Sub-processors

Last updated: 27 August 2026

This page lists the third parties that process personal data on behalf of, or in connection with, Bonded Studio (operated by Sapphire Labs) so that we can provide the Services. It supports the transparency requirements of Articles 13–14 and 28 GDPR and supplements the Privacy Policy, which remains the authoritative description of how we process personal data.

We keep this list current. Where a provider acts as an independent controller (for example, a payment provider or Merchant of Record for its own payment and fraud purposes), that provider processes data under its own terms and privacy policy in addition to any processing it performs for us.

Our primary application hosting is intended to remain in the European Union. Where a provider processes data outside the EU/EEA, we rely on an adequacy decision, the European Commission’s Standard Contractual Clauses (SCCs), and/or supplementary safeguards, together with a data processing agreement.

Several providers below are in the United States. Where a provider is certified under the EU–U.S. Data Privacy Framework (DPF), transfers rest on the European Commission’s adequacy decision of 10 July 2023; where it is not, they rest on SCCs. The DPF adequacy decision was upheld by the General Court of the EU on 3 September 2025 (Latombe v Commission, T-553/23) and an appeal is pending before the Court of Justice. Our assessment of these transfers, and what we would do if that appeal succeeded, is recorded internally in our transfer impact assessment.

Infrastructure and hosting

ProviderPurposeData involvedLocationTransfer safeguard
Hetzner Online GmbHApplication hosting, database, logs, infrastructureAccount, session, product, and log dataGermany (EU)Within EU/EEA
HostingerWebsite (bonded.studio), newsletter, email, and domain hostingWebsite, newsletter, and contact dataUnited StatesSCCs
QUIC.cloud (LiteSpeed Technologies, Inc.)Website CDN and caching (via LiteSpeed Cache)Technical request data, IP address, cached contentUnited States / global edgeSCCs

Authentication

ProviderPurposeData involvedLocationTransfer safeguard
Apple Inc.Sign in with AppleApple relay identifier, sign-in statusUnited StatesSCCs / independent controller
Google LLCSign in with GoogleGoogle account identifier, email, sign-in statusUnited StatesSCCs / independent controller

Payments and subscriptions

ProviderPurposeData involvedLocationTransfer safeguard
Apple Inc.App Store in-app purchases and auto-renewable subscriptionsPurchase/subscription status, Apple transaction dataUnited StatesIndependent controller for payments; SCCs where applicable
RevenueCat, Inc.Subscription entitlement management, receipt handling, restore/sync, app user ID mappingEntitlement status, app user ID, purchase metadataUnited StatesSCCs
Paddle.com Market Ltd (Paddle)Merchant of Record for web checkout — payment processing, tax calculation/remittance, receipts, buyer email, refunds, chargebacksBuyer email, purchase details, payment status (Paddle handles card data; we do not receive full card numbers)United Kingdom / EU / United StatesUK adequacy decision + SCCs; independent controller / Merchant of Record

Communications

ProviderPurposeData involvedLocationTransfer safeguard
Resend (Resend, Inc.)Transactional email delivery (sign-in links, password resets, gift-code emails, service messages)Email address, message content/metadataUnited StatesSCCs
Expo / EAS (650 Industries, Inc.)Mobile push-notification deliveryExpo push token, notification payloadUnited StatesSCCs

Analytics

ProviderPurposeData involvedLocationTransfer safeguard
Google LLC (Google Analytics 4)Website analytics, traffic measurement, campaign performancePseudonymous usage/event data, IP-derived data, device/browser dataUnited StatesSCCs / DPF — loaded only after consent (see Cookie Policy)
Functional Software, Inc. (Sentry)Crash reporting, error diagnostics and performance traces for the mobile app and the admin console. Our API server does not send data to SentryError and stack-trace data, device/OS and app version, breadcrumb events. Configured with sendDefaultPii: false; no user identity is attached, and credential-shaped values are scrubbed before sendUnited StatesSCCs / DPF

Advertising measurement

ProviderPurposeData involvedLocationTransfer safeguard
TikTok Technology Limited / TikTok Inc.Measuring which advertising campaigns lead to sign-ups and survey completions. Two separate integrations: (a) a server-to-server conversion feed from our own systems, sent only when a visitor arrived from a TikTok ad (identified by a TikTok click ID in the link); (b) a measurement tag in the browser on the Research Lab (research.bonded.studio) only, which is held inert until a respondent accepts research participation and never loads at all if they decline(a) TikTok click ID, event name, timestamp, page URL, purchase value where relevant, and the IP address and browser user-agent of the request. Email is sent only as an irreversible hash, and only if advanced matching is switched on — it is off by default. (b) Standard pixel event data for the two events we fireIreland (EU) / United StatesSCCs; independent controller for its own advertising purposes

Note on the web-to-app funnel and the mobile app: product analytics for the funnel (start.bonded.studio) and in-app behavioural events are first-party and stored on our own EU infrastructure (Hetzner); they are not sent to Google Analytics. The funnel deliberately runs no advertising tag in the browser — its TikTok conversion measurement is server-to-server only, which is why the funnel sets no advertising cookie. See the Privacy Policy and the web-to-app data guide for details.

Internal operations

ProviderPurposeData involvedLocationTransfer safeguard
Discord Netherlands B.V. / Discord Inc.Internal operational alerting to our private team channel — revenue events, incidents, releasesInternal account identifier (a random UUID, not a name or email), purchase amount, currency and event type. No email address, username or profile content is sentNetherlands (EU) / United StatesSCCs

Artificial intelligence

One AI provider processes users’ personal data, for content safety only.

ProviderPurposeData involvedLocationTransfer safeguard
OpenRouter, Inc.Routing content-safety checks of profile writing to the model providers belowProfile bios, prompt answers, usernamesUnited StatesSCCs
Anthropic PBCRunning the content-safety classificationProfile bios, prompt answers, usernamesUnited StatesSCCs

Why the second row exists. OpenRouter is a router, not a model provider: it forwards each request to an upstream that actually runs the model, and left unconfigured that choice can vary between requests. A register that named only OpenRouter would therefore be incomplete — the processing happens somewhere it does not name.

We pin it. The API refuses to send anything unless an explicit allowlist of upstream providers is configured, fallback routing is disabled so a request cannot be re-routed around that list under load, and providers that retain prompts or train on them are excluded. The pinned list is the second row of this table, and changing it is a change to this register.

What the processing is. An administrator starts a scan; the model is asked whether the text breaks our Community Rules and returns a verdict. The verdict can only open an item in our moderation queue for a person to read. It cannot remove content, hide it, or restrict an account — see Content Moderation Policy §1. Text that has not changed since it was last checked is not sent again.

No training. Nothing users write is used to train any model, by us or by any provider above.

Separately, AI tools may be used internally by our team to help draft editorial/website content (see Disclosures §7); this does not involve users’ personal data.

Professional and legal recipients

In addition to the sub-processors above, we may disclose personal data to legal, accounting, and tax advisers, and to courts, regulators, or authorities where legally required, as described in the Privacy Policy. These are recipients rather than routine sub-processors.

Changes

We may add or replace sub-processors as the Services evolve. Material changes will be reflected here; where required, we will provide additional notice or seek consent. For questions about a specific provider or its transfer safeguards, contact support@bonded.studio.