whats-best.ai

Project Management & Collaboration

Vikunja

EU-Made Report an error

Panel rating · 6 judges · How to read the stars

Category median

Sovereignty: 2 of 4 dimensions proven

0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.

by Vikunja (open source) · vikunja.io

Report an error on this page Is this your product? →

Read this page as one judge. Each weighs the same scores by what they care about.

The Data Protection Officer

Weighted verdict

Reads the DPA before the feature list. Optimizes for GDPR posture: EU hosting, subprocessor exposure, deletion guarantees. Rejects anything that cannot answer where the data lives.

Same scores as the panel view — this lens weights them the way this judge cares.

Scored by The Data Protection Officer

Collaboration depth

How this is scored

How much real multi-person project work the tool carries: shared planning, assignments, dependencies, workload, comments, guest access.

0 — A personal task list; a second user has no defined place in it.

3 — Tasks can be shared and assigned, but planning stays per-person — no shared timeline, workload or dependency view.

5 — Solid shared projects with assignments, comments and at least one team-level planning view; gaps appear in cross-project or capacity planning.

8 — Team-level planning is first-class: cross-project views, workload/capacity, dependencies, guest or client access with sane permissions.

10 — Handles the full span from two freelancers to a structured department in one model — planning, capacity, permissions and client involvement all without workarounds.

Report an error

The Data Protection Officer

Projects can be shared with a user, a team or a link share, tasks carry assignees, comments and attachments, and eleven relation types including blocking give real dependencies, with List, Kanban, Table and Gantt views providing a shared timeline. Cross-project visibility is achieved through saved filters rather than a dedicated view, and we found no public information on workload or capacity planning. 1 6 12

Report an error

Reporting

How this is scored

Whether the tool can answer questions about the work: progress, time, budgets, utilization — and export the answer.

0 — No reporting beyond looking at the board.

3 — Fixed per-project status views only; nothing aggregates across projects and nothing exports cleanly.

5 — Useful standard reports (progress, tracked time) with basic filters and CSV export, but limited customization and no budget/utilization depth.

8 — Configurable cross-project reporting incl. time, budgets and utilization, with dashboards and reliable exports.

10 — Reporting is a product in itself: custom report builder, scheduled delivery, API access to every metric the UI shows.

Report an error

The Data Protection Officer

The dashboard, saved filters and the Upcoming view with a date range picker let a person see overdue and due work across projects, which goes beyond fixed per-project status. We found no public information on time tracking, budgets, utilization or report exports; the only export evidenced is copying as Markdown. 7 12

Report an error

Integrations

How this is scored

How well the tool connects to the rest of the stack: native integrations, calendar/comms hooks, API and webhooks, import/export paths.

0 — A closed box — no API, no integrations, CSV out if anything.

3 — A handful of marquee integrations, no public API or an API that covers a fraction of the product.

5 — The common set (calendar, Slack/Teams, file storage) plus a documented public API; automation platforms partially covered.

8 — Broad native catalogue, well-documented API and webhooks, first-class automation-platform support and real import paths from competitors.

10 — Ecosystem-grade: everything in 8 plus the tool is itself extensible (apps/plugins, AI/MCP surfaces) and exit via API export is complete.

Report an error

The Data Protection Officer

Webhooks are genuinely deep — project and user webhooks across nineteen documented events, HMAC-SHA256 signatures, token-authenticated management — alongside CalDAV, a surface for AI clients, and importers from Todoist, Trello, Microsoft To Do, Planka, TickTick, WeKan, CSV and JSON with custom migrators supported. We found no public information on native integrations with chat or file-storage services or with automation platforms. 9 11 12

Report an error

Onboarding effort

How this is scored

Time and friction from signup to first real value for a small team, without paid services.

0 — No self-serve path — onboarding starts with a sales call and an implementation project.

3 — Self-serve exists but the first project requires configuration a newcomer cannot judge yet (workflows, custom fields, permissions) before anything works.

5 — A team gets a first project running within a day; trial requires payment details or key steps live behind docs.

8 — Signup to working project inside an hour: guided setup, sensible defaults, templates, trial without payment details.

10 — Minutes to value even for non-tool-people, importers pull existing work in, and the tool teaches its own advanced features as the team grows into them.

Report an error

The Data Protection Officer

The product begins as a personal to-do list with plain-text quick add, and cloud users can import from Todoist, Trello or Microsoft To-Do "in minutes" through a settings screen without a publicly reachable instance. Self-hosted migration carries configuration a newcomer must judge — a public URL setting for OAuth imports and a network-safety setting for local sources — and we found no public information on guided setup, templates or trial terms. 1 2 11

Report an error

European sovereignty

How this is scored

Where the company and the data actually sit: legal entity, ownership control, data residency, and subprocessor exposure to non-EU jurisdictions.

0 — Non-European vendor, data on US infrastructure under US law, no DPA worth the name.

3 — DPA and GDPR language present, but hosting defaults to the US or ownership sits outside Europe — compliance paperwork over substance.

5 — EU data residency is available and contractually fixed, but the vendor or its controlling owner is non-European, or core subprocessors put data within CLOUD Act reach.

8 — European company under European control with EU-resident data and a public DPA; remaining exposure is limited to identifiable subprocessors (e.g. a US hyperscaler's EU region) and is documented.

10 — European company, European control, EU-only data residency on European infrastructure, subprocessor list free of extraterritorial reach — verifiable, not asserted.

Report an error

The Data Protection Officer

The imprint names Konrad Langenberg Software in Lübeck with a German VAT ID, all of Vikunja Cloud runs at Hetzner in Germany and Finland under ISO/IEC 27001, and the privacy policy publishes user rights with a dedicated GDPR contact — plus self-hosting puts the data entirely on your own infrastructure. What holds this below the top is that only the hosting subprocessor is named, we found no public information on processors for email, support or payment, and no public data processing agreement for the cloud service appears on the captured pages; ownership control beyond the imprint is likewise not evidenced. 2 3 4 5

Report an error

Support & documentation

How this is scored

Whether a stuck user gets unstuck: docs quality, support channels and their availability per plan, and the health of the learning surface.

0 — No docs beyond marketing pages; support is a contact form that may answer.

3 — Docs exist but are thin or stale; support on entry plans is effectively email-only with slow turnaround.

5 — Searchable help center covering the core product; chat or email support on all plans with reasonable response times.

8 — Deep, current docs incl. onboarding guides and templates; fast chat support not gated to top tiers; visible changelog.

10 — Docs, academy, community and support so good they are a reason to buy; SLAs published, support quality independent of plan.

Report an error

The Data Protection Officer

The help center covers twenty-one topics from tasks and views through permissions and webhooks, backed by separate technical documentation for server setup, API details and development. Support runs by email with paid consulting, training and an enterprise tier bundling SLAs and priority access to the developers, but we found no public information on chat support, published response times or a visible changelog. 12 13

Report an error

Pricing transparency not rated — the vendor publishes no price

How this is scored

Can a buyer determine the real, payable cost of the tool for their team before talking to anyone?

0 — No public pricing at all — every number sits behind "contact sales".

3 — Some tiers are public, but a deciding factor (seat minimums, mandatory add-ons, billing-period surcharge, tax treatment) only surfaces at checkout or in fine print.

5 — Self-serve tiers are publicly priced and the billing-period difference is stated, but the headline number still needs qualifying — e.g. annual-only headline, taxes excluded without saying so, or an opaque enterprise tier doing real work.

8 — Every self-serve tier is fully priced with billing periods and tax treatment plain on the page; only genuinely custom enterprise work lacks a number.

10 — Every tier including enterprise has a public price or published price formula, and the headline number is the number on the invoice.

Report an error

The Data Protection Officer

The captured pages show no price for any tier of the hosted cloud offering, and the only payment information anywhere is sponsorship through GitHub Sponsors, Open Collective or Buy Me a Coffee, which funds development rather than purchasing the product. We found no public pricing for the cloud or the enterprise support packages, so the payable cost cannot be determined before contacting the vendor. 2 13

Report an error

European sovereignty — proven facts

2 of 4 dimensions proven

Built only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.

Ownership Not determined ⚠ unverified — uncited Report an error
Data residency EU only ⚠ unverified 3/3 pts 5 Report an error
Subprocessors EU only ⚠ unverified 2/2 pts 5 Report an error

Where this could be wrong

What we left out

A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.

Sources (13)

The pages every claim on this page was read from — each one checked, dated, and kept verifiable.

  1. 1 Vendor homepage vikunja.io Checked 15 Sep 2026 Details →
  2. 2 Hosted cloud vikunja.cloud Checked 15 Sep 2026 Details →
  3. 3 Privacy policy vikunja.io Checked 15 Sep 2026 Details →
  4. 4 Imprint vikunja.io Checked 15 Sep 2026 Details →
  5. 5 Security / trust page vikunja.io Checked 30 Sep 2026 Details →
  6. 6 Collaboration depth — found from sitemap vikunja.io Checked 1 Oct 2026 Details →
  7. 7 Reporting — found from sitemap vikunja.io Checked 1 Oct 2026 Details →
  8. 8 Integrations — found from sitemap vikunja.io Checked 1 Oct 2026 Details →
  9. 9 Integrations — found from sitemap vikunja.io Checked 1 Oct 2026 Details →
  10. 10 Onboarding effort — found from sitemap vikunja.io Checked 1 Oct 2026 Details →
  11. 11 Onboarding effort — found from sitemap vikunja.io Checked 1 Oct 2026 Details →
  12. 12 Support & documentation — found from sitemap vikunja.io Checked 1 Oct 2026 Details →
  13. 13 Support & documentation — found from sitemap vikunja.io Checked 1 Oct 2026 Details →