Subprocessors
Every third party that processes personal information on our behalf, what it does, and where it runs.
Why this page existsA privacy policy that says "we share data with trusted partners" tells you nothing. This is the actual list, with what each one does and what reaches it.
Section 1The current list
| Provider | What it does for us | What reaches it | Where |
|---|---|---|---|
| Vercel Inc. | Hosts the website and runs the form endpoint | Anything submitted through a form, plus request logs including IP address | United States |
| Supabase Inc. | Database, authentication and file storage for our applications | Account records and the content you create in an application | United States |
| Resend (Plus Five Five, Inc.) | Delivers messages sent through this website to our inbox | Your email address, your name and the content of the message | United States |
| Microsoft Corporation | Hosts the mailbox those messages arrive in | Your email address, your name and the content of the message | United States |
| Stripe, Inc. | Takes payment for anything bought directly from us | Your card details, which they hold and we never see, plus billing name and country | United States |
| Apple Inc. | Distributes our iOS applications and takes payment for in app purchases | Purchase and subscription status, tied to an identifier rather than to your name | United States |
| Google LLC | Distributes our Android applications and takes payment for in app purchases | Purchase and subscription status, tied to an identifier rather than to your name | United States |
| Shopify Inc. | Hosts the merchant platform our Shopify applications run on | Store details and the specific data an application asked the merchant permission for | Canada and United States |
Not every provider is involved in every product. A free app with no account touches almost none of them, and each application’s own supplement says which apply to it.
Section 2What every one of them is held to
Before a provider joins this list, and for as long as it stays on it:
- there is a written contract that limits it to processing on our instructions;
- it receives only the data its job actually requires, never a full copy of everything;
- it may not use the data for its own purposes, including training its own models;
- it is bound to confidentiality and to security measures at least as strong as ours;
- it must tell us about a breach quickly enough for us to meet our own notification deadlines;
- it must delete or return the data when we stop using it.
Section 3How we announce a change
When we add a provider that will process personal information, we update this page and bump its version before the provider goes live. Business customers and merchants under a Data Processing Addendum get at least 30 days' notice by email and can object during that window. If we cannot resolve a reasonable objection, they may end the affected service without penalty.
Removing a provider needs no notice, because it only ever reduces where data goes.
Section 4Who is deliberately not on this list
What is missing matters as much as what is present. We do not use any of the following, anywhere:
- advertising networks or advertising SDKs;
- cross site tracking or attribution services;
- data brokers or enrichment services that append information about you from elsewhere;
- session recording tools that replay what you did on a screen;
- analytics that build a profile of you across different websites.
Our website analytics set no cookies and record no personal identifiers, which is why no analytics provider appears above as a processor of personal information.
Section 5International transfers
Native Code LLC is in the United States and so is almost all of this infrastructure. For information covered by United Kingdom or European law, transfers rely on the Standard Contractual Clauses and the United Kingdom Addendum, with encryption in transit and at rest as an additional safeguard. This is set out in the Privacy Policy and in the Data Processing Addendum.