A developer built Seneschal, an OAuth broker that lets AI agents access Gmail, Calendar, and Drive with user approval while keeping tokens secure. Google's Restricted tier requires expensive security assessments and annual reviews, so Seneschal remains in Testing mode (100 users max) until demand justifies the compliance costs.
More than 44,000 people have filed legal objections to prevent their health data from being used by the Palantir-powered Federated Data Platform operated by NHS England. The coordinated campaign leverages data protection rights, forcing the NHS to justify continued use of personal information, amid broader controversy over Palantir's work with the Israeli military and US immigration enforcement.
ScrubVault is a lightweight, zero-dependency Python privacy proxy that masks personally identifiable information (emails, IBANs, credit cards, tax IDs) in prompts before sending them to cloud LLMs like ChatGPT and Claude, then restores original values in responses. It operates entirely in-memory, includes MCP server support, and provides CLI tools for auditing GDPR compliance risk and scrubbing datasets.
Turbofy is an AI-native platform that enables users to build hosted web applications, automations, and data systems in a single integrated workspace without coding. It combines functionality typically requiring six separate subscriptions, supports GDPR compliance, and allows non-programmers to create responsive apps through AI agents like Kimi K3 and Grok.
A user documents how LG WebOS artificially blocks app store access unless the TV can reach LG's telemetry and ad servers, forcing a choice between privacy and basic functionality. By isolating the TV on a network that blocks tracking domains, the author discovered WebOS deliberately gatekeeps app management and shows how this constitutes forced consent under GDPR Article 7(4).
A user documents how LG WebOS artificially locks the app store behind a mandatory telemetry requirement, blocking app management until tracking servers are accessible. By analyzing DNS logs and testing with temporary access, the author proves the lockdown is purely artificial gatekeeping and argues it violates GDPR Article 7(4) on forced consent.
Marginalia Search is a website that complies with GDPR and the EU Cookie Directive by not collecting personal information and limiting cookie use to service functionality. Access logs with IP addresses are retained for up to 24 hours, while anonymized logs may be kept longer for debugging purposes.
Luhnify is a zero-PII API service that validates government-issued IDs, passports, and VAT numbers across 200+ countries with sub-50ms response times. It offers self-service API key generation, GDPR compliance with European data residency, and flexible pricing from free student tiers to enterprise plans.