Published July 29, 2026 · Facts last verified July 29, 2026
This article is general information, not legal advice. Data protection and cross-border transfer law differ by country and are moving quickly around AI; vendor residency options change month to month. For your own situation, consult a qualified lawyer or your compliance officer. Your use of Secret Chat is governed by our Terms of Service and Disclaimers.
Typing a question into an AI chatbot feels placeless. The box is on your screen, the answer appears in the same box, and nothing in between suggests geography.
In the seconds between those two events, your sentence becomes a packet on a specific fibre, crosses a specific set of national borders, and is loaded into the memory of a specific accelerator in a specific building with a postcode. That building sits in a country. That country has courts, police, and intelligence services. And the company operating the building answers to a legal system that may not be the one you live under.
That is what "data residency" is about. It has become one of the most-marketed properties in enterprise AI — and one of the most misunderstood, because the phrase promises a great deal more than it delivers. This article is about what it actually covers, what it provably does not, and what an individual can do about it when the residency menu is not offered to them at all.
Three Words That Are Not Synonyms
Almost every confused conversation on this topic comes from collapsing three different things into one.
Data residency is a factual and contractual matter: where data physically sits. It is something a vendor can configure and promise you — a region setting, a commitment in a contract.
Data sovereignty is a legal consequence: whose law governs that data and who can compel its production. You do not choose it from a dropdown. It follows from where the data is, who holds it, and where that holder is incorporated — and those three answers are frequently in different countries.
Data localisation is a state mandate: a law requiring that certain data not leave a national territory at all. Russia's Federal Law 242-FZ is the sharpest widely-cited example, requiring personal data of Russian citizens to be stored on servers inside Russia. China layers a cross-border security assessment regime on top of its Personal Information Protection Law. India's 2023 Digital Personal Data Protection Act took the opposite structural route — a negative list, where transfers are permitted except to countries the government restricts — while keeping sectoral hard rules such as the Reserve Bank of India's requirement that payment system data be stored in India.
Residency is a setting. Sovereignty is a consequence. Localisation is an order. A vendor can sell you the first, cannot sell you the second, and has no say over the third.
The Route a Prompt Actually Takes
"Where does my data live" sounds like one question. In an AI system it is at least six, and each hop has its own answer.
- Your device. Whatever the app keeps locally — history, drafts, cached files.
- The application's own servers. If you are using anything other than the model provider's first-party app, there is a middle layer that receives your prompt before the model does.
- The provider's API entry point. Routing happens here, and it is the least visible decision in the whole chain.
- The inference cluster. The accelerators that actually read your tokens and generate the reply. This is the hop people mean when they picture "where the AI is".
- Storage at rest. Conversation history, uploaded files, logs, abuse records — if any of it is retained.
- Subprocessors. Safety classifiers, analytics vendors, web-search back ends, support tooling. Each is its own company in its own country.
A residency commitment almost never covers all six. Read carefully and it usually covers exactly one of them.
The Distinction That Does the Most Damage: Storage vs Inference
Here is the single most useful thing to understand about AI residency, and the one the marketing language is worst at conveying.
Storage residency means your saved content sits at rest in a chosen region. Inference residency means the model actually runs in that region. They are separate promises, sold separately, and for years the industry offered only the first.
OpenAI is the clearest illustration because it has publicly moved through both stages. It introduced European data residency in early 2025, and in November 2025 extended residency to business customers in the UK, Canada, Japan, South Korea, Singapore, India, Australia and the UAE. Reporting on that announcement made the boundary explicit: the expansion targeted data at rest, not data being used for inference, whose default location remained the United States — meaning that at the moment a user interacted with the model, the prompt was temporarily processed on US-based infrastructure before the result came back. On 16 January 2026 OpenAI added in-region GPU inference — what its help centre calls inference residency — for eligible ChatGPT Enterprise, Edu and Healthcare customers in the US and Europe. Separately, API customers can create a Project pinned to Europe, where requests are handled in-region with zero data retention.
Two lessons sit in that paragraph. First, for roughly a year, "OpenAI offers EU data residency" was true and simultaneously did not mean your prompt was processed in Europe. Second, even now the guarantee attaches to GPU execution on in-scope content for eligible plans — not to every operation the platform performs.
Anthropic documents its own position plainly, and it is worth quoting rather than paraphrasing. Its help centre states that it "utilizes multiple cloud service providers to process customer data" and that "by default, we may route customer traffic to select countries in the US, Europe, Asia and Australia, unless otherwise agreed upon or at your instructions." Then the line that matters: "Note that data is stored in the US." So the routing may be European while the storage is American — precisely the inverse of the assumption most people make. Enterprise customers can request US-only inference; the commonly used route to European processing for Claude models is not the first-party API at all but deployment through AWS Bedrock or Google Cloud Vertex AI in European regions.
Google's Vertex AI takes the most explicit approach of the three: regional and jurisdictional endpoints pin both storage and machine-learning processing to a stated region or multi-region, while the global endpoint deliberately does not — it routes wherever capacity is, and offers no residency guarantee. That is a reasonable engineering trade (the global endpoint exists because it is more available and often faster), but it means the same model, the same account and the same API can be inside or outside your jurisdiction depending on one string in a request.
And one corollary that catches people out: zero data retention is not residency. If nothing is stored, storage residency is a claim about an empty set. The live question becomes where the inference ran — which is exactly the promise that arrived last.
The Building Is in Frankfurt. The Company Is Not.
Suppose you get everything above: European storage, European inference, a signed commitment. Are your prompts beyond the reach of a foreign government?
Not if the company holding them is American. The 2018 CLOUD Act added 18 U.S.C. § 2713 to the Stored Communications Act, and its wording is the whole argument: a provider of electronic communication service or remote computing service "shall comply with the obligations of this chapter to preserve, backup, or disclose the contents of a wire or electronic communication and any record or other information pertaining to a customer or subscriber within such provider's possession, custody, or control, regardless of whether such communication, record, or other information is located within or outside of the United States."
The obligation attaches to the provider, not to the server. What matters is possession, custody or control — not latitude.
This is not a theoretical reading. On 10 June 2025, Anton Carniaux, director of public and legal affairs at Microsoft France, appeared before a French Senate inquiry commission on public procurement and digital sovereignty. Asked whether he could guarantee under oath that data of French citizens held in Microsoft's cloud would never be transmitted to US authorities without the agreement of French authorities, he answered: "Non, je ne peux pas le garantir." No, I cannot guarantee it. He added, fairly, that no such demand had been received.
What makes the exchange instructive is the timing. Four months earlier, in February 2025, Microsoft had completed the third and final phase of its EU Data Boundary — one of the most substantial regional-residency programmes any cloud provider has built, covering customer data, pseudonymised personal data and, in that last phase, professional services data such as support logs and case notes for core services. The same company can have the industry's most complete European residency engineering and still be unable to give that guarantee. That is not hypocrisy; it is the difference between residency and sovereignty, stated out loud.
Precision matters here, and over-claiming is easy. The CLOUD Act also created a mechanism for providers to challenge orders where the target is not a US person and disclosure would conflict with the law of a country holding a qualifying executive agreement, and orders can be contested on comity grounds. The honest summary is not "the US can take anything at any time." It is: a residency setting is not a jurisdictional firewall, and no vendor can honestly tell you otherwise.
What the Law Actually Requires (Usually Not Residency)
A surprising number of "we need EU data residency" requirements turn out, on inspection, to be requirements for something else.
The GDPR does not require European storage. It requires an appropriate Chapter V mechanism for a restricted transfer to a third country — not merely because personal data is being processed. If your processor is in the EEA, you need a data processing agreement under Article 28; you do not need a transfer mechanism. If data does leave, the routes are an adequacy decision under Article 45, or Standard Contractual Clauses with a transfer impact assessment, or one of the narrower Chapter V options.
As of today the European Commission recognises a limited list of adequate destinations, including the UK, Switzerland, Japan, South Korea, Canada for commercial organisations, and — added in January 2026 — Brazil. The United States sits on that list only through the EU–US Data Privacy Framework, and only for organisations that have self-certified to it. That route has an asterisk: the General Court dismissed the challenge to the Framework's adequacy decision in September 2025, and the applicant appealed to the Court of Justice on 31 October 2025 in Case C-703/25 P, which is pending. It is the same court that struck down Safe Harbour and Privacy Shield, which is why practitioners keep SCCs ready as a fallback rather than treating adequacy as permanent.
The EU AI Act says nothing about where your prompts live. It is a product regulation, not a privacy law: it disciplines AI systems while the GDPR disciplines the data. It imposes no residency duty, no retention limit and no restriction on tying prompts to accounts. From 2 August 2026 its Article 50 transparency obligations require that you be told you are talking to a machine and that synthetic content be marked — useful, but orthogonal to geography. We covered its actual reach in a separate guide.
HIPAA does not require US storage either. It requires a Business Associate Agreement and the Security Rule safeguards. Location is not the control; the contract and the safeguards are — a point we unpack alongside SOC 2 and DPAs in the compliance alphabet.
Where residency genuinely is the legal requirement, it is usually a localisation statute (Russia), a sectoral rule (payments, defence, some public-sector procurement), or a customer's own contractual commitment inherited down the chain.
When Location Really Did Decide the Outcome
None of the above means geography never matters. It decided one of the most abrupt regulatory actions taken against an AI chatbot.
On 30 January 2025 the Italian data protection authority, the Garante, imposed an urgent limitation on the processing of Italian users' personal data by the Chinese companies behind DeepSeek, and the app was pulled from Italian app stores. The authority had sent an information request two days earlier asking, among other things, what data was collected, on what legal basis, and in which country it was stored. The companies' position — that they did not operate in Italy and were not subject to the GDPR — was found insufficient. DeepSeek's own privacy policy stated that personal data was stored in China.
Other supervisory authorities opened inquiries in the same period, and several governments restricted the app on official devices. Whatever one thinks of the merits, the destination country was central to the decision — not incidental to it.
What Residency Never Answers
Here is the structural limitation of the whole concept, and the reason a residency checkbox can leave you no better off.
Residency answers where. It does not answer:
- Linked to whom? A record's danger to you comes from the identifier attached to it, not its coordinates.
- For how long? Retention runs on its own clock, and different classes of record run on different ones.
- Used for what? Training, evaluation, abuse review, product analytics — all governed by policy, not by geography.
- Readable by whom? Support staff, safety reviewers, subprocessors. Regional data can still be accessed by people elsewhere, which is exactly why Microsoft's EU Data Boundary needed a dedicated phase for support data.
- Producible on what order? As above — that follows the holder.
Put bluntly: a prompt stored in Frankfurt and tied to your email address, your device and your card is a worse position for you than a prompt processed in Oregon and tied to nothing at all. Location without identity is a load statistic. Identity without location is still a file about you.
And If You Are Not an Enterprise, You Get None of It
Everything described above — regional projects, jurisdictional endpoints, inference residency, data boundaries — is sold as an enterprise capability. Individual consumer subscriptions do not carry a region selector. There is no dropdown in the paid consumer tiers of the major assistants that lets you decide which continent your question is answered on.
So for most people reading this, the practical residency options are: use a provider whose default happens to suit you, use an enterprise account through an employer, run a model locally, or accept that this particular lever does not exist for you and pull a different one.
That last option is more interesting than it sounds, and it is where the rest of this article goes.
The Lever That Is Available to Individuals
If you cannot choose the country, you can still change what arrives there.
- Reduce what is stored at all. A record that does not exist has no jurisdiction. Turn off history and training where the setting exists — but know what those toggles cover; we went through the fine print on "temporary" modes separately, and the retention windows are longer than most people assume.
- Break the link between the record and you. This is the highest-leverage move available without an enterprise contract, because it devalues the record wherever it lands.
- Redact before you send. Names, case numbers, account numbers, addresses. No routing decision, in any country, protects text you typed yourself.
- Keep your own copy local. Chat history that lives in your browser's storage rather than on a server has an easy residency answer: your desk.
- Date every vendor claim you rely on. The OpenAI example above changed materially twice in fourteen months. A residency page you read last year may describe a different product.
- Ask which of the six hops is covered. Storage? Inference? Support? Subprocessors? A vendor that can answer crisply is telling you something; one that answers "we're EU-hosted" is telling you something too.
How Secret Chat AI Fits — Including Where We Fall Short
Secret Chat AI is built around the identity link rather than the map, and on a residency article it would be dishonest to describe only the flattering half.
What we do. Secret Chat AI removes you from your queries — it does not remove the data from your messages. Your prompt reaches the model through our gateway under our credentials, from our servers: the record on the provider's side carries our gateway's identity, not your name, your account, your IP or your device. We build no profile of you, no conversation is ever associated with you, and your queries are never used for training. Registration takes an email, but it is used only for account access and payment — never stored against your prompts. Retention may still apply at the provider under its own terms and configuration; the point is that whatever is retained is not linked to you. You use the model as a stranger. "Anonymously" here describes the link, not the words: write your own name or your case number into a message and it is all still sitting there in the message.
Why residency is a smaller question on our side. There is no stored chat archive to have a location. Your history, threads and files live in your own browser (IndexedDB and OPFS). A prompt exists on our servers only for as long as it takes to fetch your answer — the request record is deleted the moment your browser collects the reply, and an hourly sweep clears anything orphaned by a closed tab. You cannot ask a jurisdictional question about a conversation store that does not exist.
What we do hold, and where. We are not a zero-data service, and the honest list is short: ordinary infrastructure telemetry — IP addresses, request timestamps, error codes — kept at most 30 days, which is not a record of what you asked; an anonymous device token and basic visit data used for free-tier limits and marketing attribution, kept separate from conversations; and the Session Privacy Report PDFs generated when you delete a response, which are archived in EU-based object storage on servers in Germany and contain deletion metadata — model, provider, status, response identifiers — not prompt text. Secret Chat is operated from Montenegro, which is not among the destinations the European Commission has recognised as adequate; as our Privacy Policy states, transfers rely on standard contractual clauses where required.
What we do not offer — plainly. We do not sell a region selector. Our gateway calls the providers' standard APIs, so where inference happens is the provider's default, not something you can pin through us. We do not sign Business Associate Agreements and we are not a HIPAA or enterprise compliance solution. And anonymity is not a jurisdictional shield: it is not privilege, not a legal exemption, and not a way to place anything beyond what a court is entitled to. If your obligations require processing inside a named jurisdiction with contractual proof, you need an enterprise arrangement with in-region inference — not us. What we offer is the other axis entirely: the record arrives wherever it arrives without your identity attached to it.
Frequently Asked Questions
- What is AI data residency?
A commitment about where data physically sits — usually where saved content is stored at rest, and increasingly also where model inference runs. It is a vendor configuration and a contractual promise, not a legal status. It is distinct from data sovereignty (whose law governs the data and who can compel it) and from data localisation (a state mandate that data must not leave a country).
- Does EU data residency mean my prompt is processed in Europe?
Not automatically — that is the most common misreading. Storage residency and inference residency are separate promises. OpenAI's November 2025 residency expansion covered data at rest while inference defaulted to US infrastructure; it added in-region GPU inference for eligible Enterprise, Edu and Healthcare customers in Europe and the US on 16 January 2026. Anthropic's help centre states it may route traffic to the US, Europe, Asia and Australia by default while data is stored in the US. Google's Vertex AI pins processing to a region only on regional or jurisdictional endpoints — the global endpoint gives no residency guarantee.
- Does storing data in the EU put it beyond US authorities?
No, if the holder is a US company. The CLOUD Act obliges a US provider to disclose data within its possession, custody or control "regardless of whether such communication, record, or other information is located within or outside of the United States." In June 2025 a Microsoft France executive told a French Senate inquiry he could not guarantee under oath that French citizens' data would never be handed to US authorities — while adding that no such demand had been received. There are challenge and comity mechanisms, but a region setting is not a jurisdictional firewall.
- Does the GDPR require my data to stay in Europe?
No. The GDPR requires an appropriate Chapter V mechanism for restricted transfers to a third country — an adequacy decision, Standard Contractual Clauses with a transfer impact assessment, or another Chapter V route — not EU storage as such, and not merely because personal data is processed. An EEA-based processor needs an Article 28 data processing agreement and no transfer mechanism at all. The EU AI Act imposes no residency requirement whatsoever.
- Can I choose where my prompts are processed on a normal consumer plan?
Generally no. Residency controls across the major providers are enterprise and API features; individual consumer subscriptions do not offer a region choice. The levers that remain available to individuals are reducing what is stored, redacting identifying details before sending, keeping history local to your device, and removing the identity link so that wherever the record lands it is not attached to you — which is the approach Secret Chat AI takes.
Conclusion
Data residency is a real and useful control, and the engineering behind the better implementations is serious work. It is also the most over-read label in AI procurement. It tells you where bytes sit. It does not tell you whose law reaches them, whether the model ran in the same place as the storage, who can read them in a support queue, or — the question that actually determines your exposure — whose name they are filed under.
If you have an enterprise contract, ask for both halves in writing, ask which of the six hops each half covers, and put a date on the answer, because these products changed twice in the last fourteen months. If you do not have one, the geography lever is not offered to you, and chasing it is a poor use of your attention.
The lever you do have is the identity link. A prompt that arrives somewhere with nothing attached to it is a poor asset in any jurisdiction — uninteresting to a profiler, unhelpful to a subpoena, unusable as a record about a person. Secret Chat AI is built for that: not a promise about which country answered your question, but a design in which the answer to "whose question was it?" is not stored anywhere in the first place.
Related reading: what the GDPR right to erasure actually gets you · SOC 2, BAAs and DPAs explained · the metadata problem nobody talks about · how AI chats surface in litigation · secure AI gateway vs self-hosting
Sources
- OpenAI Help Center — Data residency and inference residency for ChatGPT
- OpenAI Help Center — Data residency for the OpenAI API
- Computerworld — OpenAI expands data residency for enterprise customers (26 November 2025)
- Anthropic — Where are your servers located? Do you host your models on EU servers?
- Google Cloud — Data residency for generative AI on Vertex AI
- CLOUD Act, H.R.4943 (115th Congress) — text of 18 U.S.C. § 2713
- Sénat (France) — Commande publique: audition de Microsoft (10 June 2025)
- The Register — Microsoft exec admits it "cannot guarantee" data sovereignty
- Microsoft — Completing the EU Data Boundary (26 February 2025)
- European Commission — Adequacy decisions
- Bird & Bird — The Garante imposes a limitation on the processing of Italian users' personal data (DeepSeek, 30 January 2025)
- Euronews — DeepSeek blocked by Italian authorities as other member states open probes