Service Providers
On this page
Effective date: September 18, 2026
Bowerbirds is operated by Felipe Ignacio Letelier Basáez, a self-employed professional in Spain. Questions about this register can be sent to felipe@bowerbirds.app.
Providers used to supply the service
The role depends on the data and the customer's relationship with Bowerbirds. A supplier processing business workspace content on our behalf may be a subprocessor under the DPA. A supplier handling records for which Bowerbirds is controller is our processor or, for specified activities, an independent controller.
Each details field below must state the actual contracting entity, enabled products, data/storage/access countries, applicable processing agreement, and transfer mechanism. An operator's business address is not a substitute for that information. Delete a conditional entry if it is not used in production.
| Provider / service | Purpose and relevant data | Role and activation | Verified contract and transfer details |
|---|---|---|---|
| Google Cloud, including hosting, storage, and Firebase / Identity Platform | API hosting and payload storage; sign-in identifiers and session data; customer content and operational metadata where handled by the enabled product. | Processor; subprocessor for covered customer content. Distinguish identity-provider activities performed as an independent controller. | Enabled products: Cloud Run (the API, brain and orchestrator services), Cloud Storage (record payloads), Cloud KMS (credential encryption), Secret Manager, and Identity Platform / Firebase Authentication (sign-in). Every Cloud Run service and the payload bucket bowerbirds-payloads-505514 run in us-central1 (Iowa, United States); the build artifact bucket is US multi-region. Storage and access countries therefore include the United States. Contracting entity and executed Cloud Data Processing Addendum: to be confirmed from the billing account. |
| Google Gemini through Vertex AI and the Gemini API | Audio transcription and other enabled AI processing; relevant inputs, context, outputs, and processing metadata. | Processor/subprocessor for the agreed content processing, subject to the actual service terms and account configuration. | Two distinct Google AI surfaces are enabled, on different terms, and must not be described as one. Vertex AI (aiplatform.googleapis.com, project bowerbirds-505514, location global unless GCP_LOCATION is set) performs media processing, routing and note generation; the global endpoint is not pinned to a single region. The Gemini Developer API (generativelanguage.googleapis.com, authenticated with an API key) performs audio transcription only. Data-use, retention and human-review conditions differ between the two — see the AI configuration statement below. |
| Neon database service | Account/workspace records, permissions, record metadata, and any content or indexes actually stored in the database. | Processor/subprocessor according to the data. Confirm the current contracting entity rather than assuming the brand identifies it. | Neon serverless Postgres 18, project misty-mouse-99623668, hosted on AWS us-east-2 (Ohio, United States) — Amazon Web Services is therefore a further subprocessor in this chain. Holds account, workspace, membership, record-metadata and ledger rows. Point-in-time history retention is configured at 6 hours. The account is currently on Neon's free plan, which should be reviewed before it holds business customer data. Contracting entity and executed DPA: to be confirmed. |
| Cloudflare | Website and edge services, authentication routing, and browser capture where enabled; request data and content needed by the enabled workflow. | Processor/subprocessor according to the product and data; confirm which features are live. | Cloudflare DNS and Workers serve bowerbirds.app, the per-estate sign-in hosts (signin, qa-signin, dev-signin), connect.bowerbirds.app and the marketing site; the orchestrator additionally holds a Cloudflare API token for the browser-capture workflow. The edge is global and terminates TLS, so request metadata including IP addresses is processed at the location nearest the visitor, and Cloudflare may set its own strictly necessary security cookies. Contracting entity and executed DPA: to be confirmed. |
| RevenueCat | Subscription and entitlement management; account/workspace identifiers, purchases, receipts, and subscription events. | Normally a service provider for Bowerbirds' billing processing. Do not infer that it receives recordings or becomes a subprocessor for all workspace content. | RevenueCat project projbf534664. Receives the workspace identifier as app_user_id, store purchase and receipt data, and subscription lifecycle events, and sends entitlement webhooks to the production API. It does not receive record content. Contracting entity, hosting countries and executed DPA: to be confirmed. |
| Stripe | Direct web checkout, billing portal, payments, refunds, and associated fraud/legal processing; billing identity and transaction information. | Role varies by activity; includes independent-controller processing under Stripe's terms. Not a recipient of general workspace content merely because it processes a payment. | Stripe is enabled for direct web checkout at https://connect.bowerbirds.app, returning to https://bowerbirds.app/welcome on success and https://bowerbirds.app/pricing on cancellation. Stripe receives billing identity and transaction data and acts as an independent controller for parts of that processing under its own terms. Card details are entered on Stripe's own surfaces and are never received by Bowerbirds. Contracting entity, account country and executed DPA: to be confirmed. |
| Resend, if transactional email is enabled | Service alerts, intended recipients, and delivery metadata. | Processor; a subprocessor only to the extent the relevant email processes Customer Personal Data on its behalf. | Resend is live in production and sends transactional mail only — workspace invitations and service alerts. It receives the recipient address, the workspace name and delivery metadata; invitation bodies deliberately carry nothing about a workspace beyond its name. Contracting entity, hosting countries and executed DPA: to be confirmed. Note that bowerbirds.app currently publishes no SPF record, which should be corrected before relying on transactional delivery. |
The AI-specific configuration, safety logging, retention, human review, and data-use conditions are not yet established, and this is the most consequential open item in this package. User content reaches two different Google surfaces under different terms. Content routed through Vertex AI falls under the Google Cloud Data Processing Addendum, by which Google does not use customer data to train its models. Content sent to the Gemini Developer API — the path dictation and transcription audio takes — falls under the Gemini API terms, where the free tier permits Google to use submitted content to improve its products, including human review, and the paid tier does not. The billing tier of the configured API key must be confirmed, and the answer reflected here, in the Privacy Policy and in the in-app AI consent copy, before publication. Transcription must not be described as covered by the Cloud DPA unless that path is moved to Vertex AI. Do not infer a retention period from the fact that an API receives inline audio rather than an uploaded file.
Customer-selected third parties and independent services
Apple handles App Store purchases and Apple Account services. Apple and Google also provide optional sign-in services. They process some information under their own terms and privacy notices. Their independent activity is not made subject to our DPA simply by naming them here.
If a customer connects GitHub, Linear, another integration, or an external tool endpoint, that destination receives the information authorized for the connection. The customer's own agreement with the destination governs that relationship. If Bowerbirds separately engages the same vendor to process data on our behalf, that separate engagement must be assessed and added above as appropriate.
Changes and further information
For business processing covered by our DPA, we notify the designated customer contact of intended subprocessor additions or replacements under the DPA's notice and objection process. An update to this page alone does not replace a required direct notice.
Relevant provider notices include RevenueCat, Stripe, Cloudflare, Neon's linked privacy notice, and Resend. These notices provide background; they are not evidence that Bowerbirds has executed the required supplier agreements or selected a particular region.