Data residency
Last updated: 25 September 2026
The short version
Everything you send to the API, and everything it returns, is processed in Saudi Arabia and never leaves it. The same is true of the account database and its backups. The only personal data that leaves the Kingdom is the email address of an account, used to deliver sign-in links and to answer your emails, and what you choose to type into the website chat.
Where each part runs
| What | Where | Personal data |
|---|---|---|
| Rendering: the HTML, web addresses and settings you send, and the PDF or image produced | Saudi Arabia, Oracle Cloud, Jeddah region (me-jeddah-1), in memory only | Whatever your documents contain. Not stored, not logged. |
| Accounts, API key fingerprints, usage counts | Saudi Arabia, the same server in Jeddah | Email address, optional company name |
| Backups of the account database | Saudi Arabia, Oracle Object Storage, Jeddah region; encrypted before upload, kept for 35 days | As above. Rendered content is never part of a backup. |
| Sign-in emails and email correspondence | Rackhost, Hungary (European Union) | Email address, message content |
| Domain name service (DNS) | Rackhost, Hungary | None |
| TLS certificates | Let's Encrypt | None |
| Website chat (only what you type into it; not part of the API) | Anthropic, United States, for questions about Sahifa; other questions are answered by our server in Jeddah | The question, if it contains any. Keys, email addresses and phone numbers are removed first; nothing is stored |
| Availability monitoring | External checks of the public website and health address, from outside the Kingdom | None |
| Administration | Yimello LLC, United Arab Emirates, over encrypted SSH to the server in Jeddah | Access only when needed to operate the service |
What this means for your audit
- There is no content delivery network, proxy or load balancer between your systems and the server. Requests go straight to Jeddah over HTTPS.
- Content sent to the API is processed in memory, returned in the same response and then discarded. It is not written to disk, logged or backed up.
- The server cannot reach private or internal networks, and every request runs in a separate, sandboxed browser context.
- Backups are encrypted on the server with a key whose private half is not kept on the server.
A signed letter for your auditor
On the Compliance plan we provide this statement as a signed letter on company letterhead, together with the data processing agreement. On other paid plans, ask at support@sahifa.dev.
Changes
If a part of the service moves to another location or provider, this page is updated first, and customers with a signed agreement are told at least 30 days in advance.