Last reviewed 5 August 2026 (C2 locked). Formius may update this list as the stack changes; material additions for design partners will be notified where practical. Source of truth: lib/legal/subprocessors.ts. Related: Privacy Policy · Platform Terms.
Core platform
| Provider | Purpose | Typical data | Hosting |
|---|---|---|---|
| Supabase | Database, authentication, storage, realtime | Account, organisation, and application data; auth sessions | Provider-hosted (project region as configured) |
| Vercel | Application hosting, edge/network delivery | Request logs, deployment artefacts; app traffic | Global edge + selected compute regions |
| Resend | Transactional email delivery | Recipient email, message metadata, template content | Provider-hosted |
| Sentry | Error monitoring and performance diagnostics | Stack traces, limited request context (secrets scrubbed where configured) | Provider-hosted |
| Upstash | Distributed rate limiting (Redis) | Rate-limit keys (IP / org / route identifiers) — not document bodies | Provider-hosted |
Optional (when enabled)
These process data only when Formius or an organisation enables the integration or feature.
| Provider | Purpose | Typical data | Hosting |
|---|---|---|---|
| Stripe | Payments / Connect / SaaS billing (when enabled) | Billing and payment metadata as configured | Provider-hosted |
| Xero | Accounting sync (optional org integration) | Invoices, contacts, and sync payloads authorised by the org | Provider-hosted |
| Formodus | Optional constitutional / estimate runtime bridge (per-org) | Payloads an organisation authorises for Formodus features | Provider-hosted (api.formodus.io as configured) |
| Sanity | Optional CMS / structured content (when enabled) | Published content and related CMS records — not primary customer job vault | Provider-hosted |
| OpenAI | Optional AI assist features (when OPENAI_API_KEY configured) | Prompts/content submitted to AI features only | Provider-hosted |
| Anthropic | Optional AI assist features (when ANTHROPIC_API_KEY configured) | Prompts/content submitted to AI features only | Provider-hosted |
| Google Analytics | Optional marketing / product analytics (when measurement ID set) | Pseudonymous usage identifiers and page/event metrics | Provider-hosted |
| Meta (Facebook Lead Ads) | Optional lead ingest webhook (when Meta credentials configured) | Lead form fields submitted via connected Meta assets | Provider-hosted |
Notes
- Customer-facing portal and quote links are served by Formius on Vercel; document content is stored in Supabase as configured for the tenant.
- AI features send only the prompts/content you submit for that feature — not a bulk export of your organisation vault.
- Questions or DPA schedule requests: support@formius.io.