Sub-processors
Last reviewed: September 12, 2026
A sub-processor is a third party that processes personal data on our behalf so we can
deliver the service. This is the complete list. Vendors marked Optional
are engaged only when a user or an organization turns on the feature that uses them;
Core vendors are always in the path.
Under our school data privacy agreement we commit to maintaining this list, binding each
sub-processor to written terms no less protective than our own, and giving an
institution 30 days' notice before adding a sub-processor that would
process student data, with a right to object.
Data residency: our database, authentication and file storage are hosted
in the United States, in a US West region, so account and student data is
stored in the US with no foreign storage. Several vendors below run global edge networks,
so request metadata such as an IP address may transit an edge location while a request is
routed. That is transit, not storage.
Core infrastructure
| Vendor | Purpose | Data processed | Engagement |
| Supabase | Database, authentication, file storage, sync, backups, serverless functions | All account and application data | Core |
| Cloudflare | DNS, rate limiting, TLS, email routing, and hosting for our administrator console behind Cloudflare Access | Request metadata, IP addresses; an administrator's sign-in identity for the Access gate | Core |
| Vercel | Hosting for the web app | Request metadata, IP addresses | Core |
| Microsoft Azure | Hosting for the marketing site | Request metadata, IP addresses | Core |
| Better Stack | Uptime and availability monitoring | Endpoint health only, no user data | Core |
Communications
| Vendor | Purpose | Data processed | Engagement |
| Resend | Email delivery and open/click engagement | Email address, name, message content, engagement events | Core |
| Twilio | Text message delivery and inbound replies; two-step verification codes by text | Phone number, message content, opt-out state, verification codes | Optional |
| Lob | Printed mail, where an organization chooses to send it | Name, mailing address | Optional |
Online sessions
| Vendor | Purpose | Data processed | Engagement |
| Daily | Video rooms for an online coaching session booked through the app | The live audio and video of that session while it runs, and each participant's connection details. A room is named by the booking, opens 15 minutes before the session and expires an hour after it. We do not record sessions | Optional |
Payments and commerce
| Vendor | Purpose | Data processed | Engagement |
| Stripe | Payment processing, payouts, in-person terminal, tax forms | Name, email, transaction and payout data. Card data is collected by Stripe and never by us | Optional |
| RevenueCat | App-store subscription entitlements and receipt validation | Pseudonymous app user ID, purchase and entitlement state | Optional |
Platform and device services
| Vendor | Purpose | Data processed | Engagement |
| Expo | Push-notification relay: every push we send goes through Expo's push service on its way to Apple or Google | Device push token, the notification's title, body and routing data | Core |
| Apple | Sign in with Apple, push notifications, in-app purchases, Health import performed on the device | Account identifier, push token, purchase state | Optional |
| Google | Sign-in, push notifications, Maps and Places lookup, Health Connect import performed on the device, YouTube playback and search | Account identifier, push token, search and location queries | Optional |
| Microsoft | Sign-in with a Microsoft account | Account identifier, name, email | Optional |
| Meta (Facebook) | Sign-in and optional profile backfill | Account identifier, name, email, and any profile fields the user grants | Optional |
| Discord | Sign-in | Account identifier, name, email | Optional |
Artificial intelligence
| Vendor | Purpose | Data processed | Engagement |
| Anthropic | AI-assisted features: reading a workout, session, meal, roster, timetable or schedule out of text, a photo or a PDF the user submits, and drafting copy a human then reviews; for gym staff, narrating the gym\'s own reports | Only the specific content the user submits for that feature and, for the weekly briefing, the user's own logged training, sleep, weight and recovery entries reduced to totals and bands, sent only when they tap to run it; for a report narrative, that gym\'s own aggregate figures, and revenue only when the requesting staff member already holds the gym\'s billing permission | Optional |
| OpenAI | Speech-to-text for a voice note left on a film review | The voice recording the user chose to transcribe, and its language. Not used to train models under the API terms | Optional |
Because this is the question institutions ask most:
- Content is sent only when a user explicitly invokes an AI feature. There is no background or bulk transmission.
- Submitted content is not used to train models.
- Requests are made server-side from our own functions; the app never calls the provider directly.
- For an organization in school-managed mode, outbound AI is off by default and stays off until that institution approves this sub-processor. It is enforced server-side at the single chokepoint every AI feature calls, so it covers all of them. Outside school-managed mode, users control AI features individually.
Reference data
| Vendor | Purpose | Data processed | Engagement |
| USDA FoodData Central | Nutrition reference lookups | Search terms only, no account data | Optional |
What we deliberately do not use
Stated because questionnaires ask, and because these absences are the substance of most
state student-privacy laws:
- No advertising networks or advertising SDKs. Declared to Apple as "Data Not Used to Track You."
- No cross-app tracking, advertising identifiers, or data brokers.
- No third-party analytics SDK. Product analytics live in our own database, with a user-facing opt-out and a global kill switch.
- We do not sell personal data, and we do not profile students for any purpose beyond delivering the service.
Changes
| Date | Change |
| July 28, 2026 | Register first published. Cloudflare, Vercel, Azure and Better Stack were added and the Privacy Policy processor list was updated to match. |
Questions about a sub-processor, or a request to be notified of changes:
help@susos.co.