Legal

Subprocessors

Effective June 2026 · Last updated 2026-06-01

Recoup relies on the following third-party services to operate. Each subprocessor has been vetted for security and compliance. We have Data Processing Agreements (DPAs) in place where required.

ProviderPurposeLocationData processed
SupabaseAuthentication, database (Postgres), file storageFrankfurt, Germany (eu-central-1)Email, OAuth tokens, user profile, songs, contracts, earnings snapshots
VercelApplication hosting and serverless functionsWashington DC, USA (iad1)Processed in transit only — no persistent data stored on Vercel
StripePayment processing and subscription managementGlobal (data residency: EU/US)Stripe customer ID, subscription status, invoice metadata. Card numbers never touch our servers.
AnthropicLLM-based contract parsing (Claude)USAExtracted contract text (not original files). Zero data retention per API terms.
DeepSeekLLM-based contract parsing (fallback provider)China (data processed via API)Extracted contract text (not original files). Zero data retention per API terms.
Songstats (via RapidAPI)Streaming and radio play data for songs you addGlobal (RapidAPI: USA)ISRC codes only — no personal data. Response data cached as earnings snapshots.
ResendTransactional email (password reset, billing notices)USAEmail address, email content
SentryError tracking and crash reportingUSAAnonymised error traces. No PII or contract content.
PostHogAnonymous product analyticsEU (eu.posthog.com)Page views and feature usage. Cookie-less. No PII. IP addresses anonymised.
CloudflareTurnstile bot protection on signup/login formsGlobalChallenge tokens only. No persistent user data.
SpotifyOAuth sign-in and playlist import (opt-in)GlobalSpotify user ID, OAuth token. Playlist metadata and track ISRCs are imported only when you explicitly trigger an import.
GoogleOAuth sign-in provider (opt-in)GlobalEmail address, display name, Google account ID
AppleOAuth sign-in provider (opt-in)GlobalEmail address (or private relay address), display name
DiscordOAuth sign-in provider (opt-in)GlobalEmail address, Discord username, Discord user ID

This list is updated as our infrastructure evolves. For questions about any subprocessor, contact hello@recoup.cloud.