Sub-processors
Draft, pending legal review. Last updated 2026-09-24. Bracketed items are still to be filled in.
The companies that process your data so Reliquary can run.
| Provider | What it does | Where | Data |
|---|---|---|---|
| Supabase Supabase privacy policy | Database and sign-in (authentication) | EU: AWS Frankfurt (eu-central-1) | All vault content, encrypted variable values, account emails |
| Vercel Vercel privacy policy | Hosting and CDN for the web app and MCP endpoint | Functions in Frankfurt (fra1); CDN and request logs global (US company) | Requests in transit, request logs with IP addresses |
| Email provider | Sending sign-in codes and invitations | [to be added: provider, location and data (email addresses, message content)] | |
| Payment provider | Billing, once plans are paid | None yet: nothing is billed during the beta. Added here before billing starts. | |
Model providers: none
Reliquary runs no AI model and sends your content to no model provider. The AI tools you connect (Claude, ChatGPT, Cursor and others) receive what their agent reads through your account, under your own agreement with their provider. They are your choice, not our sub-processors.
Changes
We update this page and tell vault owners [to be filled: notice period] before adding or replacing a sub-processor. To object, email andres@redmage.cc.