Security and trust

Data location

Where your Kisten, account data and backups are stored and processed.

Last updated: 6 October 2026

DataWhere
Your Kisten (disks, memory snapshots, local checkpoints) and the database that tracks themOne compute server owned by the operator, in Germany
Account data (e-mail, password hash, sessions, quotas, billing state, audit events)Cloudflare D1, EU jurisdiction
Off-site checkpoints, primary copy (encrypted)Cloudflare R2, EU jurisdiction
Off-site checkpoints, second copy (encrypted)Cloudflare R2, western Europe location; moving into the EU jurisdiction
Requests in transit, edge logsCloudflare's global network: requests are terminated at the Cloudflare location nearest to you
Payments and invoicesStripe (Ireland, with Stripe, Inc. in the USA)

What "EU jurisdiction" means here

For D1 and R2, an EU jurisdiction makes Cloudflare store and process that data inside the EU. A location hint (used for the second backup copy today) only expresses a preference and is not a legal guarantee. That is why the second copy is moving into the EU jurisdiction too. Both copies are encrypted with keys Cloudflare does not have (see Encryption).

Transfers outside the EU

Cloudflare and Stripe are US companies or have US parents. Transfers are covered by the EU–US Data Privacy Framework and the EU Standard Contractual Clauses in their data processing agreements. Kiste has assessed them in a transfer impact assessment. The privacy policy explains this in full: kiste.run/privacy.

Where your traffic goes

Requests to kiste.run enter Cloudflare's network at the location nearest to you, which may be outside the EU, and travel encrypted from there to the compute server in Germany. The desktop stream goes directly between your browser and the compute server where possible, otherwise through a Cloudflare TURN relay that only sees encrypted packets.

On this page