Legal
Subprocessors
Current third-party subprocessors, payment providers, and optional customer-selected destinations used to deliver TrueClara.
Last updated: June 1, 2026
Summary
This page lists third-party providers that may process data in connection with TrueClara. It distinguishes default subprocessors from payment providers and optional customer-selected destinations.
We provide at least 30 days’ notice before adding or replacing a default subprocessor that materially processes Customer Personal Data, unless urgent legal, security, or continuity needs require faster action. You may object on reasonable data protection grounds within 14 days after notice.
Default subprocessors
These providers help us operate the Service and may process Customer Personal Data depending on your configuration.
| Provider | Purpose | Data categories | Location | Status |
|---|---|---|---|---|
| Vercel | Dashboard hosting, ingestion API hosting, serverless/edge functions | Request metadata, IP address, headers, logs, Service traffic, Customer Content routed through hosted functions | United States and global edge | Active |
| Supabase | Database, authentication, project/workspace storage, export storage, event analytics storage (short-window raw events and permanent hourly rollups) | Account Data, workspace/project data, runtime telemetry, route/deploy identifiers, aggregates, route graphs, deploy metadata, observation data, export data | United States unless configured otherwise | Active |
| Upstash | Redis cache, rate limiting, queues, counters | Pseudonymous request identifiers, rate-limit state, cache keys, usage counters | United States unless configured otherwise | Active |
| Cloudflare | DNS, CDN, DDoS protection, bot management, edge security, edge event ingestion, and aggregate analytics (Analytics Engine) | IP addresses, request headers, logs, traffic metadata, route/deploy identifiers, aggregate analytics, cached content if configured | Global edge | Active |
| Resend | Transactional email and observation digest delivery | Email addresses, names if provided, workspace/project identifiers, email content, delivery metadata | United States | Active |
| Sentry | Error monitoring and diagnostics | Error traces, stack traces, diagnostic logs, browser/device metadata, potentially Customer Content included in errors | United States unless configured otherwise | Active |
| PostHog | Internal product analytics on the TrueClara dashboard only | Dashboard usage events, pseudonymous account/workspace identifiers, device/browser metadata | United States unless configured otherwise | Active |
| Anthropic | AI inference for the Clara assistant — answering user questions about a project | User questions submitted to Clara, project/route/observation context provided as prompt context, workspace/project identifiers | United States | Active for Clara features. Inference only; not used to train models. |
| OpenAI | Text-embedding generation used to detect related/duplicate signals | Short text derived from observation/bet content submitted for embedding, workspace/project identifiers | United States | Active. Inference only; not used to train models. |
| Channel.io | Live chat and support widget on the website and dashboard | Support conversation content, name/email if provided, page/usage context, device/browser metadata | Global processing | Active; loaded only after analytics consent is granted. |
| Expo Application Services (EAS) | Mobile deploy metadata ingestion for EAS Update, EAS Build, and runtime-version attribution | EAS branch, runtime version, update identifier, rollout percentage, deploy class, timestamps, project identifiers; not intended to include end-user personal data | United States and Expo subprocessors | Active for mobile projects |
| RevenueCat | Server-side mobile subscription and revenue-event integration when configured | App user identifier or customer-controlled user reference, subscription/revenue event type, amount, currency, product identifier, transaction metadata, timestamps, environment, provider metadata | United States and global processing | Active when configured |
Payment provider and independent controller
| Provider | Purpose | Data categories | Location | Status |
|---|---|---|---|---|
| Paddle | Merchant of record, checkout, subscription billing, invoices, taxes, refunds, chargebacks | Buyer details, billing address, payment metadata, tax jurisdiction, transaction IDs, subscription status | UK, Ireland, and global processing | Independent controller for payment transactions; not a DPA subprocessor |
Paddle handles the payment transaction as merchant of record. We receive limited transaction metadata and do not store complete card or bank details.
Optional customer-selected destinations and integrations
These providers are used only when you configure or interact with them. They may operate under your own relationship with the provider.
| Provider | Purpose | Data categories | Status |
|---|---|---|---|
| Slack | Notification delivery when a workspace connects Slack or configures Slack webhooks | Workspace/project names, observation details, route/deploy metadata, notification message content | Optional, customer-selected |
| GitHub | Open-source package distribution; optional CI/deploy metadata workflows if configured | Public package download metadata; optional repository, branch, commit SHA, workflow, and deploy metadata | Optional/customer-selected for integrations; independent distribution platform for packages |
| Customer webhook receivers | Notification or workflow delivery to endpoints you configure | Webhook URL, headers/secrets you provide, observation details, route/deploy metadata, payload content | Optional, customer-selected |
| Email recipients configured by Customer | Observation digests, alerts, and administrative notifications | Recipient email address, workspace/project identifiers, notification content | Optional, customer-selected |
Mobile SDK disclosure support
Customers embedding the React Native/Expo SDK are responsible for their own app-store privacy labels, Google Play Data Safety forms, privacy notices, and consent flows. TrueClara provides a Mobile SDK Data Disclosure Sheet describing the SDK data categories, purpose, identity linkage, and tracking posture.
Subprocessor obligations
For default subprocessors that process Customer Personal Data, we require written data processing terms imposing obligations no less protective than our DPA in substance, and we remain responsible for their processing as required by applicable law.
Change log
| Date | Change |
|---|---|
| June 15, 2026 | Added Anthropic and OpenAI as AI subprocessors used for Clara inference and embedding generation (inference only; not used to train models); added Channel.io for live chat support. |
| June 1, 2026 | Added Expo Application Services and RevenueCat for mobile deploy attribution and server-side revenue correlation; added mobile disclosure support note. |
| May 10, 2026 | Updated structure; separated default subprocessors, Paddle as independent payment controller, and optional customer-selected destinations. |
Contact
Questions or objections: privacy@trueclara.com
trueclara.com