"If it was opt-in, nobody would opt in.". That's Twitch's own justification for training Amazon's AI on your streams by default.
▲ 54 r/xprivo

"If it was opt-in, nobody would opt in.". That's Twitch's own justification for training Amazon's AI on your streams by default.

"If it was opt-in, nobody would opt in". That's the actual reasoning Twitch gave for why AI training is on by default rather than something users have to actively choose. Here's what that default actually hands over, and how to shut it off.

Amazon can currently pull your streams, VODs, clips, stream chats, and any images or text on your channel unless you opt out. Per Twitch's own FAQ, this data may be used to train "a model developed by Amazon whose purpose is to generate or synthesize text, audio, images, or video", meaning your face, your voice, and your community's chat logs are all in scope by default.

To turn it off: go to your profile picture, then Settings, then Security and Privacy, scroll down, and toggle off "Training for Generative AI".

Two catches that you should be are of even after you opt out. First, it only protects your own channel, if you're chatting in someone else's stream, their setting controls whether your messages get used, not yours. Second, it only applies going forward. Nobody at Twitch can tell you what's already been collected and used to train models before you ever found the toggle.

u/Euhuntix — 7 days ago
▲ 136 r/xprivo

The RAM shortage is already making PCs pricier. Now Microsoft adds a 10% Windows licensing hike on top of it. It's finally time to switch to better alternatives. Choose yours:

Microsoft is raising the price it charges PC manufacturers for Windows 11 OEM licenses. The hike took effect in July 2026 and lands between 7 and 10 percent. 

This only affects manufacturers building new PCs with Windows 11 preinstalled, not people who already own a Windows 11 machine or anyone buying a standalone retail license, which stays unchanged for Home and Pro. But manufacturers rarely absorb costs like this. Some portion of that increase typically gets passed straight through to retail prices, arriving at the worst possible moment, right as an ongoing RAM shortage is already pushing PC prices up.

This is a good moment to remember that none of this applies if you're not buying into the Windows ecosystem at all. Linux distributions carry no licensing fee, and several strong European-made options exist. So instead of using Windows save costs and increase data sovereignty:

Linux: Doesn't need any introduction I think. it's the OG.

openSUSE (Germany): backed by SUSE, mature, stable, and widely used in enterprise environments, with the Leap and Tumbleweed branches covering both stability-focused and rolling-release use cases

Linux Mint: It is the most beginner-friendly distribution for anyone coming straight from Windows, with a familiar desktop layout and minimal learning curve

Zorin OS: built specifically to feel like Windows or macOS out of the box, making it one of the smoothest transitions for former Windows users who don't want to relearn their workflow

u/Euhuntix — 8 days ago
▲ 1.3k r/xprivo+2 crossposts

uBlock Origin is no longer supporting Facebook ad-blocking, and Edge is incompatible with uBlock Origin entirely. Here are three great browser alternatives and a privacy-focused one from Europe

Two separate pieces of news for ad-blocking just landed in the same week, and together they say a lot about where browser control is heading.

First, the developer of uBlock Origin announced that the team is no longer going to chase Facebook's constant filter-evasion tricks, describing Facebook as a "disgusting anti-user site". Facebook has repeatedly changed how it identifies and serves ads in order to defeat open-source blockers, monitoring projects like uBlock Origin and adjusting its code to bypass their filters. After years of this cat-and-mouse game, the small uBlock team decided that it was no longer worth the constant maintenance just for one platform.

Secondly, and more importantly: Microsoft Edge has started to disable Manifest V2 extensions by default in the Canary, Dev and Beta channels this month. The full rollout to consumers will be completed by the end of 2026, with enterprise devices following in early 2027. uBlock Origin has been installed over 13 million times on Edge, but there is no Manifest V3 version because MV3 removes the Web Request API that the full version depends on to work effectively. Chrome killed Manifest V2 entirely in mid-2025 and will have removed the last MV2 extensions from its store by 31 August this year. Edge held out for longer, but is now following the same route.

If you use uBlock Origin's full filtering power on Edge (or any other Chromium-based browser), the best option is to switch to a different browser, since all Chromium-based browsers are heading towards the same restriction eventually.

Firefox remains the safest option since Mozilla is committed to providing full Manifest V2 support, regardless of Chrome and Edge's actions. It also runs on Gecko, one of the few major rendering engines that is not controlled by Google. 

If you want a more modern interface alongside the same privacy protections, Zen Browser is a good European option: it's free and open source, and is built directly on Firefox's Gecko engine rather than Chromium. It also adds features like Workspaces and Split View without compromising the underlying privacy protections. 

Another Firefox-based alternative worth considering is Waterfox: it's open-source with no telemetry by default, and includes Oblivious DNS support to make it harder for your ISP to track which sites you visit.

All three keep uBlock Origin working exactly as it always has.

u/Delirium222 — 9 days ago
▲ 51 r/xprivo

SMS 2FA is a single point of failure for every account you own. One stolen number unlocks all your attached accounts at once. A former Apple security director got SIM-swapped despite knowing every trick. Here's why SMS 2FA makes it so easy and two better secure, open-source options.

If you're using SMS for two-factor authentication, one compromised phone number can expose every single account tied to it, at once. That's the story that just played out with Phillip Shoemaker*, the former Director of Apple's App Store, who understood exactly how SIM-swap attacks work and still lost access to his bank, crypto exchanges, email, and Apple ID within one afternoon on vacation. So this is how it happened: A stranger walked into a carrier store, claimed to be him, and walked out with his phone number on a new SIM. No hacking, no password cracking was involved, just a convincing story at a counter.

In the EU, this is harder, but not impossible. Most European countries require ID verification to activate or transfer a SIM, which raises the bar compared to the US, where Princeton researchers found carriers handed over numbers in 39 of 50 test attempts. But remote and video-based ID verification, now common in Germany and France for convenience, opens its own attack surface: deepfakes, manipulated video feeds, or stolen ID documents can potentially bypass automated checks. And in-person social engineering still works anywhere a human is the final decision-maker at a counter.

The vast majority of people don't talk about this, but here's the thing: even app-based 2FA has a hidden dependency problem. When you scan a 2FA QR code, it contains a secret seed that generates your one-time codes. Since 2023, Google Authenticator has backed up these secrets to your Google account. Researchers found that, at the time, backup traffic wasn't end-to-end encrypted, meaning Google's servers could technically access your raw 2FA secrets. If your Google account were to be breached, you could lose not only your email but also every 2FA seed you've ever scanned. Microsoft Authenticator has offered cloud backup for longer and claims to use AES-256 encryption for keys in transit. However, it also sends personally identifiable data back to Microsoft in some cases before you have even accepted the terms. Since these codes contain metadata about which service they belong to, this data could be used for profiling. In either case, your 'independent' second factor becomes recoverable through the same account that was supposed to protect you from it**.**

The fix is to break that dependency entirely. Here are my two favourite secure options: Aegis Authenticator is open source and is developed in the Netherlands. It is deliberately local-only: your vault never leaves your device unless you manually export it. There is no cloud, no company and no metadata trail. It's available on F-Droid, so you're not pulling it from Google Play either. If you're not using an Android device(not yet switched to GrapheneOS?) or you want to sync without handing your secrets to a tech giant, Ente Auth incorporates backup and cross-device sync from the outset. It also encrypts everything end-to-end before it touches Ente's servers, meaning that Ente itself cannot read your codes, even during sync. The crypto implementation is public, so you can verify the claim yourself too if you want to.

*(https://www.linkedin.com/pulse/i-director-apples-app-store-still-got-sim-swapped-phillip-shoemaker-ewk4c)

u/Euhuntix — 11 days ago
▲ 68 r/FOSSbertarian+2 crossposts

Show me your privacy stack: what Big Tech default replaced what in your daily tools? (VPNs, Browsers, Search, Mail, Social Media & more)

What's your privacy-first swap? Drop the tool you replaced and what you replaced it with.

Here's mine, first row is European alternatives (also mainly open source), second row goes fully open source (with European providers still in the mix):

Big Tech default European alternative Open source alternative
NordVPN Mullvad (Sweden) Nym VPN (Switzerland)
Chrome Vivaldi (Norway) LibreWolf
Google Search xPrivo Search (Luxembourg) SearXNG
Gmail Posteo (Germany) Tuta (Germany)
Instagram Mastodon (Germany) Pixelfed
u/Euhuntix — 1 month ago
▲ 166 r/reformuk+1 crossposts

Good news for UK citizens: UK's minister for AI and Online Safety, Kanishka Narayan, confirmed today no action will be taken against VPNs, after realizing who actually depends on VPNs. Here is a small selection of good privacy-first open-source VPNs from Europe:

The UK's minister for AI and Online Safety, Kanishka Narayan, announced today that the government will not, for now, take action to restrict VPNs in the UK. The proposal had been justified using child protection as its rationale, a familiar pattern by this point given how the same argument has been used to push Chat Control and social media age verification in Australia

The reversal reportedly came after recognition of who actually relies on VPNs to stay safe: domestic abuse survivors reaching out for help without being tracked, LGBTQ+ people in regions where their identity carries real risk, journalists protecting sources, and whistleblowers exposing wrongdoing without being immediately identified. Banning the tool these groups depend on would have stripped away exactly the protection the policy claimed to be adding elsewhere. So that's great news and this time, the privacy argument won.

Because we are already at it, here are two strong European options that are explicitly built around minimizing what a VPN provider itself can see or hand over:

  • Mullvad VPN (Sweden): no email is required to create an account it supports privacy-preserving payment options including cash and cryptocurrency and it says it does not log user activity or connection metadata. Mullvad also has a substantial, publicly documented history of independent security and infrastructure audits, including audits that found no customer-data logging in the assessed VPN infrastructure.
  • NymVPN (Switzerland): built on a decentralized mixnet architecture rather than a traditional centralized VPN server, meaning no single operator can see both who you are and what you're doing at the same time, offering stronger protection against traffic analysis than most conventional VPNs
u/Euhuntix — 1 month ago
▲ 53 r/xprivo

Google just started it's degoogle campaign to bring more users to privacy-friendly alternatives

Google Gemini is down, time to try the privacy-friendly alternatives from Europe out there like https://www.xprivo.com

And as you are already at it, here are more privacy-friendly Google alternatives:

Gmail -> Tuta.com 🇩🇪

Google Photos -> Filen.io 🇩🇪

Chrome -> Waterfox

Google Maps -> CoMaps.app

Google Meet -> Nexcloud Talk 🇩🇪

u/Euhuntix — 2 months ago
▲ 96 r/xprivo

Strava is paywalling its API ahead of its IPO. Your fitness data, their rules. There is a fully self-hosted alternative from Portugal.

Strava announced this week that it is introducing a flat $11.99/month fee for all API access, requiring login to view public profiles and club directories, and shutting down several API endpoints including those exposing club data. Developers have a 90-day transition period before the changes take effect.

The company framed this as protection against AI-driven data scraping. The timing obviously tells a different story. Strava filed a confidential S-1 with the SEC in early 2026, is being led through its IPO by Goldman Sachs and JPMorgan, and was valued at $2.2 billion in a 2025 Sequoia Capital-led funding round. Locking down data before going public is standard pre-IPO practice.

The direction has been clear for a while. In 2024, Strava already updated its API terms to ban developers from using data to train AI models and restrict sharing with third parties. Independent developers and community tools absorbed that quietly. The new fee structure makes it impossible for smaller projects to continue at all.

Notably, Strava simultaneously announced a paid integration with Anthropic's Claude AI assistant, which means AI access to your fitness data is not being blocked. It is being reserved for paying partners.

Your data. Their rules. Until you move.

There is a fully self-hosted, open-source alternative from Portugal called Endurain, built specifically for this scenario. You host it yourself, you own the data entirely, and no API policy change or IPO preparation can affect how you access it. No subscriptions, no paywalled features, no third-party terms.

Endurain is actively developed and available on Codeberg: https://codeberg.org/endurain-project/endurain

Self-hosting might be not the right choice for everyone but it is definitely worth a look at this project.

u/Euhuntix — 3 months ago
▲ 139 r/xprivo

Doctolib markets European data sovereignty while still sending sensitive patient data to US cloud and AI giants

Doctolib is France's dominant healthcare platform, used by 500,000 medical practitioners and 90 million patients across Europe. It built its brand around a promise of French and European data sovereignty. In late April 2026, it quietly updated its privacy policy.

That update, according to an investigation by Le Canard enchaîné published yesterday (3. June 2026), means your medical consultation notes are now being used to train AI models developed by Google, Microsoft, and Anthropic.

How it works: Since 2024, Doctolib has offered doctors an AI-powered note-taking assistant for 79 euros per month. The tool automatically records and transcribes consultations. Doctolib publicly states that "no third party can access the content of medical notes." Its own privacy policy says otherwise. Those notes feed into AI models coached by Google Gemini, Anthropic Claude, and Microsoft Copilot.

The data involved is not generic. It includes family medical history, prescriptions, biological data, and clinical assessments, detailed enough that individual patients can be re-identified from the files. According to the reporting, this data can be retained and used even after a patient's death.

The Cloud Act problem & what it is: Doctolib and its US partners point out that servers are physically located within the European Union. This does not resolve the legal exposure. US companies operating under American jurisdiction are subject to the Cloud Act, which allows US authorities to compel access to data held by those companies regardless of where the servers sit. Doctolib does not make this clear to users.

The situation goes further. Doctolib has a contract with Meltio, a Californian company that hosts some data directly in the United States, with no European server layer in between.

France's data protection authority, the CNIL, has acknowledged it is not currently "in a position to rule on the legality" of the arrangement. That is a remarkable admission for the agency responsible for enforcing GDPR on one of the country's largest health data processors.

There is also a political aspect: Doctolib did not become France's dominant health platform through market competition alone. It was the platform the French government chose to run its national COVID-19 vaccination campaign, embedding it into the lives of tens of millions of people by institutional necessity. Since 2017, it has received 211 million euros in public funding from Bpifrance, on top of contracts with university hospitals and regional governments.

Doctolib's founder Stanislas Niox-Chateau has a close personal relationship with President Macron. A member of parliament from the MoDem party, Philippe Latombe, told Le Canard enchaîné he faced significant pressure from the Elysée after publicly criticizing Doctolib's hosting arrangement with Amazon Web Services.

Last year, Doctolib spent approximately 500,000 euros lobbying French parliamentarians and 300,000 euros lobbying EU institutions.

And finally the core issue: This is a case study in how data sovereignty rhetoric functions in practice. A company markets itself as a champion of European independence from Big Tech while building its product on top of Google, Microsoft, and Anthropic infrastructure, updating its privacy policy to formalize the arrangement with minimal notice, and operating under close political protection from the government that made it indispensable.

Health data is the most sensitive category of personal data that exists. It covers things people do not share with their families, employers, or governments. Once it enters a commercial AI training pipeline operated by US corporations subject to US law, the promise of European sovereignty over that data is not a technical guarantee. It is marketing.

u/Euhuntix — 3 months ago
▲ 74 r/xprivo

Google reads everything you write in Google Docs. Fileverse is a good, privacy-friendly decentralized alternative

Google Docs is convenient. That convenience has a cost most people never think about. Your drafts are indexed. Your internal templates exist at Google's discretion. Every collaborator who joins a document gets funnelled through a "Google login required" gate, which means Google knows who is working with whom, on what, and when.

Fileverse Docs (dDocs) is one of the most mature decentralized alternative available right now, and it works as a direct replacement.

What sets it apart from Google Docs and why it's really different and a good, secure alternative:

End-to-end encryption is the default. Fileverse cannot read your documents. They do not manage your encryption keys at all. Only you do. There is no server-side access, no indexing, no AI training on your writing, and no way for anyone at Fileverse to hand your content to a government subpoena because they genuinely do not have it.

Documents are stored peer-to-peer on IPFS, the distributed storage standard. This means if Fileverse disappears tomorrow as a company, your documents do not disappear with it. You pull them directly from IPFS using your own key. No central server to go offline, no company to get acquired, no subscription to lapse.

The UX feels as good as with Google Docs. Real-time and async collaboration work the way you'd expect.

  • No account required. No email, no password, nothing that can be banned or suspended
  • Native Markdown and LaTeX support
  • Dark mode, offline editing, mobile-optimised
  • Zero AI features by default. If you want AI assistance, you connect your own local model. Your documents never leave for OpenAI, Anthropic or Google
  • Fully open source at github.com/fileverse

If you work with sensitive drafts, legal documents, internal strategy, source communications, or anything you would not want indexed by a corporation whose business model is knowing what you are thinking about, this is the most serious available alternative to Google Docs that does not ask you to simply trust a different company instead.

u/Euhuntix — 3 months ago
▲ 257 r/xprivo

A Japanese manga artist just lost his entire Google account permanently because Google's AI scanned his private Google Drive files and flagged them. Years of work, gone. Every service tied to that login, gone.

A professional manga artist in Japan uploaded private files from an old comic he had drawn to his personal Google Drive. He was not distributing anything. He was not sharing it publicly. He stored his own files in what he reasonably assumed was his own private cloud storage.

Google's automated AI scanning system reviewed the files, decided they violated its policies, and banned his account. He submitted an appeal. Google rejected it and made the ban permanent.

He has now permanently lost access to years of his own original artwork, his entire Gmail history, and every website and service he had connected to his Google login. In his own words, the situation is deeply embarrassing and is causing significant disruption to his professional life. He acknowledged it might not happen to people who stay strictly within every rule, but warned others to be aware of the risk.

The part most people skip past: Google scans everything you upload

This is not new behaviour. Google has been scanning files uploaded to Drive, Photos, and Gmail for years using a combination of hash-matching tools and AI content classifiers. The scanning happens on Google's servers before or during storage, meaning the files pass through their systems in a state Google can read regardless of what you were told about privacy.

The practical implication is straightforward: Google Drive is not a private storage locker. It is a filing cabinet that your landlord has a key to, reads regularly, and can lock you out of permanently based on an automated decision with no meaningful human review and no reliable appeals process.

When your cloud storage provider can also permanently revoke access to your email, your YouTube account, your Android phone backups, your Google Maps history, your Google Pay, and every third-party login that uses "Sign in with Google," a single automated moderation decision becomes a complete digital eviction.

The actual danger here is not that Google has content policies. Every platform has content policies. The danger is that one company controls so many layers of your digital life simultaneously that a single automated strike against one layer destroys all of them at once. That architecture was never in your interest. It was built to maximise lock-in.

European alternatives that cannot do this to you

The core issue is that Google can scan your files because your files are not end-to-end encrypted. On Google Drive, Google holds the encryption keys. That means Google can always read what you store. The solution is to use storage that is end-to-end encrypted by design, where only you hold the keys and the provider is architecturally unable to read your content.

Filen.io: Based in Germany, fully end-to-end encrypted, open source client and server code, zero-knowledge architecture meaning even Filen's own engineers cannot read your files. Free tier available, paid plans competitively priced. Fully GDPR-compliant under German and EU law. No automated AI scanning of your content is technically possible because they cannot see it. This is the closest direct replacement for Google Drive with European jurisdiction and great privacy.

Tuta Drive (in Closed Beta, coming in a few months): Based in Germany, built by the team behind Tuta Mail. End-to-end encrypted, open source, zero-knowledge. Currently in closed beta with a full public release expected within the next few months. One to watch if you already use Tuta for email and want everything under one encrypted European roof.

Nextcloud: European open source platform you can self-host entirely on your own infrastructure or use with a trusted European hosting provider. Nothing ever touches a third-party company's server. Full control, no automated moderation possible by any external party.

End-to-end encryption with zero-knowledge architecture means the provider cannot read your files. No reading means no automated AI scanning. No scanning means no automated permanent bans based on content a machine misidentified in your private storage.

The manga artist's situation is a clear example of what happens when you trust convenience over architecture. The solution is simply to stop using storage where the provider can read what you upload in the first place.

u/Euhuntix — 3 months ago
▲ 26 r/xprivo

xPrivo now available on Play Store + small prize

xPrivo is now officially live on the Play Store. 

To celebrate this we have hidden an incredible prize right inside our Android app, and it could be yours! Download the app from the Google Play Store, start exploring, and keep your eyes peeled.

Pay close attention to your conversations with our AI assistant. At any given moment, a highly rare, secret link will randomly appear at the very bottom of a chat reply.

The Prize: A brand new Nothing CMF Phone 1 (e/OS ready)!

How to Play & Win:

  • Chat Naturally: The secret message is completely unrelated to your conversation topics. Just use the app as you normally would!
  • Pure Luck: The winning link is triggered entirely at random.
  • Fair Play for All: The AI assistant is completely unaware of the secret code. This means clever "prompt engineering" will not increase your chances and everyone has an absolutely equal shot at winning.

The clock is ticking, and the hunt officially closes on May 22nd. Will you be the lucky user to uncover the secret? 

Download now start chatting and start your hunt:

https://play.google.com/store/apps/details?id=com.xprivo.lux

Open to everyone who can download from the Play Store! No Reddit account is required to participate. Please note that this giveaway is not affiliated with Nothing Phone.

u/Euhuntix — 3 months ago
▲ 203 r/xprivo

US states are now trying to force age verification into Linux itself. Half of all US states have some form of age verification law. The open source community is fighting back. [This can come to the EU too]

California's Digital Age Assurance Act, Assembly Bill 1043, was signed into law by Governor Gavin Newsom in October 2025 and takes effect January 1, 2027. It requires every operating system provider to collect a user's age at account setup and transmit that data in real time to any app developer who requests it via a standardised API. The law splits users into four age brackets: under 13, 13 to 16, 16 to 18, and 18 or above. The definition of "operating system provider" is written broadly enough to cover not just Microsoft, Apple and Google but every Linux distribution, FreeBSD, SteamOS and any other general-purpose OS. Colorado and Illinois have near-identical bills moving through their own legislatures. Similar proposals are active in New York and Brazil. As of this month, roughly half of all US states have some form of age verification law on the books, nine of which were passed in 2025 alone.

The law was designed with Apple and Google in mind. Enforcing it against a Linux distribution maintained by a community of volunteers in multiple countries with no central legal entity is a structurally different problem, and nobody in the state legislatures appears to have thought it through before writing the text.

The open source community is responding in three distinct ways:

-System76, the Colorado-based Linux hardware company, spent months lobbying the Colorado legislature directly. Their effort worked. Carl Richell, System76's founder, confirmed last month that Colorado's SB26-051 has been amended to explicitly exempt open source operating systems, applications, code repositories including GitHub and GitLab, and container platforms including Docker and Podman from the requirements. The amendment does not name Linux specifically; instead it describes software distributed under licences that allow recipients to copy, redistribute and modify freely without restriction from the provider. That wording covers essentially the entire FOSS ecosystem. The bill has passed a House committee but is not yet signed into law.

-MX Linux, one of the most widely used community distributions, has taken the clearest public stance of any distro team. In its weekly update the project stated directly: "No one on the team at MX wants to implement something like age verification." The developers cited user privacy, the structural impossibility of consistent secure implementation across a decentralised OS ecosystem, and the fundamental philosophy that open source operating systems are not designed to act as gatekeepers or data collectors. Their current position is to wait for court challenges to resolve how and whether these laws apply to non-commercial open source projects before taking any further action.

-A third response has emerged from individual developers and technically sophisticated users. One approach posted to Hacker News argues that AB 1043 compliance on a Unix-like platform is technically satisfied by a single shell variable: the user enters an age category at setup, it is written to a configuration file, and any application that queries for it can read it. The law says nothing about verification, only about provision of the data. On a system with no central authority and no mandatory login service, this approach technically complies with the letter of the law while preserving the entire architecture of user autonomy that makes Linux what it is.

Why this is not really about children:

If you think AB 1043 is aimed at Google and Apple, the evidence suggests otherwise. Both companies already have age verification in their stores. Both already have parental controls, developer policies and enforcement mechanisms. The law's broad OS-level definition, which drags in volunteer-maintained community distributions with no commercial presence in California, is not the result of careful drafting aimed at large commercial platforms. It is the result of writing legislation that requires every device to report age to every application, on every platform, with every OS as a mandatory relay node.

The practical outcome of full compliance is that an operating system becomes an identity layer that transmits user age metadata to any developer who asks for it at install time. That is not a child safety feature. That is device-level identity infrastructure. The children narrative is the political justification. The technical outcome is a mandatory link between your device, your identity bracket, and every application you run.

The fight happening in Colorado right now, where System76 successfully secured an open source exemption through direct legislative engagement, is the template for what needs to happen in California, Illinois, New York and the other states still moving these bills forward. It requires people in the open source and privacy communities who have standing in those states to engage with their own legislatures the way Carl Richell did in Colorado, before the January 2027 compliance deadline makes the point moot.

MX Linux put it clearly: direct your energy at policymakers, not at Linux projects. That advice is correct. The Linux community cannot patch its way out of legislation.

This is not only a US problem. Europe is watching closely and learning.

The EU's trajectory on age verification is directly parallel and in some ways more advanced. The European Commission's formal recommendation published last month pushes all 27 member states to deploy a standardised age verification infrastructure by December 31, 2026. EU Executive Vice President Henna Virkkunen explicitly stated at a press conference in April that the system "should not be circumvented," naming VPNs as the first target.

The pattern documented in this community is consistent. Age verification is the justification. Identity infrastructure tied to device, application and operating system is the outcome. Whether that infrastructure is being built by California's legislature, Colorado's governor, or the European Commission, the technical result is the same: a mandatory link between who you are and what software you run. The open source community's entire model of anonymous, permissionless, identity-free computing is the specific thing these laws structurally undermine, whether or not that is the stated intention.

u/Euhuntix — 3 months ago
▲ 24 r/xprivo

[Early Access Test] xPrivo app is now available on Google Play in early access for testers, and we are actively looking for testers and feedback

If you try it, please share any feedback on what works, what breaks, and if possible which device you used. You can leave comments here or send feedback directly to our support email.

u/Euhuntix — 3 months ago
▲ 39 r/xprivo

🇪🇺 Happy Europe Day! To celebrate this: 50% off PRO & a 6-month PRO giveaway for 4 supporters

To celebrate Europe Day and the push for digital privacy, we’re running a special community giveaway and a promo for those who want to support European tech!

🎁 The Giveaway: Win 6 Months of PRO Free! Just leave a comment below! We will randomly select 4 commenters to win a free 6-month PRO membership.

🇪🇺 Europe Day Promo: 50% OFF PRO Want to support the project right away? Get 50% OFF your first 4 months of PRO (available on Web and the App Store).

Promo runs until 12th Mai. Winners will be announced on 13th Mai In the comments of this post.

Link to the website with the promo: https://www.xprivo.com/europe-day/

u/Euhuntix — 3 months ago
▲ 102 r/xprivo

Every time you drag a file into WeTransfer, Dropbox Transfer or Google Drive and hit share, the file travels to an American server where the provider can technically read it, scan it, flag it, hand it to law enforcement, or train AI models on it. WeTransfer's own privacy policy explicitly reserves the right to scan content for policy violations. Google Drive feeds Gemini. Dropbox has disclosed law enforcement data requests for years. None of this is a secret but most people simply do not think about it when sending a contract, a medical document or a client file. Before we look at the alternative: it's worth mentioning that I also already introduced you to Localsend a few weeks ago which is another great alternative for sending files locally. It's free a open-source, cross-platform file sharing tool. I's a great Airdrop alternative for any device in the local network.

Retyc is a French startup from Lyon, built by Emilien Mantel, that starts from the opposite assumption. Its tagline is "Hors de leur portée", out of their reach, and the architecture actually delivers on that. Files and their metadata are encrypted on your device before they leave it, using the AGE encryption standard, an open source, independently audited library, not proprietary in-house cryptography. By the time the data reaches Retyc's servers, it is already locked. Retyc itself cannot read what you sent, cannot hand the content to a third party and has explicitly committed to never integrating AI into the platform.

The zero-knowledge model goes further than most "secure" file transfer services. Many competitors encrypt files in transit and at rest, which sounds reassuring until you realise that the provider still holds the keys. Retyc's model ensures the provider never has the keys in the first place. Even the metadata, file names, sizes, sender and recipient details, is encrypted before upload.

The entire infrastructure is hosted in France, fully under EU jurisdiction and GDPR compliance is built into the architecture rather than bolted on as a checkbox.

The comparison that matters is not just against WeTransfer. It is against every file sharing tool that you or your organisation currently uses by default because it came bundled with something else. Google Drive sharing links, Outlook attachments previewed on Microsoft servers, Slack file uploads processed in US data centres. Every one of these is a tool that a US company has the technical and legal ability to access. Retyc's zero-knowledge model removes that ability entirely, which is especially relevant for anyone in a profession where client confidentiality is not optional.

It launched its public beta on March 24, 2026 and is still in early access, so treat it accordingly. Test it with non-critical files first, verify the full sender and recipient experience, and evaluate whether the current free tier limits work for your use case before integrating it into sensitive workflows. The architecture is solid and the approach is exactly what the European sovereign software stack at the file transfer layer is needing.

u/Euhuntix — 4 months ago