eveli All legal documents

Subprocessors and Service Providers

Effective: August 11, 2026
Version: 1.2
Last verified against repository: August 11, 2026

EVELI uses the providers below to operate the customer application. A provider may act as EVELI's processor, an independent controller, or both for different activities. The table describes the customer-data route found in the EVELI repository; account-level region and contract evidence is maintained in EVELI's internal vendor register because secrets and account settings do not belong in source code.

Provider/legal entityRole and purposeCustomer dataLocation and transfer approachCurrent product control
Supabase, Inc.Authentication, Postgres database and private generated-asset storageAccount identifiers, eligibility, subscription/credit records, casting state, job metadata and generated assetsProject region selected in EVELI's Supabase account; international transfers governed by the applicable Supabase DPA and transfer termsService-role credential is server-only; database access is server-enforced; generated assets use a private bucket and time-limited signed URLs
Stripe, Inc. and the Stripe affiliate identified for the transactionCheckout, subscription administration, invoicing, payment, tax and fraud preventionEmail, customer/subscription IDs, plan, country, transaction and device/fraud data; Stripe processes payment-card data directlyStripe's regional entity and global infrastructure under its published privacy, DPA and transfer termsCheckout and Billing Portal are Stripe-hosted; webhook signatures are verified; only a verified paid invoice can issue credits
Cloudflare, Inc.DNS, edge delivery, Pages hosting/functions, request security and access controls where enabledIP address, request/device and security data, site/API traffic and content necessary to deliver a requestCloudflare's global network under its DPA and applicable transfer safeguardsSecrets remain in server environment variables; production persistence requires a cryptographically verified principal
fal – Features & Labels, Inc.AI inference and generation orchestrationStructured prompts, generation parameters, permitted reference-image URLs and temporary generated OutputsUnited States/global processing under fal.ai's DPA, SCCs/UK addendum and disclosed subprocessors; Google supplies the configured underlying image modelLive generation is guarded by explicit spend switches. The reviewed code does not yet send fal.ai's no-payload-storage or restricted-media lifecycle headers, so live customer generation must remain disabled until those controls pass
Google LLC or the Google affiliate for EVELI's Workspace accountDelivery and storage of legal, privacy and support emailSender/recipient identifiers, message content and attachmentsAccount-configured Google Workspace region and Google's applicable DPA/transfer termsAccess is limited to monitored EVELI mailboxes and administrators

Current AI route

The reviewed production policy uses:

fal.ai identifies Nano Banana Pro as Google's Gemini 3 Pro Image. EVELI does not fine-tune the underlying model. Before live customer use, EVELI must send \X-Fal-Store-IO: 0\, set short-lived restricted output-media controls, copy the completed file to EVELI's private storage, and verify deletion/expiry through a test request. Until then, fal.ai's documented default may retain request input/output JSON for 30 days and generated media follows the fal account/request lifecycle.

Provider rules

Questions: legal@eveli.ai

Effective: August 11, 2026Version: 1.2

Permanent link to this exact version: /legal/v1.2/subprocessors