Service Providers and Data Recipients
These providers support the features described below. Services can use different processing locations and retention periods; we do not promise Singapore-only or zero-retention processing. Contact legal@socialgryd.com for the safeguards applicable to your records. Provider documents explain the suppliers’ terms and do not replace SocialGryd’s responsibilities.
1. Infrastructure, AI and communications
| Provider / role | Purpose and information | Processing locations and handling | Provider documents |
|---|---|---|---|
| Google Cloud / Firebase — processor or Singapore data intermediary for customer data, with service-specific roles | Authentication, Firestore, Cloud Storage, Functions/Cloud Run, media processing, push delivery, App Check, configuration, logs and enabled analytics/diagnostics. Account, content, private meals/workouts/routes, device identifiers and operational records. | Functions use US us-central1. Production Firestore is in US multi-region nam5, with seven-day point-in-time recovery and scheduled backups. Other services use service-specific and global infrastructure. | Firebase terms; Firebase processing terms; Cloud DPA; service privacy details |
| OpenAI — API processor | Meal images, text, barcode results, selected saved meals; workout prompts, selected training history, goals, saved plans and programme context; hashed safety identifier. Food requests can use web search/product lookup. | Global API endpoint, including US processing. Retrievable response storage is disabled. Standard abuse-monitoring retention and exceptions remain; no Singapore residency or Zero Data Retention guarantee is made. | Service agreement; DPA; API data controls |
| Mux — video processor | Video uploads, audio, thumbnails and encoded derivatives, content-linking metadata and playback network/device information. Older and private media paths may use Google storage. | US infrastructure and global delivery. Media derivatives and provider deletion cycles can differ from removal of a visible post. | Terms; DPA |
| Resend — email processor | Recipient addresses, email bodies and delivery/status records; marketing tracking where enabled. A Resend subprocessor is not automatically a direct SocialGryd vendor. | International service and onward providers; delivery/status records and enabled tracking have service-specific retention. | Terms; DPA |
| Google Cloud Vision — image-processing provider | Community image bytes and automated safety classifications. Image content may itself reveal identity or health. | API endpoint and service's own data-handling rules govern processing; a US calling function does not establish Vision data residency. | Data use; Cloud DPA above |
2. Analytics and monitoring
| Provider | Scope and data | Verification and documents |
|---|---|---|
| Google Analytics / Firebase Analytics and Crashlytics | Consented usage measurement and app diagnostics; page/screen and event information, device/installation identifiers and errors. Google Analytics has separate service terms. | Optional analytics and Crashlytics follow the app’s analytics choice. Collection is off until an affirmative choice; restart the app after withdrawing crash-report collection. Analytics terms; processing terms; Firebase privacy details above. |
| Sentry | Disabled in the new beta app. Older builds may have sent error, session and performance reports. | Historic reports follow provider retention and applicable deletion requests. Privacy. |
| Better Stack | Uptime monitors and incidents, monitored URLs/statuses, operational contact and incident information. Portal integration reads monitor/incident status. Broader log ingestion or session replay was not established by this review. | Monitoring records include checked URLs, response/status information and incident metadata. Storage and retention follow the enabled monitoring service. Terms; DPA; privacy. |
3. Feature-specific and independent recipients
- Google Maps/Places and chosen navigation apps: map/place searches, coordinates where used, IP and device/request information. Google has service-specific controller terms. External navigation receives the destination you choose to open. Maps terms; Google privacy.
- Apple and Google sign-in, push and app stores: authentication identifiers, permitted profile data, push tokens/payloads and purchase records where those services are used. Apple privacy; Google privacy above. These services may act independently for account, device, billing and security purposes.
- Open Food Facts: barcode/product queries and request metadata. A direct mobile lookup exposes the device's IP address; server lookups expose the server's request metadata. The full private diary is not intentionally sent to the catalogue. Terms; privacy.
- BigDataCloud: a portal location lookup can send coordinates and browser/request metadata. This applies when that portal lookup is used. Privacy.
- Google Calendar: optional administrator connection processes OAuth tokens and calendar/event data under granted scopes. It is not a general import of users' fitness diaries. Google API user-data policy.
- Ticketmaster and other external event links: code can retrieve event catalogue data; visiting an external listing shares normal browser information with that destination under its own policy. Imported listings do not certify an organiser. Ticketmaster developer terms.
- Groups, clubs, organisers and other users: receive only information provided or shared for the relevant interaction. Independent organisers are responsible for their own collection and use.
4. Changes, contracts and transfers
We update this register when recipients materially change and provide required notice, consent or contractual objection rights. Singapore transfer safeguards and any applicable EU/UK mechanisms must be supported by actual agreements and account settings; a vendor's certification does not certify SocialGryd. Contact legal@socialgryd.com for provider questions or applicable safeguards.
Anthropic, Amplitude, speculative AWS AI services, Stripe and other previously listed tools are not presented as current app data recipients without evidence of an active integration. Historic copies held by a former provider must still be considered in retention and deletion reviews. See International Transfer Information.
