Solution

EU data residency for in-app purchase data: run RevenueDot in your own EU region

To keep in-app purchase data in the EU, self-host RevenueDot in a region you choose, such as Frankfurt or Dublin. Every customer, purchase and receipt then lives in your own Postgres database, and the server never calls RevenueDot. RevenueDot Cloud does not pin data to an EU region today. This page is not legal advice.

Free up to $10,000 a month in tracked revenue. Works with the RevenueCat SDK you already ship.

Your region

Run the server and Postgres in any cloud region you pick, in or outside the EU.

No data to us

A self-hosted server has no telemetry and never calls RevenueDot's servers.

Data you can delete

The REST API has a delete-customer call, and your database is yours to query and purge.

No certification claims

RevenueDot claims no SOC 2, ISO 27001 or similar certification.

Scope

What data RevenueDot holds

For the apps that use it, RevenueDot processes app user IDs and aliases, store transaction IDs, product, price, currency, country, purchase and renewal dates, entitlement state, device platform, app version and any customer attributes you set, such as an email address. Do not send health or similar data as customer attributes. The data processing summary lists the same categories.

Steps

How to keep in-app purchase data in the EU with RevenueDot

  1. 01

    Pick an EU region

    Choose the cloud provider and region you want, for example a Frankfurt or Dublin region of your provider.

  2. 02

    Create Postgres 16 in that region

    Use a managed Postgres with point-in-time recovery in the same region, or the bundled Postgres container on a server there.

  3. 03

    Run RevenueDot there

    Clone the repository, set DATABASE_URL and a strong password in .env, and run docker compose up -d. See self-hosted in-app purchases.

  4. 04

    Put HTTPS and backups in the same region

    Terminate TLS in front of the server and keep database dumps in storage in the same region, encrypted.

  5. 05

    Connect your stores and point the SDK at your server

    Add your Apple and Google credentials, set the notification URLs, then set the SDK's proxy URL to your own HTTPS address.

Honest notes

Where data still leaves your server

  • The stores. The server calls Apple, Google, Amazon or Stripe for the apps you connect. They process purchase data under their own terms.
  • Integrations you turn on. Segment, Amplitude, Mixpanel, Meta, Slack and the other integrations send events to those vendors. Webhooks send events to your own endpoints. Turn on only what fits your policy.
  • Emails. Password resets, invites and alerts leave through the SMTP provider you configure.
  • Your app. The stock Android SDK still sends diagnostics, paywall events and ad events to RevenueCat's hosts. The planned fork sends them to your server. See the Android SDK page.

Cloud

RevenueDot Cloud and data location

RevenueDot Cloud runs on Cloudflare's network, and Cloudflare is its only listed subprocessor, with locations described as a global network and the United States. Cloud does not offer an EU-only region today. For transfers from the EEA, UK or Switzerland to countries without an adequacy decision, the EU Standard Contractual Clauses apply, according to the data processing summary, which is a summary and not the signed agreement. If you need data to stay in the EU, self-host.

Limits

What this does and does not give you

  • Hosting in the EU helps with where data sits. It does not make an app GDPR compliant. Lawful basis, notices, retention and requests from users are still your job, and your lawyer's call.
  • RevenueDot holds no compliance certification. It publishes its security policy and its code, which you can read.
  • You are the controller. A self-hosted deployment involves no processing by RevenueDot.

FAQ

EU data residency: questions people ask

Can I keep in-app purchase data in the EU?

Yes, by self-hosting RevenueDot on a server and Postgres database in an EU region. Customer, purchase and receipt data then stays in your database. The stores, integrations and email provider you connect are separate processors.

Does RevenueDot Cloud have an EU region?

Not today. RevenueDot Cloud runs on Cloudflare's network, with the United States listed as a location. If you need purchase data kept in the EU, self-host RevenueDot in your own EU region.

Is self-hosted RevenueDot GDPR compliant?

Hosting in the EU helps with data location, but compliance covers more, such as a lawful basis, privacy notices and responding to user requests. RevenueDot claims no certification. Ask your lawyer about your own obligations.

How do I delete a customer's data from RevenueDot?

The REST API v2 has a Delete a customer call, and on a self-hosted server the database is yours, so you can also remove rows directly. Deleted customers stay in older backups until those backups expire.

Does a self-hosted RevenueDot server send data to RevenueDot?

No. It has no telemetry and never calls RevenueDot's servers. It talks to the stores you connect, your webhook endpoints, the integrations you enable and your SMTP server.

Get started

Run subscriptions without the revenue share.

Start free on RevenueDot Cloud, free up to $10,000 a month in tracked revenue, or move an existing RevenueCat app with one line of code.

Already have an account? Sign in · Prefer your own servers? Self-host free