Sub-processors

Last updated September 2, 2026

Aidelly uses the third parties below to deliver the service. This page lists every one that can process customer data, what it does, and what data reaches it. If a vendor is not on this list, it does not process your data.

Where your data is stored

Aidelly's own infrastructure processes and stores customer data in the United States. The application runs on Vercel in AWS us-east-1 (Northern Virginia) and the database and file storage run on Supabase in AWS us-east-2 (Ohio). Compute and storage are in different regions, both within the United States.

Sub-processors operate under their own terms and may process data in their own regions. Rather than restate their locations here, where we could go out of date without noticing, we will confirm the current processing region for any vendor relevant to your assessment. Write to privacy@aidelly.com.

Core infrastructure

Everything runs through these. They are unavoidable for anyone using Aidelly.

Core infrastructure sub-processors
VendorWhat it doesData it can process
VercelApplication hosting, CDN, and edge networkAll application traffic and compute, including white-label custom domains
SupabaseDatabase, authentication, and file storageAll customer data, uploaded media, and authentication sessions
InngestBackground jobs, scheduling, and retriesPost content and media queued for publishing
RedisCaching and short-lived application stateSession and conversation state

Product services

Product service sub-processors
VendorWhat it doesData it can process
StripePayments, subscriptions, and invoicingBilling contact details and payment records. Card details go directly to Stripe and are never stored by Aidelly
ResendTransactional email deliveryRecipient email addresses and message contents
LoopsMarketing email and contact listsEmail address and marketing preferences
SentryError tracking and monitoringStack traces and the request context attached to an error
PostHogProduct analyticsProduct usage events and page views
CloudflareBot protection on sign-up and public forms (Turnstile)Challenge tokens, IP address, and browser characteristics
GitHubSupport ticket handlingSupport ticket contents, in a private repository
Browser push servicesWeb push notifications, via the browser vendorPush endpoint identifiers only, no message contents

AI providers

These receive prompts and the content you ask Aidelly to generate or analyse. Requests are routed through a gateway rather than sent to every provider, so which one handles a given request depends on the feature you use.

AI provider sub-processors
VendorWhat it doesData it can process
Vercel AI GatewayRoutes AI requests to the underlying model providersPrompts and generated content
OpenAIImage generation and editing, conversation titlesPrompts and images you supply or generate
OpenRouterModel access on the bring-your-own-key pathPrompts, using an API key you supply
GoogleVideo generation and YouTube dataPrompts and generated media
ReplicateImage and video generation, scene analysisMedia you supply and the output produced from it
SupadataVideo and content extraction for repurposingSource URLs and extracted transcripts
Google Custom Search and Bing SearchWeb search used by AI research toolsSearch queries

Services you connect

These receive data only when you connect the account or enable the integration. Disconnecting removes the stored credentials and stops the flow.

Customer-connected integrations
VendorWhat it doesData it can process
Instagram, Facebook, Threads, LinkedIn, X, TikTok, YouTube, Pinterest, Google Business Profile, Bluesky, MastodonPublishing, engagement, and analytics on accounts you connectPost content, media, access tokens, and the metrics we read back
Slack, Telegram, WhatsAppMessaging integrations and inbox deliveryMessages routed through the integration you enable
Google DriveImporting media from your DriveOnly the files you explicitly select
Shopify and EtsyProduct catalogue sync for commerce contentStore and product data from the store you connect

What we do not use

Assessments often ask about these, so the answers are here rather than by omission. Aidelly uses no SMS provider, no session replay or screen recording tool, no third-party feature-flag service, and no separate vector database. Feature flags are plain configuration in our own environment.

Notice of changes

We will update this page before a new sub-processor begins processing customer data. To be told when that happens, email privacy@aidelly.com and ask to be added to the sub-processor notice list.

Questions

Privacy and data processing: privacy@aidelly.com. Security: security@aidelly.com. If your assessment needs detail this page does not cover, ask and we will answer rather than point you back here.