Sub-processors
Last updated September 2, 2026
Aidelly uses the third parties below to deliver the service. This page lists every one that can process customer data, what it does, and what data reaches it. If a vendor is not on this list, it does not process your data.
Where your data is stored
Aidelly's own infrastructure processes and stores customer data in the United States. The application runs on Vercel in AWS us-east-1 (Northern Virginia) and the database and file storage run on Supabase in AWS us-east-2 (Ohio). Compute and storage are in different regions, both within the United States.
Sub-processors operate under their own terms and may process data in their own regions. Rather than restate their locations here, where we could go out of date without noticing, we will confirm the current processing region for any vendor relevant to your assessment. Write to privacy@aidelly.com.
Core infrastructure
Everything runs through these. They are unavoidable for anyone using Aidelly.
| Vendor | What it does | Data it can process |
|---|---|---|
| Vercel | Application hosting, CDN, and edge network | All application traffic and compute, including white-label custom domains |
| Supabase | Database, authentication, and file storage | All customer data, uploaded media, and authentication sessions |
| Inngest | Background jobs, scheduling, and retries | Post content and media queued for publishing |
| Redis | Caching and short-lived application state | Session and conversation state |
Product services
| Vendor | What it does | Data it can process |
|---|---|---|
| Stripe | Payments, subscriptions, and invoicing | Billing contact details and payment records. Card details go directly to Stripe and are never stored by Aidelly |
| Resend | Transactional email delivery | Recipient email addresses and message contents |
| Loops | Marketing email and contact lists | Email address and marketing preferences |
| Sentry | Error tracking and monitoring | Stack traces and the request context attached to an error |
| PostHog | Product analytics | Product usage events and page views |
| Cloudflare | Bot protection on sign-up and public forms (Turnstile) | Challenge tokens, IP address, and browser characteristics |
| GitHub | Support ticket handling | Support ticket contents, in a private repository |
| Browser push services | Web push notifications, via the browser vendor | Push endpoint identifiers only, no message contents |
AI providers
These receive prompts and the content you ask Aidelly to generate or analyse. Requests are routed through a gateway rather than sent to every provider, so which one handles a given request depends on the feature you use.
| Vendor | What it does | Data it can process |
|---|---|---|
| Vercel AI Gateway | Routes AI requests to the underlying model providers | Prompts and generated content |
| OpenAI | Image generation and editing, conversation titles | Prompts and images you supply or generate |
| OpenRouter | Model access on the bring-your-own-key path | Prompts, using an API key you supply |
| Video generation and YouTube data | Prompts and generated media | |
| Replicate | Image and video generation, scene analysis | Media you supply and the output produced from it |
| Supadata | Video and content extraction for repurposing | Source URLs and extracted transcripts |
| Google Custom Search and Bing Search | Web search used by AI research tools | Search queries |
Services you connect
These receive data only when you connect the account or enable the integration. Disconnecting removes the stored credentials and stops the flow.
| Vendor | What it does | Data it can process |
|---|---|---|
| Instagram, Facebook, Threads, LinkedIn, X, TikTok, YouTube, Pinterest, Google Business Profile, Bluesky, Mastodon | Publishing, engagement, and analytics on accounts you connect | Post content, media, access tokens, and the metrics we read back |
| Slack, Telegram, WhatsApp | Messaging integrations and inbox delivery | Messages routed through the integration you enable |
| Google Drive | Importing media from your Drive | Only the files you explicitly select |
| Shopify and Etsy | Product catalogue sync for commerce content | Store and product data from the store you connect |
What we do not use
Assessments often ask about these, so the answers are here rather than by omission. Aidelly uses no SMS provider, no session replay or screen recording tool, no third-party feature-flag service, and no separate vector database. Feature flags are plain configuration in our own environment.
Notice of changes
We will update this page before a new sub-processor begins processing customer data. To be told when that happens, email privacy@aidelly.com and ask to be added to the sub-processor notice list.
Questions
Privacy and data processing: privacy@aidelly.com. Security: security@aidelly.com. If your assessment needs detail this page does not cover, ask and we will answer rather than point you back here.