Creative AI built and hosted in Europe

FOTOhub Press Team · · 24 min read · Przeczytaj po polsku

Where your files live, what we run on our own hardware, when a job leaves Europe, and what we do not promise. A Polish company, our own server fleet, and the limits we state ourselves.

Creative AI built and hosted in Europe

There is a question that one customer in ten asked three years ago and almost every customer asks today: where does the thing I upload to an AI tool actually go. This is not a technical curiosity. It is product photography before a launch, the faces of models who signed a release, a voice actor's recording, a campaign brief, a catalogue nobody outside the company has seen. Who sees it, how long it sits there, whether somebody trains a model on it, and whether it can really be deleted afterwards.

FOTOhub is a Polish company and the platform runs on our own machines in Europe. That sentence reads like a marketing line, so this post takes it apart and shows exactly what it means and what it does not mean. You will also find a list of things we do not promise, because in this product category overclaiming is the norm and we would rather be boringly specific.

In short

The FOTOhub platform, the database, the storage holding your files and our own graphics cards all run on hardware we manage ourselves, in European data centres. We are not a wrapper on somebody else's API. A large share of the models we offer runs entirely on our machines, which means files sent to one of those never leave our infrastructure.

At the same time FOTOhub is a hub. Alongside our own models we offer partner models, because creators want the models currently leading the market in one place, not only what we managed to build ourselves. When you pick one of those, the job goes to that provider, and some of them process data outside Europe. We say so plainly, we name the providers in our privacy policy, and we show you how to build a workflow that uses only the models we run ourselves.

Then there are the unglamorous things that turn out to matter most in conversations with legal teams: published retention periods, account deletion that actually deletes, two-factor sign-in with hardware keys, team accounts with roles and an activity log, a published complaints and abuse-reporting policy, and a dedicated page about the EU AI Act. All of it is public and linked at the end of this post.

The question every customer asks now

A year ago a conversation about rolling out AI in a company started with quality. Will the model shoot the product well enough that nobody has to retouch it. Will the video flicker. Will the voice sound like a train station announcement.

Today that conversation starts somewhere else. The first question is where does this go. The second is whether we train on your material. The third is what happens if we leave. Quality is the fourth, usually phrased as "show us on our own catalogue".

This shift did not come from nowhere. It came from three things happening at once. Further obligations under the European AI regulation came into effect, so legal departments finally had to read what an AI system is and notice the ones their company had been using for years. Stories went around about customer material used to train models, sometimes on the strength of a terms change announced on a Friday after five. And something people discuss less: companies worked out that the supply chain in AI is long, and that the tool they bought is often a thin layer over somebody else's model, running on a third continent and billed by a fourth entity.

For an individual creator the stakes are different but not smaller. If you are building a portfolio, running a channel, photographing people, then your files are your work and somebody else's face. It is worth knowing whose disk they are on.

What European means on our site

The words European and sovereign are used so loosely in this industry that they have stopped meaning anything. Sometimes they mean an invoice issued in Europe. Sometimes a single proxy server in Frankfurt in front of an API on the other side of the world. Sometimes just a flag in the footer.

For us they mean four specific things.

First, the company. FOTOhub is operated by a Polish limited liability company, based in Bydgoszcz, with its court register, tax and statistical numbers written into the terms of service. We are subject to Polish and European law, and the court where you can sue us is in Poland. For the sake of completeness we will state the part others stay quiet about: alongside the Polish company we have an entity registered in Delaware, named in our privacy policy, which serves the United States market. So we are not purely EU-domiciled in the corporate sense, and we would rather write that ourselves than have somebody discover it.

Second, the hardware. The application, the database, the file storage and our graphics cards sit in European data centres, on machines we configure, patch and restart at three in the morning when that is what the job needs. This is not shared hosting and it is not a middle layer. When you generate an image on one of our own models, the electricity for that job goes into a card we rent by name.

Third, the models. We do not only resell access. We train and maintain our own family of models and we run a range of open models on our own hardware, more on that below.

Fourth, language and support. The interface ships in twenty five languages, from Polish and German to Japanese, Arabic and Vietnamese, support aims to answer in yours, and a conversation about a contract needs neither a translator nor a call at eleven at night.

Your work sits on our machines

Let us start with the part that is easiest to check and hardest to fake. FOTOhub is not an interface on top of somebody else's cloud. We run our own fleet of servers in European data centres, and everything you touch day to day runs on it.

That is where the application you open in your browser runs. That is where the database holding your projects, folders, generation history and billing sits. That is where the file storage lives, the one you upload references into and download finished material from. And that is where our graphics cards do real work for a meaningful share of the models.

This has practical consequences that are easy to miss. When you delete a file, you delete it from our storage, rather than asking an intermediary to delete it and hoping the request travels further. When you ask how many files we hold and for how long, the answer can be counted, because we have access to it. When something breaks, we fix it, instead of filing a ticket with a supplier and queueing with the rest of their customers. When more capacity is needed, we add a machine, rather than requesting a limit increase.

There is a less comfortable consequence and it is fair to name it: owning the fleet means hardware failures are ours. In exchange you get a public status page showing the state of each service, instead of a vague note about elevated latency at a third-party provider.

The models we run ourselves

This is the part that most separates FOTOhub from API wrappers, and also the part that is hardest to describe without drifting into engineering. Let us try in plain language.

A share of the models we offer are ones we download, tune and run on our own cards. The job begins and ends on our hardware. No third party sees the prompt, the file or the result, because none of them leaves our infrastructure.

That group covers a lot of the work our users do most often.

Sound and music. Music and sound effect generation, including matching audio to a finished video, runs on our machines.

Voice. Speech synthesis and our own family of voice models run with us. This is the most sensitive category of data in the whole service, because a voice sample is biometric data, so keeping it in house was a deliberate decision rather than a cost saving.

Lip sync. Matching speech to a face, also ours, also on our hardware.

Image: the IDA family and the whole tooling layer. Our own image models plus the operations nobody puts on a billboard and nobody can work without: upscaling and sharpening, face restoration, depth maps, removing and painting in parts of a frame, cutting backgrounds. Our cards compute all of that.

3D models. Turning a photo or a description into a 3D mesh, in two quality tiers, runs on our hardware.

Which means: if your workflow is record a voice, pick music, clean up photographs, cut backgrounds, build a 3D model of a product and sync speech to a face, you can run it start to finish without a single file leaving our infrastructure. For some customers that is the entire compliance conversation, closed in one paragraph.

!A server aisle in a European data centre

Partner models and what happens then

Now the part many companies in this industry leave out, and we would rather put in the middle of the table.

FOTOhub is a hub. The point of a hub is that one account and one bill give you access to the models currently leading the market, not only to what we have had time to build. So alongside our own models we offer partner models: leading image, video, speech and language models from providers in Europe, the United States and Asia.

When you choose one of those, your job goes to that provider. The prompt and the files it needs go into their system, they compute, they return a result, and we store it with us and show it inside your project. Some of those providers process data outside Europe.

There is no honest way to summarise that as "everything happens in Europe", so we will not write it. Instead we do four things.

We name the providers in the privacy policy, so you do not have to guess whose technology sits behind a given model. We limit the data we send to what the job actually requires. Reference material that has to reach a provider is covered by a retention period and a scheduled purge, rather than being left there indefinitely. And we give you a choice that means something, because the list of models we run ourselves is long enough to work on.

If your organisation has a rule that client material does not leave the European Union, that rule can be kept on FOTOhub. It requires choosing models deliberately, and that is a conversation we have with customers openly, instead of selling them a peace of mind we have no right to sell.

Sovereignty is not cutting yourself off

There is a trap here that some European providers fall into. They say our data, our servers, our models, and end up with a product that is safe and two years behind. The customer then does the predictable thing: buys the safe tool for documents and quietly generates the campaign in an American one, on a personal card. Compliance won on paper, lost in practice.

We are not taking that road. We think a European provider is obliged to be as good as anyone else, and that sovereignty should be a choice rather than a penalty. So we hold two things at once.

On one side we build our own. Our own fleet, our own models, our own tooling, because without that there is nothing to discuss and nothing to control.

On the other side we do not pretend we will single-handedly build the world's best video, image and speech model simultaneously. Nobody does. So we bring the current leaders into one place and we insist on three things: that you know whose model it is, that you know what happens to your data, and that you have an alternative here with us when you need one.

That is the difference between sovereignty as a wall and sovereignty as control. The wall is easier to put on a slide. Control is what the customer is actually buying.

What we do with your work, and what we do not

The shortest honest version: your material is used to do your job, not to improve the models everyone else uses.

We do not take your photographs, recordings, voice or prompts to add them to a general model's training pile. The privacy policy states this separately and most firmly for the most sensitive categories, namely voice samples, voice models, likenesses and likeness models, which we do not use to train general-purpose models.

There is one exception and it is a feature you pay for. If you deliberately start a training run on your own material, for instance so a model knows your product, your style or your brand, then training obviously happens. The result is simply not a better model for the whole market. The result is your model, attached to your account. That is the difference between "we learn from you" and "we let you teach the tool about you", and our whole design sits on the second side.

Beyond that, training on your data is possible only with your explicit consent. Not buried in the terms, not pre-ticked.

Who owns what you generate

After "where does this go", the second question is "whose is it". In a lot of tools the answer is surprisingly murky, and the provider's licence lets them use your work for promotion, for a conference demo or for a sample gallery.

Our terms put it plainly: content generated with the AI tools, images, video, text and code, belongs to the user. You hold full rights, you may publish, modify and sell it, on one obvious condition, that doing so does not infringe rights in the source material you worked from.

That condition is not a loophole. If you upload somebody else's photograph and have it repainted, the rights in the original still belong to somebody else and no tool changes that. Otherwise the output is yours, and you do not need our permission to earn money from something you made here.

!Reviewing documents and rights to material

How long we keep your files

This question sounds dull until you have to answer it in a vendor security questionnaire. That is when it turns out most AI tools have no answer at all.

Our periods are set out in the privacy policy. Generated material stays as long as your account exists, because it is your working library rather than our cache. Deleting a file deletes the file. Deleting an account deletes the account's data, and backups that still contain it stop containing it within thirty days. System logs live ninety days, which is what diagnostics and abuse detection need. Material from guest generations, meaning without an account, disappears after twenty four hours. Recordings from verification and anti-fraud procedures are kept for a year, because fraud protection requires it.

In one place:

DataHow long
Generated material on an accountWhile the account exists, or until you delete it
Account dataUntil account deletion
Backups after account deletionStop containing the data within 30 days
System logs90 days
Guest generation, no account24 hours
Verification and anti-fraud recordings12 months

Notice what is missing. There is no sentence saying "we retain data for as long as necessary for the purposes described in this policy", which means nothing. Numbers exist so they can be written into a processing register.

Account and team security

Data sovereignty without decent sign-in is decoration. The biggest risk to your material is not an exotic attack on infrastructure, it is the reused password of somebody who left the company six months ago.

On FOTOhub you can turn on two-factor authentication with a code from an app, and if you want more, with a hardware key or a fingerprint, using a standard that a spoofed page cannot phish. Team accounts have three permission levels, owner, admin and member, so not everyone has to see everything and not everyone can spend the budget. An admin also has a team activity log, meaning they can see who did what without writing to us for an extract. Programmatic access runs through API keys with their own limits, which can be revoked one at a time, without changing the whole organisation's password.

These look obvious written down, and in creative tools they are routinely treated as something to add later.

The AI Act: what we do and what we do not

The European AI regulation is the most quoted and least read document in our industry. We keep a dedicated page for it, because we think a tool vendor should say plainly what it takes on and what stays with the user.

What we do. We make it clear you are working with an AI system and we do not pretend there is a person on the other side. We describe what the tools are for and what they must not be used for. We run a complaints and reporting path, including reports about the use of somebody's likeness, so a person whose face or voice appeared without consent has somewhere to write and knows what to expect, even if they never had an account with us. We require consent before voice cloning. We maintain the split of roles between us as provider and you as deployer, and our terms state that the obligation to label published content as AI-generated rests with whoever publishes it.

What we do not do, and what competitors sometimes imply. We do not currently embed industry-standard technical provenance markers into output files automatically. We also do not stamp every result with a visible watermark by default, although a watermarking tool exists in the editor and you can apply it deliberately. We consider automatic provenance marking to be the right direction and we are working on it, and until it ships we will not describe it in the present tense.

We also do not hold SOC 2 or ISO 27001 certification. We follow the practices those standards describe, but a certificate is the result of an audit by an outside firm, not a vendor's assertion. When we pass such an audit, we will write about it with a date and the auditor's name.

For companies: what legal asks, and our answers

Below is what actually turns up in vendor assessments, in roughly the order it turns up.

QuestionOur answer
Who is our counterpartyA Polish limited liability company, with its address and registration numbers in the terms
Where does the platform and our files sitOn our own fleet of servers in European data centres
Does all AI computation happen in EuropeNo. Our own models yes, some partner models process data outside Europe and we name those providers
Can we work only on models you run yourselvesYes, and we will help you set that workflow up
Do you train models on our materialNot general models. Training on your data only with your explicit consent, and the result is your model
How long do you keep dataPeriods are given as numbers in the privacy policy, including 30 days for backups after account deletion
Is a data processing agreement availableFor business contracts we provide for a separate processing agreement, settled at contracting
Who are the subprocessorsModel and payment providers are named in the privacy policy
Two-factor authentication and rolesYes: app codes, hardware keys, biometrics, roles in team accounts
SOC 2 or ISO certificationWe do not hold it and we do not claim to
Is there an abuse reporting pathYes, a published complaints and reports policy, including likeness reports
Who owns the outputThe user owns generated content and may publish, modify and sell it under the terms

This table is shorter than a typical security questionnaire and that is deliberate. We would rather give twelve answers that can be checked than forty that have to be taken on faith.

How a rollout works when compliance is the condition

When a company arrives with the requirement that client material must not leave the European Union, it usually expects a project measured in months. It does not have to be. It runs in five steps and normally closes inside a week or two.

Step one: we describe what you actually want to do. Not "roll out AI", but for instance "ship three thousand product shots on white and six hundred short social videos".

Step two: we assemble the set of models. If the constraint is about data, we build the workflow from models we run ourselves, and we say openly where that means a quality trade-off and where it means none at all.

Step three: we go through the documents. Privacy policy, terms, a processing agreement with a business contract, the provider list, the retention periods. This is the part that takes longest with other vendors, because the documents have to be written first.

Step four: we set up the team account, roles, API keys and limits, so nobody generates past the budget and the activity log shows who did what.

Step five: a pilot on your material. Not on our demo. Until you see your own catalogue, everything above is still a promise.

!A product shoot in the studio

For individual creators: what changes in practice

If you have no legal department, the above may look like corporate gymnastics. It still has concrete effects on daily work.

Your library is a library, not a temporary basket. Material does not vanish after seven days because a retention window expired in somebody else's storage. You can come back to a project after six months and still have every layer.

A voice you clone requires consent, including when you are cloning a friend's voice for a joke. That is mildly inconvenient the first time and saves you the first time something goes wrong.

The bill is in your currency, the invoice looks like an invoice, and a complaint goes to a Polish company rather than into a support form with no address behind it.

And the most practical thing of all: when you write to support, somebody in your time zone answers.

Three situations where this question decides the purchase

So as not to leave this abstract, three cases that pass through our inbox every week in one form or another.

A clothing brand before a collection launch. Photographs of a collection shipping in six weeks are among the most closely guarded files in the company. Uploading them to a tool where nobody knows where files are stored is a risk legal will not accept, and marketing still needs visuals for the campaign. The answer is to compose the workflow from models we run ourselves, with a clearly stated retention period.

An agency working for a regulated-sector client. The agency signed a contract committing to specific processing conditions. It cannot simply use a tool whose terms let the vendor use the work for promotion. Here the deciding factor is the ownership clause and the absence of any licence to your work on our side.

A creator who photographs people. Sessions, portraits, a wedding, material full of faces belonging to people who consented to publication but not to landing in somebody's training set. Here one sentence decides it: we do not use likenesses or likeness models to train general-purpose models.

For investors: why this is not a compliance post

This post looks like a text about regulation and is a text about market position. Three reasons.

First, cost. A company that rents everything has variable costs equal to its supplier's price list, and a margin the supplier can take back with a single email. A company that runs its own fleet and its own models on it has a different cost structure, a higher barrier to entry and real control over margin wherever it does the work itself. That is the line between reselling and having a product.

Second, access to a market the competition cannot serve. The group of customers who cannot buy a tool without an answer to the data question keeps growing. Public administration, healthcare, finance, industry, and the agencies working for those sectors. A California vendor does not win that tender on price, because it does not clear the first questionnaire. A European vendor running its own hardware and its own models does clear it.

Third, defence against a supplier changing the terms. Anyone who built a product on a single external API can wake up to a doubled price, a switched-off model or a new data clause. Our answer is structural: some models are ours, the rest we treat as interchangeable, and contracts and billing run through us. A model can leave the market. The customer's workflow is meant to stay.

On top of that there is something you cannot buy: a reputation for telling the truth about limits. This post does not claim everything happens in Europe, and that is precisely why the things it does claim can be believed.

What we do not promise

This section is the most important one in the post and it stays in every future version.

We do not promise that every AI computation happens in Europe. Our own models, yes. Partner models depend on the provider, and some of them work outside Europe.

We do not promise a certificate we do not hold. No SOC 2 and no ISO 27001 until we pass an audit.

We do not promise automatic technical provenance marking of content. We are working on it and we will write when it works.

We do not promise nothing will ever go wrong. We run a public status page so that in that moment you do not have to take our word for anything.

We do not promise we are cheaper than everyone. We do claim that one price gives you more than a stack of separate subscriptions, and that you can do that arithmetic yourself.

How to check this yourself

You do not have to believe a blog post. Everything written here has a source you can open without creating an account.

The privacy policy contains the retention periods, the named provider list and the training clauses. The terms contain the company details, the scope of rights in outputs and the split of obligations under the AI rules. The AI Act page describes our approach to the regulation. The complaints policy describes the reporting path, including likeness reports. The status page shows the state of services live.

If a question remains that those documents do not answer, write to us. "We do not know yet" is also an answer and we prefer it to a smooth sentence with nothing in it.

A short glossary

Own model. A model we maintain and run on our hardware. The job does not leave our infrastructure.

Partner model. A third-party provider's model, offered on FOTOhub. The job goes to that provider.

Processor. In GDPR terms, a company processing data on a customer's instructions. In business deployments that is usually our role.

Data processing agreement. The document setting out what a processor may do. For business contracts we settle it at contracting.

Retention. The period after which data stops existing in the system. Ours are given as numbers.

Provenance marking. Technical information in a file recording that it was made with AI. We do not do this automatically today.

AI Act. The European regulation on artificial intelligence. It splits obligations between the provider of a system and the party deploying it.

Frequently asked questions

Do my files stay in Europe?

Files you keep on FOTOhub sit in our storage, on our machines, in European data centres. If you send a job to a partner model, the material that job needs goes to that provider, and some providers work outside Europe.

Can I use only the models you run yourselves?

Yes. The list is long enough for a full workflow: image, sound, voice, lip sync, 3D and the whole editing tool layer. For business deployments we help assemble that set.

Do you train models on my material?

Not general-purpose models. Training on your data happens only when you start the paid own-model training feature yourself or give explicit consent, and the result belongs to your account.

What happens when I delete my account?

The account's data is deleted, and backups stop containing it within thirty days. Individual files you can delete at any time.

Will I get a data processing agreement?

With a business contract, yes, settled during contracting. Write to us before you sign anything else.

Do you hold SOC 2 or ISO 27001?

No. We follow the practices those standards describe, but we have not been through an external audit and we will not claim otherwise.

Can I use generated material commercially?

Yes, under the terms. It is worth reading that section before you ship a campaign.

Does this mean you are slower or weaker than the American competition?

No. The partner models that rank among the best on the market today are available here from day one. The difference is that we say where they run, and we give you an alternative.

Finally

The easy version of this post would have been one sentence: everything happens in Europe, sleep well. It would have taken a paragraph, looked good in an advert, and been untrue.

We chose the longer version, because the customers we care about will check anyway. A company buying an AI tool today is not looking for a vendor without limits. It is looking for a vendor who knows where the limits are and can show them in writing.

A year ago we launched a platform meant to gather scattered creative work into one place. Over that year the most common question stopped being "will it make a nice photograph" and became "can I trust you with this". This post is our answer, together with the list of things we still do not have.

We are a Polish company, building from Bydgoszcz and Warsaw for users in dozens of countries, and we intend to deliver the rest of that list.

For press and investors: the privacy policy, terms of service, AI Act page, complaints policy and status page are all publicly available from the site footer. For press and partnership enquiries please use the contact form.