Trust

Service providers & sub-processors

Rerato, Inc., and where relevant its mobile-store publishing affiliate Rerato Technologies Private Limited, may use the providers below when delivering Trivana. A provider receives only the data needed for the feature you use; not every provider applies to every customer or interaction. This register supports privacy and customer diligence. It is not a description of Trivana's internal network design or security controls. Last updated August 11, 2026.

ProviderService roleData categories
SupabaseAccount and core application servicesAccount details and service content, including Learn participant and response records when those features are used
VercelApplication hosting, delivery, and aggregate site and performance measurementRequest metadata and application content submitted to or returned by the hosted service; public page-view dimensions and Web Vitals performance measurements
CloudflareNetwork and media delivery, bot protection, and optional AI traffic routingRequest and security metadata; generated audio, video, and images; prompts, prepared scripts, and generated output when AI Gateway is enabled
ElevenLabsGenerated voicePrepared script text; not intended to receive Learn participant response records
RunwayGenerated facilitator mediaPrepared facilitator scripts and host media; not intended to receive Learn participant response records
GoogleSign-in and AI-assisted content generationOAuth identifiers and basic profile information when Google sign-in is used; source content, prompts, and generated output when a supported Google model is used
OpenRouterAI model routingSource content, prompts, and generated output when model routing or a fallback is used
OpenAIContent moderation, optional transcription, and AI-assisted generationSubmitted text for moderation; source audio for transcription; source content, prompts, and generated output when an OpenAI model or fallback is used
Microsoft Azure OpenAIOptional AI-assisted content verificationSource-derived questions, answer choices, evidence text, prompts, and verification output when Azure verification is enabled
Google FirebaseMobile push delivery, app-installation services, and optional mobile analytics and crash diagnosticsPush tokens and app-installation metadata; consented mobile usage and diagnostics where enabled
StripeWeb payments and billingBilling contact and transaction metadata
ResendTransactional and notification emailEmail address and message content
HubSpotCustomer relationship management, sales communications, and consented public-site visitor attributionProspect and customer contact, organization, workshop, message, deal, and email-engagement records; after optional consent on eligible public pages, IP address, online visitor identifiers, timestamps, and visited page paths. Not intended to receive Learn participant response records
PostHogOperational and product analyticsPseudonymous account, project, cohort, session, and attempt identifiers; participation, completion, score, duration, purchase, and operational events; browser analytics only where consent applies
SentryError and performance monitoringError diagnostics, request metadata
InngestBackground workflow orchestrationWorkflow identifiers and the contact, message, booking, or operational payload needed when an enabled background workflow runs
Cal.comOptional meeting schedulingBooking contact details, scheduling preferences, and meeting metadata when a visitor chooses to book

Buyers should not place participant personal data in source material, prompts, or facilitator scripts unless a written scope expressly permits it. Prepared content can be processed by the generation providers that apply to the selected feature.

HubSpot generally acts as a processor or service provider for CRM records. Under HubSpot's current terms, it may act as a separate controller for tracking-code data if Intent data access or enrichment products are enabled. See HubSpot's Data Processing Agreement and Privacy Policy.

This page is the public summary, not a substitute for the applicable provider terms or a signed Data Processing Addendum. Customers can request the current legal entity, processing-location, transfer, or security information needed for diligence. Questions about a specific provider or a DPA? [email protected].

Security overview · Privacy policy · Trivana Learn