Data handling
All customer data is stored in the United States; there is no EU or other regional data-residency option today.
Data Residency
Qpher infrastructure runs on Google Cloud Platform in the United States (us-east1 region). Encrypted document storage for the Qpher Vault iOS app uses Cloudflare R2 (United States). All customer data is stored in the United States; we do not currently offer EU or other regional data residency (this is a future roadmap item). All data at rest is encrypted, and data in transit uses TLS encryption. Sub-processor data locations are documented in the Data Processing Agreement at /legal/dpa.
Data Retention
Account data, organization data and API keys are kept while the account is active. Audit logs are retained for the life of your account and for 24 months after the account is deleted; accounts with an armed Legacy policy are exempt from deletion while the policy is armed. PQC key pairs are not yet deleted when an account is deleted (see Data Deletion). Operational metrics carry no customer identifiers.
Data Deletion
You can delete a Qpher Portal account in Settings → Account and a Qpher Vault account in the app (Settings → Delete account); an organization owner can delete the organization in Qpher Portal. A deleted account stops working at once and can be restored for 30 days. After that, a Qpher Vault account and its documents are permanently deleted, unless the account has an armed Legacy policy; Qpher Portal accounts and organizations stay disabled but are not yet permanently deleted. Deleting an account does not yet destroy its PQC private keys; they stay encrypted in the key service. Archiving a key in Qpher Portal deletes its private key file; encrypted copies of that file can remain in our backups.
Backup & Recovery
Qpher maintains automated database backups with point-in-time recovery, giving a Recovery Point Objective (RPO) of well under one hour for database data. Cryptographic private-key material is replicated daily to a separate geographic region (US-WEST1), and object versioning provides a 30-day recovery window against accidental deletion. All backups are encrypted at rest (AES-256). Disaster recovery procedures are documented; periodic restoration rehearsals are planned as we onboard customers and have not yet been conducted.