Last updated: 27 August 2026
This page lists the third parties that process personal data on behalf of, or in connection with, Bonded Studio (operated by Sapphire Labs) so that we can provide the Services. It supports the transparency requirements of Articles 13–14 and 28 GDPR and supplements the Privacy Policy, which remains the authoritative description of how we process personal data.
We keep this list current. Where a provider acts as an independent controller (for example, a payment provider or Merchant of Record for its own payment and fraud purposes), that provider processes data under its own terms and privacy policy in addition to any processing it performs for us.
Our primary application hosting is intended to remain in the European Union. Where a provider processes data outside the EU/EEA, we rely on an adequacy decision, the European Commission’s Standard Contractual Clauses (SCCs), and/or supplementary safeguards, together with a data processing agreement.
Several providers below are in the United States. Where a provider is certified under the EU–U.S. Data Privacy Framework (DPF), transfers rest on the European Commission’s adequacy decision of 10 July 2023; where it is not, they rest on SCCs. The DPF adequacy decision was upheld by the General Court of the EU on 3 September 2025 (Latombe v Commission, T-553/23) and an appeal is pending before the Court of Justice. Our assessment of these transfers, and what we would do if that appeal succeeded, is recorded internally in our transfer impact assessment.
Infrastructure and hosting
| Provider | Purpose | Data involved | Location | Transfer safeguard |
|---|---|---|---|---|
| Hetzner Online GmbH | Application hosting, database, logs, infrastructure | Account, session, product, and log data | Germany (EU) | Within EU/EEA |
| Hostinger | Website (bonded.studio), newsletter, email, and domain hosting | Website, newsletter, and contact data | United States | SCCs |
| QUIC.cloud (LiteSpeed Technologies, Inc.) | Website CDN and caching (via LiteSpeed Cache) | Technical request data, IP address, cached content | United States / global edge | SCCs |
Authentication
| Provider | Purpose | Data involved | Location | Transfer safeguard |
|---|---|---|---|---|
| Apple Inc. | Sign in with Apple | Apple relay identifier, sign-in status | United States | SCCs / independent controller |
| Google LLC | Sign in with Google | Google account identifier, email, sign-in status | United States | SCCs / independent controller |
Payments and subscriptions
| Provider | Purpose | Data involved | Location | Transfer safeguard |
|---|---|---|---|---|
| Apple Inc. | App Store in-app purchases and auto-renewable subscriptions | Purchase/subscription status, Apple transaction data | United States | Independent controller for payments; SCCs where applicable |
| RevenueCat, Inc. | Subscription entitlement management, receipt handling, restore/sync, app user ID mapping | Entitlement status, app user ID, purchase metadata | United States | SCCs |
| Paddle.com Market Ltd (Paddle) | Merchant of Record for web checkout — payment processing, tax calculation/remittance, receipts, buyer email, refunds, chargebacks | Buyer email, purchase details, payment status (Paddle handles card data; we do not receive full card numbers) | United Kingdom / EU / United States | UK adequacy decision + SCCs; independent controller / Merchant of Record |
Communications
| Provider | Purpose | Data involved | Location | Transfer safeguard |
|---|---|---|---|---|
| Resend (Resend, Inc.) | Transactional email delivery (sign-in links, password resets, gift-code emails, service messages) | Email address, message content/metadata | United States | SCCs |
| Expo / EAS (650 Industries, Inc.) | Mobile push-notification delivery | Expo push token, notification payload | United States | SCCs |
Analytics
| Provider | Purpose | Data involved | Location | Transfer safeguard |
|---|---|---|---|---|
| Google LLC (Google Analytics 4) | Website analytics, traffic measurement, campaign performance | Pseudonymous usage/event data, IP-derived data, device/browser data | United States | SCCs / DPF — loaded only after consent (see Cookie Policy) |
| Functional Software, Inc. (Sentry) | Crash reporting, error diagnostics and performance traces for the mobile app and the admin console. Our API server does not send data to Sentry | Error and stack-trace data, device/OS and app version, breadcrumb events. Configured with sendDefaultPii: false; no user identity is attached, and credential-shaped values are scrubbed before send | United States | SCCs / DPF |
Advertising measurement
| Provider | Purpose | Data involved | Location | Transfer safeguard |
|---|---|---|---|---|
| TikTok Technology Limited / TikTok Inc. | Measuring which advertising campaigns lead to sign-ups and survey completions. Two separate integrations: (a) a server-to-server conversion feed from our own systems, sent only when a visitor arrived from a TikTok ad (identified by a TikTok click ID in the link); (b) a measurement tag in the browser on the Research Lab (research.bonded.studio) only, which is held inert until a respondent accepts research participation and never loads at all if they decline | (a) TikTok click ID, event name, timestamp, page URL, purchase value where relevant, and the IP address and browser user-agent of the request. Email is sent only as an irreversible hash, and only if advanced matching is switched on — it is off by default. (b) Standard pixel event data for the two events we fire | Ireland (EU) / United States | SCCs; independent controller for its own advertising purposes |
Note on the web-to-app funnel and the mobile app: product analytics for the funnel (
start.bonded.studio) and in-app behavioural events are first-party and stored on our own EU infrastructure (Hetzner); they are not sent to Google Analytics. The funnel deliberately runs no advertising tag in the browser — its TikTok conversion measurement is server-to-server only, which is why the funnel sets no advertising cookie. See the Privacy Policy and the web-to-app data guide for details.
Internal operations
| Provider | Purpose | Data involved | Location | Transfer safeguard |
|---|---|---|---|---|
| Discord Netherlands B.V. / Discord Inc. | Internal operational alerting to our private team channel — revenue events, incidents, releases | Internal account identifier (a random UUID, not a name or email), purchase amount, currency and event type. No email address, username or profile content is sent | Netherlands (EU) / United States | SCCs |
Artificial intelligence
One AI provider processes users’ personal data, for content safety only.
| Provider | Purpose | Data involved | Location | Transfer safeguard |
|---|---|---|---|---|
| OpenRouter, Inc. | Routing content-safety checks of profile writing to the model providers below | Profile bios, prompt answers, usernames | United States | SCCs |
| Anthropic PBC | Running the content-safety classification | Profile bios, prompt answers, usernames | United States | SCCs |
Why the second row exists. OpenRouter is a router, not a model provider: it forwards each request to an upstream that actually runs the model, and left unconfigured that choice can vary between requests. A register that named only OpenRouter would therefore be incomplete — the processing happens somewhere it does not name.
We pin it. The API refuses to send anything unless an explicit allowlist of upstream providers is configured, fallback routing is disabled so a request cannot be re-routed around that list under load, and providers that retain prompts or train on them are excluded. The pinned list is the second row of this table, and changing it is a change to this register.
What the processing is. An administrator starts a scan; the model is asked whether the text breaks our Community Rules and returns a verdict. The verdict can only open an item in our moderation queue for a person to read. It cannot remove content, hide it, or restrict an account — see Content Moderation Policy §1. Text that has not changed since it was last checked is not sent again.
No training. Nothing users write is used to train any model, by us or by any provider above.
Separately, AI tools may be used internally by our team to help draft editorial/website content (see Disclosures §7); this does not involve users’ personal data.
Professional and legal recipients
In addition to the sub-processors above, we may disclose personal data to legal, accounting, and tax advisers, and to courts, regulators, or authorities where legally required, as described in the Privacy Policy. These are recipients rather than routine sub-processors.
Changes
We may add or replace sub-processors as the Services evolve. Material changes will be reflected here; where required, we will provide additional notice or seek consent. For questions about a specific provider or its transfer safeguards, contact support@bonded.studio.