// legal
Sub-processors
Third-party services we use to operate SybilShield. Each is bound by a written DPA. Subscribe to change notifications (30-day advance notice).
| vendor | purpose | data | region | dpa |
|---|---|---|---|---|
| Vercel | Frontend hosting | HTTP logs, IP | USA · global edge | DPA |
| Hetzner | API + worker + ML + Postgres + Redis hosting (single VPS) | All customer records, app data, logs | Germany (Nuremberg) | DPA |
| Cloudflare | DNS + email routing (support@ / security@ forwarding) | Request metadata, forwarded email headers | Global edge | DPA |
| Alchemy | RPC provider | Public on-chain queries | USA | DPA |
| Discord | Ops alerts (deploy, uptime, worker errors) | Alert messages only — no customer data | USA | DPA |
| Atlos | Crypto checkout — dormant, unconfigured under the free public-good model | None (not live) | N/A | — (dormant) |
Data residency summary
PRIMARY
Customer records — Germany (Hetzner, Nuremberg). Postgres + Redis on the same VPS.
EDGE
Static assets + DNS — global edge. No customer PII.
BILLING
None. SybilShield is a free public good — no payment processors, no billing data.