Subprocessors
These are the vendors LegalKit may use to deliver core product functionality or optional features.
Last updated: March 9, 2026
Supabase
Core
Region depends on project configuration.
Purpose
Authentication, hosted database storage, policy records, consent logs, and account data.
Data in scope
Account data, hosted policy data, monitoring state, consent receipts.
Vercel
Core
Global edge delivery; primary deployment region is environment-dependent.
Purpose
Application hosting, edge delivery, hosted policy pages, and request/runtime logs.
Data in scope
Application traffic metadata and hosted content delivery.
Stripe
Optional
Processed via Stripe infrastructure.
Purpose
Subscription checkout, billing, invoicing, and customer portal.
Data in scope
Billing identifiers, plan metadata, payment status.
Resend
Optional
Processed via Resend infrastructure.
Purpose
Transactional email delivery for invites, alerts, and account workflows when configured.
Data in scope
Recipient email address and email content.
SendGrid
Optional fallback
Processed via SendGrid infrastructure.
Purpose
Fallback transactional email delivery when configured instead of or alongside Resend.
Data in scope
Recipient email address and email content.
Sentry
Optional
Processed via Sentry infrastructure.
Purpose
Application error monitoring and debugging when configured.
Data in scope
Operational telemetry and limited error context.
OpenAI
Optional
Processed via the configured AI provider infrastructure.
Purpose
AI-assisted law-monitoring/admin workflows and AI section drafting when those features are enabled.
Data in scope
Feature-specific prompts and draft content sent to the enabled AI workflow.