Processors (GDPR Art. 30)
Full list of service providers involved in processing your data. · Deutsche Version
Processors are selected to meet Art. 28 GDPR requirements. All transfers to third countries (notably the US) are covered by Standard Contractual Clauses (SCCs) per EU Commission Decision 2021/914.
Supabase Inc.
- Location:
- USA (database in EU — Frankfurt)
- Purpose:
- Authentication, storage of profile, corrections, credit transactions
- Transfer basis:
- EU data residency, EU Commission SCCs (2021/914)
- Retention:
- until account deletion; audit logs 30 days
Vercel Inc.
- Location:
- USA (edge functions in EU — Frankfurt fra1)
- Purpose:
- API hosting (Next.js server)
- Transfer basis:
- EU data residency (fra1), SCCs
- Retention:
- request logs 30 days
- DPA:
- vercel.com/legal/dpa
Anthropic PBC
- Location:
- USA
- Purpose:
- AI correction (Claude Haiku, Claude Sonnet)
- Transfer basis:
- SCCs, Anthropic API Terms §B.5 (no training on API data)
- Retention:
- 30 days for abuse monitoring, then deletion
OpenAI OpCo, LLC
- Location:
- USA
- Purpose:
- AI correction (GPT-4o-mini)
- Transfer basis:
- SCCs, OpenAI API Data Usage Policy (no training on API data)
- Retention:
- 30 days for abuse monitoring, then deletion
RevenueCat Inc.
- Location:
- USA
- Purpose:
- In-app purchase verification, webhook for credit grants
- Transfer basis:
- SCCs
- Retention:
- purchase events 7 years (tax retention)
- DPA:
- revenuecat.com/dpa
Apple Inc.
- Location:
- USA / Ireland
- Purpose:
- iOS app distribution, Apple Sign-In, in-app purchases
- Transfer basis:
- Apple Developer Program License Agreement
- Retention:
- per Apple policies
Google LLC
- Location:
- USA / Ireland
- Purpose:
- Android app distribution, Google Sign-In, in-app purchases
- Transfer basis:
- Google Play Developer Distribution Agreement
- Retention:
- per Google policies
Changes
This list is continuously updated. For material changes (new sub-processor, change of data residency) we notify active users by email 30 days in advance.