Skip to content
modsignal

Legal

Subprocessors

Last updated: July 29, 2026

modsignal uses the following third-party services (“subprocessors”) to operate the platform. Your account data, monitor configurations, snapshots, and alert history are stored in the European Union; each entry below notes where that vendor processes data.

We will update this page whenever we add or remove a subprocessor. If you would like to be notified of changes, watch this page — or ask modsignal to do it for you. Questions go to hello@modsignal.io.

Supabase

Database (PostgreSQL) and user authentication

User accounts, team data, monitor configurations, prompts, page snapshots, alert history, session tokens

EU (Frankfurt, Germany)
Vercel

Hosting for the dashboard (Next.js app) and marketing site

HTTP requests to the dashboard and marketing site, session cookies

EU (Frankfurt, Germany)
Anthropic

AI analysis for the semantic and browser-agent check tiers

Fetched content of monitored public pages and monitor prompts, processed per-check; not used for model training under Anthropic's commercial API terms

US
Upstash

QStash message queue for scheduling monitor checks; single-use sandboxes (Upstash Box) that run browser-agent checks

Scheduling: monitor IDs and schedule payloads. Browser-agent checks: URLs of monitored public pages and their rendered content, processed in a sandbox that is deleted when the check ends

EU (Frankfurt) / US (N. Virginia)
Stripe

Payment processing and subscription management

Billing details, payment methods, invoices, subscription status

EU (Dublin, Ireland)
Resend

Alert and transactional email delivery

Email addresses, alert content (change sentence, before/after evidence), invitation links

EU (Frankfurt, Germany)

Where your data lives

Data at rest — accounts, monitors, snapshots, alerts — is stored exclusively in EU data centers. Per-check processing on the semantic and browser-agent tiers happens in the US — Anthropic for AI analysis, Upstash Box sandboxes for browser-agent checks — where page content is handled transiently and not retained.

Public pages only

The content flowing through these subprocessors comes from publicly accessible web pages you chose to monitor, plus the prompts you wrote. modsignal does not monitor pages behind logins and does not collect personal data from monitored pages.

Contact

Questions about our subprocessors or data processing? Contact us at hello@modsignal.io.