Subprocessors and infrastructure.

This page identifies providers currently used to operate the Monderman public beta and separates providers that may process customer content from ordinary public-site and browser infrastructure.

Last reviewed: August 20, 2026

Factual inventory, not a contract. This page identifies current providers and does not represent that a particular DPA, certification, transfer mechanism, retention period or data-residency commitment applies. Organizational data-processing terms may be made available where required for an engagement.

Core product providers

These services may receive account, customer, participant, support, or billing information when their function is used.

ProviderPurposeBroad data categoryCustomer content?
SupabaseAuthentication, Postgres database, and temporary durable run recoveryAccount identifiers, Workspace records, Diagnostic and campaign records, acceptance recordsYes
RenderHosts the Monderman production APIAPI requests, application processing, technical logsYes
AnthropicSpecified written interpretation, interview coding, optional text refinement, and assistant functionsRelevant Diagnostic context, written observations, interview or assistant messagesYes, when an AI-assisted function is used
ResendAuthentication, invitation, notification, and inquiry email deliveryEmail addresses, names where supplied, delivery content and eventsLimited communication content
StripeHosted checkout, subscriptions, billing portal, and billing eventsBilling identity, subscription and payment informationBilling data; Diagnostic content is not ordinarily sent
GoogleOptional Google account sign-inOAuth identity, email, and authentication metadataNo Diagnostic content through sign-in
CloudflareBot verification and security-related request handlingIP/browser signals, verification tokens, request/security metadataRequest content may traverse relevant infrastructure

Public-site and browser infrastructure

GitHub Pages/Fastly serves the public site. jsDelivr, cdnjs and esm.sh deliver versioned browser libraries; Google Fonts delivers a workspace font. These services ordinarily receive browser and request metadata such as IP address and user agent. Monderman does not intentionally send Diagnostic answers to them as content-processing providers.

Questions and future changes

Questions can be sent to connect@monderman.com. Monderman will update this page when the implemented provider set materially changes. Any engagement-specific notice or objection procedure will be stated in the applicable signed organizational data-processing terms.