Legal

Subprocessors

Third-party vendors that process customer data on Supercase's behalf.

Last updated August 18, 2026

A subprocessor is a third-party company that processes customer data on Supercase’s behalf. When an enterprise customer’s data enters Supercase, it may flow through the vendors listed below.

We notify customers of material changes to this list — such as adding a new subprocessor with access to customer content — with reasonable notice where practicable, so that enterprise customers have time to raise questions before the change takes effect.

Infrastructure

SubprocessorPurposeData exposure
VercelApp hosting, compute, logsAll inbound requests and server logs
SupabasePostgres database, auth, storageAll customer data at rest
UpstashRedis-backed rate limitingIP addresses and user identifiers (user ID, email) used as rate-limit bucket keys — no business content is stored

AI / LLM

SubprocessorPurposeData exposure
Google — Gemini (Vertex AI and Gemini API)Google Gemini models for content generation, research synthesis, firmographic fallback, document ingestion (classification and evidence extraction), market-context generation and upload, and Gong extractionPrompts that include customer-supplied context (POV notes, pipeline data, uploaded documents — including document images, scans, and screenshots sent for multimodal processing)
OpenAItext-embedding-3-small for market-context RAG embeddings onlyMarket-context text uploaded by customers
ExaNeural web search for target-company researchCustomer-identified target company names and domains

External data enrichment

SubprocessorPurposeData exposure
Apollo.ioFirmographics lookup by domainTarget company domains
Financial Modeling PrepPublic-company financial data by tickerTarget tickers (public data)

Sales-call intelligence (opt-in per customer)

SubprocessorPurposeData exposure
GongPull call metadata and transcripts that the customer’s seller has selected for use in a Supercase. Only engaged when an org admin has explicitly connected their Gong tenant via OAuth.Read-only: call titles, dates, durations, participant emails, transcripts. Transcripts are streamed through extraction in-memory and not persisted by Supercase — only structured findings (claims and supporting quotes) are stored.

CRM integration (opt-in per customer)

SubprocessorPurposeData exposure
HubSpotTwo-way deal integration. Only engaged when an org admin has explicitly connected their HubSpot portal via OAuth. Reads company and deal context to populate a Supercase; writes Supercase lifecycle activity, and — where an admin has configured it — the share link and qualification methodology values.Read: company and deal metadata (names, domains, amounts, stages), deal note and call-note bodies, and contact name / job title / email — which may contain customer-supplied business context. Writes are limited to Supercase-authored timeline notes, the share link, and admin-mapped methodology field values.

Auth / identity

SubprocessorPurposeData exposure
Google (OAuth via NextAuth)Sign-in providerEmail and profile

Analytics and communications

SubprocessorPurposeData exposure
PostHogProduct analytics, application error tracking, and session replay (authenticated app surfaces only — public share pages are excluded; session-replay inputs are masked)Usage events, device information
ResendTransactional emailEmail address, email content

Notes

  • Our subprocessors may use their own sub-processors (for example, Supabase and Vercel rely on AWS and GCP). Refer to each vendor’s trust page for details.
  • Questions about a specific subprocessor or an enterprise data processing addendum (DPA)? Email hello@supercase.ai.

Questions about this document?

Email hello@supercase.ai. For enterprise customers, we also offer a data processing addendum.

Try Supercase free.

Get started for free →