Sub-processors

Last updated 2026-09-21

Everyone who processes data on our behalf to run VitalsDesk. There is nobody else: no analytics, no advertising networks, no data brokers, and no resale of anything to anyone.

The list

ProviderWhat it doesWhat it handlesWhere
SupabaseDatabase, authentication and file storageAccount records, project settings, aggregated measurements, uploaded logosUnited States / EU (per project region)
VercelApplication hosting and edge networkRequest metadata in transit, including visitor IP addresses which are used to derive a country and are never stored by usGlobal edge, United States
ResendTransactional email (alerts, reports, account notices)Recipient email address, message contentsUnited States
AnthropicWriting the plain-English summary on a monthly report (Agency plan only)Aggregated performance figures and page URLs for the report. No visitor data, and nothing that identifies a personUnited States
Google PageSpeed Insights / Chrome UX ReportLab testing of a page and public field data for a domainThe page URL being tested. No visitor data is sentGlobal

What crosses a border, and what doesn't

Visitor IP addresses reach the edge network in the ordinary course of an HTTP request and are used there to derive a country. They are never written to our database and never reach any other provider on this list. What is stored is a two-letter country code alongside aggregated timings.

The testing API receives only the URL of a page being tested. No visitor data is sent to it.

Processing on your behalf

Where you are the controller of visitor measurement data and we are your processor, the terms of that processing are the ones in our agreement and privacy policy. We process it only to provide the service to you, we impose equivalent obligations on each provider above, and we will tell account holders by email before adding a new one.

If you need a signed data processing agreement for your own records, write to timblenge@gmail.com and we will sign yours or send ours.