Threema
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign This listing EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Swiss E2EE messenger (Pfäffikon SZ, founded 2012), own servers in ISO 27001-certified Swiss data centres, no phone number required; consumer + enterprise (Threema Work) + on-prem.
Threema is an EU-owned service hosted in Switzerland, with no identified CLOUD Act exposure. It is listed under Video conferencing.
Assessment notes
Threema GmbH (Pfäffikon SZ, Switzerland, CHE-221.440.104) runs its own hardware in two physically separated, redundant data centres in the Zurich area and processes personal data for all essential functions exclusively on those Swiss servers, publishes a DPA and a named sub-processor annex without a login, ships open-source clients with reproducible builds, and is Swiss-incorporated with EU adequacy: no CLOUD Act exposure for EU or Swiss data subjects. Correction at the 2026-08 re-verify: the ISO 27001 certificate belongs to Threema's colocation partner, not to Threema GmbH — the vendor's own wording is that it "runs its own servers in data centers of an ISO 27001-certified collocation partner" — so certifications is now empty rather than claiming a certification Threema does not itself hold. The sub-processor annex names only four parties: two Swiss SMS providers, Leaseweb Netherlands BV operating the Selective Forwarding Units that route end-to-end encrypted group calls, and Twilio Inc. (USA) restricted to phone-number verification for data subjects outside Switzerland, the EU and the EEA.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned EU-incorporated and EU-controlled; no significant US ownership.
-
European This listing Swiss/EEA-owned, with no significant US ownership; treated as European.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
- Sub-processors
- 4 · 1 US
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: Yes
-
Public DPA: Yes
-
Sub-processors disclosed: Yes
-
Open-source clients: Yes
-
Third-party certification: No
Jump to
About Threema
Threema is a Swiss end-to-end encrypted messaging application developed and operated by Threema GmbH (Pfäffikon SZ, Switzerland, Commercial Register: CHE-221.440.104), founded in December 2012 by three Swiss developers as a privacy-first alternative to WhatsApp, launching on Apple's App Store the same month the app was conceived. The legal entity was formally registered as Threema GmbH in spring 2014 to support professional expansion. Key milestones: post-Snowden traction in 2013, Threema Work (business edition) launched 2016, surpassed 10 million users in early 2021 following WhatsApp's controversial terms-of-service update, and a new CEO appointed in 2024.
The product portfolio is three-tier. Threema Private (consumer): one-off purchase app for iOS + Android + desktop, no phone number or email required for sign-up; fully anonymous use possible. Threema Work (business): managed admin console, MDM integration, enforced encryption policies, SSO via SAML/OIDC, priced at €3/user/month (Core) or €5/user/month (Professional); 30-day free trial for up to 30 users. Threema OnPrem (self-hosted): the full Threema Work stack deployable on customer infrastructure, for buyers who require complete data sovereignty inside their own security perimeter. All three tiers share the same cryptographic core: end-to-end encrypted messages, voice calls, video calls, group chats, file transfers, and polls using the NaCl/libsodium cryptography library; encryption by default with no plaintext fallback.
Compliance posture is among the strongest in the messenger category. Threema runs its own hardware in two physically separated, redundant data centres in the Zurich area, operated by an ISO 27001-certified colocation partner; the vendor's own wording places that certificate with the partner rather than with Threema GmbH. Data processing for all essential functions runs on those Swiss servers (confirmed in the publicly available DPA), with one documented exception: end-to-end encrypted group calls are routed through Selective Forwarding Units operated by Leaseweb Netherlands BV in the Netherlands, an intra-EEA flow in which the forwarder only ever handles ciphertext. Switzerland holds an EU adequacy decision (Art. 45 GDPR), SCC-free for EU↔CH transfers. The DPA (threema.com/en/dpa) is publicly accessible without login and references standard contractual safeguards for any third-party functions. The company explicitly positions Threema as compliant with NIS 2, DORA, and CER EU directives. Ownership: Threema was acquired by Comitis Capital GmbH (a German investment firm focused on purpose-driven companies) from Afinum Management GmbH in early 2026, still EU-controlled, no US capital. Open-source: a Google-free Android version (Threema Libre) ships via F-Droid with reproducible builds for independent verification; the app source code is publicly auditable. Best fit: privacy-conscious individuals replacing WhatsApp or Signal with a Swiss-hosted option; German and EU enterprises needing an auditable E2EE messaging platform under their own IT control; regulated sectors subject to NIS 2 / DORA that need a compliant internal comms layer.
Sub-processor map · 4
-
Twilio Inc. USUnited States
Telephone number verification for data subjects outside Switzerland/EU/EEA only
-
F24 Schweiz AG EUSwitzerland
Telephone number verification SMS
-
Leaseweb Netherlands BV EUNetherlands
Selective Forwarding Units routing end-to-end encrypted group calls
-
Swissphone Wireless AG EUSwitzerland
Telephone number verification SMS
| Vendor | Country | Purpose | Owner |
|---|---|---|---|
| Twilio Inc. | United States | Telephone number verification for data subjects outside Switzerland/EU/EEA only | US |
| F24 Schweiz AG | Switzerland | Telephone number verification SMS | EU |
| Leaseweb Netherlands BV | Netherlands | Selective Forwarding Units routing end-to-end encrypted group calls | EU |
| Swissphone Wireless AG | Switzerland | Telephone number verification SMS | EU |
Source: the vendor’s published sub-processor list, read 26 Aug 2026.
Frameworks & certifications · none listed
Capability matrix
Table 2Capabilities of Threema
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
United KingdomEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: Yes -
-
SwitzerlandEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
France · €10/moEU-BasedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: No Sub-processors: No Open source: Yes -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: Yes
|
— |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
— |
|
|
EU-Based | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: No
Open source: Yes
|
€10/mo |