Service Providers & Data Recipients
Effective: August 4, 2026
Version: service-providers-2026-08-04
Last reviewed: August 4, 2026
Purpose-specific roles of third parties used by ResearchCast.
1. How to Read this List
Not every third party is a subprocessor. A processor handles data for ResearchCast; an independent controller determines purposes under its own legal duties; a dual-role provider can have both roles depending on the processing. The exact data processed depends on the features you use.
2. Providers and Recipients
- Vercel — Role: processor. Service/purpose: Application hosting, edge delivery, serverless runtime, logs, and deployment tooling. Data: Request metadata, IP address, user agent, URLs, application logs, and runtime telemetry. Region/transfers: Global edge and infrastructure regions, including possible non-EEA processing. Safeguards: DPA, EU Standard Contractual Clauses where required, and technical safeguards. Retention/configuration: Runtime and security logs follow the configured operational retention periods. Last verified: 2026-08-04.
- Sentry — Role: processor. Service/purpose: Error monitoring, release diagnostics, and launch-critical operational alerting. Data: Error type, scrubbed stack traces, release/environment identifiers, and query-free request paths. Default PII, request bodies, headers, cookies, user data, breadcrumbs, logs, replay, and performance traces are disabled by ResearchCast. Region/transfers: The Sentry data region selected for the ResearchCast organization, with limited provider operations and subprocessors as documented by Sentry. Safeguards: DPA and transfer safeguards where required, SDK-side data scrubbing, data minimization, and restricted organization access. Retention/configuration: Configured project retention; only minimized error events are sent. Last verified: 2026-08-04.
- Upstash / Vercel KV — Role: processor. Service/purpose: Distributed rate limiting and abuse prevention for sensitive application routes. Data: Short-lived rate-limit keys derived from IP addresses, account IDs, or hashed actor identifiers, together with counters and expiry times. Region/transfers: Configured Redis/KV database region and provider infrastructure, with possible support or subprocessor access outside the EEA. Safeguards: DPA and transfer safeguards where required, TLS, short key expiry, identifier minimization, and no application content storage. Retention/configuration: Rate-limit keys expire automatically after the applicable rate-limit window. Last verified: 2026-08-04.
- Supabase — Role: processor. Service/purpose: Postgres database, authentication, session management, and object storage. Data: Account records, auth metadata, preferences, uploads, generated audio metadata, and storage objects. Region/transfers: Configured project region where available, with support and infrastructure operations as documented by Supabase. Safeguards: DPA, SCCs where required, encryption, access controls, and RLS-backed data separation. Retention/configuration: Follows the ResearchCast retention schedule and configured backup cycle. Last verified: 2026-08-04.
- Resend — Role: processor. Service/purpose: Transactional and optional email delivery, delivery events, bounces, complaints, and provider suppressions. Data: Email address, message metadata, delivery events, bounce and complaint events. Region/transfers: Processing may include the United States and other provider infrastructure locations. Safeguards: DPA, SCCs where required, suppression controls, and limited retention. Retention/configuration: Delivery webhook events are retained by ResearchCast for 30 days by default; provider retention also applies. Last verified: 2026-08-04.
- Google Gemini API — Role: dual-role. Service/purpose: Paid model inference for script generation, paper analysis, metadata extraction, grounded research discovery where enabled, and text-to-speech. Data: Prompts, research queries, source excerpts, uploaded PDF content required for a requested generation, and generated output. Region/transfers: Google infrastructure, including possible processing outside the EEA. Safeguards: DPA or data processing terms where available, SCCs where required, and minimization by task. Retention/configuration: Paid-service prompts and responses may be retained by Google for limited abuse, safety, and legal purposes under the configured terms. Last verified: 2026-08-04.
- Paddle — Role: independent-controller. Service/purpose: Merchant of record, checkout, payment processing, invoices, subscriptions, refunds, and tax handling. Data: Billing contact, customer ID, payment status, transaction metadata, plan, tax/VAT information, and invoices. Region/transfers: Paddle infrastructure and payment network locations, including possible non-EEA processing. Safeguards: Paddle contractual terms, payment security controls, and transfer safeguards where required. Retention/configuration: Paddle retains transaction, tax, accounting, fraud, and chargeback records under its own legal duties. Last verified: 2026-08-04.
- PostHog — Role: processor. Service/purpose: Optional product analytics after consent. Data: Pseudonymous user ID, product events, URLs, device/browser metadata, and account plan metadata. Region/transfers: PostHog EU Cloud selected for the production ResearchCast project. Safeguards: Consent gating, limited event properties, DPA/SCCs where required, and opt-out controls. Retention/configuration: Configured EU Cloud retention; browser identifiers are reset when analytics consent is withdrawn. Last verified: 2026-08-04.
- Cloudflare Turnstile — Role: dual-role. Service/purpose: Bot and abuse prevention during signup and selected sensitive flows. Data: Challenge token, IP/device signals, browser metadata, and verification result. Region/transfers: Cloudflare global network. Safeguards: Security purpose limitation, provider safeguards, and transfer safeguards where required. Retention/configuration: Cloudflare processes challenge and security signals under its published retention practices. Last verified: 2026-08-04.
- Google OAuth — Role: independent-controller. Service/purpose: Optional sign-in and account creation with a Google account. Data: OAuth identifiers, email address, profile metadata returned by Google, and authentication events. Region/transfers: Google infrastructure, including possible non-EEA processing. Safeguards: User-initiated OAuth, provider security controls, and transfer safeguards where required. Retention/configuration: Google retains account and authentication records under the user relationship and Google terms. Last verified: 2026-08-04.
- Browser push services — Role: independent-controller. Service/purpose: Web Push transport through the push service selected by the user browser or operating system. Data: Push endpoint, public encryption keys, delivery metadata, and the notification title, body, and destination path. Region/transfers: Depends on the browser/device provider, which may include Google, Apple, Mozilla, or another standards-compatible push service. Safeguards: Encrypted Web Push payloads, per-device revocation, minimal notification content, and no secrets in push messages. Retention/configuration: Depends on the browser/device provider; ResearchCast removes revoked subscriptions after 30 days by default. Last verified: 2026-08-04.
3. Changes
We update this list when a provider, role, purpose, transfer route, or material configuration changes. Consumer users receive notice where a change requires it; this public list does not create a contractual subprocessor-objection process.