TelemetryDeck
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted This listing EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
German privacy-first mobile + web app analytics with on-device anonymisation, EN/DE DPA, and a transparent sub-processors list.
TelemetryDeck offers EU hosting in Germany, but a US parent or sub-processor leaves material CLOUD Act exposure. It is listed under Web analytics.
Assessment notes
German GmbH (Augsburg) with on-device anonymisation, public DPA + AVV in EN/DE and a transparent named sub-processors list, but the infrastructure mix includes Microsoft Ireland (Azure, US-owned, EU-region), AWS Inc. (Seattle), and HubSpot (US) alongside Hetzner Gunzenhausen, so customer signal data sits across multiple US-owned hyperscalers; EU-owned with a public DPA and disclosed sub-processors, but material CLOUD Act exposure due to Azure and AWS handling customer data at rest.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned This listing EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- 5 · 3 US
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: No
-
Public DPA: Yes
-
Sub-processors disclosed: Yes
-
Open-source clients: No
-
Third-party certification: No
Jump to
About TelemetryDeck
TelemetryDeck is an Augsburg-headquartered privacy-first mobile and web app analytics platform operated by TelemetryDeck GmbH (Von-der-Tann-Str. 54, 86159 Augsburg, Germany), founded in 2020 by Daniel and Lisa during the pandemic and serving more than 6,000 developers across iOS, Android, Flutter, React Native, and the web. The differentiator is on-device anonymisation: signals are hashed before they ever leave the device, so the dashboard sees only aggregate, non-identifying data, which makes app-store privacy nutrition labels trivial and removes the need for in-app tracking consent in most jurisdictions.
Trust documentation is unusually thorough for a small German vendor: a publicly-linked DPA in English, an AVV (Auftragsverarbeitungsvertrag) in German, a transparent privacy policy (last updated 30 June 2025) that names every sub-processor with its full legal address, and Standard Contractual Clauses (EU-Standarddatenschutzklauseln) cited for any third-country transfers. The infrastructure side is more mixed than the brand suggests, however. The privacy policy lists three hosting providers: Hetzner Online GmbH in Gunzenhausen (EU-owned, EU region), Microsoft Ireland Operations Ltd. in Dublin (Azure, US-owned hyperscaler in an EU region), and Amazon Web Services, Inc. (Seattle legal-entity address, region unclear), which means a non-trivial portion of customer signal data at rest sits with US-owned hyperscalers. Other sub-processors include HubSpot (US, contact management), Brevo (DE, newsletter), Meta Ireland (Instagram embed), X Corp Ireland (Twitter embed), GitHub (US, code-hosting widget), and Mastodon (DE, social embed). Per the directory's strict CLOUD Act stance, where provider ownership matters more than data-centre region (Schrems II / Microsoft Ireland v US), this combination is material CLOUD Act exposure despite an otherwise excellent transparency posture.
Pricing is freemium: 100,000 signals/month free for indie developers, with paid plans starting around €9/month; annual billing offered with 20% discount. Awards: CDR Corporate Digital Responsibility 2024, MyData Award 2025, Augusta Wirtschaftspreis für Frauen. Best fit: indie iOS/Android/Flutter developers and small mobile-app shops who want on-device privacy with a clean DPA story and don't mind the Azure-EU + AWS dependency. Procurement-grade enterprise mobile teams with strict no-US-cloud requirements should look at self-hosted Matomo for mobile, or evaluate whether the Hetzner-only data path can be selected explicitly with TelemetryDeck.
Sub-processor map · 5
-
Amazon Web Services, Inc. USUnited States
Hosting (analytics infrastructure, eu-central-1 Frankfurt)
-
HubSpot Inc. USUnited States
CRM
-
Microsoft Ireland Operations Ltd. USIreland
Hosting
-
Hetzner Online GmbH EUGermany
Hosting
-
Sendinblue GmbH (Brevo) EUGermany
Newsletter
| Vendor | Country | Purpose | Owner |
|---|---|---|---|
| Amazon Web Services, Inc. | United States | Hosting (analytics infrastructure, eu-central-1 Frankfurt) | US |
| HubSpot Inc. | United States | CRM | US |
| Microsoft Ireland Operations Ltd. | Ireland | Hosting | US |
| Hetzner Online GmbH | Germany | Hosting | EU |
| Sendinblue GmbH (Brevo) | Germany | Newsletter | EU |
Source: the vendor’s published sub-processor list, read 26 Aug 2026.
Frameworks & certifications · none listed
Capability matrix
Table 2Capabilities of TelemetryDeck
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
IrelandEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Not assessed Sub-processors: Yes Open source: Yes -
-
New Zealand · €29/moEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: Yes -
-
Germany · $6/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Not assessed
Sub-processors: Yes
Open source: Yes
|
— |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: Yes
|
€29/mo |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
$6/mo |