Core product providers
These services may receive account, customer, participant, support, or billing information when their function is used.
| Provider | Purpose | Broad data category | Customer content? |
|---|---|---|---|
| Supabase | Authentication, Postgres database, and temporary durable run recovery | Account identifiers, Workspace records, Diagnostic and campaign records, acceptance records | Yes |
| Render | Hosts the Monderman production API | API requests, application processing, technical logs | Yes |
| Anthropic | Specified written interpretation, interview coding, optional text refinement, and assistant functions | Relevant Diagnostic context, written observations, interview or assistant messages | Yes, when an AI-assisted function is used |
| Resend | Authentication, invitation, notification, and inquiry email delivery | Email addresses, names where supplied, delivery content and events | Limited communication content |
| Stripe | Hosted checkout, subscriptions, billing portal, and billing events | Billing identity, subscription and payment information | Billing data; Diagnostic content is not ordinarily sent |
| Optional Google account sign-in | OAuth identity, email, and authentication metadata | No Diagnostic content through sign-in | |
| Cloudflare | Bot verification and security-related request handling | IP/browser signals, verification tokens, request/security metadata | Request content may traverse relevant infrastructure |
Public-site and browser infrastructure
GitHub Pages/Fastly serves the public site. jsDelivr, cdnjs and esm.sh deliver versioned browser libraries; Google Fonts delivers a workspace font. These services ordinarily receive browser and request metadata such as IP address and user agent. Monderman does not intentionally send Diagnostic answers to them as content-processing providers.
Questions and future changes
Questions can be sent to connect@monderman.com. Monderman will update this page when the implemented provider set materially changes. Any engagement-specific notice or objection procedure will be stated in the applicable signed organizational data-processing terms.