Sub-processors
Version 1.0 · Effective 10 July 2026.
Transparency by design.
To operate Glowria we rely on the third-party providers below. Each is bound by a data-processing agreement, is contractually limited to processing personal data on our instructions, and — where applicable — is covered by EU Standard Contractual Clauses and the UK International Data Transfer Addendum. We update this list before adding or replacing a sub-processor and notify affected users where legally required.
| Provider | Purpose | Data | Location | Safeguards |
|---|---|---|---|---|
| Supabase (Cloud) | Managed Postgres database, authentication, storage, serverless functions. | Account data, user content, analytics events, biometric-like inputs. | EU (Frankfurt) / US. | DPA + EU SCCs + UK IDTA where applicable. |
| Cloudflare Workers | Application hosting, SSR, edge runtime. | Request metadata, IP addresses (transient). | Global edge network. | DPA + EU SCCs + UK IDTA. |
| Stripe | Payment processing and subscription billing. | Billing metadata (Stripe stores payment credentials, not us). | US (with EU affiliates). | Independent controller for PCI scope + DPA + EU SCCs. |
| OpenAI / Anthropic / Google AI Gateway | AI model inference for guidance and content generation. | Prompts and inputs necessary for the requested feature; no training on your inputs. | US / EU. | Enterprise DPA + zero-retention or short-retention configuration where offered. |
| Resend / transactional email provider | Account and transactional emails. | Email address, message metadata. | US / EU. | DPA + EU SCCs. |
| Error monitoring | Runtime error capture for reliability. | Stack traces, device metadata, pseudonymised user ID. | US / EU. | DPA + EU SCCs. |
To request the current signed DPA for any sub-processor, or to object to a specific processor, email info@glowria.ai.
See also the Privacy Policy and Cookie Policy.