Subprocessors
Last updated 3 August 2026
These are the third parties that process data on our behalf to run Chatly. The first three are core — the service does not work without them. The rest are optional, or receive nothing but an IP address.
Core infrastructure
Every Chatly instance depends on these. Data here includes message content.
| Provider | What it does | Data it processes | Location |
|---|---|---|---|
| Supabase | Database, authentication, file storage, and realtime message delivery | All workspace content and account data | United States (AWS us-west-1) |
| Amazon Web Services | Underlying infrastructure for Supabase | All workspace content and account data, at rest | United States |
| Vercel | Application hosting, serverless functions, and aggregate analytics on our public pages | Requests to the service, including IP addresses; message content in transit through server functions | United States (sfo1) |
Email delivery
| Provider | What it does | Data it processes | Location |
|---|---|---|---|
| Resend | Sends two-factor authentication codes and workspace invitations | Email address, display name, and the contents of those specific emails | United States |
Two-factor codes are delivered by email, so email delivery is on the critical path for signing in. Message content is never emailed.
Error monitoring
Enabled per instance. Where it is turned on, crash reports are sent so we can find and fix faults without waiting for someone to report them. Reports carry the error, the code path that produced it, and the account id — never message content, request bodies, or the contents of your screen. Search terms and identifiers are stripped from URLs before anything is sent, and session recording is deliberately not used.
| Provider | What it does | Data it processes | Location |
|---|---|---|---|
| Sentry | Collects application crash reports | Error type and stack trace, scrubbed page path, browser and version, and the account id of the affected user | United States |
If your organisation would rather no crash data left its instance, we can run it with error monitoring switched off entirely. Ask us.
Push notifications
| Provider | What it does | Data it processes | Location |
|---|---|---|---|
| Browser push services (Google FCM, Mozilla, Apple) | Deliver notifications to your device when the app is closed | Your push subscription and the notification content, which may include a message preview and sender name | Varies by browser vendor |
Only applies if you grant notification permission. Revoking it in your browser stops this entirely.
Content delivery
These receive your IP address and the name of the asset requested, because your browser fetches files directly from them. They receive no account data and no message content.
| Provider | What it does | Data it processes | Location |
|---|---|---|---|
| jsDelivr | Serves emoji images | IP address, requested file | Global CDN |
| Google Fonts (fonts.gstatic.com) | Serves animated emoji images | IP address, requested file | Global CDN |
| GitHub | Hosts the Windows desktop app download | IP address, only when you download the desktop app | United States |
Voice and video calls
One-to-one and small group calls connect directly between participants where the network allows. When it does not, audio and video are relayed through a TURN server.
| Provider | What it does | Data it processes | Location |
|---|---|---|---|
| TURN relay | Relays call media when a direct connection cannot be established | Call audio and video in transit, and participant IP addresses | [Confirm provider and region — currently a public fallback relay] |
| LiveKit | Optional. Hosts larger group calls where configured | Call audio and video in transit | Not currently enabled |
Optional integrations
None of these are active unless enabled for your workspace or connected by you individually. Disconnecting removes the stored tokens.
| Provider | What it does | Data it processes | Location |
|---|---|---|---|
| Single sign-on and calendar integration, where enabled | Email address, profile name, and calendar data you authorise | United States | |
| Tenor (Google) | GIF search, where enabled | Your search terms and IP address | United States |
| Spotify | Shows what you are listening to as a status, if you connect it | Your currently playing track | United States |
Changes to this list
We will update this page before adding a new subprocessor that handles customer content. Customers with a written agreement that provides for advance notice will receive it in accordance with that agreement.
Questions: privacy@chatly.team. See also our Privacy Policy and Terms of Service.