Sub-processors
Last updated: 14 August 2026
Sutrah uses the following third-party service providers ("sub-processors") to operate the product. They process data on our behalf only as needed to provide the service. We do not sell personal data. See also our privacy policy.
| Provider | Purpose | Data involved | Location |
|---|---|---|---|
| Vercel | Application hosting and serverless execution | Request metadata, application logs (may include IP address) | United States (primary; may vary by edge region) |
| Neon | PostgreSQL database hosting | Account email, location, prayer settings, encrypted OAuth tokens, prayer blocks, qada and travel data | Region selected at project creation (typically United States) |
| OAuth sign-in and Google Calendar API (when the user connects Google) | Account identity and calendar event data the user authorizes | Google global infrastructure | |
| Microsoft | OAuth sign-in and Microsoft Graph Calendar API (when the user connects Outlook) | Account identity and calendar event data the user authorizes | Microsoft global infrastructure |
| Slack | Optional Slack status updates during prayer blocks (when the user connects Slack) | User OAuth token and status text/emoji the user configures; no message or channel content | Slack / Salesforce global infrastructure |
| Resend | Optional transactional email (weekly summaries and product updates when enabled) | Recipient email address and message content | United States |
| Upstash | Optional background job queue (QStash) for debounced calendar re-optimization | User identifier in job payloads | United States / EU (depends on Upstash region) |
Questions: privacy@sutrah.app