Home

Sub-processors

Last updated: 12 August 2026

Journey relies on the following third parties to deliver the service. We maintain contractual data-protection terms and appropriate transfer safeguards with each provider. Customers receive notice before a material new sub-processor is introduced, in line with their signed agreement.

Sub-processorPurposeData sharedLocation / safeguard
Clerk, Inc.User authentication, sign-in and session managementEmail, name, sign-in events and session identifiersInternational processing under provider contractual safeguards
Vercel, Inc.Application delivery, serverless API runtime and deployment previewsRequest metadata and application data processed in transitConfigured regions; international transfers under provider safeguards
Supabase, Inc.Managed PostgreSQL database and object storageTenant application data and stored filesLondon, United Kingdom (eu-west-2)
Stripe Payments Europe Ltd.Subscription billing and payment processing where enabledBilling contact, plan and payment metadata; Journey does not store card numbersIreland / EEA
Resend, Inc.Transactional email, including invitations and notificationsRecipient address, message content and delivery eventsInternational processing under provider contractual safeguards
Anthropic, PBCLegacy compatibility processor; not active unless an operator explicitly enables the disabled compatibility runtimeNo processing by default; bounded authorised prompt content only if the legacy compatibility runtime is explicitly activatedUnited States; international transfers under provider safeguards
OpenAI, L.L.C.Advance-only governed AI assistance for authorised evidence and feedback drafts and K/S suggestions, after provider, DPIA and release approvalBounded authorised workflow content; pattern-based redaction is applied where direct identifiers are detected but cannot guarantee all personal data is removed; credentials, payment data, raw signatures and document bytes are excludedProvider-configured processing under the applicable provider terms and contractual safeguards
Functional Software, Inc. (Sentry)Operational application error, performance and replay diagnosticsAuthenticated account, tenant, role, workflow, release, request/session and bounded replay context; credentials, tokens, payment-card data, raw signatures and document bytes are excludedProvider-configured processing under contractual safeguards
PostHog, Inc.Consent-based product analytics and session diagnosticsAfter consent: authenticated account, tenant, role, workflow, release, request/session, interaction and bounded replay context; credentials, tokens, payment-card data, raw signatures and document bytes are excludedEuropean Union cloud endpoint
Google LLCConsent-based analytics and optional Google sign-inAnalytics events after consent; identity data when Google sign-in is chosenInternational processing under provider contractual safeguards
Cloudflare, Inc.DNS, domain security and edge protectionNetwork and request metadataGlobal network under provider contractual safeguards

See also: Privacy policy · Terms of service