About this list
To run our services we use a small set of trusted providers (“subprocessors”). Each processes only the data it needs, on our instructions, under contractual data-protection terms. This list reflects what is actually wired into our products and websites today.
Current subprocessors
| Provider | Role | Data involved | Region |
|---|---|---|---|
| Supabase | Authentication and database for Vault One | Account identifiers, session metadata, app records | EU hosting where configured |
| Stripe | Subscription billing and invoicing | Email, billing metadata, subscription status | EU / global |
| Resend | Transactional email (security, account, billing) | Recipient address and message content | EU / global |
| Vercel | Static hosting for websites | Request logs, IP addresses, user-agent | Global edge |
| Railway | Application/API hosting | Request logs, IP addresses | Global |
| Sentry | Error and performance monitoring (when enabled) | Error events and diagnostic context | EU / global |
| mijn.host | Domain and email mailbox provider | Email routing and DNS for our domains | Netherlands / EU |
Not our subprocessors
When you connect a financial account in Vault One (for example via bunq or Kraken), or use sign-in providers such as Google or Apple, those services act under their own terms and are not IK Studios subprocessors for your connected financial data — that data is read on your device. Product-level detail is in the Vault One Subprocessor Register.
Changes
We update this list when our providers change. For significant changes affecting business customers under a signed Data Processing Agreement, we provide notice as that agreement requires so you can object where applicable.