eveli All legal documents

Subprocessors and Service Providers

Effective: September 20, 2026
Version: 1.3
Last verified against repository: September 20, 2026

EVELI uses the providers below to operate the customer application. A provider may act as EVELI's processor, an independent controller, or both for different activities. The table describes the customer-data route found in the EVELI repository; account-level region and contract evidence is maintained in EVELI's internal vendor register because secrets and account settings do not belong in source code.

Provider/legal entityRole and purposeCustomer dataLocation and transfer approachCurrent product control
Supabase, Inc.Authentication, Postgres database and private generated-asset storageAccount identifiers, eligibility, subscription/credit records, casting state, job metadata and generated assetsProject region selected in EVELI's Supabase account; international transfers governed by the applicable Supabase DPA and transfer termsService-role credential is server-only; database access is server-enforced; generated assets use a private bucket and time-limited signed URLs
Stripe, Inc. and the Stripe affiliate identified for the transactionCheckout, subscription administration, invoicing, payment, tax and fraud preventionEmail, customer/subscription IDs, plan, country, transaction and device/fraud data; Stripe processes payment-card data directlyStripe's regional entity and global infrastructure under its published privacy, DPA and transfer termsCheckout and Billing Portal are Stripe-hosted; webhook signatures are verified; only a verified paid invoice can issue credits
Cloudflare, Inc.DNS, edge delivery, Pages hosting/functions, request security and access controls where enabledIP address, request/device and security data, site/API traffic and content necessary to deliver a requestCloudflare's global network under its DPA and applicable transfer safeguardsSecrets remain in server environment variables; production persistence requires a cryptographically verified principal
fal – Features & Labels, Inc.AI inference and generation orchestrationStructured prompts, generation parameters, permitted reference-image URLs and temporary generated OutputsUnited States/global processing under fal.ai's DPA, SCCs/UK addendum and disclosed subprocessors; Google supplies the configured underlying image modelLive generation is guarded by explicit spend switches. The reviewed code does not yet send fal.ai's no-payload-storage or restricted-media lifecycle headers, so live customer generation must remain disabled until those controls pass
Klaviyo, Inc.Lifecycle and marketing email: waitlist and beta-access messages, checkout-recovery and purchase messages, and the investor notification listEmail address, name where given, list and consent state, message engagement, and the event properties EVELI sends to trigger a messageUnited States/global processing under Klaviyo's DPA, SCCs/UK addendum and disclosed subprocessorsPrivate API key is server-only; profiles are added to a named list with the recorded consent sentence; double opt-in is enabled on the lists that require it
Google LLC or the Google affiliate for EVELI's Workspace accountDelivery and storage of legal, privacy and support emailSender/recipient identifiers, message content and attachmentsAccount-configured Google Workspace region and Google's applicable DPA/transfer termsAccess is limited to monitored EVELI mailboxes and administrators

Current AI route

The reviewed production policy uses:

fal.ai identifies Nano Banana Pro as Google's Gemini 3 Pro Image. EVELI does not fine-tune the underlying model. Before live customer use, EVELI must send \X-Fal-Store-IO: 0\, set short-lived restricted output-media controls, copy the completed file to EVELI's private storage, and verify deletion/expiry through a test request. Until then, fal.ai's documented default may retain request input/output JSON for 30 days and generated media follows the fal account/request lifecycle.

Provider rules

Questions: legal@eveli.ai

Effective: September 20, 2026Version: 1.3

This is the immutable v1.6 snapshot. The current version of this document is at /legal/subprocessors.