CrateCore

LEGAL DOCUMENT

CrateCore — Processors & Third-Party Services (Subprocessors)

Version date: August 11, 2026 (previous versions: August 7 — revised the same evening, site web analytics; August 6, August 4, and July 17, 2026)

Operator: the individual developer of the CrateCore service

Contact: legal@cratecore.app

1. Purpose

This document lists the third-party services that help CrateCore run and may process data. For each service it states what data it sees and where it is processed.

2. Services that process user data

Service: Supabase
Role: database, authentication, file storage, server functions.
Data: account identifier, e-mail (on registration), profile name, settings, collection, wishlist, notes, article states, audio chain profile, import CSV (up to 24 hours), push tokens, technical logs (including service records of sign-ins and the technical data of the connection — IP address, request headers).
Who: all of the above exists only for a registered account. As of August 6, 2026 the user data of an unregistered (anonymous) session is not sent here at all — it stays on the device. If the app opens a technical anonymous session, the service holds only the session's own identifier (a random number) and a service record that it was opened.
Region: EU — Frankfurt (eu-central-1).
Status: active.

Service: Google Firebase (Google LLC)
Role: push delivery (FCM), analytics (Firebase Analytics), crash reports (Crashlytics), app attestation (App Check).
Data: push tokens, pseudonymous technical identifiers, usage events without personal content, crash reports (device model, OS/app version, stack trace). Advertising identifiers are not collected; the user identifier is not sent to analytics.
Region: Google's global infrastructure (including the US).
Retention: Analytics — up to 2 months (user/event-level data, default setting); Crashlytics — 90 days.
Status: active.

Service: Resend
Role: delivery of service e-mails — sign-in codes.
Data: recipient e-mail, service e-mail content, delivery logs.
Region: US / global.
Status: active.

Service: Telegram (Telegram FZ-LLC)
Role: notifying the editorial team about new messages sent through the site's contact form.
Data: the text of the message (its beginning, if the message is long), the topic, the language, and the sender's e-mail address, if given. The pseudonymized IP fingerprint is not sent to Telegram.
Region: Telegram's global infrastructure; the company is registered in the UAE (outside the EEA).
Status: active.

Service: Cloudflare
Role: hosting and CDN for cratecore.app; cookieless web analytics for the site (Cloudflare Web Analytics); bot protection for the site's forms (Turnstile) — the script loads only on the sign-in page; inbound e-mail routing for legal@cratecore.app; AI illustration generation for stories (Workers AI) — no personal data involved.
Data: technical data of site visitors (IP address, request headers) to the extent needed to serve pages and protect against attacks; transit of e-mails to legal@. Web analytics: the address of the page viewed, the referring address, browser/device information, the response status code, and page-load performance metrics; the country is derived from the IP address, and the IP address itself is not stored. The counter sets no cookies, uses no localStorage, and does no "fingerprinting": no individual visitor is singled out and no profile is built. The Turnstile check on the sign-in page: the IP address and technical signals of the browser environment that tell a person from a bot; no advertising cookies are set.
Basis: performance of the contract and legitimate interest (delivering pages, preventing abuse and bots, knowing how much our own site is read). The cookieless counter needs no consent — it writes nothing to the visitor's device and reads no identifiers from it.
Region: global network.
Status: active.

Service: Google Analytics 4 (Google Ireland Limited; transfers — Google LLC)
Role: traffic statistics for the cratecore.app website. Not used in the mobile app — that uses Firebase Analytics (entry above).
Data: the address of the page viewed and the referring address, browser, device, and language information, an approximate location (country/city) derived from the IP address, the random identifier from the _ga cookie, and page-view events. Google Analytics 4 does not log or store the IP address itself. E-mail, the CrateCore account identifier, and the contents of notes and collections are never sent. Advertising features (Google Signals, a Google Ads link, remarketing) are not enabled.
Basis: the visitor's consent. Google's script loads only after "Accept" is pressed in the banner; before that, and after "Decline", not a single request goes from the page to Google and no Google cookies appear. Withdrawal of consent — see the Cookie Policy (https://cratecore.app/cookies/en/).
Region: Google's global infrastructure (including the US). Google bases transfers outside the EEA on the EU-U.S. Data Privacy Framework (Google LLC is certified under it) and on the Standard Contractual Clauses included in Google's data processing terms, which form part of the Google Analytics agreement.
Retention: user- and event-level data — per our property's setting, no longer than 14 months (the GA4 limit); aggregated reports — longer; the _ga and _ga_… cookies — up to 2 years in the visitor's browser.
Status: switched on together with the consent banner. While the property identifier is not present in the site's code, the pages carry neither Google's script nor the banner, and no analytics cookies exist.

Service: Google (sign-in and store)
Role: Google Sign-In, distribution via Google Play.
Data: Google identity token and e-mail on Google sign-in; install/update data under Google Play rules.
Region: per Google's terms.
Status: active for Android.

Service: Google Publisher Center / Reader Revenue Manager (Subscribe with Google)
Role: publisher console for Google News; in addition, Google offers a script for subscription and promo prompts on article pages (swg-basic.js from the news.google.com domain).
Data: registering the publication in the console involves no user data. If the script were installed, then on each article page view Google would receive the page address, our publication identifier, the IP address, and whatever Google cookies the reader already holds — that is, it could tie the article view to a Google account; the script also writes service records into the browser's local storage.
Region: Google's global infrastructure (including the US).
Status: the publication is registered; the script is NOT installed on the site. We have no paid features, so there is no need for it. It can only be switched on together with a consent banner for readers in the EEA, the UK, and Switzerland and an updated Cookie Policy — before it is enabled, not after.

Service: Apple
Role: Sign in with Apple and App Store distribution — once the iOS version ships.
Data: Apple identity tokens / relay e-mail (when the iOS version exists).
Region: per Apple's terms.
Status: not active (until the iOS release).

Service: payment provider (e.g. RevenueCat)
Role: subscription management, if paid features are enabled.
Data: none processed at the moment.
Status: not active; will be added to this list and to the Privacy Policy before paid features are enabled.

Service: backup storage
Role: encrypted database backups.
Data: a copy of user and content tables.
Retention: up to 30 days.
Status: to be enabled before the production launch; the specific provider and region will appear here when enabled.

3. Content pipeline services (no user data is sent)

Service: OpenRouter + DeepSeek
Role: language model for rewriting editorial stories from verifiable public facts.
Data: public facts, sources, and story drafts only. User notes, collections, CSV, e-mails, and identifiers are never sent.
Status: active.

Service: Contabo
Role: VPS hosting for the content pipeline (n8n).
Data: public facts and pipeline operational metadata; no user data.
Status: active.

4. External data and image sources

These services are content sources, not processors of user data. Exception: when the user's device loads an image directly, the source sees the device's IP address (as with any image on the internet).

5. Change notice

We update this list when services are added, removed, or materially changed.

6. Contact

Questions about this list: legal@cratecore.app.