The Safe Harbor Agreement was invalidated by the Schrems I case in 2015. The Schrems II case from 2020 invalidated the EU-US Privacy Shield Agreement.
In addition, the physical location of the servers do not change anything when the company operating those servers is American. They still need to comply with the CLOUD Act, even to the point of pulling data and encryption keys from servers based in the EU.