
Rybbit
Partially CompliantOpen-source analytics with session replay and an EU-hosted cloud on Hetzner. Widely adopted, but it never names the company behind it.

GDPR Compliance Data
Not independently verified| GDPR Status | Partially Compliant |
| HQ Country | Not disclosed |
| Ownership | Not yet verified |
| Foreign Disclosure Exposure | Not yet verified |
| Data Hosting Location | European UnionRybbit's site states "EU-hosted cloud", and its DPA names Hetzner for "Servers and storage" and Cloudflare for "Object storage and security". |
| EU Servers Available | |
| Data Processing Agreement | View DPA |
| Sub-processor List | Not verified |
| Schrems II Risk | Unknown |
| SCCs in Place |
How we reached this
No legal entity is published anywhere: not on the website, not on the GitHub organisation, and not in the Data Processing Agreement, which identifies the counterparty only as "Rybbit ('Processor', 'we', 'us')" with no company name, address or registration number. That matters practically rather than pedantically, because a DPA is a contract and you cannot establish whose law governs it or who is liable under it. The DPA does name sub-processors: Hetzner (servers and storage), Cloudflare (object storage and security), Stripe, Resend and Maxmind. The site states the cloud is EU-hosted, and Hetzner is German, so EU data residency is plausible but rests on the vendor's word. AGPL-3.0 licensed and self-hostable, which is the configuration where the unknown ownership stops mattering. Ownership and exposure recorded UNKNOWN rather than assumed.
About Rybbit
Rybbit is an AGPL-licensed analytics platform covering autocapture, session replay, funnels, user journeys and Core Web Vitals behind a single script, with an MCP server for querying it from an AI assistant. Its cloud is described as EU-hosted and its DPA names Hetzner and Cloudflare as sub-processors. Customers listed include Bosch, Texas Instruments and GOV.UK. What it does not publish is who operates it.
Key Features
Pros & Cons
Rybbit GDPR & data protection: common questions
Is Rybbit GDPR compliant?
Partly. Rybbit meets some of the requirements, with caveats worth reading before you commit. data is hosted within the European Union, and a Data Processing Agreement is published.
Where does Rybbit store data?
Rybbit states: "Rybbit's site states "EU-hosted cloud", and its DPA names Hetzner for "Servers and storage" and Cloudflare for "Object storage and security".". Data is hosted within the European Union.
Does Rybbit offer a Data Processing Agreement (DPA)?
Yes. Rybbit publishes a DPA at https://rybbit.com/dpa. A DPA is required under Article 28 GDPR whenever a provider processes personal data on your behalf.
What a DPA has to cover →Is Rybbit a European company?
We have not verified Rybbit's ultimate ownership.
Related Tools

Plausible Analytics
Lightweight, open-source, cookie-free web analytics. Fully GDPR compliant with EU data hosting.

Matomo
Leading open-source web analytics. Self-host in the EU or use cloud with EU hosting.

Mouseflow
Heatmaps, session replay, and behavior analytics. Danish company with EU-only data processing.
Spotted something wrong?
Martech moves fast. Vendors change hosting regions, get acquired, publish a new DPA or rewrite their pricing, and they rarely announce it. We check what we publish and date every compliance review, but some of what you see here will be out of date before we catch it.
If you work at Rybbit and something on this page is wrong, tell us and we will fix it. Readers, same invitation. Pointing us at the page that proves it gets it changed fastest.