Subprocessors and Service Providers
Effective: August 11, 2026
Version: 1.2
Last verified against repository: August 11, 2026
EVELI uses the providers below to operate the customer application. A provider may act as EVELI's processor, an independent controller, or both for different activities. The table describes the customer-data route found in the EVELI repository; account-level region and contract evidence is maintained in EVELI's internal vendor register because secrets and account settings do not belong in source code.
| Provider/legal entity | Role and purpose | Customer data | Location and transfer approach | Current product control |
|---|---|---|---|---|
| Supabase, Inc. | Authentication, Postgres database and private generated-asset storage | Account identifiers, eligibility, subscription/credit records, casting state, job metadata and generated assets | Project region selected in EVELI's Supabase account; international transfers governed by the applicable Supabase DPA and transfer terms | Service-role credential is server-only; database access is server-enforced; generated assets use a private bucket and time-limited signed URLs |
| Stripe, Inc. and the Stripe affiliate identified for the transaction | Checkout, subscription administration, invoicing, payment, tax and fraud prevention | Email, customer/subscription IDs, plan, country, transaction and device/fraud data; Stripe processes payment-card data directly | Stripe's regional entity and global infrastructure under its published privacy, DPA and transfer terms | Checkout and Billing Portal are Stripe-hosted; webhook signatures are verified; only a verified paid invoice can issue credits |
| Cloudflare, Inc. | DNS, edge delivery, Pages hosting/functions, request security and access controls where enabled | IP address, request/device and security data, site/API traffic and content necessary to deliver a request | Cloudflare's global network under its DPA and applicable transfer safeguards | Secrets remain in server environment variables; production persistence requires a cryptographically verified principal |
| fal – Features & Labels, Inc. | AI inference and generation orchestration | Structured prompts, generation parameters, permitted reference-image URLs and temporary generated Outputs | United States/global processing under fal.ai's DPA, SCCs/UK addendum and disclosed subprocessors; Google supplies the configured underlying image model | Live generation is guarded by explicit spend switches. The reviewed code does not yet send fal.ai's no-payload-storage or restricted-media lifecycle headers, so live customer generation must remain disabled until those controls pass |
| Google LLC or the Google affiliate for EVELI's Workspace account | Delivery and storage of legal, privacy and support email | Sender/recipient identifiers, message content and attachments | Account-configured Google Workspace region and Google's applicable DPA/transfer terms | Access is limited to monitored EVELI mailboxes and administrators |
Current AI route
The reviewed production policy uses:
- \
fal-ai/nano-banana-pro\for text-to-image generation; - \
fal-ai/nano-banana-pro/edit\for image-conditioned generation; and - \
fal-ai/nano-banana\as an allowed fallback identifier, although no role currently opts into that fallback.
fal.ai identifies Nano Banana Pro as Google's Gemini 3 Pro Image. EVELI does not fine-tune the underlying model. Before live customer use, EVELI must send \X-Fal-Store-IO: 0\, set short-lived restricted output-media controls, copy the completed file to EVELI's private storage, and verify deletion/expiry through a test request. Until then, fal.ai's documented default may retain request input/output JSON for 30 days and generated media follows the fal account/request lifecycle.
Provider rules
- Providers receive only the data reasonably needed for their service.
- Private customer Inputs and Outputs are not licensed by EVELI for a provider's generalized model training.
- EVELI maintains processor terms covering confidentiality, security, incident notification, deletion, assistance and international transfers where required.
- A new provider that will process Customer Personal Data is added to this page before activation. DPA customers may subscribe to change notices by emailing [email protected] with “Subprocessor notices” in the subject.
- A provider's independent-controller processing, such as payment-network fraud prevention or legal compliance, is governed by that provider's notice and is not mischaracterized as EVELI's processor instruction.
Questions: [email protected]