I know this is why I use Wunderlist (Berlin), rather than RTM or Things or similar (USA) - I'm more comfortable under their local privacy obligations. (In reality I don't know how much difference it makes?)
1. Is their team capable of securing their environment and releasing code that isn't vulnerable to data theft attacks?
2. Do they also store all their customers' information in Germany or is it on some US-based servers?
EC2 in Europe is hosted in Ireland only.
I mean, it's just as illegal for the US to access private data in Europe if the server it's on is owned by a US company or a European one. So it's not like AWS is especially vulnerable.
No, AWS is only in Ireland. Except for Cloudfront which is in most countries but that isn't really relevant considering the data stored there.
Cultured Code are in Stuttgart