Subprocessors
Last updated February 2026
TraceFolio uses a small number of third-party services to deliver the product. This page lists each one, what it does, and what it receives.
Current subprocessors
| Service | Purpose | Data it receives |
|---|---|---|
| Supabase | Database, private file storage, authentication | Your account email, your uploaded source files (private bucket), extracted text, findings and report data. |
| Cloudflare | Application hosting and content delivery | Request metadata (IP address, user agent) needed to serve the application. |
| OpenAI | Evidence analysis | Extracted text passages from your documents, sent per analysis stage. Content is submitted through the API and is not used to train models. |
| Google Cloud Vision | OCR for scanned documents and images | Only the image or scanned page bytes that require OCR, and only when a document has no readable text layer. |
| NexArt | Certified Execution Record issuance and verification | Cryptographic hashes and analysis parameters only — never your documents, extracted text, findings or filenames. |
| Stripe | Payments | Your billing details and card data, entered directly on Stripe's hosted checkout, plus internal report and tier identifiers. |
| Resend | Transactional email delivery | Your email address, the report title and a link to the report. Never evidence content or findings. |
Certification receives hashes only
This is worth stating separately, because it is the most common question: the certification provider never receives your documents. It receives one-way hashes plus the recorded analysis parameters. That is sufficient to prove the binding between your inputs and your report, and insufficient to reconstruct anything about their contents.
Changes
If we add or replace a subprocessor that processes customer content, this page is updated. Questions: privacy@tracefolio.ai.