All docs
4 min read Last updated:

Regional hosting

Formspring runs in one region: the EU. Application servers, the primary database, background workers, object storage for uploaded files, and backups are all EU-resident. This is the same for every team, on every plan, and it is not a setting.

There is no US region, no per-project region picker, and no plan tier that unlocks a different location. If you have read otherwise anywhere in this documentation, this page is the correct version.

What runs where

Component Location
Application servers EU data centre, Falkenstein (Germany)
Primary database EU data centre, same location as the application
Object storage (file uploads) EU object storage, Falkenstein (Germany)
Background workers EU data centre, same location as the database
Backups EU data centre, same location as the database, encrypted
Content delivery network Global, marketing pages only - never submission traffic

Submissions, uploaded files, and submission metadata do not leave the EU in the normal course of processing.

The data that does travel

Some third parties process a narrow slice of data outside the EU. This is the complete list, and each one is a sub-processor with its own agreement:

  • Payment processing for your own subscription billing. Required to take a card. Submission data is never sent.
  • Transactional email delivery, which carries the notification or autoresponder message itself.
  • Spam classification, only when you have enabled it on the form, and only for the fields that have not been marked as personal data.
  • Human-verification challenges, only on forms where you have switched a challenge on. The submission payload is not sent.
  • Optional AI features, only on plans that include them and only on forms where you have switched the specific feature on.

Every one of these is opt-in except payment processing and transactional email, both of which are required to run the service at all. The vendor names, purposes, and countries are in the sub-processors disclosure, which is the authoritative list.

Confirming where your data is

Each project page shows the residency statement under Project → Settings → Data region:

text
Project -> Settings -> Data region: EU - Falkenstein, Germany

It reads the same on every project because there is only one answer. When project metadata is exported or inspected by support, the stored machine-readable key is eu-falkenstein.

Projects created before September 2026

Between May 2026 and September 2026 the project settings panel offered a second option labelled "US - Ashburn, Virginia". That picker recorded a preference and nothing else: no code path ever read it to choose a database, a disk, a queue, or a backup target, and no customer data was ever stored outside the EU as a result of selecting it.

If you selected it, your project's data has been EU-resident the entire time, exactly like every other project. The picker has been removed, the stored value is normalised to the EU key the next time the project is saved, and the project page now reports the EU location it always had. If you chose that option because you needed US residency, the honest answer is that we never provided it - please write to info@pixelandprocess.de so we can work out what you need.

Can I pin a specific country or data centre?

No. There is a single EU location and no mechanism to select a different one. We would rather say that plainly than offer a control that does not reach the storage layer.

If a contract requires residency in a specific EU country, write to info@pixelandprocess.de before you sign it so we can tell you honestly whether we can meet it.

Cross-region replication

There is none, because there is no second region to replicate to. Backups stay in the EU with the data they were taken from.

What's next