gdprchat.eu — 88/100 (Low privacy risk)
Last analyzed
FRITS AI ApS · gdprchat.eu
Report details
Low privacy riskGDPRchat offers exceptionally strong EU-centric privacy with no tracking and self-service data controls, but users should be aware that image prompts may be used for AI training by a third-party provider.
FRITS AI ApS demonstrates a strong commitment to EU data protection, keeping almost all processing within the EU and explicitly rejecting analytics and tracking. However, the exception for image generation prompts, which are sent to Black Forest Labs without a Data Processing Agreement and may be used for training, is a notable gap in an otherwise privacy-first architecture. The policy is highly transparent about data flows, subprocessors, and technical safeguards like the default-on PII Lock.
Category Assessment
Breakdown of the policy across key compliance areas. Good = strong, fair = mixed, poor = concerning.
The policy explicitly rejects analytics and tracking, and defaults to masking PII client-side before transmission.
Exceptional detail is provided on cookie usage, IP processing purposes, and specific subprocessor roles and locations.
While most subprocessors are EU-based and barred from training, image prompts are shared with Black Forest Labs without a DPA and may be used for training.
Data is kept almost entirely within the EU, with only DPF-covered transfers to the US for optional OAuth and App Store payments.
Chat data is protected from training by DPAs, but image generation prompts are explicitly excluded from this no-training commitment.
The policy clearly describes GDPR rights, provides self-service deletion and JSON export, and lists the lead supervisory authority.
Key Findings
Notable clauses, issues, or positive practices discovered (critical first)
Image Generation Training Exception
Image generation prompts are sent to Black Forest Labs without a Data Processing Agreement, meaning this provider can use user inputs to train AI models. This contradicts the no-training commitment applied to chat data and represents a significant gap in data protection for that specific feature.
Long Retention of IP Addresses in Audit Logs
IP addresses and browser identifiers linked to security-relevant account events are retained for 24 months even after account deletion, relying on Art. 17(3)(e) GDPR. This is a notably long retention period for IP data, which the policy classifies as personal data.
Strong Data Minimization and No Tracking
The service demonstrates strong data minimization by avoiding all third-party analytics, tracking, and advertising, and by defaulting to a client-side PII masking feature (PII Lock) that blocks sensitive data from leaving the browser.
EU-Only Data Processing
Data processing is almost entirely confined to the EU (Germany, France, Netherlands), with only minimal transfers to US providers (Apple, Google, Microsoft) covered by the EU-US Data Privacy Framework for OAuth and App Store payments.
Consumer Takeaway
This is a very privacy-respecting service that keeps your data in the EU and doesn't track you, but avoid uploading sensitive personal data in image generation prompts, as that provider can use them to train AI.
Compliance Posture
Proactive and highly compliant. The controller goes beyond minimum GDPR requirements in several areas (e.g., applying a 16-year age floor across the EU, default PII masking, no tracking cookies) but carries a specific risk regarding the lack of a DPA with one subprocessor.
EU Transfers
Excellent. The service is explicitly designed to keep data within the EU (Germany, France, Netherlands). Only minimal, optional interactions (OAuth with US tech giants, iOS payments) trigger transfers to the US, which are covered by the EU-US Data Privacy Framework.
Detected Signals
Specific data points and practices identified in the text
Evidence Snippets
Direct quotes from the policy supporting these findings
Black Forest Labs' standard FLUX API Service Terms (§2(b)) grant them a perpetual licence over inputs and outputs and state that they may use them to train and improve their AI models... Image prompts are the one part of GDPRchat not covered by our no-training commitment.
Records of security-relevant account events, including the IP address and browser identifier they came from (see section 3.3), are kept for 24 months and then deleted.
GDPRchat does not use any third-party analytics, tracking, or advertising services.
PII Lock is on by default. If a piece of special category data slips through, you can delete the conversation immediately...
Missing or Unclear
- No explicit mention of Data Protection Impact Assessment (DPIA)
- No detail on the specific categories of data shared with Black Forest Labs beyond 'image prompts'
- No mention of automated decision-making with legal effects (though explicitly denied for profiling)
Questions to Ask
- What is the timeline for finalizing an enterprise agreement with Black Forest Labs that excludes training on image prompts, and will users be notified if this status changes?
- Has a proportionality assessment been documented to justify the specific 24-month retention period for IP addresses in the security audit log, rather than a shorter timeframe?
- How does the client-side PII Lock feature handle unstructured special category data (e.g., detailed medical narratives) that does not match standard identifiers like names or IBANs?
Share this analysis
Anyone with this link can view the result above.
Built by DentroChat
100% European AI chat for everyone
Chat with AI, work with files, generate images, and search the web. Data stays in Europe.
Other analysed privacy policies
View allproton.me
88/100
Low privacy riskProton offers strong privacy by default with end-to-end encryption, minimal data collection, and no ad tracking, though some user data does flow to US-based processors for support and payments.
View report →startpage.com
90/100
Low privacy riskStartpage offers exceptional privacy by design, collecting virtually no personal data and explicitly rejecting tracking, profiling, and search logging, though minor data flows to third-party ad and analytics providers exist.
View report →kolsetu.com
85/100
Low privacy riskKolsetu generally respects EU privacy rules, but it over‑collects usage data, lacks a public DPO, and provides limited detail on some international transfers.
View report →greenpt.com
82/100
Low privacy riskGreenPT offers strong EU data sovereignty and minimal tracking, but its policy is suspiciously silent on whether your chat data is used to train AI models, and it relies on a weak safeguard for US-based search transfers.
View report →