// public sandbox · real alchemy ingestion · model v0.5.0-gov-expanded · status
SYBILSHIELD

// legal

Sub-processors

Third-party services we use to operate SybilShield. Each is bound by a written DPA. Subscribe to change notifications (30-day advance notice).

vendorpurposedataregiondpa
VercelFrontend hostingHTTP logs, IPUSA · global edgeDPA
HetznerAPI + worker + ML + Postgres + Redis hosting (single VPS)All customer records, app data, logsGermany (Nuremberg)DPA
CloudflareDNS + email routing (support@ / security@ forwarding)Request metadata, forwarded email headersGlobal edgeDPA
AlchemyRPC providerPublic on-chain queriesUSADPA
DiscordOps alerts (deploy, uptime, worker errors)Alert messages only — no customer dataUSADPA
AtlosCrypto checkout — dormant, unconfigured under the free public-good modelNone (not live)N/A— (dormant)

Data residency summary

PRIMARY

Customer records — Germany (Hetzner, Nuremberg). Postgres + Redis on the same VPS.

EDGE

Static assets + DNS — global edge. No customer PII.

BILLING

None. SybilShield is a free public good — no payment processors, no billing data.