ProductLift is built EU-side and GDPR-aware. Here's what you need to know as a portal owner.
For each end user:
uid you pass via SSOWe don't track behavioral profiles, advertising IDs, or content beyond what users actively post and vote on.
EU-based servers. See Data location for specifics.
A DPA is available. Email support@productlift.dev to receive the latest signed version.
We use a small list of sub-processors (Stripe for billing, AWS S3 for file storage, OpenAI / Anthropic for AI features when you've enabled them). The current list is part of the DPA.
End users have GDPR rights you need to be able to fulfill:
ProductLift uses functional cookies only (session, CSRF, preferences). No tracking or advertising cookies on portals you host. If you use Analytics features, those are controlled by you.
If you turn on AI features (auto-reply, auto-tag, KB answers), post and comment text is sent to the AI provider. See Turning off AI and AI features overview.