Providers, Processors and Other Recipients
Last updated: August 3, 2026
This page identifies third parties relevant to the processing described in the Privacy Policy. A party’s role may vary by feature: the same provider may be Verxion’s processor in one flow and a separate controller in another.
1. Verxion processors
| Provider | Service and main data | Location / transfer | Processing terms |
|---|---|---|---|
| Railway | API and service hosting; PostgreSQL database; operational logs | Production region in the EU; support access may occur under the contract | Railway DPA |
| Amazon Web Services (KMS) | Encryption-key custody; receives cryptographic operations, not plaintext content | eu-north-1 (Stockholm, EEA) | AWS GDPR Center |
| Upstash | Redis for rate limits, idempotency and security; identifiers and hashes | eu-west-2 (UK); EU–UK adequacy decision | Upstash DPA |
| Resend | Transactional email and requested lists; email address, message content and delivery | Sending domain configured in Ireland; the US entity may be covered by SCCs | Resend DPA |
| Sentry | Web, server, and mobile error/performance diagnostics; filtered technical traces, pseudonymous IDs and HTTP metadata | Code targets the European project/region; live configuration and retention require release verification | Sentry DPA |
| Vercel | Hosting/CDN for the public site and web app; HTTP requests and deployments; Blob storage only if enabled | Global CDN and possible US access; SCCs in applicable terms | Vercel DPA |
| Cloudflare | R2 and CDN/Image Transformations for exercise-instruction images; objects and delivery logs | Bucket configured in Western Europe; US entity and global CDN, with SCCs | Cloudflare DPA |
| PostHog | Optional product analytics; pseudonymous ID, events from a closed catalogue, and minimised language/onboarding state. No autocapture, automatic exceptions, or session recording | European host configured; subject to prior consent | PostHog Trust Center |
On web and native, PostHog is constructed only after a current persisted granted choice for the active account. Rejection or withdrawal keeps the adapter closed, rotates local identity, clears queued events, and opts out. Contractual and live-configuration verification for every provider remains part of the external release gate.
2. Separate controllers and user-selected third parties
- Apple and Google, when selected for authentication.
- MCP clients and connected applications you authorize through OAuth. The client receives only granted scopes, but its later use is governed by its own terms.
- BYOK AI providers selected for the built-in agent—OpenAI, Anthropic, Google, or OpenRouter and any downstream provider. Verxion relays the conversation using your key. For OpenRouter, code requests
data_collection: "deny"and zero-data-retention routing; equivalent guarantees for direct providers depend on your provider settings and agreement and are not asserted by Verxion. - The AI provider’s search partners, only when you enable web search and the model uses it.
- OpenFoodFacts for food lookups, and YouTube, Vimeo, TikTok, or Instagram/Meta if you add a video link from which minimal public metadata is retrieved.
- Coaches and other authorized users, within the relationship, visibility, and permissions configured in Verxion.
- App stores, for app distribution and review. Payments and subscriptions are not currently enabled; any payment provider will be added before a purchase is activated.
3. International transfers
Where a provider or its subprocessors allow access outside the EEA, the applicable adequacy decision, Standard Contractual Clauses, DPA, and supplementary controls must be confirmed from the executed terms and live account before release. Code-level measures include encryption, pseudonymization, minimization, European-region configuration, and restricted access. Third parties chosen directly by the user may process data in other countries under their own policies.
4. Changes
We will publish material changes before they take effect where possible and update the Privacy Policy or request a new acceptance/choice where law or a purpose change requires it. Contact or reasoned objection: [email protected].
| Date | Change |
|---|---|
| 2026-08-04 | Web and native PostHog are constructed only after a persisted choice; native capture uses a closed catalogue, anonymous account boundary, disabled automatic capture, and identity/queue reset on withdrawal. |
| 2026-08-04 | Telegram was removed from the current code. It ceases to be an active recipient in each environment after that artifact is deployed and verified; related secrets must then be revoked. Feedback remains in Verxion’s database and may be answered through the listed email provider. |
| 2026-08-03 | Inventory reconciled with production: Cloudflare R2, browser PostHog, browser/server Sentry, BYOK harness, and Telegram channel. Removed absolute statements about regions or contracts that cannot be verified from code alone. |
| 2026-06-20 | Added optional AI-provider web search. |
| 2026-05-08 | Initial publication. |