F
Forkin

Sub-processors

We use the service providers (“processors”) below to operate Forkin. All are bound by Data Processing Agreements under Article 28 GDPR. International transfers outside the European Economic Area, United Kingdom, Switzerland, Quebec, Australia, New Zealand, Brazil, Mexico, Japan, South Korea, Singapore, Hong Kong, Taiwan, Israel, Chile, Colombia, Argentina, Peru, or South Africa rely on the safeguards listed, together with the transfer and privacy-impact assessments we keep internally where required. This page is the canonical, up-to-date list referenced by our Privacy Policy. Material changes are announced in-app at least 14 days before they take effect.

ProcessorLocationRoleCategories of dataSafeguard
Hetzner Online GmbHGermany / Finland (EEA)Application hosting, PostgreSQL database, and S3-compatible object storage (Nuremberg) for uploaded photos (product, meal, price tags, receipts, body-progress)All collected, including photosEEA
Bunny.net (BunnyWay d.o.o.)Slovenia (EEA), EU-only routingCDN / edge / WAFRequest metadata, asset deliveryEEA
Scaleway SASFrance (Paris) + Poland (Warsaw)Generative AI (vision/text models) for photo & text analysis and content moderation; transactional email; Key Manager (KMS) for body-photo encryptionPhotos, text content, email address, encryption keysEEA
NexGen Cloud Ltd (Hyperstack)Iceland (EEA)GPU inference (image embeddings, voice transcription, text-to-speech)Photos, audioEEA
DataCrunch Oy (Verda)Finland (EEA)On-demand GPU for nightly product-catalogue AI batchProduct-catalogue photos (not account data)EEA
Brevo (Sendinblue SAS)France (EEA)Marketing email (newsletter, impact digest)Email addressEEA
Soverin B.V.Netherlands (EEA)Inbound email hostingEmail content you send usEEA
Stripe Payments Europe Ltd.Ireland (EEA), with US group transfersWeb subscription payments (Merchant of Record, via RevenueCat Billing)Billing dataEEA + EU–US DPF / SCCs for any US transfer
RevenueCat, Inc.USASubscription state & entitlements (web + mobile)Subscription metadata, pseudonymous user IDEU–US DPF + SCCs
Apple Inc.USAiOS distribution, in-app purchases, Sign in with Apple, push (APNs)Identifiers, transaction dataEU–US DPF + Apple DPA
Google LLCUSAAndroid distribution, in-app purchases, OAuth, push (FCM)Identifiers, transaction dataEU–US DPF + Google DPA
Functional Software, Inc. (Sentry)EU ingest (Germany) / US supportCrash reportsStack traces, device modelEU–US DPF + SCCs
PostHog, Inc.EU (eu.i.posthog.com)Product analytics (consent-gated)Event metadata onlyEEA
Termly, Inc.USACookie consent banner + policy hostingIP, consent stateEU–US DPF
Expo (650 Industries, Inc.)USAPush token relay (APNs/FCM bridge)Device push tokenEU–US DPF

Apple HealthKit and Google Health Connect are not sub-processors: when you enable health sync, nutrition and body-weight data is exchanged on your device with the platform’s health store under Apple’s or Google’s own terms; we do not receive a copy through them.