ConKarma — Sub-processors
Last Updated: September 25, 2026
This page lists the third-party service providers ("sub-processors") that
process personal information on behalf of XTZ Group, Inc. ("ConKarma") in
connection with the Service. It supplements the categories disclosed in
our Privacy Policy §6 and is updated whenever the list
changes. This document is the canonical sub-processor list; the public
/legal/subprocessors page and the Confluence copy mirror it.
Current sub-processors
| Sub-processor | Role | Region | Transfer mechanism |
|---|---|---|---|
| IONOS SE (privacy policy) | Application hosting: the virtual server that runs the ConKarma backend API (goia_api) and ConKarma's web front-ends. | EU/EEA (Germany, Berlin) | Provider processes within the EU/EEA (Germany), so no restricted transfer of EEA / UK / Swiss personal data outside the EEA arises for this processing. |
| DigitalOcean, LLC (privacy policy) | Application hosting (managed Kubernetes) and container registry for the ConKarma backend API (goia_api) and web front-ends. | USA | DigitalOcean's Data Processing Agreement incorporating the EU Standard Contractual Clauses (2021 set); DigitalOcean, LLC is certified under the EU-US Data Privacy Framework. |
| Google LLC / Google Ireland Ltd. | Authentication: Sign in with Google via direct OpenID Connect — goia_api is the OAuth client and connects to Google directly (no Firebase Auth, no intermediary); this social sign-in may alternatively be brokered through Supabase Auth (see the Supabase row) — either path, no Firebase Auth is involved; on sign-in we receive only the Google sub, email address, and email-verified flag, persisted to auth_identities; push delivery (Firebase Cloud Messaging); installations identifier (Firebase Installations); abuse / integrity signals (Firebase App Check); crash reporting (Firebase Crashlytics); aggregate product analytics (Google Analytics for Firebase / Google Analytics 4) — and, only under the separate explicit adult-analytics consent you give (GDPR Art. 9(2)(a)), GA4 additionally processes anonymised, surface-level adult-zone (Ember) feature-usage metadata (which feature/pillar was used and a coarse action verb — pseudonymous GA4 client identifier only, no PII and no user content, never content/act-level detail; Google Signals, ads-personalisation, and Google data-sharing are OFF for that stream, which is never used for advertising); advertising on free accounts only (Google AdMob — free adult accounts may receive personalised ads unless they exercise Do-Not-Sell / Do-Not-Share, including Global Privacy Control; free teen (13–17) accounts receive only non-personalised ads; never on child accounts; never on subscribed accounts — see /legal/do-not-sell-or-share); Google Calendar API for opt-in two-way calendar sync (per-cell-member adult consent only — gated by COPPA verification for cells with under-13 members; narrowest scopes only — calendar.calendarlist.readonly to enumerate the user's calendars and calendar.events to read / write events on the one calendar they pick; one-tap revocation from ConKarma Settings or from myaccount.google.com; details at /help/google-calendar-sync); AI Gateway generation/moderation (one of the AI providers behind our vendor-neutral AI Gateway, alongside Anthropic and OpenAI — see their rows below); Google Cloud Vision SafeSearch (via the AI Gateway) performs image child-safety classification of uploaded images before they are shown to others (with OpenAI moderation as a fallback), processing only the image being checked and returning only a safety verdict — the image is not retained for moderation and is not used to train models; where an image-generation feature is offered, Google ('NanoBanana') via the AI Gateway generates an image from a PHOTOGRAPH YOU UPLOAD (data category: user-uploaded photograph), processed solely to return the generated image, not used to train models, and not retained by the provider beyond the request — ConKarma discards the source photograph within 24 hours and derives no biometric template, faceprint, or voiceprint from it; and, where you enable voice-note transcription, Google Cloud Speech-to-Text (via the AI Gateway) performs speech-to-text conversion of the RAW AUDIO of a voice note into a text transcript, processed solely to return the transcript and not used to train models. | USA; EU/EEA | EU Standard Contractual Clauses (2021 set) with supplementary measures; UK International Data Transfer Addendum; Swiss FDPIC addendum. Google LLC is certified under the EU-US Data Privacy Framework, the UK Extension to the DPF, and the Swiss-US DPF for relevant transfers. |
| Transactional email (SMTP relay) | Delivery of account, consent, and security emails only — activation codes, password-reset codes, magic links, and parental-consent messages — through a standard SMTP relay service configured for ConKarma. The relay receives only the recipient email address and the message body for the transactional email being sent; no habit, content, relationship, or child-account data. ConKarma does not use Postmark. | USA; EU/EEA | EU Standard Contractual Clauses (2021 set) with supplementary measures; UK International Data Transfer Addendum; Swiss FDPIC addendum. |
| Supabase, Inc. (privacy policy) | Backend platform on behalf of the goia_api service and — following the 2026 re-adoption of Supabase Auth — an authentication and session processor. Roles: (a) Authentication & session — Supabase Auth is the social-login broker (ADR-147): when you sign in with a social provider (Google / Apple), that provider's token is exchanged through Supabase Auth for a ConKarma app session, and in that exchange Supabase processes your email address, the provider authentication identifier, and the short-lived Supabase access token / session. Supabase Auth also delivers SMS one-time codes — to a phone number in E.164 format — for two-factor authentication (adults only). ConKarma's own self-hosted email / password sign-in and direct OpenID Connect ("Sign in with Google / Apple") remain available in parallel; Firebase Authentication is not used and stays retired. (b) Database — managed PostgreSQL (with the Supavisor connection pooler). (c) Object storage — object storage for user-uploaded media (Supabase is ConKarma's only user-media object store). Children under 13 are routed to the COPPA parental-consent flow before any account is created, and phone numbers are never collected for under-13 accounts. The application database, object storage and Supabase Auth are provisioned in AWS London (United Kingdom); the separate administrative database is provisioned in AWS Ireland (EU); data at rest is encrypted on Supabase's managed infrastructure. Supabase runs the underlying compute, database, and storage on Amazon Web Services (AWS) as its own infrastructure sub-processor; AWS is not a direct ConKarma sub-processor and is governed by Supabase's DPA flow-down obligations. SMS one-time codes are delivered through the SMS gateway configured in Supabase Auth, which Supabase engages under the same DPA flow-down; that gateway is not a direct ConKarma sub-processor. Personal data processed by Supabase Auth: email address; phone number (E.164) for OTP; authentication identifiers (provider sub / Supabase user id); and session / token data. | United Kingdom (London) — application database, object storage and Auth; EU/EEA (Ireland) — administrative database | EU Standard Contractual Clauses (2021 set) with supplementary measures; UK International Data Transfer Addendum; Swiss FDPIC addendum. |
| Upstash, Inc. (privacy policy) | Managed Redis for the goia_api backend. Used as an ephemeral key-value cache for abuse-prevention rate-limit counters (keyed by email address or IP address), short-lived single-use codes (activation codes, password-reset codes, magic-link codes), and a JWT refresh-token denylist (revoked-token hashes). Retention: rate-limit and code entries expire on a short TTL (seconds to minutes); denylist entries persist until the token's natural expiry. No habit, content, relationship, or child-account data is written to Redis. Upstash operates the underlying compute on hyperscale cloud infrastructure (AWS / Google Cloud) as its own infrastructure sub-processor; that infrastructure is not a direct ConKarma sub-processor and is governed by Upstash's DPA flow-down obligations. | EU/EEA (Ireland) | EU Standard Contractual Clauses (2021 set) with supplementary measures; UK International Data Transfer Addendum; Swiss FDPIC addendum. |
| freeipapi.com (operated from Düsseldorf, Germany — privacy policy) | GeoIP resolution. On each backend request that needs approximate location, goia_api sends the caller's IP address to freeipapi.com, which returns coarse geolocation (country, region / US-state, city, and approximate latitude/longitude). Used only for: account security (new-device / unknown-location login alerts and the Active Sessions display), sign-in risk checks on two-factor / OAuth login, US-state child-safety gating (Family Shield and state-specific rule controls — a legal-compliance purpose), and feature-flag geo-targeting. Only the IP address is sent — no name, account id, email, habit, content, relationship, or child-account data. Results are cached briefly on our side (Redis, ~24 h TTL) to minimise calls; on any lookup failure the location is treated as unknown and child-safety gates resolve to their most-restrictive setting. freeipapi logs API requests for monitoring and does not publish a fixed retention window. This supersedes the former self-hosted MaxMind GeoLite2 database lookup, which was an in-process file read and involved no data flow to a third party (GOIA-1378). | EU/EEA (Germany) | Provider processes within the EU/EEA (Germany), so no restricted transfer of EEA / UK / Swiss personal data outside the EEA arises for this processing; a written processor agreement is being put in place (CK-678) and data is minimised to the IP address in the interim. |
| Anthropic, PBC (privacy policy) | AI text generation + UGC text safety-moderation via the vendor-neutral AI Gateway: generates content you request (weekly recaps, family/relationship coaching prompts, voice-memo summaries) and automatically screens user-submitted free text for child-safety before it is shown (e.g. custom sitter activities). For moderation we send ONLY the text being checked + a fixed safety instruction — no account id, profile, age, or relationship data — and retain only a SHA-256 hash of the text plus the safe/unsafe verdict, never the raw text. This moderation ledger (hashes plus verdicts) is retained for at most 90 days and is purged when you delete your account. Where an AI-powered adult (Ember) feature is used — or where child-safety moderation applies to Ember content you submit — that processing occurs only under the explicit adult-feature consent you give (GDPR Art. 9(2)(a)); we do not otherwise process Ember content with AI. Conflict-resolution features are never AI-mediated. | USA | EU Standard Contractual Clauses (2021 set) + UK IDTA + Swiss FDPIC addendum. |
| OpenAI, L.L.C. (privacy policy) | Fallback AI provider for the same generation + UGC text safety-moderation features via the AI Gateway, and the fallback image child-safety classifier when Google Cloud Vision SafeSearch is unavailable, used for resilience when the primary provider is unavailable; same data-minimisation as above. Additionally, where an image-generation feature is offered, OpenAI ('DALL·E 3') via the AI Gateway generates an image from a PHOTOGRAPH YOU UPLOAD (data category: user-uploaded photograph — an image of a person where you choose a photograph of yourself); the photograph is processed solely to return the generated image, is not used to train the provider's models, and is not retained by the provider beyond the request. ConKarma discards the source photograph within 24 hours of the request and derives no biometric template, faceprint, or voiceprint from it. Additionally, where you enable voice-note transcription, OpenAI ('Whisper') via the AI Gateway performs speech-to-text conversion of the RAW AUDIO of a voice note you record into a text transcript; the audio is processed solely to return the transcript, is not used to train the provider's models, and is not retained by the provider beyond the transcription request. | USA | EU Standard Contractual Clauses (2021 set) + UK IDTA + Swiss FDPIC addendum. |
Independent controllers (not sub-processors)
The following parties also receive personal information in connection with the Service but act as independent controllers for the purposes they describe in their own terms — not as our sub-processors:
- Apple Inc. — App Store billing, Sign in with Apple (direct OpenID Connect; goia_api is the OAuth client — we receive the Apple
sub, the email or Apple private-relay address, and the email-verified flag), APNs push delivery. Governed by Apple's Privacy Policy. - Google LLC (Play billing only) — Google Play subscription and one-time purchase processing. Governed by Google's Privacy Policy.
- Microsoft Corporation — Microsoft Store app distribution (both the main ConKarma listing — family-first; Apple 9+ confirmed, its Microsoft Store IARC age tier pending submission (CK-266) — and the separate ConKarma After Dark companion-app listing — Adults Only / 18+ IARC rating; distinct MSIX packages and bundle ids per Microsoft Store policy), Store billing for both listings, and any Microsoft Account sign-in associated with a purchase on Windows. Governed by the Microsoft Privacy Statement.
How we vet sub-processors
Before engaging a sub-processor we:
- Sign a written processor agreement that mirrors GDPR Art. 28 obligations — including confidentiality, sub-processing controls, security measures, audit rights, and assistance with data-subject requests.
- Confirm they support a recognised cross-border transfer mechanism for any data leaving the EEA, UK, or Switzerland.
- Document the scope of personal information they receive and constrain it to what is necessary for the contracted role.
- Review their public security posture (SOC 2, ISO 27001, or equivalent) and breach-notification commitments.
Notification of changes
We will publish updates to this list before adding a new sub-processor, or within a reasonable period after replacing one, so EEA / UK controllers and contracting customers can object as required by Art. 28(2) GDPR. To receive notice by email, write to legal@conkarma.app.
Contact
XTZ Group, Inc. 2261 Market Street #4524, San Francisco, CA 94114, USA legal@conkarma.app