camocopy.com — 92/100 (Low privacy risk)
Last analyzed
Restoflix Sàrl.-s · camocopy.com
Report details
Low privacy riskCamocopy is a highly privacy-friendly AI assistant from Luxembourg that minimizes data collection, keeps all data in the EU, and avoids third-party tracking or advertising.
Camocopy demonstrates strong EU privacy compliance by strictly limiting data collection (e.g., only email for registration, anonymized IP hashes), processing all data within the EU, and using DPAs with all processors (Hetzner, Scaleway, Nebius, Microsoft, AWS, Google). It avoids performance/advertising cookies, third-party tracking, and unnecessary data sharing. However, it uses non-EU AI model providers (OpenAI via Microsoft, Anthropic via AWS, Google) with SCCs, and lacks explicit opt-outs for AI model training. User rights are clearly outlined, and retention periods are purpose-limited.
Category Assessment
Breakdown of the policy across key compliance areas. Good = strong, fair = mixed, poor = concerning.
Collects only essential data (email for registration, anonymized IP hashes, device/browser metadata) and avoids unnecessary tracking or profiling.
Policy is detailed, specific, and clearly explains data types, purposes, legal bases, and processors, though AI training opt-outs are not explicitly addressed.
Shares data only with necessary EU-based processors (hosting, payment, CDN) under DPAs, with no evidence of sharing for ads or analytics.
Data stays in the EU by default, but non-EU sub-processors (e.g., Microsoft/Google US entities) are used with SCCs, introducing residual transfer risk.
No explicit statement on whether user data is used to train AI models, nor is there an opt-out mechanism described.
All GDPR rights (access, rectification, deletion, portability, objection, withdrawal of consent) are clearly listed and actionable via settings or email.
Key Findings
Notable clauses, issues, or positive practices discovered (critical first)
Lack of clarity on AI model training and opt-outs
The policy does not explicitly state whether user interactions with the AI assistant (e.g., chat logs) are used to train Camocopy’s or third-party models (OpenAI, Anthropic, Google). There is no mention of an opt-out for AI training, which is a growing expectation under GDPR (Art. 22, 6(1)(a)) and emerging EU AI Act guidance. This is a critical gap for a privacy-focused AI service.
Use of non-EU AI model providers with SCCs introduces transfer risk
While primary processing occurs in the EU, Camocopy uses Microsoft (Ireland), AWS (Luxembourg), and Google Cloud (Ireland) as AI model providers, which may transfer data to their US parent companies (Microsoft Corporation, Google LLC) or sub-processors. SCCs are in place, but this does not eliminate the risk of US government access under laws like FISA 702 or the CLOUD Act. The policy does not clarify whether user prompts/responses are logged or used for model training by these providers.
Reseller data flows are not controlled by Camocopy
Camocopy links to resellers (Digistore24, Creem.io) but states that 'our servers do not transmit data to [them]'; instead, user browsers send data directly. This means Camocopy has no control over or visibility into how these resellers process data, which could create compliance gaps if users are unaware they are leaving Camocopy’s privacy framework.
Strong data minimization and EU-only processing by default
Camocopy collects only essential data (email, anonymized IP hashes, device/browser metadata) and explicitly states that 'information collected from users never leaves the EU.' Hosting providers (Hetzner, Scaleway, Nebius) and CDN (Bunny.net) are all EU-based, with DPAs in place. This aligns with GDPR principles of data minimization and storage limitation (Art. 5(1)(c), (e)).
No performance, advertising, or third-party cookies
Camocopy explicitly states it does not use performance, advertising, or third-party cookies, which is a strong privacy signal. Only strictly necessary first-party cookies (e.g., session, language, XSRF tokens) are used, with short durations (1 hour to 30 days).
Consumer Takeaway
You can trust Camocopy with your data: it collects very little, keeps it in the EU, and doesn’t sell or share it for ads. But if you’re concerned about AI model training or non-EU sub-processors, ask them directly for details.
Compliance Posture
Strong GDPR compliance with clear legal bases, DPAs, and EU-only processing, but reliance on SCCs for non-EU sub-processors (e.g., Microsoft Corporation, Google LLC) introduces residual risk. No evidence of non-compliance, but transparency could improve on AI training opt-outs and sub-processor chains.
EU Transfers
Data is primarily processed in the EU, but transfers to non-EU sub-processors (e.g., Microsoft Corporation, Google LLC, Anthropic) occur under SCCs. This meets GDPR requirements but carries inherent risk due to potential US government access (e.g., FISA 702).
Detected Signals
Specific data points and practices identified in the text
Evidence Snippets
Direct quotes from the policy supporting these findings
The privacy of the application's users is a top priority. As a European company based in Luxembourg, we place great emphasis on adhering to strict data protection guidelines and ensure that users' personal data is not misused and that the information collected from users never leaves the EU.
We only collect and use personal data of our users to the extent necessary for providing a functional website, as well as our content and services.
We only engage companies based in the EU as partners for our services, ensuring that your data never leaves the EU.
The Data Processing Addendum (DPA) incorporates the EU Standard Contractual Clauses (SCC) and thus provides sufficient guarantees within the meaning of Art. 46 et seq. GDPR. The SCCs apply in particular to data transfers to affiliated companies or sub-processors outside the EU/EEA, such as Microsoft Corporation in the USA.
Our website does not use performance cookies. Our website does not use advertising cookies. Our website does not use third-party cookies.
Texts and data exchanged via the chat interface with the AI assistant are processed by AI models hosted on these servers.
Missing or Unclear
- Explicit confirmation that user prompts/responses are NOT used to train Camocopy’s or third-party AI models
- Opt-out mechanism for AI model training (if applicable)
- Details on data retention periods for chat logs and AI interaction data
- Clarification on whether Microsoft/AWS/Google log or retain user prompts/responses for their own purposes
- Sub-processor list for AI model providers (e.g., full chain of sub-processors for Microsoft, AWS, Google)
- Explanation of how anonymized IP hashes are generated and whether they can be re-identified
- Data protection impact assessment (DPIA) for AI processing activities
Questions to Ask
- Does Camocopy or any of its AI model providers (Microsoft, AWS, Google) use user prompts, responses, or other interaction data to train or improve AI models? If so, how can users opt out?
- Can you provide a full list of all sub-processors involved in AI model inference, including their locations and the legal mechanisms (e.g., SCCs, adequacy) used for transfers?
- What is the retention period for chat logs and other data generated through the use of the AI assistant? Are these logs deleted after a session or retained for a specific period?
- How are anonymized IP address hashes generated, and is there any risk of re-identification?
- Do Microsoft, AWS, or Google retain or log user prompts/responses for their own purposes (e.g., model improvement, auditing)? If so, under what legal basis and for how long?
- Has Camocopy conducted a Data Protection Impact Assessment (DPIA) for its AI processing activities, and can you share the results or a summary?
- Are there any circumstances under which Camocopy would share user data with non-EU entities outside of the SCC framework (e.g., for legal requests)?
Share this analysis
Anyone with this link can view the result above.
Built by DentroChat
100% European AI chat for everyone
Chat with AI, work with files, generate images, and search the web. Data stays in Europe.
Other analysed privacy policies
View allstartpage.com
90/100
Low privacy riskStartpage offers exceptional privacy by design, collecting virtually no personal data and explicitly rejecting tracking, profiling, and search logging, though minor data flows to third-party ad and analytics providers exist.
View report →eualternative.eu
94/100
Low privacy riskNineties Engineering OÜ's website EU Alternative is a model of privacy-by-design, collecting almost no personal data, avoiding all tracking, and keeping everything hosted exclusively in the EU.
View report →gdprchat.eu
88/100
Low privacy riskGDPRchat offers exceptionally strong EU-centric privacy with no tracking and self-service data controls, but users should be aware that image prompts may be used for AI training by a third-party provider.
View report →proton.me
88/100
Low privacy riskProton offers strong privacy by default with end-to-end encryption, minimal data collection, and no ad tracking, though some user data does flow to US-based processors for support and payments.
View report →