A subprocessor is a third-party company that processes customer data on Supercase’s behalf. When an enterprise customer’s data enters Supercase, it may flow through the vendors listed below.
We notify customers of material changes to this list — such as adding a new subprocessor with access to customer content — with reasonable notice where practicable, so that enterprise customers have time to raise questions before the change takes effect.
Infrastructure
| Subprocessor | Purpose | Data exposure |
|---|---|---|
| Vercel | App hosting, compute, logs | All inbound requests and server logs |
| Supabase | Postgres database, auth, storage | All customer data at rest |
| Upstash | Redis-backed rate limiting | IP addresses and user identifiers (user ID, email) used as rate-limit bucket keys — no business content is stored |
AI / LLM
| Subprocessor | Purpose | Data exposure |
|---|---|---|
| Google — Gemini (Vertex AI and Gemini API) | Google Gemini models for content generation, research synthesis, firmographic fallback, document ingestion (classification and evidence extraction), market-context generation and upload, and Gong extraction | Prompts that include customer-supplied context (POV notes, pipeline data, uploaded documents — including document images, scans, and screenshots sent for multimodal processing) |
| OpenAI | text-embedding-3-small for market-context RAG embeddings only | Market-context text uploaded by customers |
| Exa | Neural web search for target-company research | Customer-identified target company names and domains |
External data enrichment
| Subprocessor | Purpose | Data exposure |
|---|---|---|
| Apollo.io | Firmographics lookup by domain | Target company domains |
| Financial Modeling Prep | Public-company financial data by ticker | Target tickers (public data) |
Sales-call intelligence (opt-in per customer)
| Subprocessor | Purpose | Data exposure |
|---|---|---|
| Gong | Pull call metadata and transcripts that the customer’s seller has selected for use in a Supercase. Only engaged when an org admin has explicitly connected their Gong tenant via OAuth. | Read-only: call titles, dates, durations, participant emails, transcripts. Transcripts are streamed through extraction in-memory and not persisted by Supercase — only structured findings (claims and supporting quotes) are stored. |
CRM integration (opt-in per customer)
| Subprocessor | Purpose | Data exposure |
|---|---|---|
| HubSpot | Two-way deal integration. Only engaged when an org admin has explicitly connected their HubSpot portal via OAuth. Reads company and deal context to populate a Supercase; writes Supercase lifecycle activity, and — where an admin has configured it — the share link and qualification methodology values. | Read: company and deal metadata (names, domains, amounts, stages), deal note and call-note bodies, and contact name / job title / email — which may contain customer-supplied business context. Writes are limited to Supercase-authored timeline notes, the share link, and admin-mapped methodology field values. |
Auth / identity
| Subprocessor | Purpose | Data exposure |
|---|---|---|
| Google (OAuth via NextAuth) | Sign-in provider | Email and profile |
Analytics and communications
| Subprocessor | Purpose | Data exposure |
|---|---|---|
| PostHog | Product analytics, application error tracking, and session replay (authenticated app surfaces only — public share pages are excluded; session-replay inputs are masked) | Usage events, device information |
| Resend | Transactional email | Email address, email content |
Notes
- Our subprocessors may use their own sub-processors (for example, Supabase and Vercel rely on AWS and GCP). Refer to each vendor’s trust page for details.
- Questions about a specific subprocessor or an enterprise data processing addendum (DPA)? Email hello@supercase.ai.