VibeID

Subprocessors

Last updated: 2026-04-29

Draft

This list is published in good faith ahead of legal review and will be reaffirmed by counsel before any paid customer goes live. Questions? privacy@skygem.tech.

A subprocessor is a third-party service that processes customer or end-user data on VibeID’s behalf. The table below lists every active subprocessor as of the date above. We notify customers at least 30 days before adding a new subprocessor or removing an existing one. Email privacy@skygem.tech to receive change notifications.

Vendors marked opt-in only process data when a team explicitly connects the integration; teams that do not connect it never transit data through that vendor.

VendorPurposeDataRegion
Vercel, Inc.Hosting, edge runtime, build pipeline, Web AnalyticsRequest logs, IP, headers, page views, Core Web Vitals telemetryUnited States (iad1)
Supabase, Inc.Database, auth, storage, edge functionsAccount info, card metadata, contacts, meeting notes, integration tokens (encrypted), team data, device push tokensUnited States
Stripe, Inc. (and Stripe Payments Europe Ltd.)Subscription billing and Customer PortalEmail, team identifier, billing-period dates, seat count, payment-method metadataUnited States (PAN-EU controller for EU customers)
Functional Software, Inc. d/b/a SentryError monitoring, crash analytics, source mapsStack traces, error messages, breadcrumbs, app version, device info. PII keys (email, phone, password, token, auth, jwt, session, cookie) are redacted client-side before transmission.United States (us.sentry.io)
PostHog, Inc.Product analyticsPage views, button clicks, feature usage, session identifier, anonymized IPUnited States (us.i.posthog.com)
Cloudflare, Inc.AI text generation (Workers AI — primary provider)User-submitted card context (name, role, company, vibe), AI bio promptsUnited States / global edge
Groq, Inc.AI text generation (overflow fallback when primary quota exhausted)Same prompt categories as Cloudflare, only when primary quota is exhaustedUnited States
Apple Inc.Sign in with Apple identity providerEmail, anonymized provider identifier, auth tokens at sign-in onlyUnited States
Google LLCopt-inSign in with Google identity provider; Google Calendar event read; Gmail signature install; Google Wallet pass issuanceEmail, OAuth scopes (userinfo.email, gmail.settings.basic, calendar.readonly), calendar event metadata, wallet object payloadUnited States
HubSpot, Inc.opt-inCRM contact bidirectional syncName, email, phone, company, role, custom properties — only for teams who connect HubSpotUnited States
650 Industries, Inc. d/b/a ExpoPush notifications and over-the-air app updatesDevice push tokens, notification titles + bodies, OTA update metadataUnited States (exp.host, u.expo.dev)

Available but not active

The following providers are wired in our codebase as fallbacks or future integrations but are not active in the current production configuration. They will be added to the list above with 30-day notice if they become active: DeepSeek (AI overflow), Resend (transactional email, M4+), OpenAI and Google Gemini (additional AI fallbacks).

Not subprocessors

jsDelivr / Fontsource is used to fetch web font binaries during static rendering; no customer or end-user PII transits this CDN. Apple Wallet uses Apple’s public Web Save endpoint with cert pinning; no separate subprocessor agreement applies.