# Where is my data?

This page explains what XMemo stores for each security mode, where it is processed, who can decrypt it, what happens during export or deletion, and how you can verify the active boundary from your own account.

- Canonical: https://docs.xmemo.dev/docs/security/where-is-my-data
- Locale: en-US
- Content-Locale: en-US
- Canonical-Content-Digest: c0058e6fcf05a87e666d8680ed831e494b51ed49b3aad776a01fc3232612a919
- Edition-Digest: 55131e1f1068e9a0c4ca59ac1730a761ceb8dc6e4e27a54255bf2c9ab89bebdd

## Quick comparison

## Cloud-managed mode

- The XMemo server can process memory content for server-side semantic recall, ranking, and exports.
- This is the most convenient mode, but it is not zero-knowledge.
- Deletion removes memory rows and associated metadata. DSAR exports can include plaintext because the service can process memory content on your behalf.

## Keyguard mode

- The wizard stores the KMS binding in setup preflight data and commits personal_default_mode = keyguard.
- Recall requires your KMS grant to remain valid. Revoking the grant blocks future decrypt/unwrap operations.
- XMemo deletes its ciphertext and metadata on account deletion; your tenant remains responsible for KMS key rotation or destruction.

## Vault mode

- XMemo cannot decrypt vault memories, cannot reset your vault key, and cannot recover data if every enrolled device and recovery kit is lost.
- DSAR exports for vault data contain ciphertext and envelope metadata. You decrypt them locally with your device or recovery kit.
- Hosted semantic features may be limited unless the feature can operate on client-provided or privacy-preserving representations.

## Production data boundary

- Managed Postgres: the production storage boundary for account, memory, vector, setup, and audit records.
- Database RLS/runtime context: deployment-specific controls that require target verification of the runtime role, migration ledger, runtime-context flag, and owner/team CRUD matrix.
- Supabase compatibility: useful for local or OSS adoption, but its service-role behavior is not equivalent to production hardening.

