Who helps run Joura

Subprocessors & Service Providers

The short list of trusted providers we use to run the app and website. None of them ever receive your family's on-device content. This page is part of our Privacy Policy.

Last updated: September 9, 2026. These are the service providers ("subprocessors") that process limited information on our behalf to operate Joura. Each acts under a written data-processing agreement and only processes information to provide its service to us. None of them receives the encrypted, on-device content described in our Privacy Policy (your moments, notes, or your child's information).

ProviderWhat it does for usData it handlesPrimary regionTransfer safeguard
PostHogProduct analytics (structural usage events)Anonymous identifier + structural events; no contentUnited StatesSCCs / UK IDTA via DPA
SupabaseAnonymous backend: analytics mirror, opt-in feedback, waitlistAnonymous identifier; feedback text and optional email you choose to send; waitlist emailUnited StatesSCCs / UK IDTA via DPA
SentryCrash and error diagnosticsStructural crash data; no content; configured with personal identifiers off, so it does not store your IPUnited StatesSCCs / UK IDTA via DPA
RevenueCatSubscription managementPurchase and subscription status tied to an anonymous identifierUnited StatesSCCs / UK IDTA via DPA
VercelWebsite hosting and privacy-conscious site analyticsStandard web request data; aggregate analyticsUnited States / global edgeSCCs / UK IDTA via DPA
AppleApp distribution and in-app purchases (iOS)Purchase records under Apple's own policyUnited States / globalApple terms; SCCs where applicable
GoogleApp distribution and in-app purchases (Android)Purchase records under Google's own policyUnited States / globalGoogle terms; SCCs where applicable
Transactional email providerSends waitlist and reply emailsThe email address you submitUnited StatesSCCs / UK IDTA via DPA

Our standard

We keep this list current and short. We choose providers that support strong data-protection commitments, we sign a data-processing agreement with each, and we do not use vendors from jurisdictions we have chosen to avoid on security grounds. For international transfers we rely on the European Commission's Standard Contractual Clauses (and the UK IDTA), and on the EU-U.S. Data Privacy Framework where a provider is certified. See the EU / UK Privacy Notice for detail.

Changes

If we add, remove, or change a provider, we will update this page and the date above. Questions: contact@wandering-castle.com.

Back to Joura   Read the Privacy Policy →