Legal · Data processing
How service providers process Deniable data.
This page summarises the technical roles that support Deniable. The Privacy Policy remains the authoritative notice for purposes, legal bases, retention, rights, and international transfers.
Hosting and application delivery
Netlify provides hosting, deployment, CDN delivery, and server execution for the website and its routes. Production secrets are kept in the deployment environment and are not shipped to the browser.
Authentication and database
Neon provides managed PostgreSQL storage and authentication services. Account, catalogue, API, billing-ledger, delivery, and consent records are stored there according to the product's retention rules.
Private file storage
Cloudflare R2 stores private dataset archives and related product files. The application issues short-lived signed requests after the relevant account and purchase checks; the bucket is not intended to be a public file host.
Payments, tax, and accounting
Stripe handles checkout, payment processing, tax calculation, refunds, and payment references. sevdesk receives the structured information needed to create paid invoices and accounting records. Full card numbers are not stored by Deniable.
Transactional email
Resend sends authentication, support, account, and paid-invoice messages from verified Deniable sending domains. Messages are limited to the information needed for the specific communication.
Optional analytics
Google Analytics is optional and is loaded only after analytics consent. It is not required for account access, dataset delivery, or API usage.
More detail
For retention targets, legal bases, data-subject rights, safeguards, and provider-transfer information, read the Privacy Policy. Questions can be sent through Contact Deniable.
Last updated: 15 September 2026