Last updated: September 2025
Supabase Inc.
Role / purpose: Database (Postgres), storage, authentication (email/password, JWT)
Server / processing location(s): AWS us-west-1 (N. California, USA)
Safeguard for transfers outside UK/EU: EU SCCs + UK Addendum
Vercel Inc.
Role / purpose: Hosting and CDN for the web dashboard
Server / processing location(s): Primary: EU (Frankfurt, Ireland); Global edge nodes incl. US
Safeguard for transfers outside UK/EU: SCCs + UK Addendum
Stripe Payments Europe Ltd.
Role / purpose: Payment processing, invoicing, and fraud checks
Server / processing location(s): EU (Ireland); transfers to Stripe, Inc. (US) for support
Safeguard for transfers outside UK/EU: Intra-group BCRs, SCCs + UK Addendum
Postmark / Twilio SendGrid (ActiveCampaign LLC or Twilio Inc., depending on provider chosen)
Role / purpose: Transactional email delivery
Server / processing location(s): US (East/West coast regions)
Safeguard for transfers outside UK/EU: SCCs + UK Addendum
Sentry (Functional Software Inc.)
Role / purpose: Crash and performance analytics
Server / processing location(s): EU (Frankfurt) data centre by default; US fallback
Safeguard for transfers outside UK/EU: SCCs + UK Addendum
Zendesk Inc. / Freshdesk (if applicable)
Role / purpose: Customer support / ticketing
Server / processing location(s): EU (Ireland or Frankfurt); support mirrored to US HQ
Safeguard for transfers outside UK/EU: SCCs + UK Addendum
Sahha Technologies Pty Ltd
Role / purpose: SDK for wellness signal ingestion
Server / processing location(s): AWS ap-southeast-2 (Sydney, AU)
Safeguard for transfers outside UK/EU: SCCs + UK Addendum
OpenAI, L.L.C.
Role / purpose: AI inference (e.g., GPT-5 models)
Server / processing location(s): Primary: US (Azure US-East/West)
Safeguard for transfers outside UK/EU: SCCs + UK Addendum; configured with no training retention
Google LLC
Role / purpose: AI inference (Gemini models)
Server / processing location(s): US (Google Cloud regions, typically us-central1/us-east1)
Safeguard for transfers outside UK/EU: SCCs + UK Addendum; configured to disable data logging where possible