SUB-PROCESSORS

Who else touches your data.

Last updated September 4, 2026 · applies to the preview release

1. Who processes data for us

These services process data on our behalf so C4Stage can work — the same list the privacy policy describes, gathered here with what each one sees. We update this page before adding a new one, not after.

Supabaseauthentication, the database, and the realtime messaging behind live cursors, presence and comments; it can see everything the product stores.

Resenddelivery of transactional email — invitations, confirmations, password resets; it sees your email address and the content of that email.

Stripepayments as the merchant of record: checkout, tax, receipts and invoices, the billing portal and payment support; it sees your email address, name, billing address and payment details — card numbers go straight to Stripe and never reach our servers.

OpenRouter and the AI model providers it routes toassistant requests; it sees the diagram text and prompt you send to the assistant, only when you invoke it.

Sentryerror reporting and server monitoring: when something breaks it receives the stack trace, the page or route, the browser and operating system, and a random event id; from our servers it also receives log lines, request timings and CPU profiles of our own code — no screen recordings, no email addresses (removed before sending), no diagram content.

HostingAmazon Web Services or Vercel, confirmed at launch; it runs the application, while Supabase separately hosts the database, auth and realtime messaging.

2. Changes

If what we collect or how we use it changes, the privacy policy changes with it, and this page is updated to match.