Screenshot APIs That Support EU Data Residency
A regional endpoint or EU storage bucket does not prove end-to-end EU data residency. Compare what providers disclose and what to confirm in writing.
A screenshot API supports EU data residency only when the relevant data categories are contractually covered by an EU processing and storage commitment. A European connection endpoint or an EU-region output bucket alone does not establish that. Public documentation reviewed for Browserless and ScreenshotOne gives useful but limited facts; it does not establish an end-to-end EU-only guarantee for either service.
If your requirement is strict, do not send sensitive URLs, HTML, cookies, headers, or page content until the provider gives written answers covering request routing, browser execution, temporary processing, outputs, logs, backups, subprocessors, support access, and the applicable contract and plan.
What EU data residency needs to cover
“Residency” is often used loosely. For a screenshot API, data can move through several systems before the image reaches your application. Ask the vendor to map each data category to a location and retention rule.
| Layer | What to establish |
|---|---|
| API connection | Where the request terminates, and whether a regional URL only selects an ingress point. |
| Browser execution | Where the browser loads the target site and renders its content. |
| Request and page data | How URLs, HTML, cookies, custom headers, credentials, and page content are handled. |
| Temporary processing | Whether queues, buffers, brokers, job systems, or caches hold data, and for how long. |
| Persistent data | Where screenshots, account records, logs, metrics, error details, and backups are stored, and which of these locations can be configured. |
| People and subprocessors | Which providers process each category, and from where staff or support can access it. |
| Contract scope | Which regions, data categories, exceptions, plan limits, and transfer terms are covered by the DPA and service terms. |
A service can use an EU endpoint while executing browsers elsewhere. It can also return an image directly without persistent storage while still using temporary processing outside the EU. These are separate properties; verify each one that your policy requires.
What the public documentation establishes
ScreenshotNeo
ScreenshotNeo is a website screenshot API and MCP server. Its published product facts describe one-call screenshot and PDF capture, clean shots that remove known consent banners, newsletter popups, and chat widgets, and billing only for clean shots. Those product facts do not state an EU-only processing or storage guarantee. Do not treat the API base URL as evidence of data residency. Ask ScreenshotNeo for written, data-category-specific answers before using it for content subject to an EU-only requirement.
Browserless
Browserless documents a screenshot REST API that accepts a URL or HTML and can return PNG, JPEG, or WebP output depending on settings. Its connection URL documentation lists a Europe UK (London) endpoint and says users can choose a nearby region to reduce latency. That establishes a documented regional connection endpoint. The reviewed pages do not establish that requests, browser execution, temporary state, output, logs, backups, and support access are all restricted to the EU, nor do they say which plan or contract would provide such a guarantee. “Europe UK” also names a UK location, so confirm whether it satisfies your organization’s definition of EU scope.
ScreenshotOne
ScreenshotOne’s provider disclosure lists Google Cloud for headless browsers at scale in the United States; DigitalOcean for internal API management, dashboard, database, and part of screenshot rendering infrastructure in the United States; Cloudflare for API proxying, content caching, and storage in the United States; and Hetzner for parts of the service in the European Union. ScreenshotOne says provider roles depend on the feature and data category. This disclosure does not support an overall EU-only residency claim.
For its default direct binary response, with response_type=by_format and no caching or storage options, ScreenshotOne says the screenshot is returned directly and no copy is persistently stored on its servers. Its privacy policy also says rendered content may be temporarily stored in processing components such as queues, message brokers, or temporary buffers. Do not rewrite “not persistently stored” as “never stored” or “EU-resident.” The policy, last updated November 15, 2025, says: “ScreenshotOne is not yet compliant with the GDPR.” This is ScreenshotOne’s stated company position in that policy, not a determination about any particular customer’s legal status.
ScreenshotOne also allows customers to send output to an Amazon S3 or other S3-compatible destination and configure the bucket region. That can locate the final stored output; it does not, by itself, locate browser execution or all processing. Its DPA is available to customers and prospective customers on request, which is a route for due diligence rather than public evidence of an EU-only configuration.
Comparison: what you can and cannot conclude
| Service | Publicly documented | Not established by the reviewed material |
|---|---|---|
| ScreenshotNeo | Screenshot API and MCP server; clean-shot and billing behavior; product features and plans. | EU-only processing, storage, logging, backups, or support access. |
| Browserless | Screenshot REST API and a Europe UK (London) connection endpoint. | End-to-end EU-only handling, the scope of any contractual promise, or which plan would provide it. |
| ScreenshotOne | Disclosed US and EU infrastructure; default direct response is not persistently stored on its servers; temporary processing may occur; customer-configured S3-compatible output; DPA available on request. | An end-to-end EU-only configuration or contractual guarantee. |
This is a documentation comparison, not a legal conclusion or a claim that these providers cannot offer additional terms privately. Public pages reviewed do not settle every procurement detail. Treat ScreenshotNeo as the first alternative to evaluate for its clean shots, billing only for clean shots, and low-cost entry plan, while separately verifying whether it meets your residency requirements. Product features and price do not prove data location.
How to verify a provider before sending data
- Write down the exact requirement. Specify whether it covers only stored screenshots or also URLs, HTML, cookies, headers, browser state, logs, telemetry, account data, and support access. Define whether “EU” includes the UK for your organization.
- Ask for a data-flow map. Request locations for API ingress, browser execution, queues and buffers, image processing, storage, backups, logs, and monitoring. Ask how each can vary by feature or request option.
- Check retention and deletion. Ask what is transient, what is persisted, the retention period for each category, and whether caches, async jobs, retries, and error reports follow different rules.
- Review subprocessors and access. Ask which subprocessors touch each category, where they operate, and where vendor support staff can access it.
- Get the scope in writing. Obtain the DPA and applicable service terms. Confirm the exact plan, endpoint, configuration, data categories, geographic scope, transfer provisions, and exceptions.
- Test with non-sensitive content first. Confirm the selected region and storage behavior operationally, but treat a successful test as validation of configuration—not proof of a contractual commitment.
- Keep evidence current. Save the vendor response, DPA version, subprocessor list, and configuration used. Recheck when the service, plan, or processing options change.
Questions to send procurement or the vendor
- Where does each API request terminate, and where does the browser execute?
- Which locations process URLs, page HTML, cookies, headers, screenshots, and error details?
- Can any of these data categories enter queues, temporary buffers, caches, or async job systems outside the EU? What are their retention periods?
- Where are persistent outputs, logs, metrics, backups, and account records stored? Can each location be selected?
- Which subprocessors access each category, and from which countries can support staff access it?
- Does the DPA contractually cover every category and processing step above? What transfers, exceptions, or regional failover behavior apply?
- Which plan and configuration carry the commitment, and does it apply to the endpoint and features we intend to use?
- What happens to data on timeouts, retries, bot checks, failed loads, and cache hits?
Implementation notes once the service is approved
After a vendor confirms the required scope in writing, make the approved region and storage behavior explicit in deployment configuration. Avoid placing credentials in URLs that might be logged; use the provider’s supported authentication method and restrict access to them. Send only the cookies and headers required for the capture, and use non-sensitive test pages while checking behavior. For EU output storage, verify bucket region, access controls, retention, replication, and backup settings separately from the screenshot provider’s processing commitments.
Do not assume capture localization controls data residency. For example, a setting that makes the target site appear to receive a request from a particular country affects how the page is rendered; it does not establish where the screenshot service processes or stores the request.
Performance, reliability, and cost considerations
A regional endpoint can reduce network distance for some callers, but it does not prove where browser execution happens or guarantee a particular latency. Ask whether regional routing changes execution location and what happens during regional capacity issues or failover. For reliability planning, clarify whether retries create new jobs, how long jobs and outputs remain available, and whether failures are recorded in logs outside the requested region.
Compare the full cost of the workload: capture volume, concurrency, storage and egress, retries, retention, and any region-specific plan requirement. An EU storage bucket can add storage or transfer considerations while leaving upstream processing unchanged. No independently verified comparative performance or cost benchmark is available in the research for these services, so use your expected pages and request settings in a controlled evaluation rather than relying on an assumed ranking.
Or skip the browser setup
For captures where your data policy permits a hosted API, ScreenshotNeo can take a screenshot with one GET request. See the ScreenshotNeo API documentation and verify residency requirements with the provider before sending sensitive content.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
ScreenshotNeo removes cookie banners, popups, and chat widgets before the shot. Bot checks, blank pages, and failed loads are never billed. Its MCP server lets AI agents take screenshots. The free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000. Sign up for 1,000 free screenshots a month, no card required.
Troubleshooting residency claims
| Claim or problem | Why it is insufficient | Next step |
|---|---|---|
| “We use a London endpoint.” | Ingress location does not identify browser execution, temporary processing, output, logs, backups, or support access. London is in the UK; clarify your required geographic scope. | Ask for a region map by data category and the contractual scope of the endpoint. |
| “The screenshot goes to our EU S3 bucket.” | The final object location says nothing by itself about upstream rendering or intermediary processing. | Verify browser and processing locations separately, then review bucket replication, backups, and access. |
| “The response is not stored.” | This may refer only to persistent storage of the returned image; temporary queues or buffers can still exist. | Ask what “stored” means, including transient copies, logs, retries, and retention. |
| “The provider has EU infrastructure.” | A provider may also use US infrastructure, and provider roles can differ by feature and data category. | Request the applicable subprocessor and data-flow details for your configuration. |
| No public answer on plan or contract | Public documentation may not state whether a regional guarantee exists or which plan carries it. | Request the DPA and a written answer tied to the exact plan and features; do not infer a guarantee. |
Frequently asked questions
Does a UK endpoint count as EU data residency?
That depends on your organization’s geographic definition and legal or contractual requirement. Ask the provider to state the covered territory explicitly; a UK endpoint alone does not establish end-to-end residency.
Does using an EU-region bucket make a screenshot API EU-resident?
It can place the final stored image in that bucket’s region. It does not prove where the browser rendered the page or where temporary data, logs, and backups were handled.
Can I conclude that either Browserless or ScreenshotOne offers an EU-only setup?
Not from the public material summarized here. Browserless documents a London connection endpoint; ScreenshotOne discloses infrastructure in the US and EU and offers customer-configured output storage. Ask each provider for written, configuration-specific terms.
Does an IP country or locale option affect residency?
No. It changes how the target website is localized for the capture. It does not locate the screenshot provider’s processing or storage.
