Last updated: September 9, 2026. These are the service providers ("subprocessors") that process limited information on our behalf to operate Joura. Each acts under a written data-processing agreement and only processes information to provide its service to us. None of them receives the encrypted, on-device content described in our Privacy Policy (your moments, notes, or your child's information).
| Provider | What it does for us | Data it handles | Primary region | Transfer safeguard |
|---|---|---|---|---|
| PostHog | Product analytics (structural usage events) | Anonymous identifier + structural events; no content | United States | SCCs / UK IDTA via DPA |
| Supabase | Anonymous backend: analytics mirror, opt-in feedback, waitlist | Anonymous identifier; feedback text and optional email you choose to send; waitlist email | United States | SCCs / UK IDTA via DPA |
| Sentry | Crash and error diagnostics | Structural crash data; no content; configured with personal identifiers off, so it does not store your IP | United States | SCCs / UK IDTA via DPA |
| RevenueCat | Subscription management | Purchase and subscription status tied to an anonymous identifier | United States | SCCs / UK IDTA via DPA |
| Vercel | Website hosting and privacy-conscious site analytics | Standard web request data; aggregate analytics | United States / global edge | SCCs / UK IDTA via DPA |
| Apple | App distribution and in-app purchases (iOS) | Purchase records under Apple's own policy | United States / global | Apple terms; SCCs where applicable |
| App distribution and in-app purchases (Android) | Purchase records under Google's own policy | United States / global | Google terms; SCCs where applicable | |
| Transactional email provider | Sends waitlist and reply emails | The email address you submit | United States | SCCs / UK IDTA via DPA |
Our standard
We keep this list current and short. We choose providers that support strong data-protection commitments, we sign a data-processing agreement with each, and we do not use vendors from jurisdictions we have chosen to avoid on security grounds. For international transfers we rely on the European Commission's Standard Contractual Clauses (and the UK IDTA), and on the EU-U.S. Data Privacy Framework where a provider is certified. See the EU / UK Privacy Notice for detail.
Changes
If we add, remove, or change a provider, we will update this page and the date above. Questions: contact@wandering-castle.com.