Where your server physically sits determines which laws apply to it, which courts can compel your provider, and how far away your users are in milliseconds. It is an infrastructure decision as much as a legal one. We chose Germany deliberately, for three reasons.
Statutory privacy protection, not policy promises
A privacy policy is a document a company writes about itself and can rewrite whenever it likes. The GDPR is law, it applies regardless of what we would prefer, and it is enforced by regulators with the power to fine. Germany layers additional national protections on top, and its data protection authorities are among the more active in the EU.
The practical effect is that "we respect your privacy" isn’t something you have to take on trust. Data minimisation, purpose limitation, and your rights of access and erasure are obligations we are held to externally.
Disclosure requires legal process
We do respond to lawful orders from German authorities. That isn’t optional, and any provider claiming otherwise is either offshore in a way that will eventually cause you problems, or isn’t being straight with you. What matters is the shape of the process: a properly issued order, subject to judicial oversight, rather than an informal request that a provider can quietly honour.
Asking whether a provider will hand over data is the wrong question. Ask what someone has to do first, and how little there is to hand over.
Our answer to the second half is the token model: we hold no name, no email, and no billing identity, so there is very little to produce even under a valid order.
Network position
Frankfurt hosts DE-CIX, one of the largest internet exchange points in the world by traffic. Dense peering there means shorter paths to most European networks, which shows up directly as lower latency for European users and fewer intermediate hops overall.
- Typical latency to Western Europe: single-digit to low double-digit milliseconds.
- Excellent transit to Eastern Europe and the Nordics.
- Reasonable transatlantic routes, though North American users will always be better served closer to home.
What Germany doesn’t give you
EU hosting isn’t a shield for illegal content, and we don’t market it as one. Our Acceptable Use Policy is enforced, and material such as CSAM, malware distribution, or DDoS infrastructure results in immediate termination and, where applicable, referral to law enforcement. Privacy for ordinary people and impunity for abuse are different products; we only sell the first one.
If your users are concentrated in North America or Asia, the latency argument here works against you, and an honest recommendation is to host closer to them. Jurisdiction is worth optimising for, but not at the cost of a service that feels slow to everyone who uses it.