If your messenger runs on a US cloud provider, the US government can use the CLOUD Act to reach in and take your data, even if the server is in Europe. beChat runs on an independent European hosting provider in Germany. The US CLOUD Act does not apply. European law does, and European law has stronger privacy protections.
The CLOUD Act, explained simply
The Clarifying Lawful Overseas Use of Data Act, known as the CLOUD Act, was passed by the US Congress in 2018. It says that US-based cloud providers must hand over data stored on their servers when served a valid US legal warrant, regardless of where in the world that data is stored. In other words: if your messenger runs on AWS, Google Cloud, or Microsoft Azure, the US government can potentially access the data through a CLOUD Act order, even if the server hardware is sitting in a Frankfurt or Dublin data center.
This is not a theoretical concern. The CLOUD Act was explicitly designed to let US law enforcement bypass foreign data protection laws by going directly to the US company that operates the infrastructure. The Department of Justice argued for the law on the grounds that cross-border data requests were too slow under mutual legal assistance treaties (MLATs).
Imagine your messages are in a safety deposit box. If the bank is American, the US government can order the bank to open the box, even if the box is in a branch in Europe. The CLOUD Act is that order. beChat doesn't use an American bank.
Why server location alone is not enough
A common misconception is that a messenger is "European" if the server is physically in Europe. That is not the full picture. What matters is two things:
- Where the server is hosted. The physical location determines which country's law applies by default.
- Who operates the service. The CLOUD Act reaches through the operator, not just the location. If a US company operates the service, the CLOUD Act can compel that company regardless of server location.
So a messenger that uses a European data center but is run by a US company is still subject to the CLOUD Act through the company. And a messenger that is run by a European company but hosts on AWS is subject to the CLOUD Act through the cloud provider.
beChat addresses both: the server is in Germany, hosted on an independent European provider, and the operator is governed by Belgian law. Neither layer is subject to the CLOUD Act.
European law: the GDPR and beyond
European law provides some of the strongest data protection in the world. The General Data Protection Regulation (GDPR), in effect since 2018, gives every individual the right to:
- Know what data a company holds about them
- Request deletion of that data
- Receive a copy of their data in a portable format
- Object to processing of their data
For a zero-knowledge messenger like beChat, GDPR compliance is simpler than for services that hold large amounts of personal data. beChat stores an anonymous PIN, a device fingerprint, public keys, and encrypted message blobs. There is no name, no phone number, no email, no contact list, and no readable message content to hand over even if a court orders it.
How beChat compares to other messengers on jurisdiction
| Messenger | Server location | Operator jurisdiction | CLOUD Act exposure |
|---|---|---|---|
| beChat | Germany (EU) | European (Belgian law) | No |
| Signal | US | US (Signal Foundation) | Yes |
| US / global (Meta) | US (Meta) | Yes | |
| iMessage | US / global (Apple) | US (Apple) | Yes |
| Telegram | Dubai | UAE | No, but UAE law applies |
| Threema | Switzerland | Swiss law | No |
| Session | Distributed (onion) | Distributed | No central server |
| SimpleX | Self-hostable | Depends on operator | Depends |
What this means for you
If you are in Europe and want a secure messaging app from Europe, the key questions are: where is the server, who operates it, and what law applies? beChat gives you a clear answer to all three: Germany, an independent European provider, and Belgian/European law.
If your threat model includes potential US government access to your data — whether through the CLOUD Act, a National Security Letter, or a FISA court order — then using a messenger with US infrastructure or a US operator is a risk. beChat eliminates that risk by being European-hosted and European-operated.
If your threat model goes beyond US jurisdiction and includes any government, the zero-knowledge architecture matters even more. beChat's server stores no readable message content. Even a fully lawful order against the operator yields only encrypted blobs, a PIN, and a device fingerprint.
Frequently asked questions
Does the CLOUD Act apply to beChat?
No. The CLOUD Act applies to US-based cloud providers and companies. beChat is not a US company and does not use US cloud infrastructure. The server runs on an independent European hosting provider in Germany. Any data request must go through Belgian and European legal channels.
Is a messenger secure if it uses European servers but is run by a US company?
Not necessarily. If a US company operates the messenger, the CLOUD Act can potentially compel that company to hand over data even if the servers are in Europe. The key question is who operates the service and under what jurisdiction, not just where the server hardware sits.
Does GDPR protect my messages on a European messenger?
GDPR protects your personal data. For a zero-knowledge messenger like beChat, the personal data stored is minimal: an anonymous PIN, a device fingerprint, and public keys. Message content is end-to-end encrypted and not accessible to the operator. GDPR gives you the right to access and delete the data the operator holds.
Keep reading
Learn more about beChat as a secure messaging app from Europe, read the full security model, or see how beChat compares to Signal, WhatsApp, Threema, and others.