Legal
Subprocessor List
Document details
Version: 1.0 (draft). Effective date: none — this draft is not yet in effect, and nothing in it is in force. Last updated: 12 August 2026. Responsible entity: [SPHEROMNI RESPONSIBLE ENTITY — TBD]. Governing law and jurisdiction: [PRIMARY JURISDICTION — TBD]. Contact: [PRIVACY CONTACT — TBD].
Change history:
- Version 1.0 — first published as a page at Milestone 19, mirroring the register maintained in the repository since Milestone 0. Not in effect.
The canonical register lives in the repository
docs/privacy/data-inventory.md holds the authoritative subprocessor register and is updated whenever a subprocessor is introduced, as part of the release's legal review. This page mirrors it. If the two ever disagree, the repository is right and this page is a bug.
Current subprocessors
Neon — Database hosting. Everything Spheromni stores server-side: account records, identity links, sessions, consent receipts, file and folder metadata and stored file text, community content, subscription and seller records, audit entries, and performance telemetry where you have consented to it.
Render — Application and API hosting. Every request and response passes through it, so all of the above passes through transiently in processing. Nothing is stored there beyond the running application.
Google, GitHub, Apple, LinkedIn (as identity providers) — Authentication, for whichever one you choose to sign in with. The provider identifier, your email address, and where the provider supplies them a display name and avatar. Spheromni never receives your provider password, and the provider receives nothing about what you do inside Spheromni.
Google (as storage provider, Drive) — File storage, only if you connect your own Drive — a separate, explicit consent you can withdraw at any time. The file contents stay in your own Google account and are never stored by Spheromni. Spheromni holds a cached copy of Drive file names and metadata, and the encrypted access grant.
What is not on this list, and why
No payment processor. Payment is not activated, no billing provider is configured, no card details are asked for or held anywhere in the product, and no charge has ever been made. That is a fact about the build rather than an omission. Activating payment after commercial and legal review adds a processor, and this register changes with it.
No analytics provider. The only measurement in the product is first-party performance telemetry, off unless you turn it on, stored in Spheromni's own database. There is no analytics SDK, no tag manager and no session-replay tool.
No advertising network, no data broker, no enrichment service and no audience platform. Spheromni does not sell or share personal data for advertising by any definition.
No AI provider. There is no model, no inference call and no AI service anywhere in the product, so there is nobody to list.
No email or messaging provider. Spheromni sends no email and no notification of any kind, so no delivery service processes your address.
No error-reporting or logging vendor. Errors are handled inside the application and its own database.
Sub-subprocessors and transfers
Neon, Render and Google each run on infrastructure whose regions and onward processors are theirs to disclose. Which of those regions is engaged, and which transfer mechanism covers it, is [INTERNATIONAL TRANSFERS — TBD BY COUNSEL] — it depends on the primary jurisdiction, which is unresolved, and on deployment regions that are not yet fixed. It is an open item rather than an answered question written vaguely.
Changes to this list
A new subprocessor is added to the canonical register and to this page in the same change, and recorded in the change history above. Note the honest limit: this build sends no email and no notification, so there is no advance-notice mechanism for a subprocessor change and none is promised. Building one is a tracked open item.
Contact
[PRIVACY CONTACT — TBD], or see the Privacy Notice for what each category of data is and why it is processed.