Back
Security

Where is My Data Stored?

Where VULK stores conversations, project files and media, and how storage differs from CDN delivery and AI processing.

Where is My Data Stored?

Configuration checked: 19 September 2026.

VULK uses different services for its database, file storage, application servers and content delivery. A database location does not describe every service involved in a project.

Storage locations

Data or serviceProviderCurrent location or configuration
Main database, including account records, Studio conversations and stored project sourceAWS RDS PostgreSQLFrankfurt, Germany (eu-central-1); encrypted at rest
Uploaded images and other media stored as files in the Studio media storeCloudflare R2Cloudflare reports Western Europe (WEUR); the bucket uses the default jurisdiction
Separate project-file storage, including mobile build artifactsCloudflare R2Cloudflare reports Eastern Europe (EEUR); the bucket uses the default jurisdiction
Automated backups of the main RDS databaseAWS RDSRegional backups with a configured retention of 30 days
Application servers inspected for this configurationHetznerFalkenstein, Germany
PostgreSQL service for VULK-managed application backendsHetzner-hosted backend serviceFalkenstein, Germany; separate from the main VULK database on AWS RDS
Help center and self-hosted support inbox, including its local database and attachment storageHetzner, with Chatwoot operated by VULKHelsinki, Finland; separate from the Studio database and generated-application backends

Text attachments that are incorporated into a Studio conversation are stored as message content in the main database. Images and other media stored as files follow the R2 storage path. Project content can also be copied into preview, build or publishing environments when those features are used.

Data in applications you create

The main VULK database stores builder conversations and project source. The managed backend of a generated application uses a separate PostgreSQL service. The location and 30-day automated backup setting of the main RDS database must not be assumed to apply to the generated application's database or its backups.

An external backend or integration selected for an application has its own storage and processing scope. Publishing the application through Cloudflare does not move its database to Cloudflare or establish a new database residency guarantee.

What the R2 location means

Cloudflare's regional location and its jurisdiction restriction are separate settings. Our current R2 configuration reports European locations, but does not enforce the EU jurisdiction restriction. We therefore cannot currently guarantee that R2 storage is exclusively restricted to the European Union.

Cloudflare describes these settings in its R2 data location documentation.

CDN delivery and publication

Cloudflare also delivers content through its global network. Media served through the CDN and published applications have a delivery path separate from the underlying database or object store. A European storage location is not a guarantee that all CDN processing takes place in Europe.

AI processing

AI features send the input needed for a request to the services used for that feature. This can include prompts, relevant project files and attached media. The storage region does not determine the processing region of those services.

When the assistant uses the backend inspection tool, a limited sample of application records can also be included in the model request. The tool masks values in columns identified as credentials, such as passwords and tokens. This masking does not anonymize all application data or remove every possible personal-data field.

VULK does not currently provide an end-to-end guarantee of EU-only AI processing. The region in this article should not be interpreted as such a guarantee.

Support conversations

The chat in this help center is a support conversation, separate from project-building conversations in the Studio. The Studio database location does not describe storage of support messages.

The help-center chat sends visitor messages to VULK's self-hosted Chatwoot inbox so the support team can follow up. The AI assistant processes the current message and relevant conversation history through OpenRouter. Escalation notifications can also send excerpts and contact or technical context to Telegram. These are separate processing paths; hosting the support inbox in Finland does not make all support processing EU-only.

The widget sends the visitor's message to the inbox separately from requesting the AI answer. An AI answer does not confirm that the inbox received that message. The widget does not automatically copy the AI assistant's replies to Chatwoot. The displayed conversation is held in the current widget state; a browser session identifier reconnects the visitor to the support inbox.

Starting a new chat clears the widget's current conversation state. It does not request deletion of previously stored support conversations. For a data deletion request, contact [email protected].

Data protection enquiries

For institutional requirements, a data processing agreement (DPA/AVV), or a specific residency requirement, contact [email protected]. The agreed scope needs to cover the services and data involved in your use of VULK.

A supplier's DPA does not replace an agreement between VULK and your organization. A paid subscription alone is not confirmation that a particular AVV has been signed or that all requested services and guarantees are covered.

See also our subprocessor and GDPR information and Privacy Policy.

On this page

VULK Support

Online

Hi! How can I help you today?

Popular topics

AI support • support.vulk.dev