Legal
Subprocessors
The third-party processors the platform uses, what each one is used for, the categories of data each receives, and where tenant data is stored.
Version 1.1.0 · Effective
Draft — not yet reviewed by counsel
This text has not been reviewed by a qualified legal practitioner and is published for review rather than as an executed instrument. The review state is recorded in mybase/docs/legal/README.md.
Operator details outstanding
The operating entity name, registered address, governing-law jurisdiction and privacy contact have not been configured for this deployment. Each appears below as a marked placeholder rather than a guess.
1. Scope
This page lists the subprocessors [PENDING — operator to supply] engages to provide the platform. It is the authoritative list referenced by the Data Processing Addendum; the DPA does not restate it, so that there is only ever one list to keep accurate.
A subprocessor appears here when product code can transmit customer data to it. Whether a given tenant actually transmits data to a given subprocessor depends on which features that tenant enables — the AI subprocessors, for example, receive nothing from a tenant that never uses the assistant.
2. Current subprocessors
| Subprocessor | Purpose | Categories of data received | When engaged |
|---|---|---|---|
| Supabase | Managed Postgres database, authentication and file storage. Each tenant runs on its own dedicated database project. | All customer data: account identities and credentials, profiles, posts, messages, events, course progress, uploaded files. | Always — this is where the tenant database lives. |
| Vercel | Application hosting, CDN and custom-domain management. | HTTP request metadata (IP address, user agent, requested path) and any data in transit through the application; custom domain names configured by a tenant admin. | Always, for deployments hosted by us. |
| Stripe | Payment processing for subscriptions and ticketed events. | Billing contact details, payment card data (collected by Stripe directly — the platform never receives card numbers), subscription and transaction records. | When a tenant or member makes a payment. |
| Resend | Transactional email delivery (invitations, confirmations, notifications). | Recipient email address and name, and the contents of the message sent. | When the platform sends an email. |
| Google (Gemini) | AI assistant inference and text embeddings for search. | Assistant prompts and the community content supplied to the assistant as context; text submitted for embedding. | When the assistant or semantic search is used. |
| OpenAI | AI assistant inference (alternative provider). | Assistant prompts and the community content supplied to the assistant as context. | When the assistant is used with this provider configured. |
| Anthropic | AI assistant inference (alternative provider). | Assistant prompts and the community content supplied to the assistant as context. | When the assistant is used with this provider configured. |
| fal.ai | Image and video generation for assistant and creative features. | Generation prompts and any image supplied as an input to a generation. | When a member generates an image or video. |
| Google (Fonts) | Delivery of the webfonts this community’s theme uses, unless the community self-hosts them. | HTTP request metadata only: IP address, user agent and referring page, sent by the visitor’s browser when it fetches the stylesheet and font files. No account data and no cookie. | On every page load, for any visitor, unless the community self-hosts its fonts. |
| Tavily | Web search used to ground assistant answers. | The search query derived from the member’s assistant prompt. | When the assistant performs a web search. |
3. What leaves the platform when the AI assistant is used
The AI assistant is not self-hosted. When a member uses it, the prompt and the community content retrieved as context for that prompt are transmitted to the configured inference provider — Google, OpenAI or Anthropic — and, where the assistant performs a web search or generates media, to Tavily or fal.ai respectively.
A tenant that does not want this can leave the assistant disabled. There is no configuration in which assistant inference happens without a transfer to one of these providers.
4. Data region
Tenant databases are provisioned by default in AWS ap-southeast-2 (Sydney). The region is set per tenant at provisioning time and can be changed on request before a tenant database is created; it cannot be changed in place afterwards without a migration.
Hosting, email, payment and AI subprocessors listed above operate their own infrastructure and may process data outside that region. The default database region is a statement about where the tenant’s Postgres database resides, not a guarantee of single-region processing across every subprocessor.
5. Changes to this list
This list is updated in the same change that introduces a new subprocessor to the platform. Customers with an executed Data Processing Addendum are notified of additions in accordance with that addendum before the new subprocessor begins processing their data.
Questions about this list go to [PENDING — operator to supply].