Data residency

EU-hosted MCP memory server: what leaves your machine

An MCP memory server keeps what your coding assistant learns: fixes, decisions, error messages, file paths. That experience often holds more than code. Sometimes it holds your customers' data.

This page lists what cachly sends from your machine, where each part lands, and how you check it yourself.

When the location matters

  • You handle personal data under the GDPR. A lesson can hold some: an email address in a stack trace, a name in a failing test, an account ID in a log line.
  • You must avoid transfers to third countries. Under the GDPR, personal data sent outside the EU or EEA is a transfer and needs its own legal basis (Chapter V). Storage on a server in the EU is no such transfer.
  • Your company has a policy. Security reviews ask which services see source code, and in which country.
  • Your customers set terms. Contracts often name the countries their data may go to.

This page describes data flows. Whether they fit your obligations is a call for your data protection officer.

What leaves your machine

The cachly MCP server and its hooks run on your machine. They send these kinds of data:

Lessons
What you or your assistant store: topic, what worked, what failed, context, files and commands. They go to your own cachly instance.
Your prompt
Before each turn, the UserPromptSubmit hook ranks your lessons on your machine. It keeps a copy of them in a temp file that only your user can read. When several lessons share words with the prompt, it sends the prompt and the top candidates to cachly's reranker, which orders them by meaning.
Search queries
When your assistant searches its lessons, the MCP server sends the query to compute its embedding and to rank the results with the reranker.
The end of a turn
When Claude's final answer reports a fix, with words like "fixed" or "root cause", the Stop hook sends the start of that answer to your instance as a new lesson.
Lesson text for embeddings
When a lesson is stored, its text goes to the embedding service. Embeddings are number vectors that let search find lessons by meaning.
Usage pings
Event name, version, editor, your API token, the instance ID and up to 80 characters of each search query.

Calls to the cachly API use HTTPS. The MCP server also connects directly to your instance, over TLS by default.

Where it lands

Storage
Each brain gets its own Valkey instance (an open-source key-value store). It runs at Hetzner in Nuremberg, Germany.
Embeddings
cachly computes them on its own servers in the EU. This is the default as soon as you are signed in. The client sends text to OpenAI, Google, Mistral or Cohere only when you name one of them in CACHLY_EMBED_PROVIDER.
Reranker
A model on a server cachly runs in the EU.
Network edge
The cachly API, api.cachly.dev, runs behind Cloudflare. Cloudflare is a US company. It ends the encrypted connection in one of its data centers and forwards the request to cachly's servers. Your prompt, lessons and API token pass through it on the way.

Our rule: lesson text goes to no AI service outside the EU. The hosted service has no setting that changes this. Only you can, on your own machine, by naming another embedding provider.

Check it yourself

  • Read the client

    The MCP server and its hooks are open source. Search the code for fetch( and api.cachly.dev to see every call.

  • Find where your instance runs

    Copy the host from your instance's connection string. Look up its address and who owns it:

    terminal
    nslookup <your-instance-host>
    whois <address> | grep -i -E 'country|org'
  • See the network edge

    Cloudflare names itself in the response. The cf-ray value ends with the code of the data center that served you, for example FRA for Frankfurt.

    terminal
    curl -sI https://api.cachly.dev \
      | grep -i -E '^(server|cf-ray)'
  • Keep embeddings with cachly

    Leave CACHLY_EMBED_PROVIDER unset. Any value you set there sends lesson text to that provider instead.

  • Keep your prompt on your machine

    Set CACHLY_LESER=0. The hook then ranks by words alone and sends no prompt. Searches your assistant runs skip the reranker too.

  • Turn off usage pings

    Set CACHLY_NO_TELEMETRY=1.

  • Write lessons without personal data

    Write "the customer's email in the error" instead of the address itself. The lesson works just as well.

Hooks inherit the environment Claude Code starts in, so set the variables in your shell profile. Add them to the env block of the cachly entry in .mcp.json as well, for the MCP server.

Where cachly's reach ends

  • Your model provider. cachly puts lessons into your assistant's context. From there they travel with your prompt to the model your assistant uses. Where that provider processes them is part of your assistant's setup.
  • The network edge. API traffic passes through Cloudflare, a US company. If your policy rules out US companies even in transit, the hosted service is the wrong fit. A LESSONS.md in your repository keeps lessons inside your own tools.
  • Choices on your machine. An embedding provider you name yourself gets the text you send it, on its own terms.
  • The legal assessment. Data flows are facts. Whether they meet your obligations, your data protection officer decides.

Getting started

cachly turns your fixes, decisions and git history into experience for Claude Code, Cursor, GitHub Copilot and Windsurf. Lessons live in your own instance in Germany.

Claude Code
/plugin marketplace add cachly-dev/cachly-mcp
/plugin install cachly-brain@cachly

How the lessons come back into a session: Claude Code hooks and the UserPromptSubmit guide.

Sources

Checked against the code on .

More: Lessons learned for coding agents ยท AI memory in three layers ยท All docs