Subprocessors

Last updated: November 26, 2025

We use the following service providers (“Subprocessors”) to help us deliver the Services. Each Subprocessor is contractually required to handle personal information securely and only under our instructions.

NamePurposeCookie CategoryCategories of dataRegionTraining on customer contentRetention highlightsLinks
SupabaseDatabase, authentication, storageStrictly necessaryAccount/profile, auth/session, app DB records, stored assets, logsGlobal/USN/A (no model training)Customer‑controlled; daily backups; PITR optionalDPASecurityPrivacy
StripePayments & billingStrictly necessaryPayment method, billing info, fraud/risk telemetry, receiptsGlobalN/A (no model training)Retained as needed for legal, fraud, tax, reportingPrivacyDPA
OpenAIAI chat processingStrictly necessaryPrompts, attachments, outputs, usage/abuse telemetryGlobalNo by defaultAPI data retained up to 30 days; ZDR available for eligible orgsYour dataBusiness data
FAL.aiAI image generationStrictly necessaryPrompts, input image URLs/files, job metadata, outputsGlobalNot publicly stated (see Privacy/Terms)Generated files available ≥ 7 days; then may be deletedPrivacyTermsFAQ
ResendTransactional emailsStrictly necessaryMessage metadata/content, delivery/bounce events, logsGlobalN/A (no model training)Backups ~7 days; optional content storage off (paid add‑on)PrivacySecurityContent storage
VercelHosting, infrastructure & analyticsAnalytics (requires consent)Deployment artifacts, runtime logs (IP, UA, URL, timestamps), high-level analyticsGlobalN/A (no model training)Retained as needed to provide services and meet legal obligationsPrivacyDPATrust Center
Google (Google Analytics)Product analytics and usage measurementAnalytics (requires consent)Pseudonymous identifiers (cookies), IP address, device/browser data, page views and eventsGlobalN/A (no model training on customer content)Retention per Google Analytics configuration and policiesPrivacyAnalytics data
LinkedIn (Insight Tag)Advertising and conversion analyticsMarketing (requires consent)Pseudonymous identifiers (cookies), IP address, device/browser data, page visits and conversionsGlobalN/A (no model training on customer content)Retention per LinkedIn’s policies; users can manage preferences in their LinkedIn accountPrivacyInsight Tag

We may update this list as our Service evolves. For questions, contact matt@vistafy.ai.