Anytype
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based This listing EU-operated, with at most minor or transient US exposure.
-
EU-Hosted EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Local-first peer-to-peer E2E-encrypted knowledge OS published by a Swiss association in Zug (Anytype, 2019); Any Source Available License; data lives on user device.
Anytype is a European service hosted in Switzerland, with at most minor, transient US exposure under the CLOUD Act. It is listed under Docs & wikis.
Assessment notes
Anytype is a local-first, peer-to-peer, end-to-end-encrypted knowledge OS for macOS / Windows / Linux published by Any Association, a Swiss association registered c/o Sielva Management AG, Gubelstrasse 11, CH-6300 Zug. The Berlin entity Anylab GmbH appears in the privacy policy only as the Article 27 GDPR representative in the EU, which is the construct used by a controller established outside the EU, not as the controller itself. Source code published under Any Source Available License 1.0 (source-available with anti-competitive-hosting clause; the company opened repositories to its 100,000-strong community); 7,000+ GitHub stars. Local-first architecture means data lives on the user's device with peer-to-peer sync, and anything synced to the Anytype Network is end-to-end encrypted, so no server holds plaintext customer content. The Anytype Network is stated to run in Switzerland and the European Union. Funded through €13.4M raise. Signals: Swiss (non-EU) controller under the Swiss adequacy decision rather than an EU entity, end-to-end encrypted content, source-available codebase. Gaps: no publicly accessible DPA, only privacy policies and legal pages that EU buyers cannot self-serve a processor agreement from; and the July 2026 privacy policy names five US service providers (Amplitude for analytics, Stripe for payments, Typeform for surveys, Twilio SendGrid and Loops for email), so account metadata is processed in the United States under SCCs even though document content never is.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned EU-incorporated and EU-controlled; no significant US ownership.
-
European This listing Swiss/EEA-owned, with no significant US ownership; treated as European.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
- Sub-processors
- 0 none disclosed
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: Not assessed
-
Public DPA: No
-
Sub-processors disclosed: Yes
-
Open-source clients: Yes
-
Third-party certification: No
Exposure depends on how you run this product.
Vendor-operated: the sub-processors below apply.
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Deploy on your own EU infrastructure and you control hosting and every sub-processor.
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Jump to
About Anytype
Anytype is a knowledge-management platform published by Any Association, a Swiss association registered c/o Sielva Management AG in Zug, built around an unusual architecture in the docs-and-wikis category: local-first, peer-to-peer synchronization, end-to-end encryption. Customer data lives on the user's device (macOS, Windows, Linux, plus mobile) with peer-to-peer sync between the user's own devices and any team / shared workspaces. The central Anytype servers never hold plaintext customer data; encryption is end-to-end with customer-controlled keys. The product positions itself as an offline-first, private alternative to Notion / Obsidian / Roam Research, marketed under the tagline "A safe haven for digital collaboration."
Source code is published on GitHub under the Any Source Available License 1.0, a source-available licence with an anti-competitive-hosting clause that lets customers inspect, audit, and self-modify the codebase but prevents running a competing managed service. The company has opened repositories to its 100,000-strong community and accumulated 7,000+ GitHub stars across the various repositories (anyproto/anytype-ts and others). Funding totals approximately €13.4M; the specific investor list did not surface at audit. The Berlin entity Anylab GmbH appears in the privacy policy only as the designated Article 27 GDPR representative in the EU, the construct used by a controller established outside the EU, rather than as the operating company.
For an EU-sovereignty audit the architecture is the strongest part of this listing. Local-first is structurally the strongest data-residency posture available: customer data is on the customer's device by default, never in plaintext on any cloud, and the privacy policy states that the Anytype Network is maintained in Switzerland and the European Union. The corporate side is Swiss rather than EU: the controller is Any Association in Zug, covered by the Swiss adequacy decision, with no US-VC control on record and a source-available licence with reasonable restrictions. The July 2026 privacy policy also names five US service providers, Amplitude for analytics, Stripe for payments, Typeform for surveys, and Twilio SendGrid and Loops for transactional email, so account metadata is processed in the United States under SCCs even though document content never is, and CLOUD Act exposure is recorded as Minor on that metadata path. Best fit: privacy-maximalist knowledge workers, researchers, journalists, and EU SMBs / agencies wanting a Notion alternative with offline + E2E architecture; teams replacing Obsidian or Roam with a multi-device sync option that doesn't depend on a central cloud.
Sub-processor map · none disclosed
Frameworks & certifications · none listed
Capability matrix
Table 1Capabilities of Anytype
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
United Kingdom · €0/moEU-BasedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Not assessed Sub-processors: No Open source: Yes -
-
United Kingdom · €3/moEU-BasedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: No Sub-processors: No Open source: Yes -
-
France · €5/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Not assessed Sub-processors: No Open source: Yes -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Based | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Not assessed
Sub-processors: No
Open source: Yes
|
€0/mo |
|
|
EU-Based | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: No
Open source: Yes
|
€3/mo |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Not assessed
Sub-processors: No
Open source: Yes
|
€5/mo |