Data location
Where your Kisten, account data and backups are stored and processed.
Last updated: 6 October 2026
| Data | Where |
|---|---|
| Your Kisten (disks, memory snapshots, local checkpoints) and the database that tracks them | One compute server owned by the operator, in Germany |
| Account data (e-mail, password hash, sessions, quotas, billing state, audit events) | Cloudflare D1, EU jurisdiction |
| Off-site checkpoints, primary copy (encrypted) | Cloudflare R2, EU jurisdiction |
| Off-site checkpoints, second copy (encrypted) | Cloudflare R2, western Europe location; moving into the EU jurisdiction |
| Requests in transit, edge logs | Cloudflare's global network: requests are terminated at the Cloudflare location nearest to you |
| Payments and invoices | Stripe (Ireland, with Stripe, Inc. in the USA) |
What "EU jurisdiction" means here
For D1 and R2, an EU jurisdiction makes Cloudflare store and process that data inside the EU. A location hint (used for the second backup copy today) only expresses a preference and is not a legal guarantee. That is why the second copy is moving into the EU jurisdiction too. Both copies are encrypted with keys Cloudflare does not have (see Encryption).
Transfers outside the EU
Cloudflare and Stripe are US companies or have US parents. Transfers are covered by the EU–US Data Privacy Framework and the EU Standard Contractual Clauses in their data processing agreements. Kiste has assessed them in a transfer impact assessment. The privacy policy explains this in full: kiste.run/privacy.
Where your traffic goes
Requests to kiste.run enter Cloudflare's network at the location nearest to you, which may be outside the EU, and travel encrypted from there to the compute server in Germany. The desktop stream goes directly between your browser and the compute server where possible, otherwise through a Cloudflare TURN relay that only sees encrypted packets.