Skip to main content
Home

Sub-processors

Last updated: 30 July 2026.

These are the third parties that process data on behalf of Rolegend so the product can work. Each entry says what that company receives and where it processes it. This list is part of Nightshift Software's Privacy Policy and of the service schedule for Rolegend.

Supabase

Sign-in, the database everything is stored in, and file storage for generated images.

Vercel

Hosting. The site and its API run as Vercel functions, and the platform holds the server logs they write.

PostHog

Product analytics and error tracking. Counts what accounts do inside the game so we can tell whether the product works, and receives the server's error reports so a failure is visible rather than merely logged.

Anthropic

Generates the GM's narration when Anthropic is the platform's configured model provider, and is the failover target for an OpenAI-primary deployment when an Anthropic key is set.

OpenAI

Three jobs. It generates the GM's narration when OpenAI is the configured provider (or the failover target); it produces the embeddings behind lore retrieval, which it does whichever provider generates the narration; and it generates entity images.

Stripe

Subscription payments and the billing portal.

Resend

Sends product email - the welcome message, the account-deleted confirmation, and the other notices under src/server/email/.

Transfers outside the UK

Supabase, Vercel and PostHog process in the EEA, so nothing leaves it for those three. The rest process in the United States, and each transfer is covered by that company’s own arrangement rather than by one blanket mechanism:

These describe each company’s published terms as at 30 July 2026. They are stated here because they are checkable, not because a lawyer has reviewed this page.

Not on this list

Session recording. Nothing records your screen or what you type. PostHog is on the list above for errors and for basic usage analytics, and its session-replay feature is switched off in code.

Optional integrations. The code supports the integrations below, but each one is inert until an operator sets an environment variable, and that variable is what picks the recipient - so the code alone cannot name a company for any of them. Whether any is switched on in production: {{OPTIONAL_INTEGRATIONS_IN_USE}}

Changes

Adding a sub-processor means updating this page. It carries the date it was last checked against the code, at the top.

Contact

Questions about anything here: support@rolegend.com.