
62/100
Medium privacy riskeustella makes strong privacy promises — no data selling, no third-party sharing, no AI training on your data, and all processing stays in the EU — but this is marketing copy, not a binding privacy policy, and critical details on data collection, retention, sub-processors, and user rights are absent from the provided text.
View report →linkedin.com
55/100
Medium privacy riskLinkedIn collects a vast amount of your data—including from your contacts, calendar, and across the web—uses it to train AI models with no clear opt-out, shares it extensively with Microsoft and advertisers, and retains it broadly, though EU users get some extra protections.
View report →slack.com
72/100
Medium privacy riskSlack collects a wide range of personal and usage data, relying heavily on broad legitimate interests to process it and transfer it globally, though it does provide standard GDPR rights and safeguards like Standard Contractual Clauses.
View report →berlin.de
80/100
Low privacy riskThe Berlin Senate Chancellery's privacy policy is generally strong, using two-click consent for third-party media and anonymizing IPs, though it relies on standard contractual clauses for some sub-processors outside the EEA and lacks clarity on AI training.
View report →duckduckgo.com
82/100
Low privacy riskDuckDuckGo lives up to its no-tracking promise for core search and browsing, but its growing optional features (Duck.ai, Sync & Backup) and the Microsoft ad partnership introduce data flows the policy doesn't fully explain, especially around AI training and international transfer safeguards.
View report →startpage.com
90/100
Low privacy riskStartpage offers exceptional privacy by design, collecting virtually no personal data and explicitly rejecting tracking, profiling, and search logging, though minor data flows to third-party ad and analytics providers exist.
View report →peerpush.com
55/100
Medium privacy riskPeerPush has strong anonymization practices for its public analytics but falls short on GDPR basics by failing to disclose legal bases, lacking an EU representative, and using vague language around international data transfers.
View report →bestalternatives.eu
65/100
Medium privacy riskBest European Alternatives genuinely minimizes data and avoids cookies, but uses US-based processors without addressing international transfer safeguards and omits key GDPR rights and legal details.
View report →europealternatives.com
78/100
Low privacy riskEurope Alternatives is a privacy-friendly directory that collects almost no personal data, but clicking partner links can send your data to third parties—including potentially outside the EU—with no clear safeguards described.
View report →european-alternatives.eu
45/100
High privacy riskEuropean Alternatives collects minimal data and uses privacy-friendly tools, but its privacy policy is an unfinished template with placeholder text for critical sections like data storage, retention, and deletion — making it non-compliant as-is.
View report →free.fr
58/100
Medium privacy riskFree collects a vast and vaguely defined array of personal data—including profiling scores and detailed usage metrics—shares it widely with ad networks and the Iliad group, and transfers some outside the EU, though it does clearly outline standard GDPR rights.
View report →lhv.com
62/100
Medium privacy riskLHV Bank collects a sweeping range of personal and financial data, shares it widely with fraud prevention agencies and payment intermediaries, and relies heavily on legitimate interest for marketing and analytics — but it does cover GDPR rights and uses manual review for profiling decisions.
View report →tella.com
55/100
Medium privacy riskTella collects sensitive video data and shares it with numerous US-based AI and analytics providers without clearly stating if your data trains their models, making it a mixed bag for EU users.
View report →calendly.com
65/100
Medium privacy riskCalendly collects a wide range of personal and usage data, shares it with advertising partners, and while it offers standard EU rights and transfer mechanisms, its vague retention periods and silence on AI training for its Notetaker feature are concerning.
View report →cal.com
55/100
Medium privacy riskCal.com provides standard GDPR rights and a subprocessor list, but fails to specify the legal basis for EU-to-US data transfers and remains silent on AI training data usage.
View report →gemini.com
52/100
Medium privacy riskGemini collects extensive personal and financial data as a regulated crypto exchange, shares it widely with third parties for marketing and analytics, and transfers it globally, though it provides standard GDPR rights and SCCs for EU users.
View report →privacy.claude.com
30/100
High privacy riskThis is only a navigation page for Anthropic's Privacy Center — no actual privacy policy text was provided, so a meaningful compliance assessment is impossible.
View report →zoom.com
65/100
Medium privacy riskZoom's privacy portal demonstrates significant investment in compliance infrastructure and EU-specific safeguards, but the page itself is a navigation hub rather than a substantive policy, leaving critical details about data collection, AI training, and third-party sharing behind links that weren't provided for analysis.
View report →cake.com
62/100
Medium privacy riskCAKE.com provides standard EU data rights and transfer safeguards but collects highly intrusive workplace surveillance data—like screenshots, background location, and app usage—on behalf of employers, who act as the data controllers for their employees.
View report →langdock.com
78/100
Low privacy riskLangdock is a privacy-conscious EU-based AI platform that explicitly bans using your content to train AI models and keeps data in the EU, though it relies on some US sub-processors and has vague retention periods in places.
View report →eualternative.eu
94/100
Low privacy riskNineties Engineering OÜ's website EU Alternative is a model of privacy-by-design, collecting almost no personal data, avoiding all tracking, and keeping everything hosted exclusively in the EU.
View report →dentro.chat
97/100
Low privacy riskOne of the strongest privacy policies in the AI chat space — fully EU-hosted, transparent subprocessor list, no AI training on user data, and no US-based providers.
View report →robotstxt.es
68/100
Medium privacy riskRobotstxt generally respects EU privacy but lacks clear details on legal bases, third‑party processors and AI use.
View report →kolsetu.com
85/100
Low privacy riskKolsetu generally respects EU privacy rules, but it over‑collects usage data, lacks a public DPO, and provides limited detail on some international transfers.
View report →policies.google.com
55/100
Medium privacy riskGoogle collects a very wide range of personal data, shares it broadly, and uses it for AI training with limited opt‑out options, making its privacy stance mixed at best.
View report →pcloud.com
65/100
Medium privacy riskpCloud lets you choose EU or US storage but still shares extensive personal and usage data with many parties and lacks clear limits on AI training or US‑transfer safeguards.
View report →fenritec.eu
68/100
Medium privacy riskFenritec generally respects EU privacy rules but lacks clear limits on data use for AI, proactive sub‑processor disclosure and detailed data‑minimisation statements.
View report →qdrant.tech
65/100
Medium privacy riskQdrant’s policy leans heavily on legitimate‑interest and US third‑party transfers, gives consent options for newsletters, but lacks clear limits on data collection and any mention of AI model training, making it only moderately privacy‑friendly.
View report →