ScopeDiff

Sub-processors

Every third party that touches your data, and exactly what each one sees.

Last updated August 31, 2026

These are the services we rely on to run ScopeDiff. Each one processes some data on our behalf. This is the complete list — there is nothing else.

ServiceWhat it doesWhat it seesWhere
VercelApplication hosting and serverless computeAll request traffic in transit; server logs (IP address, request path, timing)United States
SupabaseDatabase, authentication, and file storageAccount email, scope records, project and client names, uploaded logos, encrypted GitHub tokenUnited States
AnthropicAI parsing of agreements and drafting of status updatesText of an uploaded agreement during a parse; your notes and repository activity during upkeepUnited States
StripeSubscription payments and billing managementBilling email, payment method (held by Stripe, never by us), subscription statusUnited States
GitHubOptional sign-in, and reading repository activity you connectGitHub username; pull request titles and descriptions, commit subjects and author names from repositories you connectUnited States
ResendTransactional email (sign-in links, billing confirmations)Account email address and the contents of those messagesUnited States
Gravity (trygravity.ai)Advertising attribution — our servers report a signup back to the ad platform when a visitor who arrived from one of our ads creates an accountThe ad click ID from the URL that brought you here, and a signup event tied to it. Sent server-to-server; no Gravity script runs in your browser, and never your email, account data, app activity, or anything on a shared recordUnited States

Worth calling out

  • Anthropic does not train on API data. Text sent for parsing is not used to train models. Anthropic may retain inputs for a limited period for safety and abuse monitoring, under its own terms.
  • Stripe holds card details; we never do.Payment information is entered on Stripe’s hosted checkout and never reaches our servers.
  • Your uploaded agreement is not stored by anyone in this list except in transit through Vercel and Anthropic to be read. See the Privacy Policy for exactly what that means.
  • One advertising provider, and no tracking script. We chose not to install Gravity’s browser pixel. Instead, when an ad click leads to a new account, our own servers send Gravity the click ID and nothing else — no code from Gravity runs on any page of this site, in the app, or on any shared scope record. The Privacy Policy describes the one first-party cookie involved.

Changes

Before we add a sub-processor, we will update this page at least 30 days in advance. If you want to be emailed when that happens, write to hello@scopediff.comand we’ll add you to the list.

Related: Privacy Policy · Security

TermsPrivacySecuritySub-processorshello@scopediff.com© 2026 ScopeDiff