ResearchCast
ResearchCast

Service Providers & Data Recipients

Effective: August 4, 2026

Version: service-providers-2026-08-04

Last reviewed: August 4, 2026

Purpose-specific roles of third parties used by ResearchCast.

1. How to Read this List

Not every third party is a subprocessor. A processor handles data for ResearchCast; an independent controller determines purposes under its own legal duties; a dual-role provider can have both roles depending on the processing. The exact data processed depends on the features you use.

2. Providers and Recipients

  • Vercel — Role: processor. Service/purpose: Application hosting, edge delivery, serverless runtime, logs, and deployment tooling. Data: Request metadata, IP address, user agent, URLs, application logs, and runtime telemetry. Region/transfers: Global edge and infrastructure regions, including possible non-EEA processing. Safeguards: DPA, EU Standard Contractual Clauses where required, and technical safeguards. Retention/configuration: Runtime and security logs follow the configured operational retention periods. Last verified: 2026-08-04.
  • Sentry — Role: processor. Service/purpose: Error monitoring, release diagnostics, and launch-critical operational alerting. Data: Error type, scrubbed stack traces, release/environment identifiers, and query-free request paths. Default PII, request bodies, headers, cookies, user data, breadcrumbs, logs, replay, and performance traces are disabled by ResearchCast. Region/transfers: The Sentry data region selected for the ResearchCast organization, with limited provider operations and subprocessors as documented by Sentry. Safeguards: DPA and transfer safeguards where required, SDK-side data scrubbing, data minimization, and restricted organization access. Retention/configuration: Configured project retention; only minimized error events are sent. Last verified: 2026-08-04.
  • Upstash / Vercel KV — Role: processor. Service/purpose: Distributed rate limiting and abuse prevention for sensitive application routes. Data: Short-lived rate-limit keys derived from IP addresses, account IDs, or hashed actor identifiers, together with counters and expiry times. Region/transfers: Configured Redis/KV database region and provider infrastructure, with possible support or subprocessor access outside the EEA. Safeguards: DPA and transfer safeguards where required, TLS, short key expiry, identifier minimization, and no application content storage. Retention/configuration: Rate-limit keys expire automatically after the applicable rate-limit window. Last verified: 2026-08-04.
  • Supabase — Role: processor. Service/purpose: Postgres database, authentication, session management, and object storage. Data: Account records, auth metadata, preferences, uploads, generated audio metadata, and storage objects. Region/transfers: Configured project region where available, with support and infrastructure operations as documented by Supabase. Safeguards: DPA, SCCs where required, encryption, access controls, and RLS-backed data separation. Retention/configuration: Follows the ResearchCast retention schedule and configured backup cycle. Last verified: 2026-08-04.
  • Resend — Role: processor. Service/purpose: Transactional and optional email delivery, delivery events, bounces, complaints, and provider suppressions. Data: Email address, message metadata, delivery events, bounce and complaint events. Region/transfers: Processing may include the United States and other provider infrastructure locations. Safeguards: DPA, SCCs where required, suppression controls, and limited retention. Retention/configuration: Delivery webhook events are retained by ResearchCast for 30 days by default; provider retention also applies. Last verified: 2026-08-04.
  • Google Gemini API — Role: dual-role. Service/purpose: Paid model inference for script generation, paper analysis, metadata extraction, grounded research discovery where enabled, and text-to-speech. Data: Prompts, research queries, source excerpts, uploaded PDF content required for a requested generation, and generated output. Region/transfers: Google infrastructure, including possible processing outside the EEA. Safeguards: DPA or data processing terms where available, SCCs where required, and minimization by task. Retention/configuration: Paid-service prompts and responses may be retained by Google for limited abuse, safety, and legal purposes under the configured terms. Last verified: 2026-08-04.
  • Paddle — Role: independent-controller. Service/purpose: Merchant of record, checkout, payment processing, invoices, subscriptions, refunds, and tax handling. Data: Billing contact, customer ID, payment status, transaction metadata, plan, tax/VAT information, and invoices. Region/transfers: Paddle infrastructure and payment network locations, including possible non-EEA processing. Safeguards: Paddle contractual terms, payment security controls, and transfer safeguards where required. Retention/configuration: Paddle retains transaction, tax, accounting, fraud, and chargeback records under its own legal duties. Last verified: 2026-08-04.
  • PostHog — Role: processor. Service/purpose: Optional product analytics after consent. Data: Pseudonymous user ID, product events, URLs, device/browser metadata, and account plan metadata. Region/transfers: PostHog EU Cloud selected for the production ResearchCast project. Safeguards: Consent gating, limited event properties, DPA/SCCs where required, and opt-out controls. Retention/configuration: Configured EU Cloud retention; browser identifiers are reset when analytics consent is withdrawn. Last verified: 2026-08-04.
  • Cloudflare Turnstile — Role: dual-role. Service/purpose: Bot and abuse prevention during signup and selected sensitive flows. Data: Challenge token, IP/device signals, browser metadata, and verification result. Region/transfers: Cloudflare global network. Safeguards: Security purpose limitation, provider safeguards, and transfer safeguards where required. Retention/configuration: Cloudflare processes challenge and security signals under its published retention practices. Last verified: 2026-08-04.
  • Google OAuth — Role: independent-controller. Service/purpose: Optional sign-in and account creation with a Google account. Data: OAuth identifiers, email address, profile metadata returned by Google, and authentication events. Region/transfers: Google infrastructure, including possible non-EEA processing. Safeguards: User-initiated OAuth, provider security controls, and transfer safeguards where required. Retention/configuration: Google retains account and authentication records under the user relationship and Google terms. Last verified: 2026-08-04.
  • Browser push services — Role: independent-controller. Service/purpose: Web Push transport through the push service selected by the user browser or operating system. Data: Push endpoint, public encryption keys, delivery metadata, and the notification title, body, and destination path. Region/transfers: Depends on the browser/device provider, which may include Google, Apple, Mozilla, or another standards-compatible push service. Safeguards: Encrypted Web Push payloads, per-device revocation, minimal notification content, and no secrets in push messages. Retention/configuration: Depends on the browser/device provider; ResearchCast removes revoked subscriptions after 30 days by default. Last verified: 2026-08-04.

3. Changes

We update this list when a provider, role, purpose, transfer route, or material configuration changes. Consumer users receive notice where a change requires it; this public list does not create a contractual subprocessor-objection process.

Related legal pages

Privacy PolicySecurity
ResearchCast
ResearchCast

Keep up with the research that matters to you.

Product

  • Research Profiles
  • Features
  • How it works
  • Paper to Podcast

Company

  • About
  • Blog
  • FAQ
  • Contact

Legal

  • Privacy
  • Terms
  • Imprint
  • Security
  • Service providers & data recipients
  • Cookie policy
  • Right of withdrawal
  • Verträge hier kündigen
  • Vertrag widerrufen
  • Illegal-content reports & DSA contact

ResearchCast. Built by researchers, for researchers, in Germany.