Sign in

Security & data

Where your data lives, who can see it, and what we promise never to do with it.

What we hold

That’s the list. We don’t ingest anything beyond it.

Where it lives

Your data lives in the EEA, twice: two synchronized copies on dedicated database hosts in Norway (gigahost.no AS), with a quorum witness in the Netherlands (Leiden, operator-managed) that casts the cluster’s tie-breaking vote and holds no user data. The application servers run separately, also in Norway, and hold no database.

Losing any single host loses no data. If one database host is down, writes pause until it returns instead of running unreplicated — we’d rather delay a write than hold your data in one copy.

Storage path is EEA-only. No user data is persisted on US-based hosting or in US-based data warehouses. The application database, vector store, audit log, and backups all live within the EEA (gigahost.no Norway + operator-managed Leiden NL).

Edge / network-routing path — three anycast POPs today, one of them outside the EEA. TLS termination is performed by HAProxy on an anycast pool of three VPS nodes: Switzerland (Zürich, iFog GmbH), Norway (Trondheim, gigahost.no AS) and the United States (Houston, Texas, iFog GmbH). These nodes see in-flight traffic for the duration of a single TLS connection only; they persist no data and hold nothing at rest. The Norway leg is intra-EEA; the Swiss leg relies on the Switzerland adequacy decision (Commission Decision 2000/518/EC); the US leg is an in-transit third-country leg.

Before the managed tiers open to the public, the US POP is retired from this domain and the pool returns to EEA + Switzerland only. We are publishing the current state rather than the intended one, because a security page that describes a plan as if it were a fact is worse than no page.

Storage remains EEA-only regardless. No user data is persisted on US-based hosting or in any US data warehouse; the US node terminates TLS and forwards over IPsec to the EEA storage layer.

Sub-processors (companies whose code touches your data)

Operator-elected sub-processors (omoikane chooses these on your behalf):

User-elected sub-processors (you choose these by selecting a BYOM provider — default tier is BYOM-Free, see pricing):

When you choose BYOM, your CV / posting / coaching / draft data is sent to your chosen provider per the provider’s own privacy policy (not omoikane’s). At provider-add time we surface a clear data-residency banner so you can make an informed choice.

The full register, with current status of each, is at Sub-processors.

What we promise never to do

These commitments are in our Terms and our Privacy Policy and they’re load-bearing — if any of them ever changed, we’d lose every reason this product is worth using.

Data export and deletion

Two endpoints, accessible from your account settings:

You don’t need to ask permission, write to us, or wait for review. Settings → Account → Export / Delete.

Encryption

Audit and access

Operator access to your data and key account events are logged. Audit rows are kept for 12 months, and if you delete your account they are de-linked from your identity.

The operator (the human running this) does not access your applications or drafts unless you explicitly ask for support. Doing so generates a typed audit event you can see in your settings.

Reporting a vulnerability

If you find a security issue, please email security@omoikane.coach before disclosing publicly. We respond within 48 hours and credit responsible disclosure in the changelog.


← Back to home