gdprchat.eu — 88/100 (Low privacy risk)

Last analyzed

Run a new analysis on another policy

FRITS AI ApS · gdprchat.eu

Report details

Low privacy risk

GDPRchat offers exceptionally strong EU-centric privacy with no tracking and self-service data controls, but users should be aware that image prompts may be used for AI training by a third-party provider.

FRITS AI ApS demonstrates a strong commitment to EU data protection, keeping almost all processing within the EU and explicitly rejecting analytics and tracking. However, the exception for image generation prompts, which are sent to Black Forest Labs without a Data Processing Agreement and may be used for training, is a notable gap in an otherwise privacy-first architecture. The policy is highly transparent about data flows, subprocessors, and technical safeguards like the default-on PII Lock.

Last analyzed
SourceURL

Category Assessment

Breakdown of the policy across key compliance areas. Good = strong, fair = mixed, poor = concerning.

Data MinimizationGood

The policy explicitly rejects analytics and tracking, and defaults to masking PII client-side before transmission.

TransparencyGood

Exceptional detail is provided on cookie usage, IP processing purposes, and specific subprocessor roles and locations.

Third-party SharingFair

While most subprocessors are EU-based and barred from training, image prompts are shared with Black Forest Labs without a DPA and may be used for training.

International TransfersGood

Data is kept almost entirely within the EU, with only DPF-covered transfers to the US for optional OAuth and App Store payments.

AI/Model TrainingFair

Chat data is protected from training by DPAs, but image generation prompts are explicitly excluded from this no-training commitment.

User RightsGood

The policy clearly describes GDPR rights, provides self-service deletion and JSON export, and lists the lead supervisory authority.

Key Findings

Notable clauses, issues, or positive practices discovered (critical first)

Warning

Image Generation Training Exception

Image generation prompts are sent to Black Forest Labs without a Data Processing Agreement, meaning this provider can use user inputs to train AI models. This contradicts the no-training commitment applied to chat data and represents a significant gap in data protection for that specific feature.

Info

Long Retention of IP Addresses in Audit Logs

IP addresses and browser identifiers linked to security-relevant account events are retained for 24 months even after account deletion, relying on Art. 17(3)(e) GDPR. This is a notably long retention period for IP data, which the policy classifies as personal data.

Info

Strong Data Minimization and No Tracking

The service demonstrates strong data minimization by avoiding all third-party analytics, tracking, and advertising, and by defaulting to a client-side PII masking feature (PII Lock) that blocks sensitive data from leaving the browser.

Info

EU-Only Data Processing

Data processing is almost entirely confined to the EU (Germany, France, Netherlands), with only minimal transfers to US providers (Apple, Google, Microsoft) covered by the EU-US Data Privacy Framework for OAuth and App Store payments.

Consumer Takeaway

This is a very privacy-respecting service that keeps your data in the EU and doesn't track you, but avoid uploading sensitive personal data in image generation prompts, as that provider can use them to train AI.

Compliance Posture

Proactive and highly compliant. The controller goes beyond minimum GDPR requirements in several areas (e.g., applying a 16-year age floor across the EU, default PII masking, no tracking cookies) but carries a specific risk regarding the lack of a DPA with one subprocessor.

EU Transfers

Excellent. The service is explicitly designed to keep data within the EU (Germany, France, Netherlands). Only minimal, optional interactions (OAuth with US tech giants, iOS payments) trigger transfers to the US, which are covered by the EU-US Data Privacy Framework.

Detected Signals

Specific data points and practices identified in the text

Data Collected
NameEmail addressCryptographic hash of passwordOrganisation nameChat messagesUploaded documentsIP addressBrowser identifierAccept-Language headerVoice audio (transcribed then discarded)Coarse location coordinates (if enabled)
Processing Purposes
Service provision and conversation storageAuthentication and securityRate limiting and abuse preventionSecurity audit loggingCountry-level location estimation for VATPayment processingSpeech-to-text transcriptionReverse geocoding
Third-party Sharing
AI model providers (Mistral AI, Scaleway)Infrastructure provider (Hetzner)Image generation provider (Black Forest Labs)Payment processor (Mollie)Transactional email provider (Scaleway)Web search provider (Linkup)Price comparison provider (DataForSEO)Map tiles and geocoding (OpenStreetMap Foundation)Video embedding (YouTube)OAuth providers (Apple, Google, Microsoft)
International Transfers
EU-based processing for core servicesUS transfers for OAuth and iOS payments (EU-US DPF)UK transfer for OpenStreetMap (UK adequacy decision)
AI / Model Training
Chat providers barred from training via DPAImage generation provider (Black Forest Labs) NOT barred from training

Evidence Snippets

Direct quotes from the policy supporting these findings

Black Forest Labs' standard FLUX API Service Terms (§2(b)) grant them a perpetual licence over inputs and outputs and state that they may use them to train and improve their AI models... Image prompts are the one part of GDPRchat not covered by our no-training commitment.

Records of security-relevant account events, including the IP address and browser identifier they came from (see section 3.3), are kept for 24 months and then deleted.

GDPRchat does not use any third-party analytics, tracking, or advertising services.

PII Lock is on by default. If a piece of special category data slips through, you can delete the conversation immediately...

Missing or Unclear

  • No explicit mention of Data Protection Impact Assessment (DPIA)
  • No detail on the specific categories of data shared with Black Forest Labs beyond 'image prompts'
  • No mention of automated decision-making with legal effects (though explicitly denied for profiling)

Questions to Ask

  • What is the timeline for finalizing an enterprise agreement with Black Forest Labs that excludes training on image prompts, and will users be notified if this status changes?
  • Has a proportionality assessment been documented to justify the specific 24-month retention period for IP addresses in the security audit log, rather than a shorter timeframe?
  • How does the client-side PII Lock feature handle unstructured special category data (e.g., detailed medical narratives) that does not match standard identifiers like names or IBANs?
This analysis is generated by AI and is not legal advice. Always consult a qualified legal professional for compliance decisions.

Share this analysis

Anyone with this link can view the result above.

Built by DentroChat

100% European AI chat for everyone

Chat with AI, work with files, generate images, and search the web. Data stays in Europe.

EU-hosted infrastructureText, files, images & web searchFast, Thinking & Creative modesPrivacy-first by defaultNo data leaves Europe
Try free →
View all