Subprocessors

Last updated February 2026

TraceFolio uses a small number of third-party services to deliver the product. This page lists each one, what it does, and what it receives.

Current subprocessors

ServicePurposeData it receives
SupabaseDatabase, private file storage, authenticationYour account email, your uploaded source files (private bucket), extracted text, findings and report data.
CloudflareApplication hosting and content deliveryRequest metadata (IP address, user agent) needed to serve the application.
OpenAIEvidence analysisExtracted text passages from your documents, sent per analysis stage. Content is submitted through the API and is not used to train models.
Google Cloud VisionOCR for scanned documents and imagesOnly the image or scanned page bytes that require OCR, and only when a document has no readable text layer.
NexArtCertified Execution Record issuance and verificationCryptographic hashes and analysis parameters only — never your documents, extracted text, findings or filenames.
StripePaymentsYour billing details and card data, entered directly on Stripe's hosted checkout, plus internal report and tier identifiers.
ResendTransactional email deliveryYour email address, the report title and a link to the report. Never evidence content or findings.

Certification receives hashes only

This is worth stating separately, because it is the most common question: the certification provider never receives your documents. It receives one-way hashes plus the recorded analysis parameters. That is sufficient to prove the binding between your inputs and your report, and insufficient to reconstruct anything about their contents.

Changes

If we add or replace a subprocessor that processes customer content, this page is updated. Questions: privacy@tracefolio.ai.