Sub-processors
A sub-processor is any third party that processes personal data on our behalf to deliver the Service. We list them all here with their role, the data categories involved, where the processing happens, and the legal mechanism for any transfer out of the EEA/UK. This page is updated whenever we add, remove, or materially change a sub-processor.
Currently engaged sub-processors
Heroku (Salesforce, Inc.)
- Role: Platform-as-a-service host for the application servers, job worker, and Heroku Postgres database.
- Data categories: all production application data (account, game, log, backup).
- Location: the deployed region is configured in
app.json. Current region: United States. A move to an EU region is on the compliance roadmap (Phase 4.4). - Transfer mechanism for EU/UK data: Salesforce's EU-US Data Privacy Framework certification, supplemented by Standard Contractual Clauses incorporated into the Salesforce/Heroku DPA.
- Public DPA: [Salesforce / Heroku DPA](https://trust.salesforce.com/en/agreements/).
OpenAI, L.L.C.
- Role: Vision and text models used to scan handwritten turn sheets and extract structured player orders. May be used for optional NPC/narrative generation in supported game types.
- Data categories: images of submitted turn sheets, extracted text, minimal per-game context required for the scan. No account identifiers are sent beyond what the request needs.
- Location: United States.
- Transfer mechanism: OpenAI's EU-US Data Privacy Framework certification plus SCCs incorporated into the OpenAI API Data Processing Addendum. We operate under the API Data Processing Addendum, which contractually prevents OpenAI from using our submitted content to train their models.
- Public DPA: [OpenAI API Data Processing Addendum](https://openai.com/policies/data-processing-addendum).
Anthropic, PBC (optional / per-deployment)
- Role: Text model used as an optional alternative or backup for AI-assisted features. Only engaged when a deployment explicitly configures it.
- Data categories: same scope as OpenAI, only when Anthropic is enabled.
- Location: United States.
- Transfer mechanism: SCCs incorporated into Anthropic's DPA; EU-US DPF where applicable.
- Public DPA: [Anthropic Commercial Terms](https://www.anthropic.com/legal/commercial-terms).
ForwardEmail
- Role: transactional and marketing email delivery. ForwardEmail is the only email-delivery provider currently engaged; the
EMAILER_PROVIDERenvironment variable selects ForwardEmail in every published deployment. - Data categories: recipient email address, message subject/body, delivery metadata.
- Location: as disclosed by ForwardEmail.
- Transfer mechanism: SCCs as incorporated in ForwardEmail's privacy terms; EU-US DPF where applicable.
- Public DPA: [ForwardEmail Privacy](https://forwardemail.net/en/privacy).
GitHub, Inc. (Microsoft)
- Role: source-code mirror of the project's repository, including the Markdown source of these legal documents. Pull requests, reviews, and issue discussion happen on GitHub. When you read this page on the deployed Service it is served from our application servers, not GitHub.
- Data categories: source code, commit metadata, authorship. No end-user personal data.
- Location: United States.
- Transfer mechanism: EU-US DPF plus SCCs as per GitHub's DPA.
- Public DPA: [GitHub Data Protection Agreement](https://docs.github.com/en/site-policy/privacy-policies/github-data-protection-agreement).
GitLab Inc.
- Role: primary source-code host and CI/CD pipeline for the project. CI runs tests, lints, and deploy jobs. No production user data is sent to CI.
- Data categories: source code, CI job logs, author metadata of contributors. No end-user personal data.
- Location: United States.
- Transfer mechanism: EU-US DPF plus SCCs as per GitLab's DPA.
- Public DPA: [GitLab DPA](https://about.gitlab.com/handbook/legal/dpa/).
Not currently engaged
Payment processor
Paid subscriptions are not offered at the time of publication of this document. When they are introduced, the payment processor will be added here with its role, data categories, location, and transfer mechanism. Payment processing will be handled entirely by the processor — we will receive only a token and minimal transaction metadata, and we will not store card data at any point.
Web font provider
We previously loaded web fonts from Google Fonts. We now self-host the fonts used by the Service, so no font-related requests are made to Google from your browser. Web fonts are therefore not a sub-processor.
Policy on changes
- Adding a sub-processor that accesses end-user personal data is a
material_changeto this document and triggers re-consent where applicable. - Replacing a sub-processor like-for-like (for example, switching email providers) is announced in this list and in the release notes; existing consents are preserved.
- Removing a sub-processor is a maintenance change and does not require re-consent.
How to object
If you disagree with our use of a specific sub-processor, email privacy@playbymail.games. Depending on which sub-processor is involved, objection may mean we cannot continue to provide the Service to you; we will explain the implications before acting.