Docs navigation

Platform

EU data residency

foro.sh runs on European infrastructure by construction. There's no region to select when you deploy; it's simply where everything runs - and, unlike the short version of this claim you'll see elsewhere on the site, this page names the actual provider, the operating entity, the GDPR roles each of us holds, and exactly which narrow paths leave the EU and why.

EU data residency by concern: what foro.sh does, and what that rules out
Concernforo.shWhat that rules out
Compute & routingOVH Groupe SAS (France), every planNo region picker, no non-EU fallback region
Log storageOVH Object Storage, FranceNot applicable
OperatorDJH Tech, a Netherlands sole proprietorshipNo US entity in the chain for a CLOUD Act warrant to reach
Ownership chainNo non-EU parent companyNo foreign-government access via a parent
Request pathNo non-EU provider between caller and containerNo Chapter V third-country transfer to account for
ComplianceGDPR by default, DPA on requestNot applicable

Every container, every deploy

The compute a deployed server runs on, the proxy that routes to it, and the storage that holds its logs are all EU-based. There isn't a separate "EU tier" a workspace opts into - it's the same per-project container and network every deploy gets, run this way by default, on every plan.

Named plainly: the platform - API, database, job queue, identity service, and reverse proxy - and every container it deploys run on infrastructure operated by OVH Groupe SAS, a company incorporated and headquartered in France. PostgreSQL and Redis run self-hosted on that same infrastructure rather than as separate managed databases from a third vendor, which is one fewer party in the chain, not one more. Persisted logs, nightly database backups, and uploaded project archives sit in OVH Object Storage, also in France.

Controller for the account, processor for what you deploy

foro.sh is operated by DJH Tech, a sole proprietorship registered in the Netherlands - not a subsidiary of a larger group, and not a US company anywhere in its structure. That matters for more than the provider table below: it is also the entity whose GDPR role changes depending on which data you mean.

For account data - your identity, email, encrypted repository tokens, and billing records, where they exist - foro.sh is the controller, processing it under performance of the contract with you (Art. 6(1)(b) GDPR) and a legitimate interest in keeping accounts secure (Art. 6(1)(f)). For the content you deploy and whatever your own MCP server does with data at runtime - including the logs and metrics that server produces - foro.sh acts as processor, and you, or your organisation, remain the controller. A data processing agreement covering that relationship is available on request for paid plans. The full breakdown, category by category, is the privacy policy's job; this page states the split, not the whole document.

The non-EU touchpoints, named

"Fully European" describes the request path and the storage layer, not a claim that literally nothing ever crosses a border. It doesn't, for the paths that matter most - but a short list of narrower, named paths can, and hiding that list would make the rest of this page less credible, not more.

PathWhat leaves the EUWhy it exists
GitHub sign-in or repo connectionYour GitHub OAuth token, and the repo contents GitHub serves back over HTTPS at build timeCustomer-initiated: only if you choose GitHub. Codeberg (Germany) and direct archive upload are EU-local alternatives for the same repo-connection step.
GitLab repo connectionYour GitLab OAuth token, and the repo contents GitLab serves back over HTTPS at build timeCustomer-initiated: only if you choose GitLab. Codeberg (Germany) and direct archive upload are EU-local alternatives for the same repo-connection step.
Dashboard chat (optional)Chat messages and tool results, to whichever OpenAI-compatible endpoint you configureBring-your-own-key by design. Where that provider is located is your choice, not foro's - leave it unconfigured and nothing is sent.
Build-time package registriesOrdinary HTTPS requests for base images and dependencies (e.g. Docker Hub, PyPI)An ordinary package download, not an upload of your project or its secrets. Every registry publicly serves the same package to anyone who asks for it.
Cloudflare (DNS, TLS challenges)DNS queries for the foro.sh zone and the domain names used in DNS-01 certificate challengesNo project content or customer data crosses this path - only the hostname being routed. Cloudflare, Inc. participates in the EU-US Data Privacy Framework.
Let's Encrypt (certificate issuance)The domain name a certificate is issued forStandard for TLS issuance industry-wide; no personal or project data involved beyond the hostname itself.

Every other subprocessor in the platform - Codeberg (Germany), WeSender (Netherlands) for account email, Mollie (Netherlands) for billing, UptimeRobot (Czech Republic) and Healthchecks.io (Latvia) for external monitoring - is itself EU-based. The complete, currently-maintained list lives on the privacy policy, which is the page we update first if any of this changes.

How this compares to a typical setup

"EU-hosted" means different things depending on what it's actually describing. Picking an EU region from a US-parented cloud provider satisfies a residency checkbox; it doesn't change which legal system can compel that provider to produce data. The distinction that actually matters for a security review is jurisdiction over the company, not just geography of the disk.

foro.shTypical US-parented platform
Compute & object storage providerOVH Groupe SAS - incorporated and headquartered in FranceA US-incorporated hyperscaler, even when you pick its "EU region"
Operating entityDJH Tech - a Netherlands sole proprietorship, with no US parent anywhere above itUsually a Delaware or California corporation, or a subsidiary of one
Reachable by a US CLOUD Act warrantNo - no entity in the hosting chain is subject to US jurisdictionYes - the US parent can be compelled regardless of which region the data physically sits in
EU hosting availabilityThe only mode there is, on every plan including FreeOften a specific region selection, sometimes gated to a higher tier
Cross-border transfer mechanism neededNone for the request path - there is no non-EU hop to coverStandard Contractual Clauses or similar, layered on top of a still-US-reachable provider
Non-EU touchpointsA short, named list (see above) - narrow, and optional in the case of GitHub and GitLabUsually the primary compute and storage substrate itself

Why it matters for a team

For a server that touches real customer or company data, where the platform actually runs is usually one of the first questions a security review asks. Here that question has a short answer: nothing between a caller and the container leaves the EU, so the third-country transfer rules in Chapter V of the GDPR never come into play for the request path. What your own server chooses to call is still yours to account for, and the table above is the starting point for scoping that. Jurisdiction is one half of a security review; the other is what's enforced on the container itself, covered on the security specifications page.

None of this is a substitute for reading the actual policy. It's the pillar page for the topic - the privacy policy is the binding document, with the full subprocessor list and retention ladder; this page exists so the shape of the answer doesn't require reading it first.

Does the US CLOUD Act reach data hosted on foro.sh?

The CLOUD Act lets US law enforcement compel a company that is subject to US jurisdiction to produce data it controls, no matter which country the servers holding it are in - it reaches the company, not the country the disks happen to sit in. It does not, on its own, reach a company with no US incorporation, no US parent, and no US operations. foro.sh's compute and object storage run on OVH Groupe SAS, a French company, and the platform itself is operated by DJH Tech, a Netherlands sole proprietorship - neither is a US entity, so a CLOUD Act warrant has no US company in that chain to serve. The exception is the narrow set of named paths that do touch a US company: GitHub, Inc., if you connect a GitHub repo or federate sign-in through it; GitLab Inc., if you connect a GitLab repo; and Cloudflare, Inc. for DNS and certificate challenges only, which never carries your project data. Codeberg (Germany) and direct archive upload sidestep both GitHub and GitLab entirely if that specific exposure matters to you.

Is EU hosting a paid add-on, or an "EU region" you have to pick?

Neither. There's no region selector at deploy time and no separate EU tier to opt into - every container, on every plan including Free, runs on the same EU infrastructure by default. Enterprise doesn't get a different guarantee here; it gets a longer log-retention window, not better jurisdiction.

Does Schrems II apply to foro.sh?

Schrems II is the 2020 CJEU ruling that invalidated the EU-US Privacy Shield and requires an extra transfer-impact assessment whenever personal data crosses into a country without an adequacy decision - most often the US. It's a question you have to answer when a provider in your chain sits outside the EU; it's not one foro.sh needs an answer for on the request path, because there is no non-EU hop in it to assess. It does still apply, narrowly, to the paths you choose yourself - GitHub if you connect a repo through it, and your own LLM provider if you turn on dashboard chat - the same short list named above.