Trust
Service providers & sub-processors
Rerato, Inc., and where relevant its mobile-store publishing affiliate Rerato Technologies Private Limited, may use the providers below when delivering Trivana. A provider receives only the data needed for the feature you use; not every provider applies to every customer or interaction. This register supports privacy and customer diligence. It is not a description of Trivana's internal network design or security controls. Last updated August 11, 2026.
| Provider | Service role | Data categories |
|---|---|---|
| Supabase | Account and core application services | Account details and service content, including Learn participant and response records when those features are used |
| Vercel | Application hosting, delivery, and aggregate site and performance measurement | Request metadata and application content submitted to or returned by the hosted service; public page-view dimensions and Web Vitals performance measurements |
| Cloudflare | Network and media delivery, bot protection, and optional AI traffic routing | Request and security metadata; generated audio, video, and images; prompts, prepared scripts, and generated output when AI Gateway is enabled |
| ElevenLabs | Generated voice | Prepared script text; not intended to receive Learn participant response records |
| Runway | Generated facilitator media | Prepared facilitator scripts and host media; not intended to receive Learn participant response records |
| Sign-in and AI-assisted content generation | OAuth identifiers and basic profile information when Google sign-in is used; source content, prompts, and generated output when a supported Google model is used | |
| OpenRouter | AI model routing | Source content, prompts, and generated output when model routing or a fallback is used |
| OpenAI | Content moderation, optional transcription, and AI-assisted generation | Submitted text for moderation; source audio for transcription; source content, prompts, and generated output when an OpenAI model or fallback is used |
| Microsoft Azure OpenAI | Optional AI-assisted content verification | Source-derived questions, answer choices, evidence text, prompts, and verification output when Azure verification is enabled |
| Google Firebase | Mobile push delivery, app-installation services, and optional mobile analytics and crash diagnostics | Push tokens and app-installation metadata; consented mobile usage and diagnostics where enabled |
| Stripe | Web payments and billing | Billing contact and transaction metadata |
| Resend | Transactional and notification email | Email address and message content |
| HubSpot | Customer relationship management, sales communications, and consented public-site visitor attribution | Prospect and customer contact, organization, workshop, message, deal, and email-engagement records; after optional consent on eligible public pages, IP address, online visitor identifiers, timestamps, and visited page paths. Not intended to receive Learn participant response records |
| PostHog | Operational and product analytics | Pseudonymous account, project, cohort, session, and attempt identifiers; participation, completion, score, duration, purchase, and operational events; browser analytics only where consent applies |
| Sentry | Error and performance monitoring | Error diagnostics, request metadata |
| Inngest | Background workflow orchestration | Workflow identifiers and the contact, message, booking, or operational payload needed when an enabled background workflow runs |
| Cal.com | Optional meeting scheduling | Booking contact details, scheduling preferences, and meeting metadata when a visitor chooses to book |
Buyers should not place participant personal data in source material, prompts, or facilitator scripts unless a written scope expressly permits it. Prepared content can be processed by the generation providers that apply to the selected feature.
HubSpot generally acts as a processor or service provider for CRM records. Under HubSpot's current terms, it may act as a separate controller for tracking-code data if Intent data access or enrichment products are enabled. See HubSpot's Data Processing Agreement and Privacy Policy.
This page is the public summary, not a substitute for the applicable provider terms or a signed Data Processing Addendum. Customers can request the current legal entity, processing-location, transfer, or security information needed for diligence. Questions about a specific provider or a DPA? [email protected].