Before a school or university puts student work into a tool, someone always asks where the data actually goes.
Examplary runs in the EU. Accounts, tests, results and uploaded files are stored in Frankfurt, backed up to Ireland, and encrypted the whole way. AI processing is the exception: it isn't EU-only by default, though on the Examplary for organizations plan you can confine it to the EU as well.
This guide covers where each kind of data lives, how it's protected, how backups and recovery work, and what happens when you delete something.
Where your data lives
Our default storage location is Frankfurt, Germany. A few things sit elsewhere in the EU on purpose, mostly so that a problem in one region can't take your data with it.
| What | Where |
|---|---|
| Accounts, tests, questions, results and audit logs | Frankfurt, Germany |
| Uploaded files, images and scanned answer sheets | Frankfurt, Germany |
| The search index behind the search bar | Frankfurt, Germany |
| Emails we send you (sign-in codes, notifications) | Frankfurt, Germany |
| Daily backups | Cork, Ireland |
| Product analytics | EU |
| AI processing | Depends on your workspace. See AI processing and residency |
Encryption and access
Every connection uses TLS. Plain HTTP requests are redirected to HTTPS. The database, file storage and every backup are encrypted at rest, with keys managed by our cloud provider.
Uploaded files get a long, random address that can't be guessed, and the storage behind them can't be listed or browsed. Every file is served with a noindex, nofollow header, so uploads never turn up in a search engine. Downloads we generate for you, such as an audit log export, use private links that expire, so they can't be passed on by accident.
Inside the product, who can see what is governed by roles and permissions, and every meaningful action is written to your audit log.
Backups and recovery
We run two kinds of backup. One protects against mistakes, the other against disasters.
The production database has point-in-time recovery switched on, so we can restore it to any moment in the last 35 days, down to the second.
Every night, a full export of the database is also written to storage in a secondary data center in Cork, Ireland, a different region from the live data in Frankfurt. Because that copy lives somewhere else entirely, a regional outage or an accidental deletion in Frankfurt can't take the backups with it.
Backups are kept for 90 days and then expire, with an automated alerting system in place in case a backup fails or doesn't complete successfully.
AI processing and residency
By default, AI requests go to whichever region of our AI provider has capacity. That gives the best availability, but no residency guarantee: a request may be processed outside the EU.
On the Examplary for organizations plan, you can pin it down.
Choosing an AI processing region is available on the Examplary for organizations plan. If you're interested in upgrading, contact us via hi@examplary.ai.
Choosing a region
Go to Account → Access & domains and find AI processing region. There are two options:
| Region | What it means |
|---|---|
| Global (default) | Requests are routed to whichever region has capacity. Best availability, no residency guarantee. |
| European Union | Requests, and any files sent along with them, stay inside the EU, both the processing itself and the storage behind it. Availability can be marginally lower, since fewer regions can serve a request. |
Only workspace Owners and Admins can change the setting. If you can't see it, your workspace isn't on a plan that includes it, so talk to your account manager, who can also set it for you while you're being onboarded.
What the setting covers
Everything that runs through a model: generating questions, grading answers, giving feedback, and scanning handwritten answer sheets. Uploaded source materials go to storage inside the chosen region too, not just the prompt text.
Switching region doesn't change which models you get or what they cost. The same models serve both regions, so the setting decides where a request is processed, not what it answers.
A change takes effect for every request from that moment on. It doesn't move anything that was processed before, and files uploaded for generation are re-uploaded into the new region the next time they're used.
Every change of region is written to your audit log as org.ai_region_changed, with the old and new value, so a compliance review can find it without digging through settings history.
What we don't do with your content
Your materials, your students' answers and your prompts are never used to train our or our provider's AI models. They are only processed to produce the result you asked for.
When you delete something
Deleting a test, a user or a file removes it from your workspace straight away: it disappears from lists and from search, and the API stops returning it.
Two things outlive that. A deleted item can still exist in the nightly exports taken before you deleted it, and those expire on the normal 90-day schedule. The audit log entry recording that something was deleted, and by whom, is kept for the life of your organization and can't be removed.
If you need a full erasure, such as a GDPR request from a student or parent, or closing down a workspace entirely, email privacy@examplary.ai and we'll handle it as a formal request rather than as a delete in the dashboard.
Questions we get asked a lot
Can we get a data processing agreement? Yes. Email hi@examplary.ai and we'll send you ours.
Who else touches our data? We use Amazon Web Services and Google Cloud for hosting and AI processing, both under data processing agreements, plus a small number of processors for things like payments and product analytics. Our DPA lists them and explains the legal basis for each.
Do you fill in security questionnaires? Yes, send it to hi@examplary.ai. If you're documenting an AI system for compliance purposes, the EU AI Act guide covers most of what those questionnaires ask about.