Where data lives
Application data
All workspace data (documents, cards, personas, skills, sessions) is stored in the EU. Backups are EU-resident.
Authentication
Auth state and session tokens are EU-hosted.
File storage
Uploaded files and generated artefacts are stored in EU object storage.
Logs & audit
Application logs and the audit trail are EU-resident and retained per the DPA.
AI inference
AI calls are routed through the Lovable AI Gateway, which fans out to several model providers. Some providers offer EU-resident inference; others don't. The EU-Model Restriction policy pins your org's traffic to EU-eligible models only.
Today, EU-Model Restriction is enforced server-side in 5 of approximately 14 AI edge functions (the most-trafficked ones). The admin UI shows the truthful "5 of 14" status. We're rolling out the rest; we don't claim "all AI is EU-only" until that count is 14/14.
BYOK as a residency lever
With BYOK enabled, AI calls go through your own provider account — for example an Azure OpenAI deployment in West Europe. That makes residency a contractual matter between you and your provider, and Keypra simply doesn't see the prompt content beyond what's needed to route it.
Sub-processors
The full sub-processor list (and how we notify you of changes) is published at /legal/sub-processors.