Back to home

Legal

Subprocessors

The service providers deepface.dev uses to deliver, secure, monitor, and bill for the platform.

Effective date: August 11, 2026

How we manage providers

We limit providers to the information required for their role and use contractual and technical safeguards for international transfers where required. Processing locations can vary according to our configured service region and each provider's supporting infrastructure.

Supabase

Purpose: Database, authentication, private invoice storage, MCP processing, and asynchronous job queue.

Data: Account, usage and billing records; MCP request content in transit; and queued async-request data where that workflow is enabled.

Fly.io

Purpose: Private gateway and model-processing infrastructure.

Data: API content in transit and temporary processing files, plus limited operational metadata.

Vercel

Purpose: Website, dashboard, MCP proxy, and server-route hosting.

Data: Website requests, account interactions, and public tester or MCP request content in transit.

PostHog

Purpose: Consent-controlled product analytics and session replay.

Data: Non-account-linked, allowlisted product interaction metadata and masked replay data. API content, tester previews, and deepface.dev user or account identifiers are excluded.

PayFast

Purpose: Payment processing and payment-method tokenisation.

Data: Payment, billing and transaction-verification information. PayFast may retain this information for up to 7 years where required by legal, regulatory, and contractual obligations.

Resend

Purpose: Transactional service email delivery.

Data: Recipient address and service-message delivery metadata.

Slack

Purpose: Customer feedback and operational alert delivery.

Data: Support messages and limited operational alert metadata.

Changes

We update this page when a provider or its role changes. Questions can be sent to hello@deepface.dev.