Subprocessors and Third-Party Services
SUPLOAD LLC
Version 2.3.1 · Last Updated: September 2, 2026
This page has two parts. Subprocessors are vendors Supload LLC engages to process personal data on Supload's behalf to deliver the service. Third-party services you connect are your own accounts (sign-in, cloud storage, and the App Store) that you use with Supload. Those providers act as your own service providers under your agreements with them, not as Supload's subprocessors, and your media goes to them directly from your device.
We will update this page before engaging any new subprocessor and provide at least 30 days' notice to Enterprise customers. We send subprocessor change notifications to the Enterprise account administrator's email address on file. All other customers may subscribe to notifications by emailing [email protected] with the subject line "Subprocessor Notifications."
Enterprise customers who object to a new subprocessor may contact [email protected] within the 30-day notice period. If the objection cannot be resolved, the Enterprise customer may terminate their agreement in accordance with their Enterprise plan terms.
Part 1: Supload’s Subprocessors
These vendors process personal data on Supload’s behalf.
| Subprocessor | Function | Data Processed | Infrastructure Location |
|---|---|---|---|
| Supabase, Inc. (hosted on Amazon Web Services) | Backend infrastructure: authentication, database, crash reporting, opt-in analytics, feedback, billing audit records, session management | Account information (email, name, user ID), opt-in usage analytics (recorded with your account identifier, personal details stripped), crash reports, feedback submissions, billing metadata (billing email, subscription and invoice status), security and account-activity logs (including IP address and device/browser user agent for security-sensitive actions), session tokens | United States (AWS US West) |
| Cloudflare, Inc. (Cloudflare Pages) | Hosting for the customer portal (subscription management, user allocation, billing) and the Supload marketing website, plus cookieless, privacy-preserving web analytics for the marketing website, and public DNS lookups used to verify that an Enterprise customer owns a domain they have added and to check that an outbound webhook address is safe to call | IP address (processed transiently by Cloudflare for routing and security), page requests, aggregate cookieless web-analytics measurements for the marketing website (page views, referrer, coarse country and device/browser type, no cookies, no device identifiers, not linked to you), and, for the DNS lookups, only the host name being looked up (an Enterprise customer’s domain, or the address of a webhook they configured) — never a user identity, an account, or file content | Global CDN (edge network) |
| Stripe, Inc. | Subscription billing (secure web checkout) for Pro purchased on our website and for Enterprise plans | Billing email, organization name, internal account identifiers (organization and user IDs), subscription status, and limited payment-method metadata. For card payments Stripe’s notification also names the card brand and last four digits; Supload discards both on receipt and stores neither. Supload never receives or stores full card numbers, bank account details, or wallet credentials. On Stripe’s own checkout and portal pages, Stripe also collects device and browser information (including through cookies) for fraud prevention, authentication, and its own service analytics | United States |
| Resend, Inc. | Email delivery (transactional notifications, usage digests) | Email address, notification content | United States |
| Google LLC (Google Forms) | Pre-launch waitlist collection. The waitlist links from our marketing website to a form hosted by Google on docs.google.com; it is not collected on sup-load.com. Retired once the App has launched | Your email address and anything else you type into the waitlist form | United States |
DNS resolution. Two of Supload’s backend checks — confirming that an Enterprise customer controls a domain they have added, and confirming that a customer-configured webhook address is safe for our servers to call — need to look up a public DNS record. Supload asks Cloudflare’s public DNS resolver first and falls back to Google Public DNS only if Cloudflare does not answer, so that a single resolver outage cannot disable a security check. All either resolver receives is the host name being looked up: an Enterprise customer’s own domain, or the address of a webhook that customer configured. No user identity, account data, or file content is involved, and no lookup is made on behalf of an individual user. Google Public DNS is used here only as this fallback resolver. It is a different service from the Google Forms waitlist described in the table above, and from the Google sign-in and Google Drive integrations described in Part 2, which you connect yourself.
Planned subprocessors: none at this time. The Google Forms entry above covers only the pre-launch waitlist and will be removed from this list when the waitlist is retired at launch. This page will be updated before any new subprocessor is engaged.
Part 2: Third-Party Services You Connect
When you sign in or link cloud storage, you connect your own account with these providers. They process your data under their own terms and privacy policies as your providers, not on Supload's behalf. Supload's role is to send your media from your device directly to the account you choose.
Sign-In (Identity Providers)
| Provider | Function | Data Involved |
|---|---|---|
| Google LLC | Google Sign-In, and Google Workspace single sign-on for Enterprise | Email address, display name, profile photo URL |
| Apple Inc. | Sign in with Apple, App Store distribution, and In-App Purchase billing for Pro purchased in the App | Email address (may be an Apple private relay address), display name, and, for purchases made in the App, subscription status and an Apple subscription record |
| Microsoft Corporation | Enterprise single sign-on via Microsoft Entra ID (MSAL) | Email address, display name, organization identifiers |
Supload never receives or stores a password for your account. For Enterprise customers using directory sync (SCIM 2.0), the organization's identity provider also shares user provisioning data (email, display name, group membership, active status) with Supload to manage organization membership.
Each provider's handling of your sign-in data is governed by its own privacy policy: the Google Privacy Policy, the Apple Privacy Policy, and the Microsoft Privacy Statement.
Cloud Storage (Your Upload Destination)
| Provider | Function | Data Involved |
|---|---|---|
| Google LLC | Google Drive, your upload destination | Your media files, uploaded directly from your device to your own Google Drive |
| Dropbox, Inc. | Dropbox, your upload destination | Your media files, uploaded directly from your device to your own Dropbox account |
| Microsoft Corporation | Microsoft OneDrive, your upload destination (connected via MSAL) | Your media files, uploaded directly from your device to your own OneDrive account |
Your use of these providers is governed by your own agreement with them: the Google Terms of Service, the Dropbox Terms of Service, and the Microsoft Services Agreement (or your organization's agreement for work and school accounts). See our Terms of Service, Section 5.3.
What Supload’s Servers Never Touch
Your photos and videos. Media files go directly from your device to your own cloud storage (Google Drive, Dropbox, or Microsoft OneDrive). They are never routed through, stored on, or processed by Supload’s servers.
Payment card information. Apple processes payment for Pro purchased inside the App, as merchant of record. From Apple we receive a subscription record and subscription status, and no payment-method details at all. Stripe processes payment for Pro purchased on our website and for all Enterprise subscriptions through a secure web checkout, and shares subscription status, billing email, and limited payment-method metadata with us. For card payments Stripe’s notification also names the card brand and last four digits; Supload discards both when the notification is processed and stores neither. Stripe supports cards and common wallets and pay-over-time options (such as Apple Pay, Link, Cash App Pay, Klarna, and Amazon Pay), and processes all of those directly. Supload never receives or stores full card numbers, bank account details, wallet credentials, or other payment credentials from either.
Authentication passwords. You sign in through Google, Apple, or your organization’s SSO. Supload never receives, stores, or processes your password. We receive only an authentication token and basic profile information (email, display name).
Cloud storage credentials. Your Google Drive, Dropbox, and OneDrive passwords are never shared with Supload. Cloud OAuth tokens are stored only in your device’s iOS Keychain (hardware-encrypted, accessible after first unlock, not synchronized to other devices) and are used solely to maintain your cloud connection. They are never stored on Supload’s servers.
Advertising data. We do not use advertising subprocessors, ad networks, or data brokers.
Analytics with personal details. Usage analytics are opt-in, first-party, and stripped of personal details before storage. They are recorded with your account identifier so we can delete them when you delete your account.
AI or ML training data. We do not use your content or personal data to train AI or machine learning models, we do not permit our subprocessors to do so on our behalf, and we do not use subprocessors for automated profiling of user data.
Data Processing Agreements
Supload maintains data processing terms with each of its infrastructure and billing subprocessors: the Supabase Data Processing Addendum, the Cloudflare Data Processing Addendum, the Stripe Data Processing Agreement, and the Resend Data Processing Addendum. These terms include obligations for data protection, security, confidentiality, and compliance with applicable data protection laws including GDPR, UK GDPR, CCPA, and other US state privacy laws. Each agreement requires the subprocessor to protect personal data with safeguards at least as protective as those described in our Privacy Policy and required by applicable law, and to use it only to provide its service to Supload.
The pre-launch waitlist form is the one exception, and we state it plainly: it runs on Google Forms under Google’s standard terms for the account that operates it, not under a negotiated data processing agreement. It collects only what you type into the waitlist form, it is used only to send launch news, and it is retired once the App has launched. You can ask us to delete your entry at any time at [email protected].
The sign-in and cloud storage providers you connect (Google, Apple, Microsoft, Dropbox) process your data under their own consumer or organizational terms with you, so no Supload subprocessor DPA applies to that processing.
For Enterprise customers who require a Data Processing Agreement between their organization and Supload LLC, a standard DPA is available upon request at [email protected].
Data Retention
| Where | Data | Retention |
|---|---|---|
| Supabase (AWS) | Account information | Until account deletion |
| Supabase (AWS) | Terms acceptance record and legal-notice log | 4 years after account deletion |
| Supabase (AWS) | Usage analytics | 28 days (auto-purged) |
| Supabase (AWS) | Crash reports | 90 days (auto-purged) |
| Supabase (AWS) | Feedback submissions | Up to 90 days (auto-purged). On account deletion, message text, contact email, and diagnostic logs are erased, and only a de-identified record may remain |
| Supabase (AWS) | Billing audit records (billing action and time, and the payment-method identifier Stripe assigned — no card brand or card digits) | Up to 1 year |
| Supabase (AWS) | Audit trail (includes IP address and user agent) | 1 year (auto-purged) |
| Supabase (AWS) | Session tokens | Session duration |
| Supabase (AWS) | Hashed email address on a personal organization record | Purged no longer than 2 years after account deletion |
| Supabase (AWS) | Apple subscription record (purchases made in the App) | Until account deletion; a minimal billing record with the account identifier removed is purged no longer than 2 years after deletion |
| Google / Apple / Microsoft | Authentication tokens | Session duration, stored only on your device |
| Google Drive / Dropbox / OneDrive | Your media files | Managed by you in your own cloud storage account |
| Stripe | Billing email, organization name, internal account identifiers (organization and user IDs), subscription status | Per Stripe’s retention policy |
| Resend | Email delivery logs | Per Resend's retention policy |
| Cloudflare | IP addresses | Processed transiently by Cloudflare for routing and security |
| Google (Google Forms) | Launch waitlist entry | Until the waitlist is retired after launch, or sooner on request to [email protected] |
For complete retention details, see our Privacy Policy, Section 7.
International Data Transfers
Supload LLC is based in the United States, and its subprocessors are based in the United States or operate global infrastructure. If you use the App from outside the United States, you provide your account data directly to Supload in the United States. The App is not currently offered in the EEA or the UK; see our Privacy Policy, Section 8.3. Our subprocessors commit to Standard Contractual Clauses and equivalent safeguards in their data processing agreements where their own transfers require them. Launch waitlist entries are submitted to and stored by Google LLC in the United States. Photos and videos transfer directly from your device to your own cloud provider. For details, see our Privacy Policy, Section 13.
Questions
Contact [email protected] with any questions about our subprocessors or data processing practices.