Sovereignty
eustella defines digital sovereignty as control over the full AI stack — the models, the infrastructure, and the data. Not where something was built, but who decides how it runs and where your data lives.
Our Position
Sovereignty means control, not origin
eustella does not ask where an AI model comes from. eustella asks who controls it. A closed API model from California sends every prompt, every document, and every conversation to servers outside European jurisdiction. An open-source model, by contrast, can be hosted on European infrastructure, audited, adapted for European languages, and taken offline entirely.
Sovereignty is not a flag over a training cluster. Sovereignty is the ability to decide what your AI does, where it runs, who can access the data it processes — and under which law that data is protected.
eustella runs every model on EU-based servers operated by European cloud providers. No API calls leave European territory. No US or Chinese corporation can revoke access, change model behaviour, or harvest user data. That is what digital sovereignty looks like in practice.
The US CLOUD Act Problem
Why an EU data centre address is not enough
Many AI startups claim to be European and GDPR-compliant because they host on AWS, Microsoft Azure, or Google Cloud in an EU region. This is misleading. Under the US CLOUD Act (Clarifying Lawful Overseas Use of Data Act, 2018), US authorities can compel any US-headquartered company to hand over data stored on its servers — regardless of where those servers are physically located. An AWS data centre in Frankfurt is still subject to US law.
This is not a theoretical risk. The CLOUD Act was specifically designed to override geographic data protections. If your AI provider runs on AWS, Azure, or GCP, your data can be accessed by US government agencies without a European court order, without your knowledge, and without your consent.
eustella does not use AWS, Azure, Google Cloud, or any other US-headquartered cloud provider for its AI infrastructure. eustella hosts exclusively on European cloud providers — companies headquartered in the EU, governed by EU law, and outside the reach of the US CLOUD Act. European servers operated by European companies under European jurisdiction. That is the only configuration that makes GDPR compliance genuinely enforceable.
When an AI startup says 'your data stays in Europe' but runs on Amazon or Microsoft infrastructure, the legal reality is different from the marketing. eustella believes European users deserve honesty about where their data actually lives — and under which law it can be accessed.
Core Philosophy
Control, not origin
eustella uses open-source models that run entirely under European control. Once downloaded, these models belong to whoever hosts them. They cannot phone home, be remotely updated, or be shut down by their creators. eustella hosts them in Europe, under European law.
Closed API models work differently. Every request travels to a foreign data centre, is processed on hardware controlled by a foreign corporation, and returns through infrastructure subject to foreign law. The provider can change the model, adjust its safety filters, raise prices, or cut off access at any time — without notice and without recourse.
eustella treats model origin the same way Europe treats energy hardware: what matters is not where a solar panel was manufactured, but who owns the grid it feeds into. eustella evaluates models on capability, safety, and licence terms — then runs them under full European control.
The European AI Gap
Why Europe needs to be pragmatic
Europe spent years debating how to build its own foundation models. Billions in public funding were announced. Strategic papers were published. The results, so far, are modest. Mistral in Paris is the notable exception — a genuine European frontier lab. But one lab cannot carry an entire continent's AI ambitions.
Meanwhile, European citizens and businesses adopted American AI at scale. ChatGPT, Claude, and Gemini process hundreds of millions of European queries every month. The data flows to US servers, trains US models, and generates value for US shareholders. Europe consumes AI brilliantly but controls almost none of it.
eustella sees this dependency as the real sovereignty risk — not the nationality of a model's training data, but the quiet, structural reliance on three American corporations to decide what AI can and cannot do in Europe. When OpenAI changes a content policy, European users comply. When Anthropic adjusts a safety filter, European workflows break. When Google deprecates an API, European businesses scramble.
eustella exists because waiting for a European GPT-5 is not a strategy. Europe needs sovereign AI now, built with the best available tools — wherever those tools originate — and hosted on infrastructure that is genuinely European, not just geographically located in Europe.
The Pragmatic Path
How eustella achieves sovereignty in practice
eustella selects the strongest open-source models available globally and deploys them on European cloud infrastructure operated by European companies. No closed APIs. No US cloud providers. No foreign data transfers.
eustella can audit every model it runs — inspecting for bias, censorship patterns, and safety behaviour. Closed models require blind trust. Open models allow verification. eustella chooses verification.
eustella can fine-tune models for European languages, cultural context, and regulatory requirements — because eustella controls the models, not a foreign API provider.
eustella can replace any model at any time. If a better model appears tomorrow, eustella can adopt it without renegotiating a contract, migrating an API, or asking permission from a foreign corporation. Sovereignty means never being locked in.
The Data Layer
Your conversations & agents stay in Europe — and stay yours
Control over the models and the servers only counts if it reaches the data that flows through them. This is the third pillar of sovereignty, and the one you feel most directly: what happens to everything you type, upload, and ask.
Your data is never sold and never shared with advertisers. This is a commitment, not a setting you have to hunt down and switch off.
And it stays under your control. You can see exactly what eustella remembers about you, change it, or delete it — down to a single conversation or your entire account, at any time.
Read our Privacy PolicyLimits of Technical Sovereignty
Where sovereignty still has limits — and why we say so
eustella is an independent European company, headquartered in Vienna and not owned by any American holding. Where we have a genuine choice, we take the European one — our servers (IONOS, Scaleway), our AI inference (Verda), our document processing (Mistral), and our web search (Linkup) all run with EU companies, on EU soil, under EU law.
But total sovereignty is not yet possible for every layer of a modern app, and we would rather name the gaps than market around them. The first is the compute itself: the GPUs that run AI models are designed by American companies and fabricated in Asia — no European chip can replace them today. What eustella controls is where those chips run and who operates them: on European providers, on European soil, under European law. It is the same logic Europe applies to a power grid — what matters is who owns and operates it, not where every component was manufactured.
The second is a specific set of services that simply have no European alternative — usually because a US platform mandates them. Here are specific examples:
App-store downloads
Getting the app onto your phone at all means going through Apple’s App Store or Google Play. There is no other way to reach an iPhone, and it is how the overwhelming majority of Android users install apps.
App-store billing & card payments
Every in-app purchase has to run through Apple’s or Google’s own payment system — a platform rule that applies to every app in the world — and card payments in general flow through the international card networks. There is no European rail that replaces this end to end. Your card details go straight to the payment provider; we never see them.
Push notifications — Apple APNs & Google FCM
Delivering a notification to your phone happens at the operating-system level, through Apple or Google. No European service can reach an iPhone or Android device without them — every app on your phone is in the same position.
Logins — Apple & Google
Social sign-in goes through the provider itself: signing in with Google means going through Google. And Apple’s rules require that any app offering a third-party login like Google must also offer Sign in with Apple. You can always skip both and sign in with an email address and a password instead.
One more service is worth explaining, because it is a choice rather than a platform requirement: we also use PostHog for some product analytics. We chose it for a simple reason — even though PostHog is a US company, its software is open source, so we are never locked in and can move to a self-hosted or fully European setup whenever we decide to. Today it already runs on PostHog’s EU Cloud in Frankfurt, and the data is pseudonymous and never includes the content of your conversations.
Where we depend on these services, we keep the data to a minimum, put legal safeguards in place, and commit to switching to a European provider the moment a credible one exists. The full itemised list — every processor, what it does, and why — is public, and we mean it when we ask: if you know a European alternative we have missed, tell us.
See our full sub-processor listGet started with eustella
Create your free account — eustella works everywhere, on web, iOS, and Android.