Go to content
cutty.dev
All posts

Why hosting in the European Union

The decision about where the server is located seems technical. For you as a user, it specifically means who can read your data and under what law the tool you are using operates.

The data protection officer at the company receives a list of tools from you for approval. With each one, they ask a single question: where is the data flowing. Regarding the link shortener that you added without thinking, it turns out that the server is located somewhere in Ohio. And suddenly, a simple service for 9 dollars per month requires an addendum on transfer to a third country, SCC clauses, and a half-hour conversation that no one planned.

You know it. Most popular network tools, including URL shorteners, have been grinding your data on servers in the US. Technically nothing wrong. The problem only begins with the question "what next".

cutty.dev responds to this differently because it is based entirely in the EU.

Where your links physically reside

Account. Links. Click statistics. Encrypted passwords for protected addresses. All of this sits on servers in the EU and does not move from there. There is no replica in the USA "just in case," there is no copy in Asia. Backups also stay in the same region, they do not travel.

What do you get from this?

If someone from compliance asks you about data transfers outside of Europe, the answer fits in one word. There are none. You don't add layers of agreements for an American provider, because there is no American provider. The standard terms and conditions are simply sufficient. We operate under the same law as you, with the same obligations and the same right to request data deletion.

A page where no one is watching you

Go into your competitors' tools and take a look at the page code. You will usually find a zoo of third-party scripts there. Analytics, marketing automation, a heatmap, yet another pixel from someone you've never heard of. Each of them sees what you are doing and has its own plans for that knowledge.

We don't have that here. Only our own scripts, period.

We collect click statistics ourselves, into our own database, and we do not sell them to anyone. It looks like this: someone clicks your link, an entry lands in the database with a hashed IP address, country, device type, and source. Not a single byte goes outside. You view it in the panel, we look at the aggregated numbers to monitor if the server is alive. That is the end of the list of interested parties.

And these 25 languages? After all, AI translates them

Good question, and I have asked myself the same. The cutty interface speaks Arabic, Chinese, German, Japanese, Hebrew, and a dozen other languages, and it is translated by an AI model. It sounds like a hole in this whole story about privacy, because after all, AI is usually someone's API somewhere far away.

It's just that we do the translations ourselves. The model runs on our own infrastructure, locally, and text from the interface never leaves our network. Open models have reached a level that didn't exist even two years ago (I was surprised myself how good it is), so there is no reason to pay anyone for an API or let data out the door.

What this means in practice

Do you run a company in Poland, Germany, anywhere in the EU, and GDPR actually affects you? It affects everyone who processes customer data. In that case, cutty fits without asterisks and without an "EU only" note squeezed in fine print in the pricing list.

Are you a freelancer or do you have a small side business and all this GDPR sounds like something for corporations with a legal department? Great, because you don't have to do anything. No extra documentation, no addendums. The tool simply works in accordance with the law that already applies to you anyway.

It is worth adding what hosting in Europe does NOT mean here. It does not mean slow loading. A site from Warsaw loads in half a second; from Berlin, Prague, or Madrid, it is the same. It also does not mean reduced features. Links, passwords, QR codes, statistics, those 25 languages, four login methods—everything is there. Just more private.

Have hard questions? Write

If you are a data inspector, auditor, or work in compliance and need specifics regarding the server region, backups, or administrative access, write to [email protected]. I reply on the same day, in writing, without evasion.

And if you belong to the rest, meaning people who just want to shorten a link and be done with it? Shorten the first one without creating an account and see how it works. The rest will work itself out.