Skip to content
Independently verified · Quarterly re-audit
EU VETTED
INSIGHT

The state of US exposure in European web analytics, 2026

We verified 10 European and privacy-first web analytics tools against their published sub-processor lists and ownership records. 4 operate with no US exposure anywhere in the visitor-data path.

By EU Vetted Editorial Published DISCLOSURE Some links on this site are affiliate links. We may earn a commission at no extra cost to you. Editorial signals and rankings are never influenced by affiliate relationships.

Of 10 European analytics tools, 4 are fully clear of US exposure

Web analytics is the healthiest category in our directory by this measure: 4 of 10 tools run their entire visitor-data path on EU-incorporated infrastructure with no US parent above them. The surprises are elsewhere, in well-known names that read as clean and are not. We checked every tool against its own published sub-processor list, DPA and ownership records, and classified each on our four-level CLOUD Act exposure scale (none, minor, material, direct).

CLOUD Act exposure Tools
None 4
Minor 2
Material 3
Direct 1
Any exposure 6

Every tool, and where the exposure enters

Tool Country Ownership Hosting CLOUD Act exposure Where it enters
Plausible Analytics Estonia EU-owned Germany None Bootstrapped Estonian company; analytics run on Hetzner (DE), Bunny (SI) and UpCloud (FI), with the few US sub-processors ancillary and off the analytics data path
Pirsch Analytics Germany EU-owned Germany None German GmbH with analytics data at rest on Hetzner; US sub-processors are limited to ancillary functions such as payments and CAPTCHA
Simple Analytics Netherlands EU-owned Netherlands None Dutch company on Worldstream and Leaseweb (NL) plus Bunny CDN (SI), with zero-knowledge encryption; the gap is a missing unified public DPA
GoatCounter Ireland EU-owned Germany None Open-source project run from Ireland on Hetzner (DE and FI), no third-party sharing; no formal DPA artefact, which matters for procurement but not jurisdiction
Wide Angle Analytics Germany EU-owned France Minor Berlin GmbH on European cloud infrastructure (OVHcloud Open Trusted Cloud catalogue); the DPA is not self-servable and must be requested from support
Trackboxx Germany EU-owned Germany Minor German product, but the at-rest hosting provider is not publicly disclosed and AWS Simple Email Service (US) handles newsletter email
Matomo New Zealand Other Germany Material The controlling entity is InnoCraft Limited (New Zealand) and Matomo Cloud stores customer data at rest on AWS (EU region); the on-premise edition avoids both
TelemetryDeck Germany EU-owned Germany Material German GmbH with an admirably transparent sub-processor list, which is exactly how we know Azure and AWS handle customer signal data at rest alongside Hetzner
PostHog United Kingdom EU HQ, US-funded US or EU (Frankfurt) region Material London-founded but Y Combinator and Google Ventures anchor the cap table, and the managed cloud runs US and EU regions
Umami United States US-owned DE region available Direct Umami Software, Inc. is a Delaware C-Corp; the MIT-licensed self-host path on EU infrastructure removes the vendor exposure entirely

Two patterns are worth reading out of this table. First, privacy engineering and jurisdiction are different axes: Matomo and TelemetryDeck are serious privacy products, and both still classify material because of who owns the entity or what the data sits on at rest. TelemetryDeck deserves credit for being the reason we can say so precisely, since its sub-processor disclosure is among the most transparent in the category. Second, open source changes the answer: Matomo on-premise and self-hosted Umami run entirely on infrastructure the customer chooses, which removes the exposure their managed clouds carry. The verdicts in this table are for the hosted products, since that is what most buyers deploy.

Our four-level classification records whether customer data could fall under US extraterritorial reach: none (EU/EEA/Swiss operator, no US parent, no notable US sub-processor), minor (a transient US sub-processor such as a CDN, with data at rest staying in the EU), material (a US parent or US-owned hyperscaler in the core data path), and direct (the operator itself is US-incorporated). For web analytics the data path we read is specific: where visitor events are stored at rest, what serves the tracking script, and who owns and finances the operator.

Sources are the vendors' own published documents: sub-processor lists, DPA annexes and ownership records, re-checked quarterly. Every figure and verdict on this page renders live from the dataset, so the page updates when a re-verification changes a classification. The cross-category picture is in our CLOUD Act exposure analysis; the same tools compared as Google Analytics replacements are in best European Google Analytics alternatives and on the Google Analytics alternatives page; all listings with per-tool detail are on the web analytics category page.

The figures on this page may be republished with attribution. Cite as "Source: EU Vetted, verified July 2026" and link to this page. Numbers render live from our dataset and change when a quarterly re-verification changes a classification, so the link, not a copied figure, is the durable reference.

Frequently asked questions

Which European web analytics tools have no US exposure in 2026?
Of the 10 tools we verified, 4 operate with no US parent and no US-incorporated sub-processor in the visitor-data path: Plausible Analytics (Estonia), Pirsch Analytics (Germany), Simple Analytics (Netherlands) and GoatCounter (Ireland). The full per-tool breakdown, including where the exposure enters for the others, is in the table on this page.
Is a privacy-focused analytics tool automatically outside the CLOUD Act?
No. Cookieless tracking and IP anonymisation address GDPR questions, not jurisdiction. A tool can collect nothing personal and still store its data on a US-owned hyperscaler, answer to a US corporate parent, or run on US capital. That is why 6 of 10 tools in this snapshot carry some exposure despite privacy-first positioning across the category.
How is this data verified and how often is it updated?
Each tool is checked against its own published sub-processor list, DPA and ownership records, and re-verified quarterly. Figures on this page render live from the dataset, so they update when a re-verification changes a classification.
METHODOLOGY

For every product we read the public DPA, sub-processors document, hosting region declaration, and corporate ownership records. Each is timestamped. Signals are editorial, re-verified quarterly. We never accept self-attestation.

Read methodology →