What an EU gateway does to your risk profile
Why the jurisdiction of the traffic filter matters more than the promise behind it.
When you add a bandwidth-sharing SDK to your app, you're not just adding code. You're inheriting a slice of the operator's risk profile: their buyers, their filtering, their jurisdiction. So the right question isn't “does this vendor have a use policy?” — everyone has a document. The right question is: where is the policy enforced, and what happens when it's violated?
A policy is a promise. A gateway is a mechanism.
There are two architectures in this industry. In the first, the operator publishes rules and trusts buyers to follow them; enforcement is reactive — someone complains, someone investigates. In the second, every buyer request physically passes through the operator's gateway before it touches any device, and the rules are applied there, in code.
The difference shows up in one detail: with gateway enforcement, a request to a prohibited category — a bank, a government domain, an account-creation endpoint — is dropped before it reaches a user's device. Not detected later. Not investigated after a complaint. Dropped. Your users' connections are never party to the request at all.
Why the EU part matters
Jurisdiction determines what an operator must do, not what it says it does:
GDPR applies by default. An EU operator processes consent, records and operational data under EU law — the strictest widely-adopted privacy regime. The consent basis — GDPR Article 6(1)(a) — isn't a marketing choice, it's a legal obligation with enforcement behind it.
There is a real entity to hold accountable. NextGen Connectivity OÜ (operating as Clearhop) is an Estonian company with a public registration number, published policies and a registered address. If something goes wrong, there is a door to knock on — which is exactly what your counsel checks first.
Gateway logs live under EU rules. Every request is logged and attributable to a specific vetted buyer. Abuse reports get investigated against records, not memories — and confirmed violations end the buyer's access.
What this means for a publisher, concretely
Three practical consequences for you and your app:
When your store reviewer or counsel asks “what prevents abuse?”, you have a mechanism to point at — not a paragraph. The compliance page is written for exactly that conversation.
Your users' IP addresses appear only in traffic that already passed the published acceptable-use policy. The nine prohibited categories aren't aspirational — they're a filter.
If a report ever names your app, attribution works in your favor: the operator can show which buyer sent what, when, and through which consented device — and act on it.
The question to ask any vendor
One question separates architectures faster than any sales call: “If a buyer sends a request to a prohibited destination, at what point is it stopped — and can you show me the log?” An operator with gateway enforcement answers in one sentence. An operator without it changes the subject.
RELATED
First in, best terms.
A limited set of founding partners get elevated rates, a direct line to the team, and a say in the SDK roadmap.
Request access