Subprocessors

Last updated 2026-08-21.

Convexly uses the third-party providers listed below to deliver the service. Each subprocessor is contractually bound by a Data Processing Addendum, listed where public. Subprocessors process personal data only on Convexly's documented instructions and are subject to confidentiality and security obligations comparable to those in Convexly's own privacy policy.

We update this page whenever we add, remove, or materially change a subprocessor. If you have signed a DPA with Convexly, you will receive advance notice of material changes per that agreement.

SubprocessorPurposeData sharedRegionDPA
Supabase, Inc.Managed PostgreSQL database, authentication, and row-level security. Primary application data store.Account data (email, display name, plan type), wallet analyses, watchlists, alerts, API metadata, optional journal entries.United StatesView →
Stripe, Inc.Payment processing, subscription management, and invoicing.Billing email, payment method (tokenized by Stripe; card numbers never touch Convexly), subscription history, invoices.Global (primarily US)View →
Vercel, Inc.Hosting for the Convexly web application and API edge routes. CDN and DDoS protection.Web request metadata (IP address, user agent), response bodies. No persistent data storage on Vercel.Global edge (primarily US)View →
Railway CorporationHosting for the Convexly FastAPI backend and background workers.Request metadata and ephemeral compute. Persistent storage is in Supabase; Railway does not retain application data.USView →
OpenAI, L.L.C.Large language model inference for optional text structuring, summarization, and analysis assistance.Text submitted by the user when they explicitly use AI features. Not used for model training per OpenAI API terms.USView →
Resend (Resend Technologies, Inc.)Transactional email delivery (wallet-watch emails, signal digests, onboarding sequence, account notices).Email address, display name, email content.USView →
PostHog, Inc.Product analytics for funnel measurement and feature adoption.Pseudonymous event data (page views, feature usage, calibration quiz completion). User identification limited to internal user IDs for signed-in users.US (PostHog Cloud US)View →
Cloudflare, Inc. (R2 object storage)Object storage for derived on-chain analysis caches and research archive exports.Derived caches of public blockchain activity (wallet addresses and transactions already public on Polygon) and research evidence archives. No account or personal data.North AmericaView →
Alchemy Insights, Inc.Blockchain RPC provider for reading public Polygon on-chain data (wallet activity, market resolutions).Queried wallet addresses and block ranges. These are public on-chain identifiers; no account or personal data.US -

Scope notes

Wallet addresses submitted to the public wallet analyzer are public on-chain identifiers, not account data. The analysis queries public blockchain data through the RPC provider listed above, and results are cached so repeat lookups are fast; the cache holds derived analysis of public data and is not associated with any user unless they choose to save or watch that wallet. Stripe card numbers never touch Convexly servers; Stripe tokenizes them client-side.

Contact

For security diligence, DPA requests, or questions about this list: research@convexly.app.