

Where are the photos of the document processed though? And if not on the phone itself, is the server backend open source as well? Can I self-host it? And is the data which is used to generate certificates deleted immediately or stored in the backend? I have questions.
To be honest, I simply wouldn’t feel comfortable storing this data on the third party servers hosted on hyper scaler infrastructure. That probably works for most but I’m not keen on a Telekom / AWS combination there. The regulation itself is a totally different discussion. There’s arguments both in favor and against and I don’t really wanna judge that here. I’ll say though, that IMHO the OS level is totally the wrong place to do it. Just gives large non-European companies a powerful bonus datapoint.