Your analytics data
In the European Union — Frankfurt, Germany (eu-central-1).
That is a single region. Your page views, your sites, your account and your team memberships all live there. Backups stay in the same region.
It is not replicated to other regions, and it is not moved.
Your billing data
Stripe, who process payments for us. They hold your payment method, your billing address and your invoice history.
Stripe never receives analytics data. The two systems share nothing except your subscription's identity — which plan you are on and whether it is paid. No page view, no visitor identifier and no site data reaches them.
Stripe operates globally with EU processing for EU customers. Their own data processing terms cover that half.
Where requests are handled
Your visitors' page views are received by our collector and written to the database in Frankfurt. Regional edge infrastructure may terminate the HTTPS connection closer to your visitor before forwarding it, which is how the request reaches us quickly — but nothing is stored at that layer.
Your visitors' IP addresses are not stored anywhere, in any region. The IP is used in-memory to resolve a country, region and city, and — on the cookieless modes — to derive a session identifier, and is then gone. See What we store, and what we don't.
Transfers
Analytics data does not leave the EU in normal operation.
For billing, the transfer is Stripe's and is governed by their terms and by Standard Contractual Clauses where those apply.
If you need this documented formally, see Data processing agreement.
Who can reach your data
Access is enforced at the database level rather than by application convention, so a bug in a query cannot cross the boundary. There are exactly three paths in:
A signed-in member of your organisation, with an accepted membership.
An API key you created, scoped to your organisation and — optionally — to specific sites. See Authentication.
A share link you created, which is read-only, anonymous, and shows only what you chose to show. See Public dashboards.
There is no fourth path. A request with no credential reaches nothing.
Our own staff access is limited to what is needed for support and incident response, and is not a routine part of operating the service.
If a region matters to your compliance
Right now there is one region and it is in the EU, which is the answer most compliance questions are looking for. Data residency in another region is not available — there is no US or Asia-Pacific option to select. If you need one, support@truestat.io is where to say so.