What this page is
Appsanic is operated by Encode Digital Software Solutions Pty Ltd (ACN 690 774 719), a company registered in New South Wales, Australia (“Appsanic”, “we”, “us”). A sub-processor is a third party we engage to process personal information on our behalf so that we can deliver the service. We publish this list so that customers, procurement teams, and privacy regulators can see, at a glance, who we rely on, what each provider does, the categories of data it handles, and where it operates.
Each sub-processor named below is engaged under a written contractthat requires it to process personal information only on our documented instructions, to apply appropriate technical and organisational security measures, to support our obligations under the Australian Privacy Principles (“APPs”) in the Privacy Act 1988 (Cth), and - where the provider processes data of individuals in the European Union or the United Kingdom - to meet the requirements of Article 28 of the GDPR. This page is read together with our Privacy Policy, Terms of Service, and Security overview.
Data Processing Addendum.Enterprise and business customers who need a signed Data Processing Addendum (“DPA”), including standard contractual clauses for cross-border transfers, can request one by emailing contact@appsanic.com. The DPA incorporates this sub-processor list by reference.
Core infrastructure
These providers underpin the platform itself. They store your account and project data, serve the web application, and run the AI agent. A point worth calling out for data residency: the AI agent executes on machines located in Australia (Sydney).
| Provider | Purpose | Data processed | Primary region |
|---|---|---|---|
| Supabase Inc. | Postgres database, authentication, file storage, and realtime. | Account, project, authentication, billing, and audit data; generated source code; uploaded assets; conversation history; brand kits. | US / EU (per Supabase project configuration) |
| Netlify, Inc. | Frontend web hosting, edge delivery, and serverless functions. | Request metadata, session state, static assets. | Global (US-primary) |
| Fly.io, Inc. | Runs the AI agent in short-lived, single-job machines (build, plan, research, and history compaction). | User prompts, project source code, conversation history, brand kit, and connector credentials decrypted in memory only for the duration of the job. | Australia (Sydney) |
Where the AI agent runs. When you ask the agent to build, plan, research, or otherwise work on a project, our application spawns an ephemeral, single-job Fly.io machine in Sydney. That machine reads the relevant project files and conversation history, performs the work, and is then torn down. Any connector credentials needed for a direct API call are decrypted in memory only, server-side, for that job and are never written back in plaintext. Because the agent workload runs in Australia, the data it processes during a job stays onshore for the life of that job. See our Security overview for the full technical picture.
Payments
Billing and subscriptions are handled by Stripe. Card data is entered directly into Stripe’s systems; Stripe holds that data and carries PCI-DSS compliance. Appsanic never receives full card numbers - we only ever reference the card brand, the last four digits, and the expiry so you can recognise the card on file.
| Provider | Purpose | Data processed | Primary region |
|---|---|---|---|
| Stripe Inc. | Payment processing, subscription management, invoicing, and fraud prevention. | Billing address, plan, subscription status, payment history, and card brand, last four digits, and expiry. Full card numbers are held by Stripe and never received by us. | US / AU |
For more on plans, credits, tax, and refunds, see our Pricing and Refund Policy.
Communications
| Provider | Purpose | Data processed | Primary region |
|---|---|---|---|
| Resend Inc. | Transactional email - confirmations, password resets, new-device alerts, billing notices, team invites, and contact-form delivery. | Email address, message contents. | US |
AI model providers
Appsanic uses a single foundation-model provider to power the agent: Anthropic. We do not use any other AI model provider for the platform. The agent runs on commercial Claude models provided by Anthropic; the API call is made from the ephemeral Fly.io worker described above.
Prompts and generated outputs are processed ephemerally under a commercial API agreement and are notused to train any AI model. As part of its work the agent can run a research sub-step that uses Anthropic’s server-side web search and fetch; this can send search queries out to the public web on your behalf.
| Provider | Purpose | Data processed | Primary region |
|---|---|---|---|
| Anthropic PBC | Large-language-model inference powering the build agent, including internal compaction, plan, and research sub-tasks, and a server-side web-search step. | Prompt content, previous turns of the conversation, and the project files the agent reads as context. Search queries issued during the research step may be sent to the public web. | US |
The agent never sees your connector secrets. Connector credentials are encrypted at rest with AES-256-GCM and are decrypted only server-side, in memory, for a direct API call. A redaction layer strips secret-like fields from tool results before they reach the model, and the agent’s system prompt forbids it from requesting credentials. The only credential exposed to your browser is the Supabase anonymous (public) key, which is designed for browser use.
On-demand connectors (activated by you)
The following providers process data only when you explicitly connect themto a project - for example, to export your code or build and distribute your app. Data sent to them is at your direction and is governed by each provider’s own terms and privacy policy. They are not engaged by us to process your data generally; they act only when you activate them.
| Provider | Purpose | Data processed |
|---|---|---|
| GitHub Inc. | Code export, repository creation, and pull requests. | OAuth token, repository metadata, and the file contents you push. |
| Expo (EAS) | Cloud builds for iOS and Android. | Project source code and any signing credentials you provide. |
| Apple Inc. | App Store distribution. | App metadata, binary, and your developer credentials. |
| Google LLC | Google Play distribution. | App metadata, binary, and your developer credentials. |
Beyond these distribution and build providers, Appsanic offers a range of managed connectors that you can optionally connect to a project. Each is governed by its own terms, and you control whether and when it is activated. See the full list on the Connectors page. As explained above, the AI agent never sees the decrypted secret for any connector.
Overseas transfers and data residency
Because some of our sub-processors are located outside Australia, your personal information may be processed in the United States, the European Union, and Australia, depending on the provider and its configuration. Before disclosing personal information to an overseas recipient, we take reasonable steps, as required by Australian Privacy Principle 8, to ensure the recipient handles that information consistently with the APPs - principally through the written data-processing agreements described above and, where applicable, standard contractual clauses.
A notable data-residency point in your favour: the AI agent itself runs in Australia (Sydney) on Fly.io. While Supabase data may be stored in the US or EU per project configuration, the compute that reads your project files and prompts during a build job is onshore for the life of that job.
Where you are an individual in the European Union, the United Kingdom, or California, additional protections may apply under the GDPR, the UK GDPR, or the California Privacy Rights Act (CPRA) respectively. Our Privacy Policy explains those rights and the transfer mechanisms we rely on.
Updates to this list
We update this page whenever we add, remove, or materially change a sub-processor. Enterprise customers receive advance notice by email before a new sub-processor begins processing their data, in line with their DPA. Any customer can subscribe to change notifications by emailing contact@appsanic.com and asking to be added to the sub-processor notifications list.
The “Last updated” date at the top of this page reflects the most recent change. The machine-readable list embedded on this page is kept in lockstep with the tables above.
Questions and DPA
For any question about sub-processing, data residency, standard contractual clauses, or to request our Data Processing Addendum, contact contact@appsanic.com. This single address handles all privacy, security, and legal matters. Privacy and legal enquiries receive a substantive response within 30 days, consistent with the Privacy Act and APP 12. You can also reach us via our Contact page.
Electronic notice to contact@appsanic.com is our preferred method of notice. A postal address is available on request. Appsanic is operated by Encode Digital Software Solutions Pty Ltd (ACN 690 774 719), New South Wales, Australia.
