Data residency

Where your data lives — and who answers for it

Last updated: August 2026

Most memory vendors put “EU compliant” on the homepage and then name no storage location at all in their privacy policy. This page does the opposite: every claim here is specific, named, and checkable.

The most important difference is not a server location but a line of accountability. Palim is operated by a natural person with a service address in Germany. There is no holding company in a third country, no representative carrying the responsibility on someone else's behalf, and no ambiguity about which supervisory authority applies.

The hard facts

Controller under Art. 4(7) GDPR
Jan Ole Schmidt, Kellersweg 7, 35764 Sinn, Germany

Service address inside the EU — see the imprint.

EU representative under Art. 27 GDPR
Not required

Art. 27 requires a representative only for controllers with no establishment in the Union. This controller is established in Germany.

Competent supervisory authority
Hessian Commissioner for Data Protection and Freedom of Information (HBDI), Postfach 3163, 65021 Wiesbaden, Germany

You can complain directly, in German or English.

Content storage location
Frankfurt am Main, AWS eu-central-1

Database and auth run on Supabase in the EU region.

API server location
Render, Frankfurt region

Declared in render.yaml, the service's infrastructure definition.

Governing law
German law, GDPR and BDSG

Complete subprocessor list

This is the full list. Anyone not named here does not see your content.

Stated plainly: your sessions and memories live and stay in the EU. The last two entries are the exceptions, and we list them here instead of letting them disappear under “EU hosting” — email delivery runs through a US service, and in one narrowly bounded edge case a single brain topic leaves the EU for consolidation.

This is part of the truth too: Supabase, Render, and Vercel are US companies operated here in EU regions. “Data in the EU” therefore does not mean “vendors with no US ties” — it means processing happens in the EU and a German controller is accountable for it. Anyone promising you more than that is selling a simplification.

ServicePurposeProcessing location
SupabaseSupabase Inc.Database and authentication — your sessions, memories, and account live hereEU — Frankfurt, AWS eu-central-1
RenderRender Inc.Runs the MCP and API serverEU — Frankfurt region
VercelVercel Inc.Serves this marketing website, plus optional analytics after your consentGlobal CDN — processes no session content
ResendResend, Inc.Transactional email such as the weekly digest — processes your email address and the content of that messageUnited States
AnthropicAnthropic PBCNot in use. Palim can have an oversized brain topic rewritten by a language model, which would transmit that one topic's decrypted content. The feature is switched off and has to be enabled deliberately — a stored key alone is not enoughUnited States — currently inactive, see below

Encryption — and what we explicitly do not claim

Supported content fields are encrypted server-side at rest with AES-256-GCM. A per-user key is derived via scrypt from a master key managed by Palim. Transport runs over HTTPS/TLS.

This is not end-to-end and not zero-knowledge encryption. Palim can decrypt your content in order to provide the service — search, distillation, and retrieval do not work otherwise.

We say this bluntly because the opposite claim is common in this market and rarely holds: advertising that no single party holds all the keys while simultaneously searching and summarizing content server-side describes two things that cannot both be true. We would rather make the verifiable claim than the prettier one.

Deletion under Art. 17 GDPR — where this actually stands

You can delete individual sessions and memories at any time. What matters is what happens to the distilled knowledge: Palim condenses saved sessions into topic documents, and a deletion that only removes the source session would leave the content standing in that second layer.

That was broken twice and has been fixed: deletions now propagate into the distilled layer without removing entries that other, undeleted sessions also carry. Both failure directions — deleting too little and deleting too much — have been verified since 10 August 2026 and are re-checked against production in a recurring self-test.

What is still missing, stated just as plainly: there is no one-click full account deletion today. It runs through an informal message to privacy@usepalim.com and is carried out manually. Self-service for this is in progress.

The one place data could leave the EU — and how to check it yourself

Palim condenses saved sessions into topic documents. When a topic outgrows its size limit there are two paths: trim it locally, which loses detail, or have a language model rewrite it, which transmits the decrypted content to that model's provider.

The second path is switched off. More useful than that promise is that you can verify it: the service publishes its own state at api.usepalim.com/health under „brain_consolidation“. If it reads „none“, this transfer is not happening.

The switch is deliberately separate from the credentials: a stored API key does not enable the feature. Naming a provider without its credentials stops the service from starting at all, rather than quietly falling back to some other route. If this is ever turned on, it will say so in that field, in the subprocessor list above, and in the privacy policy — before it runs.

What you can verify yourself

Every claim on this page can be cross-read: the controller in the imprint, the processing details in the privacy policy, the server location in the service's infrastructure definition, the consolidation state in the /health endpoint.

If something here is no longer accurate, that is a mistake and not marketing latitude. Write to privacy@usepalim.com and the page gets corrected.

Compared: Palim and MemoryLake

MemoryLake is currently the most visible competitor in cross-tool memory and actively markets to Europe. The table below lists only points that can be read off the other side's public privacy policy.

CriterionPalimMemoryLake
Storage location namedYes — Frankfurt, AWS eu-central-1No — the privacy policy names no storage location, only possible processing in countries other than your country of residence
EU representative under Art. 27 GDPRNot required — controller established in GermanyNo representative named; operator based in Singapore
Subprocessor listComplete, with purpose and processing locationNot published
German-language versionYes — site, privacy policy, and supportNo German version
Supervisory authority identifiableYes — HBDI, WiesbadenNot derivable from the privacy policy

Basis: our own review of the publicly available privacy policy at memorylake.ai, retrieved 13 August 2026. Vendors change their policies — verify for yourself if it matters. This compares transparency and accountability disclosures only, not feature scope or quality.

Frequently asked questions

Does my data leave the EU?

Your stored sessions and memories live and are processed in Frankfurt (AWS eu-central-1). One exception concerns email: when Palim sends you a message, such as the weekly digest, the delivery provider Resend processes your email address and the content of that message in the United States. A second path exists in the code — rewriting oversized brain topics with a language model — but it is switched off, and you can verify that at api.usepalim.com/health under „brain_consolidation“. If it reads „none“, nothing but email delivery leaves the EU.

Is Palim end-to-end encrypted?

No, and we do not claim it is. Content is encrypted at rest with AES-256-GCM, but Palim can decrypt it to provide the service. End-to-end encryption would be incompatible with server-side search and distillation.

Why does Palim have no EU representative under Art. 27 GDPR?

Because the article does not require one here. An Art. 27 representative is mandated for controllers without an establishment in the Union. Palim's controller is established in Germany — the role a representative would fill is already occupied.

Can I have my account fully deleted?

Yes, by writing to privacy@usepalim.com. Deletion is currently carried out manually; a self-service option is in progress. Individual sessions and memories you can delete yourself at any time, including the entries distilled from them.

Who is liable if something goes wrong?

The controller named in the imprint, under German law, at a service address you can actually reach. You do not have to pursue your rights against an entity in a third country.