Methodology, affiliate policy and corrections
How the editor tests products, how affiliate partnerships work, how sources and datasets are handled, and the log of past corrections.
How we test
Reviews on this site are written by the editor, not by a staff of reviewers. Every product is placed into one of three categories, stated plainly wherever it matters:
- Desk researched: built from the provider's own documentation, pricing pages and support articles, each claim tied to a dated source. No account was created and no feature was used directly.
- Hands-on tested: the editor used the product directly and recorded what happened. A hands-on test record states who ran it, the account state (signed in or out, fresh or existing), the plan or tier used, the dataset or input used for the test, the date it was run, how many runs were made, the results, and the test's limitations. Device and screenshots are recorded when the test involves them. The published DeepL and Google Translate Dutch comparison is an example of this record format: a signed-out, screenshot-free test with its limitations stated openly.
- Vendor verified: a factual claim (encryption model, headquarters, ownership) that the provider has confirmed directly, beyond what its own marketing pages state.
Screenshots are reviewed for account or file identifiers before publication; that review removed three unsafe screenshots in the September 2026 corrections (see below). Pricing carries a capture date because prices change; a price without a date should be treated as unverified.
Affiliate policy
Some of the products listed here have affiliate partnerships. When you sign up through a partner link, the editor may earn a commission at no extra cost to you. That revenue funds hosting, research time and testing.
In a roundup or comparison section that lists more than one otherwise comparable product, the affiliate partner is listed first. This is a house rule about ordering, not about which product wins the recommendation: a product with no affiliate relationship can still be marked as the better choice, and the text says so when it is.
Commissions do not change verdicts. A product is recommended because of how it scored on data sovereignty, privacy, GDPR compliance, feature parity, pricing and ease of migration, not because of the size of a commission.
Every tracked affiliate link carries rel="sponsored", the attribute search engines expect for a paid or commission-bearing link. The site is cookieless: clicking an affiliate link records the page path, the placement on that page, a CTA identifier and the partner's sub-ID, with no cookie and no visitor identifier attached.
Data and sources
Factual attributes (whether a product is open source, whether it is self-hostable, whether it has a free tier, its headquarters, its parent company, its price) are published only when there is an exact-quote source behind them. When no such source exists, the field is left null rather than approximated or inferred.
Published pricing datasets, such as the European Cloud Storage Cost Index, tie every price to a vendor source URL and a capture date. Prices are never converted between currencies: a price quoted in US dollars is shown in US dollars, a price quoted in euros is shown in euros, and the two are never mixed into a single comparison figure.
Corrections
When a published claim turns out to be wrong, outdated or unsupported, it is corrected and logged here with the date, the pages affected, and a one-sentence summary. Spotted something that belongs on this list? Write to info@builtineu.eu.
Removed the claim that Gmail reads your emails to serve ads and train AI. It appeared in the excerpt, the opening paragraph and the social copy, and therefore in the article's structured data. Google's own pages state that Gmail messages are not scanned or read to show ads and that personalised ads are not based on Gmail content. The article now states what Google documents that it does process (spam, phishing and malware filtering, and smart features that the user can switch off), notes that Google's no-training commitment is written for Workspace customers rather than consumer Gmail, and relocates the comparison to the encryption model, the jurisdiction and the business model.
- Gmail messages are not scanned or read to show ads: https://support.google.com/mail/answer/6603
- Personalised ads are not based on content from Drive, Gmail or Photos, and automated systems analyse content to provide features: https://policies.google.com/privacy
- Smart features use Gmail content to personalise the apps and are a setting the user can turn off: https://support.google.com/mail/answer/10079371
- Gmail blocks more than 99.9 percent of spam, phishing attempts and malware, which requires inspecting message content: https://safety.google/intl/en_us/gmail/
- Google Workspace does not use customer data to train generative AI models without the customer's prior permission or instruction: https://knowledge.workspace.google.com/admin/gemini/generative-ai-in-google-workspace-privacy-hub
- Proton Mail encrypts message bodies and attachments end to end, but subject lines and sender and recipient addresses are encrypted without being end-to-end encrypted: https://proton.me/support/proton-mail-encryption-explained
Replaced an exposed Proton Drive screenshot with a lossless conversion of Proton's own official version-history illustration. Decoded pixels match, and the retention example is explained as configurable, not a new account test.
- Official Proton help illustration showing configurable version-history retention: https://proton.me/support/version-history
Removed three screenshots and their identifier-bearing captions and alt text (an Internxt dashboard image and two Proton Pass vault screenshots) because they exposed account or item detail. No replacement screenshots were substituted.
Stripped EXIF, XMP and IPTC metadata from 14 inline screenshots, with decoded pixels verified unchanged, and corrected captions describing pCloud's Rewind, encryption and business pricing screens and Proton Pass's import screen so the text matches what each screenshot shows.
Corrected kDrive's encryption model, Proton's ownership structure, and Tresorit's cryptography and business-compliance claims, and removed an unsupported CLOUD Act immunity claim, an unsourced 70 percent statistic, breach guarantees, an acquisition prediction, and stale prices.
- kDrive encrypts at rest and in transit and sits under the Infomaniak foundation's control structure: https://www.infomaniak.com/en/trust-center
- Proton is majority owned by the Proton Foundation: https://proton.me/support/who-owns-protonmail
- Tresorit's headquarters and its majority ownership by Swiss Post: https://tresorit.com/contact
- Tresorit's encryption and ISO 27001:2022 certification, with HIPAA covered by a separate business associate agreement: https://tresorit.com/security
- Internxt's company details and reported security audit results: https://internxt.com/about
- CLOUD Act jurisdiction reaches data within a provider's possession, custody or control regardless of where it is stored: https://www.justice.gov/d9/press-releases/attachments/2019/04/10/department_of_justice_cloud_act_white_paper_2019_04_10_final_0.pdf
Distinguished pCloud's 6 September USD promotional pricing, historical EUR screenshots, and the separately captured 5 September lifetime Crypto price, and made lifetime terms and region-switch costs explicit instead of presenting historical quotes as current offers.
- pCloud's current displayed USD lifetime offers: https://www.pcloud.com/cloud-storage-pricing-plans.html
- pCloud Crypto yearly price of USD 49.99, with a separately captured USD 150 lifetime price dated 5 September: https://www.pcloud.com/encrypted-cloud-storage.html
- Lifetime means the owner's life or 99 years, whichever is shorter, and the service can cease operating: https://wwwte.pcloud.com/terms_and_conditions
- Region selection between Luxembourg and Dallas, and a US$19.99 fee to relocate an account: https://www.pcloud.com/data-regions.html
Removed an obsolete transcript field from the public rendering of a historical pCloud video while preserving the video's ID, date, title and chapters, and added a note that the recording has not been re-recorded or corrected.
Separated Proton Pass account reset from data recovery so losing one recovery method is no longer described as inevitable vault loss, corrected Bitwarden Premium to US$19.80 billed annually before tax with third-party alias costs and offline caveats stated separately, and labelled historical Proton pricing instead of presenting a mixed-currency savings claim as current.
- Proton's account recovery methods and their effect on data recovery: https://proton.me/support/set-account-recovery-methods
- Proton Pass desktop offline access and the historical 2024 lifetime offer: https://proton.me/support/how-to-use-proton-pass-desktop-app
- Bitwarden Premium pricing and its alias generator integrations: https://bitwarden.com/pricing/
Required every listed deal to have both active European software and a valid, configured affiliate destination, and rejected empty, unsafe or misassigned links so the page no longer implies a commission-bearing offer where only an ordinary website link exists.
Fixed a campaign mismatch on Proton Pass's affiliate link, resolved historical Proton campaign aliases to their current equivalents, and kept Proton Meet on its ordinary website until an approved affiliate campaign exists for it.
Removed unsupported blanket GDPR, data-use and data-sovereignty claims from free and open-source category pages, in both visible text and structured data, and aligned the visible FAQ answers with what the page's schema markup states.