Legal & Trust
Subprocessors
Operational subprocessors used by our service providers.
⚠️ Requires legal review before production release.
This page lists operational subprocessors used in running the service. It is for transparency and may be updated.
Subprocessors
Last updated: 2026-07-20
This page lists operational subprocessors (service components provided by third parties) that can process personal data while delivering Klugliv’s services.
Current subprocessors (high-level)
| Subprocessor / service provider | Why it’s used | Personal data processed (examples) | Location (best-effort) |
|---|---|---|---|
| AWS (eu-central-1 configured) | Hosting and OCR-related infrastructure (API Gateway, Lambda, S3, CloudWatch, KMS, IAM, budgets). | Receipt images/inputs, OCR results that are returned to the app, operational logs. | Configured region in this repository: eu-central-1. |
| Supabase | Auth and data storage (Postgres + object storage) for the current system slice. | Account identifiers, receipt records, derived shopping history, and related objects. | Depends on Supabase project configuration. |
| Google Cloud Vision | OCR processing for receipts. | Receipt images submitted for OCR; OCR outputs. | OCR processing can involve cross-border transfers depending on routing/configuration. |
| PostHog (when configured) | Mobile analytics events. | Event names/properties describing usage patterns. | Depends on PostHog host configured in the app build. |
Updates
We update this page when:
- we introduce a new subprocessors
- we change how existing subprocessors are used in a way that materially affects personal data processing