Subprocessor List

This page lists the third parties VERA relies on to run the Service. It forms part of the Data Processing Addendum. It is deliberately short, because VERA's architecture keeps most data in one place: uploaded files and generated images are stored in the application database rather than in a separate object storage provider, so there is no additional file host in this list.

Version
1.0
Effective
July 28, 2026
Last updated
July 28, 2026
Revisions
1
On this page (6 sections)
  1. 1. Infrastructure subprocessors
  2. 2. Core service subprocessors
  3. 3. Conditional subprocessors
  4. 4. Platforms you connect
  5. 5. Changes and notification
  6. 6. A note on deployment configuration

1. Infrastructure subprocessors

These process data for every customer because they host or serve the Service.

SubprocessorPurposeData processedLocation
Railway and/or Vercel (hosting)Application hosting, edge delivery, and the managed PostgreSQL database that holds all account dataAll customer data, including uploaded files and generated images stored in the databaseUnited States
Vercel (Web Analytics and Speed Insights)Page view and performance measurement on public marketing pagesPage paths, performance timings, and a closed set of non-identifying custom event valuesUnited States

2. Core service subprocessors

These are engaged for functions every account uses or may use.

SubprocessorPurposeData processedLocation
StripeSubscription billing, hosted checkout, the billing portal, and payment processingName, email address, billing address, payment method, subscription and invoice history. Card details are collected by Stripe directly and never reach VERAUnited States
AnthropicAI text generation, analysis, classification, and the VERA agentThe prompt and the business context relevant to the task, which may include customer records the user asked VERA to work withUnited States
ResendTransactional email from VERA: email verification, password reset, sign-in links, welcome and trial reminder messages. Used when configured as the system mail transportRecipient email address and message contentUnited States
Google (sign-in)Google OAuth sign-in, where enabledEmail address, name, and profile image received from Google at sign-inUnited States

3. Conditional subprocessors

These process data only when the corresponding feature is configured for the deployment or connected by you. If you never use the feature, they never receive your data.

SubprocessorEngaged whenData processedLocation
OpenAIAI image generation is configured and usedThe image prompt and generation settings. VERA composes text and logo overlays itself, so brand copy is not required to leave our serversUnited States
Google (Gemini)AI image generation is configured with Gemini and usedThe image prompt and generation settingsUnited States
TwilioSMS sending is configured, either at the platform level or with your own Twilio credentialsRecipient phone number and message contentUnited States
An SMTP provider you or the operator configuresEmail is sent over SMTP rather than Resend, which also powers one-time sign-in linksRecipient email address and message contentDepends on the provider
GNewsIndustry Radar is usedSearch topics derived from your business profile. No customer records are sentEuropean Union

4. Platforms you connect

When you connect a third-party platform, data flows between VERA and that platform on your instruction. Those platforms are not VERA's subprocessors: you have your own relationship and your own agreement with each of them, and VERA acts on your authorization to reach them.

VERA's catalog covers roughly 150 providers across accounting, payments, CRM, scheduling, email, communication, marketing, social, ecommerce, shipping, analytics, field service, hospitality, real estate, HR, documents, and developer tools. Each provider's card in the Integrations area states what VERA reads and writes before you connect it. Notable ones include Stripe Connect, Shopify, Square, WooCommerce, QuickBooks Online, Jobber, HubSpot, Xero, Meta (Facebook and Instagram), X, TikTok, LinkedIn, Pinterest, YouTube, Google (Analytics, Ads, Calendar, Gmail, Business Profile), Mailchimp, Klaviyo, and Calendly.

You can review and disconnect any connection at any time in Integrations. Disconnecting removes VERA's stored credential and stops future access.

5. Changes and notification

VERA gives at least 30 days' notice before adding or replacing a subprocessor, by updating this page and notifying account holders. Business customers may object on reasonable data protection grounds under section 6 of the Data Processing Addendum.

To be notified of changes, or to raise an objection, write to support@myvera.io.

6. A note on deployment configuration

VERA is built so that most third-party services are optional and are enabled by configuration. A deployment with no AI key, no SMS credentials, and no email transport runs against local mocks and sends nothing to any of them.

This list therefore describes the maximum set of subprocessors that the production Service may engage. If you need a definitive statement of which are active for your account, ask us at support@myvera.io and we will confirm in writing.

Change history

Every revision of this document, newest first. Material changes are notified to account holders before they take effect where practicable.

  1. v1.0July 28, 2026

    Initial Subprocessor List published.

Questions about this document?

Legal and contracts: support@myvera.io. Privacy and data rights: support@myvera.io. Security reports: support@myvera.io.

Related

This document is a carefully drafted policy written against how VERA actually works. It is not legal advice, and it should be reviewed by a licensed attorney in your jurisdiction before you rely on it.