Sub-processors List

Version 1.0Effective: June 3, 2026

TL;DR — The Short Version

We use third-party companies to run Skylina. Here's who, what they do, and why. All are contractually bound to protect your data. We review them annually.

1. Overview

Skylina uses the following third-party service providers ("sub-processors") to process your personal data. All sub-processors are contractually bound to data protection obligations consistent with GDPR Article 28.

2. Sub-processors

ProviderPurposeData SharedLegal Basis
PolsiaPlatform infrastructure, orchestrationAccount data, generation dataData Processing Agreement
AnthropicAI code generation (Claude API)User prompts (processed, not retained long-term per Anthropic policy)Data Processing Agreement
Sapiom (Polsia)AI image generationUser prompts for image generationData Processing Agreement
Neon (Supabase)PostgreSQL database hostingAll structured user dataDPA, SOC 2 Type II
StripePayment processingPayment card data (tokenized, not stored by Skylina)Payment Services Agreement
RenderCloud hosting and deploymentApplication data, logsData Processing Agreement
CloudflareCDN, DDoS protection, DNSIP addresses, request metadataData Processing Agreement

3. Annual Review

We conduct annual reviews of all sub-processors, collecting updated SOC 2 reports, security questionnaires, and compliance documentation. Last review: June 2026. Next scheduled review: June 2027.

4. Notification of Changes

We will notify you via email at least 30 days before adding a new sub-processor or changing how data is processed by existing sub-processors.

5. Questions?

Questions about sub-processors: privacy@skylina.polsia.app

© 2026 Skylina, built with Polsia.