Nibbin, Inc.

Subprocessors

The named list, kept current · effective June 10, 2026 · referenced from the Privacy Policy

These are the third parties that process data to run Nibbin. We publish the named list here and update it before anyone new begins processing your data. Your Field Study screen captures never reach any of them — they stay on your device by architecture (see the Data & AI page).

SubprocessorWhat they doData they processRegion
VercelWeb application hosting & deliveryApp traffic; aggregate usage analyticsUnited States / global edge
SupabasePostgres database & the encrypted token vaultAccount data; connection tokens (KMS-encrypted in the vault — we never store them in plaintext)United States
AnthropicLarge language model inference (the Grovekeeper, scan summaries, the work you delegate)Only the content a given task needs; contractually barred from retaining or training on it; never your raw study dataUnited States
Voyage AIText embeddings for agent-memory semantic retrievalAlready-redacted derived memory text (facts, preferences, entities) — never raw email or study contentUnited States
ResendTransactional email (Field Notes, account mail)Your email address and the message content we send youUnited States
StripePayments & billingBilling details — Stripe handles card data directly; we never see full card numbersUnited States
Google / Gmail + CalendarEmail + calendar connectors — read and write scopes requested at connect (with your explicit OAuth grant); execution gated by owner-set action level (Observe / Draft / Act)Email metadata and message content you direct a Nibbin to act on; calendar events created by trusted Nibbins; access token held encrypted in the vaultUnited States
SentryError monitoring & performance tracingStack traces, request metadata, and application events — no user-generated contentUnited States
TelegramInbound and outbound bot messages (reach-me channel)Chat ID and message content for notifications and inbound commands you initiateGlobal (Telegram infrastructure)
TwilioSMS delivery (reach-me channel)Your phone number and message content for notifications you requestUnited States
Meta / WhatsAppWhatsApp messaging (reach-me channel)Your phone number and message content for notifications you requestUnited States / global edge
What never reaches a subprocessor

Your Field Study screen captures and recordings (processed and deleted on your device — the capture component has no network capability); your vault tokens in readable form; and your raw connected-service content beyond the specific task at hand. Only redacted, structured text leaves your device, and only on your explicit action.

Changes to this list

We update this page before adding any new subprocessor. New service channels under development (for example, text-message and chat notification providers) will be listed here, with their region and the data they process, before they ever handle your data.

Questions, or something here that doesn't match what you see in the product? That's a bug — tell us: hello@nibbin.com