1. Scope
This page lists providers that process personal data on behalf of Kapier or participate in the prepared connected-service chain. A provider receives document content only when its listed feature is used. Local-mode document content is not sent to these providers by Kapier.
Backup still involves server-side content processing: readable text chunks are sent to Cloudflare Workers AI to create the search vectors described below. Enabling backup does not authorize Mistral OCR or the GPT-5.6 Luna summary route.
Cloud intelligence is still disabled for general production users. The services below describe the launch chain prepared and tested with synthetic content. Kapier does not promise zero data retention, verified no-training controls, or EU-only inference in this version.
2. Service inventory
Cloudflare, Inc.
Account-backed backup or Cloud intelligence- Purpose
- Runs Kapier's API and durable document workflow, protects requests, stores encrypted document objects in private R2 storage, and creates backup-search embeddings with Workers AI BGE-M3.
- Data involved
- IP and request metadata, account/job identifiers, consent and usage metadata, encrypted connected document content, readable page bytes during authorized processing, and readable backup text chunks sent to Workers AI for embedding.
- Location
- United States / global edge network. Encrypted R2 objects currently use Eastern Europe placement; this is not an EU-only processing promise.
- Provider terms
- Cloudflare DPA
Supabase, Inc.
Account creation or connected features- Purpose
- Provides authentication, the account database, job and billing metadata, and encrypted OCR and insight records.
- Data involved
- Email, account and session identifiers, profile data, consent/job/usage records, operational events, encrypted connected results, and backup-search vectors and content hashes stored separately from encrypted document text.
- Location
- The Kapier project is in AWS eu-west-1 (Ireland). Supabase support and subprocessors may operate in other countries under its DPA.
- Provider terms
- Supabase DPA
Mistral AI SAS
Cloud intelligence only, after a per-document choice- Purpose
- Performs optical character recognition on document pages through the stateless Mistral OCR API.
- Data involved
- Selected document page images, page order and request metadata, and OCR output. Kapier does not use Mistral Files or Batch APIs.
- Location
- France / European Union by default for the standard API endpoint. Mistral documents possible temporary transfers outside the EU for some features and subprocessors.
- Provider terms
- Mistral DPA
Vercel Inc.
Website visits; Cloud intelligence after OCR- Purpose
- Hosts and protects the public Kapier website. For Cloud intelligence, it also routes recognized text and structured summary requests through Vercel AI Gateway.
- Data involved
- For website visits: IP address, user agent, requested URL, timestamps, and security/access metadata. For Cloud intelligence: recognized document text, prompt and output schema, generated result, token/usage counts, and request metadata.
- Location
- United States / global service. The current Luna route is listed for US regional inference. Kapier has not enabled Gateway zero-data-retention routing. Vercel's published DPA covers Pro and Enterprise plans; the current Hobby plan must be upgraded or separately covered before launch.
- Provider terms
- Vercel DPA
OpenAI, Microsoft Azure, or Amazon Web Services
Cloud intelligence only, after OCR- Purpose
- Produces the evidence-linked structured summary selected by Kapier through Vercel AI Gateway using GPT-5.6 Luna.
- Data involved
- Recognized document text, instructions and output schema, and the generated structured response. Document page images are not sent to the summary model in the current path.
- Location
- United States for the current model route. The downstream host is not yet pinned and Vercel lists OpenAI, Microsoft Azure, and AWS Bedrock routes. Kapier will pin and disclose the final host before public launch.
- Provider terms
- Vercel GPT-5.6 Luna route details
RevenueCat, Inc.
Subscription and paid-feature checks- Purpose
- Validates subscription status, restores purchases, and supplies the entitlement used to authorize paid connected features.
- Data involved
- App user identifier, Apple receipt and transaction information, entitlement state, last-seen, and limited device/technical data. No document content.
- Location
- United States and RevenueCat's listed subprocessor locations.
- Provider terms
- RevenueCat DPA
Google Workspace
Only when you contact us by email- Purpose
- Receives and stores email sent to Kapier's contact address.
- Data involved
- Your email address, message, attachments, and support correspondence.
- Location
- European Union, United States, and other Google Workspace processing locations under its data-processing terms.
- Provider terms
- Google Workspace data-processing terms
3. Apple services
Apple is not presented as a Kapier subprocessor for its own App Store, purchase, device-backup, or Sign in with Apple services. Apple handles those services under its own terms and privacy policy. Kapier receives the limited account, transaction, or entitlement data Apple makes available to provide the feature you requested.
Apple Vision document recognition and supported Apple Intelligence generation run on the device in Kapier's local path. Kapier does not send that local document content to its own servers.
Read Sign in with Apple & Privacy and Apple's App Store privacy information for Apple's independent processing.
4. Services not active in the launch configuration
- PostHog code exists in the app, but no production key is configured. Product analytics is disabled and PostHog is not a current production subprocessor.
- Google Document AI has an implemented adapter but is disabled and is not used in the iOS MVP path.
- Sentry is not integrated into Kapier.
We will update this page and the Privacy Policy before enabling a provider in production where that change affects user data.
5. International transfers and safeguards
The primary Supabase database is in Ireland and Mistral's standard API is hosted in the EU by default. Other providers operate globally, and the prepared GPT-5.6 Luna summary path performs inference in the United States. Its downstream host is not yet pinned.
Where the GDPR requires a transfer mechanism, Kapier uses an applicable adequacy decision, the European Commission's Standard Contractual Clauses through provider data-processing terms, or another lawful safeguard. Provider-level contractual coverage and account controls must be reviewed before the prepared Cloud intelligence path is opened to general production users.
6. Changes and notice
We will update the date at the top and revise this list before a new provider begins handling production data where reasonably practicable. Material changes will also be communicated in the app or by another appropriate channel when law or our agreement with you requires it.
To request email notice of subprocessor changes, email contact@nestorcodecrafters.com with the subject “Kapier subprocessor updates.”
7. Contact
Questions or objections about a listed provider can be sent to contact@nestorcodecrafters.com. Include the provider name and the feature involved, but do not attach a sensitive document.