Skip to main content

Help · Privacy + data

Where your ConKarma data physically lives.

Data residency is one of the questions we get most often, and the answer should be boringly straightforward.

Your ConKarma data is stored in one region for every account: the application database, media storage and sign-in (Supabase) run in AWS London, United Kingdom, with a separate administrative database in AWS Ireland (EU). The backend servers are hosted by IONOS in Germany and DigitalOcean in the United States. Where you sign up or travel doesn't change where your data is stored; the full sub-processor list, with regions and transfer safeguards, is at /legal/subprocessors.

Data is encrypted at rest by the provider and in transit with TLS 1.3 minimum. Access is cell-scoped — only your cell members can see your data — and any ConKarma admin access for authorized support is audit-logged and reviewable on request. Children's accounts run a COPPA parent-consent flow with no advertising or marketing profiling.

Region

One region for every account. The application database, media storage and sign-in (Supabase) run in AWS London, United Kingdom; a separate administrative database runs in AWS Ireland (EU). The servers that run the ConKarma backend are hosted by IONOS in Germany and DigitalOcean in the United States. Where you sign up or travel doesn’t change where your data is stored. The full list, with regions and transfer safeguards, is at /legal/subprocessors.

The actual stack

Database: Postgres hosted on Supabase. Image and media storage: Supabase Storage. Both run in London. Short-lived sign-in codes and rate-limit counters: Redis on Upstash, in Ireland. Encrypted at rest by the provider, encrypted in transit (TLS 1.3 minimum) between your device and us.

Cell-scoped access

Data is keyed to cells. Your data is only accessible to your cell members. ConKarma admins can access cell data only for a narrow set of authorized support purposes, every access is audit-logged, and the audit trail is reviewable on request.

COPPA for children

For accounts opened by or for children under 13, the parent-consent flow runs at activation. Retention defaults to 7 years from last activity — configurable downward, not upward. No advertising serves to a child account. No marketing profiling, ever.

Per-jurisdiction addenda

The base privacy policy applies globally. Layered on top: California (CCPA + CPRA), the EEA + UK (GDPR + UK-GDPR), Quebec (Loi 25), Australia (Privacy Act 1988), Brazil (LGPD). The addenda live at /legal/addenda — they explain what changes for your jurisdiction.

Frequently asked questions

Where is my data physically stored?
Does my data region change when I travel abroad?
Can ConKarma staff read my cell's data?
Is there anything specific for children's data?