The architecture layers from the Tor network inward: Tor hidden service -> nginx reverse proxy on localhost -> Node.js application on localhost -> PostgreSQL on localhost (or encrypted socket). All components communicate exclusively on localhost interfaces. No traffic ever leaves the server's network stack in cleartext except through the Tor process itself.
This strict localhost isolation is enforced at the application level by binding each service to 127.0.0.1, and at the network level by iptables rules that drop outbound traffic from processes other than tor. Defense in depth: if the application code has a bug that tries to make an external request, the iptables rules catch it before it reaches the network.
PostgreSQL binds to the Unix socket at /var/run/postgresql by default on Debian, which is inherently localhost-only. Use Unix socket connections from Node.js: set the host parameter in the database connection to the socket path. This avoids TCP socket overhead and keeps all database communication within the kernel's IPC mechanisms.