Service Providers and Data Recipients

Version 2.0 | Published: 7 September 2026

Beta policy update. Published 7 September 2026. Updated contractual terms apply to new registrations on express acceptance and to existing accounts from 8 October 2026 after notice and any required fresh acceptance. Existing rights are preserved. Corrected operator information and new safety/privacy controls apply as they are released; notices describe those controls and do not create consent by themselves. Read the complete update.

These providers support the features described below. Services can use different processing locations and retention periods; we do not promise Singapore-only or zero-retention processing. Contact legal@socialgryd.com for the safeguards applicable to your records. Provider documents explain the suppliers’ terms and do not replace SocialGryd’s responsibilities.

1. Infrastructure, AI and communications

Provider / rolePurpose and informationProcessing locations and handlingProvider documents
Google Cloud / Firebase — processor or Singapore data intermediary for customer data, with service-specific rolesAuthentication, Firestore, Cloud Storage, Functions/Cloud Run, media processing, push delivery, App Check, configuration, logs and enabled analytics/diagnostics. Account, content, private meals/workouts/routes, device identifiers and operational records.Functions use US us-central1. Production Firestore is in US multi-region nam5, with seven-day point-in-time recovery and scheduled backups. Other services use service-specific and global infrastructure.Firebase terms; Firebase processing terms; Cloud DPA; service privacy details
OpenAI — API processorMeal images, text, barcode results, selected saved meals; workout prompts, selected training history, goals, saved plans and programme context; hashed safety identifier. Food requests can use web search/product lookup.Global API endpoint, including US processing. Retrievable response storage is disabled. Standard abuse-monitoring retention and exceptions remain; no Singapore residency or Zero Data Retention guarantee is made.Service agreement; DPA; API data controls
Mux — video processorVideo uploads, audio, thumbnails and encoded derivatives, content-linking metadata and playback network/device information. Older and private media paths may use Google storage.US infrastructure and global delivery. Media derivatives and provider deletion cycles can differ from removal of a visible post.Terms; DPA
Resend — email processorRecipient addresses, email bodies and delivery/status records; marketing tracking where enabled. A Resend subprocessor is not automatically a direct SocialGryd vendor.International service and onward providers; delivery/status records and enabled tracking have service-specific retention.Terms; DPA
Google Cloud Vision — image-processing providerCommunity image bytes and automated safety classifications. Image content may itself reveal identity or health.API endpoint and service's own data-handling rules govern processing; a US calling function does not establish Vision data residency.Data use; Cloud DPA above

2. Analytics and monitoring

ProviderScope and dataVerification and documents
Google Analytics / Firebase Analytics and CrashlyticsConsented usage measurement and app diagnostics; page/screen and event information, device/installation identifiers and errors. Google Analytics has separate service terms.Optional analytics and Crashlytics follow the app’s analytics choice. Collection is off until an affirmative choice; restart the app after withdrawing crash-report collection. Analytics terms; processing terms; Firebase privacy details above.
SentryDisabled in the new beta app. Older builds may have sent error, session and performance reports.Historic reports follow provider retention and applicable deletion requests. Privacy.
Better StackUptime monitors and incidents, monitored URLs/statuses, operational contact and incident information. Portal integration reads monitor/incident status. Broader log ingestion or session replay was not established by this review.Monitoring records include checked URLs, response/status information and incident metadata. Storage and retention follow the enabled monitoring service. Terms; DPA; privacy.

3. Feature-specific and independent recipients

4. Changes, contracts and transfers

We update this register when recipients materially change and provide required notice, consent or contractual objection rights. Singapore transfer safeguards and any applicable EU/UK mechanisms must be supported by actual agreements and account settings; a vendor's certification does not certify SocialGryd. Contact legal@socialgryd.com for provider questions or applicable safeguards.

Anthropic, Amplitude, speculative AWS AI services, Stripe and other previously listed tools are not presented as current app data recipients without evidence of an active integration. Historic copies held by a former provider must still be considered in retention and deletion reviews. See International Transfer Information.