Where Your Koltrix Data Lives
Koltrix runs on its own servers on OVHcloud in Frankfurt. Where your mail, attachments and AI requests go, who else touches them, and what we don't have yet.

On this page(8 sections)
"Where is my data stored?" is one of the first questions a careful customer asks an email provider, and one of the easiest to answer vaguely. This post answers it specifically for Koltrix: which servers, which country, which other companies are involved, and which gaps we haven't closed yet.
Everything here matches what's on our security page. If the two ever disagree, the security page is the one we keep current, and you should tell us.
The short answer
Koltrix runs on servers we operate ourselves, hosted by OVHcloud in Frankfurt, Germany, inside the European Union. Your mail is stored there. We aren't built on top of another email provider's infrastructure: the mail servers, the database and the attachment storage are ours to run.
What's stored, and how it's separated
Messages and metadata
Every workspace gets its own PostgreSQL schema. Your messages, threads, labels, contacts and settings live in a schema that belongs to your workspace alone, rather than in one large shared table keyed by customer ID. That design choice doesn't replace access control in the application, but it does make the boundary between workspaces something the database itself understands.
Attachments
Attachments are kept in our own object storage, in the same hosting environment. They aren't handed to a third-party file host.
Outbound mail
When you send, from the composer, through the API or through the SMTP relay, the message is DKIM-signed by our mail server before it leaves. Your application never handles a private key, and each domain gets its own 2048-bit key.
Who else is involved
No hosted product runs entirely on its own. Here are the other companies that touch Koltrix traffic or data, and why.
| Provider | Role | What it sees |
|---|---|---|
| OVHcloud | Hosting (Frankfurt, Germany) | The servers your data is stored on |
| Cloudflare | Network edge for our web traffic | Web requests to the app and site as they pass through |
| OpenRouter, routing to TypeSafe's Jev model | Sorting and spam scoring, when AI is on | Headers, subject and a truncated body |
| OpenRouter, routing to Google Gemini and DeepSeek models | Summaries and drafts, when AI is on | Headers, subject and a truncated body |
| Dodo Payments | Merchant of record for billing | Billing details, not your mail |
The full, current list is on our subprocessors page, linked from the security page.
The AI part, in detail
AI is where most "where does my data go" answers get slippery, so here's ours without the fog.
- Sorting and spam scoring send a message's headers, subject and a truncated body to the classifier, TypeSafe's Jev model, called through OpenRouter.
- Summaries and drafts send the same kind of excerpt to our generative provider: Google Gemini and DeepSeek models, also through OpenRouter.
- Nothing else is sent. Attachments never leave our servers for an AI provider, and quoted history is stripped before a body is sent.
- No training on your mail. Neither provider is permitted to train on your content under our agreements with them.
- You can switch it off. AI can be turned off for a whole workspace. Sorting then falls back to our own spam engine, and no message content leaves our servers at all.
That means the AI features in Koltrix, such as Triage, Drafts, Pitch Shield and Promise Keeper, do send excerpts of your email to providers outside our own infrastructure while they're switched on. We think that's a reasonable trade for most teams, but it's your call, and the off switch is per workspace rather than buried in a support ticket.
Protections in transit and at the edges
A few related details from the security page:
- HTTPS everywhere, and opportunistic TLS on SMTP in both directions.
- Scoped API keys. Each key carries its own permissions, so a key that only sends can't read mail. Keys are shown once and stored hashed.
- Remote images are proxied. Images in incoming email are fetched through our proxy, so your IP address isn't handed to the sender, and known tracking pixels are removed.
- Agents can't act on their own. The agent runtime has no tool that can send, forward or delete a message.
What we don't have yet
A data-location post that only lists strengths isn't much use for a security review, so here are the gaps, stated as plainly as on the security page:
- No third-party certification. No SOC 2, no ISO 27001. We haven't been audited, and we won't imply otherwise.
- No SSO or SAML.
- No dedicated sending IP.
- No published penetration test.
- Off-site backups are still being set up. Until we say they're running, don't treat Koltrix as your only copy of business-critical mail. You can export everything at any time.
- No choice of region. Frankfurt is where Koltrix runs today. If you need data stored in a specific country outside the EU, we can't offer that.
If your procurement process requires a named certification, that's a legitimate reason to choose a different provider today. Our post on what Koltrix doesn't do yet covers the other cases where waiting is the right decision.
Questions worth asking any email provider
Whether or not you choose Koltrix, these are the questions we'd ask a mail host before trusting it with customer conversations:
- Which country and which hosting company store my mail?
- Is the provider running its own mail servers, or reselling someone else's platform?
- Which subprocessors receive message content, and which only see metadata?
- If AI features are involved, what exactly is sent, to whom, and can I turn it off?
- Are providers allowed to train on my content?
- What certifications exist, and can I see the reports?
- How are backups handled, and where do they live?
- How do I export everything if I leave?
A provider that answers all eight specifically, including the uncomfortable ones, is usually one that has thought about the rest too.
Key takeaways
- Koltrix runs on its own servers on OVHcloud in Frankfurt, Germany, with a separate PostgreSQL schema per workspace and attachments in our own object storage.
- While AI is on, headers, subject and a truncated body are sent through OpenRouter to the classifier and generative models; attachments are never sent, and providers can't train on your mail.
- AI can be switched off per workspace, and then no message content leaves our servers.
- We have no SOC 2 or ISO certification, no SSO, no region choice, and off-site backups aren't running yet. Export is available at any time.
Start with Koltrix
Your domain, one inbox, and an API that sends.
A team inbox where AI sorts and drafts (nothing is sent without your click), plus the transactional API and SMTP relay your product sends with. 7 days free, no card.

