IN SHORT
- The platform, the database and everything you build sit in the European Union, in Frankfurt.
- One exception, stated plainly: model processing may happen outside the EEA under the European Commission's standard contractual clauses. Data the AI never sees never leaves.
- Support can open your studio to help you. That door exists, it is named, and it is the honest answer to "who can see my data".
- Export everything as files and as a database dump. Test it in your first month, while nothing is wrong.
Where it physically sits
In Frankfurt, inside the European Union. The application, your database, the files you upload and the continuous backups are all in the same place, and none of them are replicated outside the EU.
This matters less for the legal box-ticking than people assume and more for the practical questions. Latency is low from Bulgaria. There is a single jurisdiction to reason about. And when a client asks where their customer records are held, the answer is one city rather than a paragraph.
The full statement lives on the security page rather than here, because that page is maintained as a commitment and this article is commentary on it. If the two ever disagree, the security page is the one that counts.
The one exception, said before you ask
Model processing may happen outside the EEA, under the European Commission's standard contractual clauses. That is the only part of the picture that leaves Europe, and it only involves what you actually send to a model.
The practical rule is short: data the AI never sees never leaves. If a customer's payment history is not part of the text you send for processing, it is not part of the transfer. Systems that read invoices send invoices, not the whole customer file.
A supplier who tells you nothing ever leaves the EU while running models is either not running models or not telling you everything. We prefer to name the exception and let you design around it, because the design that keeps sensitive fields out of model calls is straightforward once you know to build it.
Who can actually see it
You and whoever you give a login to. Plus one more: support can open your studio in order to help you. That door exists and is named on the security page rather than hidden in a subprocessor list.
The support door is the one people are surprised to be told about, which is exactly why it is stated. Every hosted platform has some version of it; the difference is whether the supplier writes it down.
| Who | What they can reach |
|---|---|
| You and your colleagues | Everything, according to the roles you set |
| Support, when helping | Your studio - the openly named door |
| Stripe | Card data only; it never touches our database |
| The model provider | Only the text of a request you send |
| Anyone else | Nothing |
How you take it all out
Records export as files you can open in a spreadsheet, and the database exports as a full dump. Both are yours, on request, without a negotiation and without a leaving fee.
The right you are exercising here is not contractual generosity, it is Article 20 of the GDPR: personal data in a structured, commonly used, machine-readable format. What we add is the rest of it - the tables that are not personal data, the files, the schema - because a export that is technically compliant and practically useless helps nobody.
Test it in your first month. This is the single piece of advice in this article that people skip and later regret. An export you have opened once, while everything is calm, is a fact. An export you have been promised is a sentence in a contract.
What happens if you stop paying, or we stop existing
Stopping is not a cliff. When a balance cannot cover the monthly draw there are fourteen days of grace before anything is switched off, and your data is not deleted at the moment your credits run out.
Keeping every system on the account running draws 1,250 credits a month. Because it is a draw from a balance rather than a subscription, there is no card that fails, no dunning cycle and no automatic escalation - an account simply stops drawing when it stops buying.
On the harder version of the question, the honest answer is a procedure rather than a promise: take the export, keep it somewhere you control, and repeat it on a schedule you decide. Any supplier who answers "we will always be here" is answering a different question than the one you asked.
What we do not have
No ISO 27001 or SOC 2 certificate of our own, no two-factor authentication yet, no 24/7 on-call, no published penetration test, and backups that are taken continuously but have never been rehearsed as a full restore.
That list is uncomfortable to print and it is the reason to trust the rest of the page. A supplier that publishes only its strengths has told you about its marketing, not its security.
If your situation requires a certified supplier - because a client demands it, or because a tender does - that is a legitimate reason to choose someone else, and it is better learned now than during a procurement review. The full gap list, kept current, is on the security page.
QUESTIONS
Is my data used to train models?
No. What you build and what you put in it are yours; it is not read, extracted or used for training.
Can I get a database dump rather than spreadsheets?
Yes. Ask and we produce a full dump. The spreadsheet export exists because most people want to open the file, not restore it.
What happens to my data if I stop using the platform?
Take the export first - that is the step that matters. Nothing is deleted at the moment credits run out, and there is a fourteen-day grace period when a balance cannot cover the monthly draw.
Are you a data controller or a processor?
For the systems you build with your own customers' data, you are the controller and we are the processor. The privacy page sets out what that means in practice, including subprocessors.
How quickly would we be told about a breach?
Within 72 hours of becoming aware, matching the GDPR obligation, with the honest caveat that a breach at an upstream provider reaches us on their timetable and not ours.
RELATED
Security - the maintained version of everything summarised here
Your data and exports - how to run the export yourself
Seven security questions - what to ask any supplier, including us
Privacy - controller, processor and the subprocessor list