Subprocessors
Version 2026.3 · Last updated: 2026-08-30 · Effective: pending approval
ThutaTech services are currently in private beta: public sign-up is closed and no paid plans are on sale yet. Statements about accounts and billing describe how the Services will operate at public launch.
This is a draft pending legal review. It is not the final version and is not legal advice.
This policy is not yet available in your selected language and is shown in English.
SUBP-01 — About this list
These are the third-party providers that process data to operate ThutaTech products, grouped by product. "Location" is the provider's primary processing region as currently understood; entries marked (confirming) are being verified against provider documentation before public launch and are not final. We update this page before adding a provider that materially changes data handling.
SUBP-02 — Ecosystem-wide
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Clerk | Authentication, sessions, user profiles | Name, email, avatar, OAuth identity | United States |
| Vercel | Web hosting (marketing, Account Center, Studio, Flow web, Thuta Learning) | Request data, server logs | United States / global edge |
| Vercel Web Analytics | Cookieless aggregate web analytics (learn.thutatech.com only) | Page visited, referrer, country/region derived from IP (IP not retained), device type, browser, OS; visitor hash discarded after 24 hours | United States |
SUBP-03 — Account Center
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Managed PostgreSQL host (confirming) | Primary database | Account, billing, credits, career-analysis data | (confirming) |
| PayPal | Subscription payments | Payment metadata, subscription IDs | United States |
| Upstash | Rate limiting | IP-keyed counters | (confirming) |
| Svix (via Clerk) | Webhook delivery | User lifecycle event payloads | United States |
SUBP-04 — Thuta App Builder
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Supabase | Database and storage | Prompts, projects, generated code, boot reports | (confirming) |
| AI providers per the AI Data Use Policy (Google Gemini; optionally OpenRouter, DeepSeek, Z.ai, OpenAI-compatible) | AI generation | Prompts, project context | US / (varies; PRC for DeepSeek & Z.ai if enabled — pending owner decision) |
| StackBlitz (WebContainer) | In-browser preview runtime | Generated app code (client-side execution) | United States |
| Expo (EAS) | Mobile builds | App bundles and configs | United States |
| Google Play / Apple App Store | Store submission (user-initiated) | App metadata, binaries | United States |
SUBP-05 — Thuta Studio
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Managed PostgreSQL host (confirming) | Database | Projects, assets metadata, collaboration | (confirming) |
| Object storage (S3-compatible) (confirming adapter & region) | File storage | Uploads, exports | (confirming) |
| OpenAI | AI features | Prompts, content being edited | United States |
| Liveblocks | Realtime collaboration (presence, comments, co-editing) | Collaboration session data | United States |
| Inngest | Background job orchestration (exports, bulk jobs) | Job payloads and metadata | United States |
| Sentry | Error monitoring | Error traces, technical context | United States / EU (confirming) |
| Resend | Transactional email | Email address, notification content | United States |
| Pexels, Pixabay, Unsplash, Freesound, Giphy, Tenor | Stock media and GIF search | Search queries | US / EU |
Payment note: Stripe was removed on 2026-07-18 (owner decision — the ecosystem is PayPal-only); Studio print checkout is disabled until a PayPal-based checkout ships. Background-removal AI (img.ly) runs entirely in your browser — no server processor involved.
SUBP-06 — Thuta Flow
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Cloudflare (Workers, D1, Queues, R2) | Backend, database, queueing, audit archive | Workflows, execution logs, credentials, webhook payloads | Global edge (US entity) |
| OpenAI-compatible endpoints, Anthropic | Workflow AI nodes | Node prompts and content | United States |
| Meta (Facebook, Instagram, Threads), Google (YouTube) | User-connected integrations | OAuth tokens, content you post via workflows | United States |
SUBP-07 — Thuta Agent (pre-release)
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Model providers via router (configuration pending) | AI processing | Mission prompts, context | (pending) |
| Tavily | Web search | Search queries | United States |
SUBP-08 — Thuta IDE
BYOK (default): ThutaTech operates no subprocessor in the IDE's AI path — requests go directly from your device to the provider whose API key you configured, under your agreement with that provider. Update checks are served from releases.thutatech.com (Cloudflare, United States/global edge).
Managed mode (optional, signed-in):
| Provider | Purpose | Data | Location |
|---|---|---|---|
| OpenRouter | Managed-AI model routing (via the Account Center gateway), pinned to Zero-Data-Retention, non-PRC endpoints per request | Prompts, code context of Managed-mode requests (transient) | United States |