Skip to main content
GoogleCustomer feedback

A small UK-based app developer stopped using Firebase Analytics and removed their app from EU distribution on Apple and Google Play stores due to concerns about GDPR Article 27 compliance risks...

What happened

A small UK-based app developer stopped using Firebase Analytics and removed their app from EU distribution on Apple and Google Play stores due to concerns about GDPR Article 27 compliance risks associated with the product.

Source

RedditSep 27, 2026By u/luckoftheirish2999

r/gdpr

Small UK indie app developer cold-emailed about GDPR Article 27 - how worried should I actually be?

upvotes
11
comments
33

Post

Highlighted: the lines this signal was extracted from

I’m a UK-based indie developer with a small budgeting app. A company recently cold emailed me out of the blue saying that because my app had been available to EU users, GDPR Article 27 required me to appoint an EU representative. They were selling this service for around €490/year. That email is what prompted me to look into all of this. My situation: - Very few users and essentially no revenue. - No user accounts or backend. I don’t collect names, email addresses or other obvious identifying information. - Users enter their budgeting/financial data locally on their own device. Optional backups go to the user’s own iCloud/Google Drive account. I don’t receive or have access to those backups. - I did use Firebase Analytics, but I have now completely unlinked Google Analytics from the Firebase project. As soon as Article 27 was brought to my attention, I removed the app from both Apple and Google Play throughout the EU/EEA. I am no longer offering the app or in-app purchases to EU/EEA users. I understand that removing the app now doesn’t necessarily determine what the legal position was historically. What I’m trying to understand is the real-world risk for someone in my position. Has anyone here dealt with Article 27 as a very small non-EU developer? Would Article 27 actually have applied to an app with this architecture and such limited processing? Now that...

Keep reading with a free account

The rest of this post, and every signal for Google, is in your free account.

Comments on the post

5 of 33 comments
  • “This was not a targeted email this was just your name on a blast list of app developers. If you collect no personally identifiable information, article 27 does not apply to you at all. This is basically a scam.”

    u/DarlingBri41 points · Sep 27, 2026View

  • “I applaud you for taking this seriously, doing your own research and even making changes to what you're doing. As already mentioned though, this is a scammy sales tactic and you were fine as you were.”

    u/cortouchka14 points · Sep 27, 2026View

  • “real-world risk falling to a scam. For starters: it's not at all obvious your app is subject to GDPR. To be so subject, it must target the EU. Because EU, there isn't a bright line there. Things that would make it an obvious yes: advertising in the EU. Almost certainly yes: building in EU-specific languages. Probably yes: offering payment (outside the app store) in euros (only probably because”

    u/xasdfxx6 points · Sep 27, 2026View

  • “It’s a scam. Ignore it. You can even leave firebase on by disabling PIP or put a consent banner before it.”

    u/Comfortable-Fall14194 points · Sep 27, 2026View

  • “It's always helpful to call these organisations out so that they can be subjected to the might of the community's collective scrutiny. If you don't feel able to, and I recognise why you might not want to, perhaps someone else who recognises these tactics might shine a light on their similar experiences from an anonymous account?”

    u/Biddles812 points · Sep 27, 2026View

Extracted by Autobound

From the Signal API record
Signal
Customer feedback

What this signalsUser posts often show product pain before it reaches reviews or churn.

Subreddit
r/gdpr
Stage
Switched
Event date
Sep 2026

Companies

  • AppleAlso named

The full record

From the Signal API record

Numbers

Mentions
223

Details

Timing
Completed
Category
Security
Virality
Somewhat high
Post kind
Text
Prominence
Core
Company's role
Vendor

Topics and mentions

Topics

  • compliance
  • analytics
  • legal risk
  • gdpr
  • privacy

Flair

  • EU 🇪🇺

Products named

  • Firebase Analytics
  • Google Analytics
  • Google Play

Extraction

Sentiment
Negative
Detected
Sep 27, 2026
signal_type
reddit-company
signal_subtype
customerFeedback

Use this data

Get every Reddit signal for Google and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Google this week?”

  2. Send it to your own tools

    The Signal API returns Reddit signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full reddit-company record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/4f90a2ca-4825-5fe5-a484-35a15874cf4d returns this record as JSON. POST /v1/companies/enrich returns every signal for google.com.

{
  "signal_id": "4f90a2ca-4825-5fe5-a484-35a15874cf4d",
  "signal_type": "reddit-company",
  "signal_subtype": "customerFeedback",
  "detected_at": "2026-09-27T16:39:24+00:00",
  "company": {
    "name": "Google",
    "domain": "google.com"
  },
  "data": {
    "nsfw": false,
    "stage": "switched",
    "awards": 0,
    "timing": "completed",
    "topics": [
      "gdpr",
      "compliance",
      "privacy",
      "analytics",
      "legal risk"
    ],
    "post_id": "1wrow3s",
    "summary": "A small UK-based app developer stopped using Firebase Analytics and removed their app from EU distribution on Apple and Google Play stores due to concerns about GDPR Article 27 compliance risks associated with the product.",
    "category": "security",
    "comments": [
      {
        "url": "https://www.reddit.com/r/gdpr/comments/1wrow3s/comment/pcebcuj/",
        "depth": 0,
        "score": 41,
        "author": "DarlingBri",
        "excerpt": "This was not a targeted email this was just your name on a blast list of app developers. If you collect no personally identifiable information, article 27 does not apply to you at all.\n\n This is basically a scam.",
        "posted_at": "2026-09-27T16:47:38.000Z",
        "author_url": "https://www.reddit.com/user/DarlingBri/"
      },
      {
        "url": "https://www.reddit.com/r/gdpr/comments/1wrow3s/comment/pceeqvz/",
        "depth": 0,
        "score": 14,
        "author": "cortouchka",
        "excerpt": "I applaud you for taking this seriously, doing your own research and even making changes to what you're doing.\n\n As already mentioned though, this is a scammy sales tactic and you were fine as you were.",
        "posted_at": "2026-09-27T17:01:35.000Z",
        "author_url": "https://www.reddit.com/user/cortouchka/"
      },
      {
        "url": "https://www.reddit.com/r/gdpr/comments/1wrow3s/comment/pcev8ir/",
        "depth": 0,
        "score": 6,
        "author": "xasdfxx",
        "excerpt": "real-world risk\n\n falling to a scam.\n\n For starters: it's not at all obvious your app is subject to GDPR. To be so subject, it must target the EU. Because EU, there isn't a bright line there. Things that would make it an obvious yes: advertising in the EU. Almost certainly yes: building in EU-specific languages. Probably yes: offering payment (outside the app store) in euros (only probably because",
        "posted_at": "2026-09-27T18:07:06.000Z",
        "author_url": "https://www.reddit.com/user/xasdfxx/"
      },
      {
        "url": "https://www.reddit.com/r/gdpr/comments/1wrow3s/comment/pceiko2/",
        "depth": 0,
        "score": 4,
        "author": "Comfortable-Fall1419",
        "excerpt": "It’s a scam. Ignore it.\n\n You can even leave firebase on by disabling PIP or put a consent banner before it.",
        "posted_at": "2026-09-27T17:17:06.000Z",
        "author_url": "https://www.reddit.com/user/Comfortable-Fall1419/"
      },
      {
        "url": "https://www.reddit.com/r/gdpr/comments/1wrow3s/comment/pcf852d/",
        "depth": 0,
        "score": 2,
        "author": "Biddles81",
        "excerpt": "It's always helpful to call these organisations out so that they can be subjected to the might of the community's collective scrutiny.\n\n If you don't feel able to, and I recognise why you might not want to, perhaps someone else who recognises these tactics might shine a light on their similar experiences from an anonymous account?",
        "posted_at": "2026-09-27T18:58:02.000Z",
        "author_url": "https://www.reddit.com/user/Biddles81/"
      },
      {
        "url": "https://www.reddit.com/r/gdpr/comments/1wrow3s/comment/pch1mfi/",
        "depth": 0,
        "score": 2,
        "author": "SiteRelEnby",
        "excerpt": "Not worried. Don't actively market it in the EU specifically, and you're fine until you get big enough that the cost of a GDPR rep (which can be had for closer to $100-200/yr, $500/yr is bullshit) is no longer prohibitive. Until that time, just make sure you have a clear contact like privacy@, gdpr@, etc going to an inbox that's monitored.\n\n Predatory companies being scummy, nothing more. Same sor",
        "posted_at": "2026-09-27T23:36:27.000Z",
        "author_url": "https://www.reddit.com/user/SiteRelEnby/"
      },
      {
        "url": "https://www.reddit.com/r/gdpr/comments/1wrow3s/comment/pciyycj/",
        "depth": 0,
        "score": 1,
        "author": "Eisn",
        "excerpt": "Do you have a backend server that the app connects to? Do you have a website for the app that also has things like user accounts?",
        "posted_at": "2026-09-28T06:38:27.000Z",
        "author_url": "https://www.reddit.com/user/Eisn/"
      }
    ],
    "evidence": [
      "[post] I did use Firebase Analytics, but I have now completely unlinked Google Analytics from the Firebase project.",
      "[post] As soon as Article 27 was brought to my attention, I removed the app from both Apple and Google Play throughout the EU/EEA."
    ],
    "virality": "somewhat_high",
    "post_date": "2026-09-27T16:39:24.000Z",
    "post_kind": "text",
    "post_text": "I’m a UK-based indie developer with a small budgeting app.\n\nA company recently cold emailed me out of the blue saying that because my app had been available to EU users, GDPR Article 27 required me to appoint an EU representative. They were selling this service for around €490/year.\n\nThat email is what prompted me to look into all of this.\n\nMy situation:\n\n- Very few users and essentially no revenue.\n\n- No user accounts or backend.\n\nI don’t collect names, email addresses or other obvious identifying information.\n\n- Users enter their budgeting/financial data locally on their own device.\n\nOptional backups go to the user’s own iCloud/Google Drive account. I don’t receive or have access to those backups.\n\n- I did use Firebase Analytics, but I have now completely unlinked Google Analytics from the Firebase project.\n\nAs soon as Article 27 was brought to my attention, I removed the app from both Apple and Google Play throughout the EU/EEA.\n\nI am no longer offering the app or in-app purchases to EU/EEA users.\n\nI understand that removing the app now doesn’t necessarily determine what the legal position was historically.\n\nWhat I’m trying to understand is the real-world risk for someone in my position.\n\nHas anyone here dealt with Article 27 as a very small non-EU developer?\n\nWould Article 27 actually have applied to an app with this architecture and such limited processing?\n\nNow that...",
    "sentiment": "negative",
    "subreddit": "gdpr",
    "event_date": "2026-09",
    "post_flair": [
      "EU 🇪🇺"
    ],
    "post_title": "Small UK indie app developer cold-emailed about GDPR Article 27 - how worried should I actually be?",
    "prominence": "core",
    "source_url": "https://www.reddit.com/r/gdpr/comments/1wrow3s/small_uk_indie_app_developer_coldemailed_about/",
    "entity_role": "vendor",
    "post_author": "luckoftheirish2999",
    "upvote_ratio": 0.8666666666666667,
    "mention_count": 223,
    "mention_surge": true,
    "subreddit_url": "https://www.reddit.com/r/gdpr/",
    "total_upvotes": 11,
    "comments_total": 38,
    "total_comments": 33,
    "event_date_text": "now",
    "other_companies": [
      {
        "name": "Apple",
        "role": "partner",
        "domain": "apple.com"
      }
    ],
    "post_author_url": "https://www.reddit.com/user/luckoftheirish2999/",
    "signal_category": "feedback",
    "comments_included": 7,
    "products_mentioned": [
      "Firebase Analytics",
      "Google Analytics",
      "Google Play"
    ]
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.