Subprocessors
Who else touches the data, and what they do with it.
Every vendor with access to Aperture data is named here. Each processor has a Data Processing Agreement in place; independent controllers and font providers operate under their own terms, noted individually below. Training-off configurations are verified every 90 days.
01Active subprocessors.
-
Cloudflare.
- Role
- Hosting, CDN, Workers, R2 object storage, DNS, bot-protection (Turnstile) on the participant join form, and first-party, cookieless Web Analytics.
- Data accessed
- Facilitator and participant request metadata, including IP address and browser user-agent at the network edge (used for routing, security, and abuse prevention), deck image assets, transient session tokens. Web Analytics is aggregate and does not identify individual visitors.
- Training-off
- Not applicable (no AI service).
- DPA
- In place.
-
Supabase.
- Role
- Postgres database, authentication, row-level security, file storage. Sends magic-link sign-in emails as part of authentication.
- Data accessed
- Facilitator account data (email, auth method, display name), session configurations, saved Selections, participant submissions and the debrief aggregate (keyed by a pseudonymous per-session token), optional facilitator-collected participant names, consent and renewal records.
- Training-off
- Not applicable (no AI service).
- DPA
- In place.
-
Hetzner Online GmbH.
- Role
- Hosts Aperture's self-hosted research database and backend — the image-research response collection at research.aperturedeck.com and prolific.aperturedeck.com — on a dedicated server in Germany (EU).
- Data accessed
- Research-respondent data only: pseudonymous projective responses and demographics. Not customer (facilitator or participant) data. Respondents are identified only by a hashed per-session token; Prolific respondents by a Prolific ID, with no email.
- Training-off
- Not applicable (infrastructure hosting only; no AI service).
- DPA
- In place.
-
Resend.
- Role
- Delivery of Aperture's own emails: welcome and account-state notices, conversion-nurture sequences, California ARL pre-renewal reminders, and dunning notices. (Magic-link sign-in emails are sent by Supabase as part of authentication; transaction receipts are issued separately by Paddle as Merchant of Record.)
- Data accessed
- Subscriber email address and display name, and the message content for the specific email.
- Training-off
- Configured where the provider offers AI features.
- DPA
- In place.
-
Sentry.
- Role
- Application error monitoring and performance tracing for the Studio app and the access-broker.
- Data accessed
- Diagnostic and error events with technical metadata (stack traces, page URLs, browser and runtime information). No participant data. We configure Sentry not to send default personal information such as IP address.
- Training-off
- Configured where the provider offers AI features.
- DPA
- In place.
-
Google Fonts.
- Role
- Web font delivery (Lustria, JetBrains Mono).
- Data accessed
- Visitor hostname and IP for font CDN routing. No personally identifiable data passed.
- Training-off
- Not applicable (font hosting only).
- DPA
- Covered under Google Cloud terms.
-
Fontshare.
- Role
- Web font delivery (Switzer).
- Data accessed
- Visitor hostname and IP for font CDN routing. No personally identifiable data passed.
- Training-off
- Not applicable.
- DPA
- Covered under Indian Type Foundry terms.
02Independent controllers, not subprocessors.
-
Paddle.
- Role
- Merchant of Record and legal seller of record for all Aperture purchases. Checkout, payment processing, invoicing, tax calculation and remittance, fraud prevention, chargeback and refund handling.
- Data accessed
- Buyer name and email, billing address, card details (Paddle-held, never seen by Aperture), a Paddle customer and subscription identifier, and transaction and subscription records.
- Relationship
- Buyers contract with Paddle directly at checkout, so Paddle acts as an independent controller for checkout and transaction data, not as Aperture's processor. No Article 28 processor DPA applies to the Merchant of Record relationship; Paddle discloses order information to Aperture controller-to-controller under its legitimate interests. For Paddle's seller-analytics dashboard, Paddle acts as Aperture's processor under the Paddle Data Processing Addendum.
-
Prolific.
- Role
- Research-participant recruitment and payment for the image-research program (not the Studio product).
- Data accessed
- Pseudonymous Prolific participant ID. No name or email is shared with Aperture.
- Relationship
- Prolific acts as an independent controller under its own terms, not as Aperture's processor. No Article 28 processor DPA applies.
03Change policy.
-
Material changes notified to subscribers by email.
Adding a new subprocessor that processes personal data, removing an existing one, or changing what data a subprocessor accesses are all material. Notice goes out before the change takes effect.
-
Updates posted here.
This page is the canonical list. The change history is captured in the annual transparency report.
-
Right to object.
If a subprocessor change is unacceptable to you, you can cancel within the notice window with a pro-rata refund. Specifics in the privacy policy and Terms of Service.
04Verification cadence.
-
Quarterly re-verification, every 90 days.
DPA currency, training-off configuration, role scope, and access boundaries are re-verified on a 90-day cadence. Each verification is timestamped and logged.
-
Public verification log.
The full verification log is published continuously. Annual report consolidates the quarterly summaries.
Questions about a specific subprocessor, or want to flag a concern? Write to privacy@aperturedeck.com.