← CrateCore · All legal documents · Русская версия

CrateCore — Processors & Third-Party Services (Subprocessors) Version date: July 17, 2026 Operator: the individual developer of the CrateCore service Contact: [email protected] 1. Purpose This document lists the third-party services that help CrateCore run and may process data. For each service it states what data it sees and where it is processed. 2. Services that process user data Service: Supabase Role: database, authentication, file storage, server functions. Data: account identifier, e-mail (when an account is linked), profile name, settings, collection, wishlist, notes, article states, audio chain profile, import CSV (up to 24 hours), push tokens, technical logs. Region: EU — Frankfurt (eu-central-1). Status: active. Service: Google Firebase (Google LLC) Role: push delivery (FCM), analytics (Firebase Analytics), crash reports (Crashlytics), app attestation (App Check). Data: push tokens, pseudonymous technical identifiers, usage events without personal content, crash reports (device model, OS/app version, stack trace). Advertising identifiers are not collected; the user identifier is not sent to analytics. Region: Google's global infrastructure (including the US). Retention: Analytics — up to 2 months (user/event-level data, default setting); Crashlytics — 90 days. Status: active. Service: Resend Role: delivery of service e-mails — sign-in codes. Data: recipient e-mail, service e-mail content, delivery logs. Region: US / global. Status: active. Service: Cloudflare Role: hosting and CDN for cratecore.app; inbound e-mail routing for [email protected]; AI illustration generation for stories (Workers AI) — no personal data involved. Data: technical data of site visitors (IP address, request headers) to the extent needed to serve pages and protect against attacks; transit of e-mails to legal@. Region: global network. Status: active. Service: Google (sign-in and store) Role: Google Sign-In, distribution via Google Play. Data: Google identity token and e-mail on Google sign-in; install/update data under Google Play rules. Region: per Google's terms. Status: active for Android. Service: Apple Role: Sign in with Apple and App Store distribution — once the iOS version ships. Data: Apple identity tokens / relay e-mail (when the iOS version exists). Region: per Apple's terms. Status: not active (until the iOS release). Service: payment provider (e.g. RevenueCat) Role: subscription management, if paid features are enabled. Data: none processed at the moment. Status: not active; will be added to this list and to the Privacy Policy before paid features are enabled. Service: backup storage Role: encrypted database backups. Data: a copy of user and content tables. Retention: up to 30 days. Status: to be enabled before the production launch; the specific provider and region will appear here when enabled. 3. Content pipeline services (no user data is sent) Service: OpenRouter + DeepSeek Role: language model for rewriting editorial stories from verifiable public facts. Data: public facts, sources, and story drafts only. User notes, collections, CSV, e-mails, and identifiers are never sent. Status: active. Service: Contabo Role: VPS hosting for the content pipeline (n8n). Data: public facts and pipeline operational metadata; no user data. Status: active. 4. External data and image sources These services are content sources, not processors of user data. Exception: when the user's device loads an image directly, the source sees the device's IP address (as with any image on the internet). - Discogs — release metadata via CrateCore's server-side requests; no user personal data is sent to Discogs, and the API token lives only on the server. - MusicBrainz / MetaBrainz — planned source of CC0 metadata (offline ingest); the live public API is not used in the production path. - Cover Art Archive / Internet Archive — release covers: the app and the site load the image directly by URL. - Wikimedia (Wikidata, Wikipedia, Commons) — public facts and freely licensed images; story images load directly from Wikimedia servers. 5. Change notice We update this list when services are added, removed, or materially changed. 6. Contact Questions about this list: [email protected].