What a subprocessor is
A subprocessor is a third party we engage to process personal data on our behalf in order to run DumpNotes. We remain responsible to you for what they do with it. Each is bound by a data processing agreement requiring them to process data only on our instructions, to keep it secure, and to delete or return it when the relationship ends.
This page supplements the Privacy Policy. It is the authoritative list; if a provider is not on it, it does not receive your data.
Current subprocessors
| Provider | Purpose | Location | Terms |
|---|---|---|---|
| Clerk | Authentication, sessions, user management | United States | View |
| Supabase | Database and file storage | United States / regional (Postgres, AWS) | View |
| Google (Gemini API) | AI summarising, organising, search and assistant responses | United States / global | View |
| Paddle.com Market Ltd | Payments, invoicing, tax, Merchant of Record | United Kingdom / European Union | View |
| Upstash | Redis-backed rate limiting | United States / regional | View |
| Vercel | Application hosting, CDN, edge network, server logs | United States / global edge | View |
What each one receives
| Provider | Data categories |
|---|---|
| Clerk | Email, hashed password, name, avatar, sign-in events, device and IP |
| Supabase | All note content, notebooks, events, reminders, messages, image attachments, profiles, usage counters, subscription status |
| Google (Gemini API) | Only the note text or prompt involved in a request you invoke, plus minimal context |
| Paddle.com Market Ltd | Email, billing name and address, country, tax ID, card data (held by Paddle, never by us), transaction records |
| Upstash | Account identifier or IP address, and a short-lived request counter |
| Vercel | All request traffic in transit, IP address, request metadata, error diagnostics |
Only Supabase holds your notes at rest. Google sees note text only for the specific requests you invoke, and only the parts relevant to them. Nobody else on this list ever receives note content.
Notice of changes
Before we add a new subprocessor or materially change what an existing one does, we will:
- update this page with the new entry and the date;
- give at least 30 days’ notice by email to account holders, where the change affects a category of data or introduces a new kind of processing;
- ensure the new provider is bound by protections at least as strong as those we already have in place.
If you object to a new subprocessor on reasonable data protection grounds, tell us at admin@dumpnotes.app within the notice period. We will try to find an alternative; where we cannot, you may cancel and receive a pro-rata refund for the unused part of any prepaid period.
Where a provider fails, we may urgently engage a replacement to keep the Service running, and will notify you as soon as practicable afterwards.
How we vet them
- a signed data processing agreement, with the Standard Contractual Clauses where the transfer requires them;
- a published security posture and, for the providers holding content, independent audit or certification;
- encryption in transit and at rest;
- a documented breach notification commitment;
- the ability to delete data on instruction within a defined period;
- the narrowest scope of data that will do the job.
Each of these providers is a widely used infrastructure vendor, chosen partly because their compliance documentation is public and verifiable rather than asserted.
Who we deliberately do not use
- No advertising networks or ad exchanges.
- No third-party analytics or session replay tools.
- No data brokers or enrichment services.
- No CRM or marketing automation platform holding your account data.
- No offshore support vendor with access to your content.
If any of that changes, it appears in the table above first, with the notice described in section 4.
Contact
Questions, objections or requests for a provider’s DPA: admin@dumpnotes.app
[Legal entity name], [Registered address]