Subprocessors
Version 2026.3 · Last updated: 2026-08-30 · Effective: pending approval
ThutaTech services are currently in private beta: public sign-up is closed and no paid plans are on sale yet. Statements about accounts and billing describe how the Services will operate at public launch.
This is a draft pending legal review. It is not the final version and is not legal advice.
SUBP-01 — About this list
These are the third-party providers that process data to operate ThutaTech products, grouped by product. "Location" is the provider's primary processing region as currently understood; entries marked (confirming) are being verified against provider documentation before public launch and are not final. We update this page before adding a provider that materially changes data handling.
SUBP-02 — Ecosystem-wide
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Clerk | Authentication, sessions, user profiles | Name, email, avatar, OAuth identity | United States |
| Vercel | Web hosting (marketing, Account Center, Studio, Flow web, Thuta Learning) | Request data, server logs | United States / global edge |
| Vercel Web Analytics | Cookieless aggregate web analytics (learn.thutatech.com only) | Page visited, referrer, country/region derived from IP (IP not retained), device type, browser, OS; visitor hash discarded after 24 hours | United States |
SUBP-03 — Account Center
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Managed PostgreSQL host (confirming) | Primary database | Account, billing, credits, career-analysis data | (confirming) |
| PayPal | Subscription payments | Payment metadata, subscription IDs | United States |
| Upstash | Rate limiting | IP-keyed counters | (confirming) |
| Svix (via Clerk) | Webhook delivery | User lifecycle event payloads | United States |
SUBP-04 — Thuta App Builder
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Supabase | Database and storage | Prompts, projects, generated code, boot reports | (confirming) |
| AI providers per the AI Data Use Policy (Google Gemini; optionally OpenRouter, DeepSeek, Z.ai, OpenAI-compatible) | AI generation | Prompts, project context | US / (varies; PRC for DeepSeek & Z.ai if enabled — pending owner decision) |
| StackBlitz (WebContainer) | In-browser preview runtime | Generated app code (client-side execution) | United States |
| Expo (EAS) | Mobile builds | App bundles and configs | United States |
| Google Play / Apple App Store | Store submission (user-initiated) | App metadata, binaries | United States |
SUBP-05 — Thuta Studio
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Managed PostgreSQL host (confirming) | Database | Projects, assets metadata, collaboration | (confirming) |
| Object storage (S3-compatible) (confirming adapter & region) | File storage | Uploads, exports | (confirming) |
| OpenAI | AI features | Prompts, content being edited | United States |
| Liveblocks | Realtime collaboration (presence, comments, co-editing) | Collaboration session data | United States |
| Inngest | Background job orchestration (exports, bulk jobs) | Job payloads and metadata | United States |
| Sentry | Error monitoring | Error traces, technical context | United States / EU (confirming) |
| Resend | Transactional email | Email address, notification content | United States |
| Pexels, Pixabay, Unsplash, Freesound, Giphy, Tenor | Stock media and GIF search | Search queries | US / EU |
Payment note: Stripe was removed on 2026-07-18 (owner decision — the ecosystem is PayPal-only); Studio print checkout is disabled until a PayPal-based checkout ships. Background-removal AI (img.ly) runs entirely in your browser — no server processor involved.
SUBP-06 — Thuta Flow
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Cloudflare (Workers, D1, Queues, R2) | Backend, database, queueing, audit archive | Workflows, execution logs, credentials, webhook payloads | Global edge (US entity) |
| OpenAI-compatible endpoints, Anthropic | Workflow AI nodes | Node prompts and content | United States |
| Meta (Facebook, Instagram, Threads), Google (YouTube) | User-connected integrations | OAuth tokens, content you post via workflows | United States |
SUBP-07 — Thuta Agent (pre-release)
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Model providers via router (configuration pending) | AI processing | Mission prompts, context | (pending) |
| Tavily | Web search | Search queries | United States |
SUBP-08 — Thuta IDE
BYOK (default): ThutaTech operates no subprocessor in the IDE's AI path — requests go directly from your device to the provider whose API key you configured, under your agreement with that provider. Update checks are served from releases.thutatech.com (Cloudflare, United States/global edge).
Managed mode (optional, signed-in):
| Provider | Purpose | Data | Location |
|---|---|---|---|
| OpenRouter | Managed-AI model routing (via the Account Center gateway), pinned to Zero-Data-Retention, non-PRC endpoints per request | Prompts, code context of Managed-mode requests (transient) | United States |