Effective date: May 29, 2026
Processor and International Transfer List
Third-party providers Nuna currently expects to use for account, billing, AI, hosting, app distribution, and support operations.
Supabase
- Role: account authentication, account metadata, entitlement metadata, and database hosting.
- Data categories: email, user id, account plan, billing metadata, chat usage counts, and technical logs.
- Purpose: authentication, account management, entitlements, and service reliability.
- Region/transfer: project region and transfer-basis details will be maintained in this list as provider terms are finalized.
OpenRouter and model providers
- Role: AI routing and model response provider.
- Data categories: user prompts and the relevant profile, log, or conversation context needed to answer the request.
- Purpose: provide AI-assisted chat responses.
- Region/transfer: may involve international processing under provider retention and transfer terms.
Stripe
- Role: payment processor, subscription billing, checkout, and customer portal.
- Data categories: account email, Stripe customer/subscription ids, payment and invoice metadata, plan and cancellation state.
- Purpose: process payments, renewals, cancellations, refunds, and billing support.
- Region/transfer: may involve international processing under Stripe terms and transfer mechanisms.
Hosting and deployment providers
- Role: host the web app, API routes, webhooks, logs, and static assets.
- Data categories: technical request metadata, IP address, headers, logs, and webhook requests.
- Purpose: app delivery, security, observability, and reliability.
- Region/transfer: provider, region, and transfer-basis details will be maintained in this list as hosting terms are finalized.
Apple and Google
- Role: app distribution, store account, crash/diagnostic channels, and platform services where enabled.
- Data categories: platform account identifiers, device diagnostics, purchase metadata if enabled, and app review/support metadata.
- Purpose: distribute mobile apps and operate platform requirements.
- Region/transfer: governed by Apple and Google platform terms; complete store privacy labels before launch.
Support and email providers
- Role: receive and respond to support, privacy, billing, and deletion requests.
- Data categories: requester email, message content, request status, and minimal audit information.
- Purpose: support operations, privacy rights handling, and incident communications.
- Region/transfer: provider and region details will be maintained in this list as support tooling is finalized.