Last updated: 31 July 2026
This page distinguishes between two different kinds of third party involved in the Service: (1) processors that handle personal data strictly on SLP Command's behalf, under a data processing agreement and SLP Command's instructions, and (2) independent platforms that process certain data for their own purposes, under their own terms, principally Apple in its role as operator of the App Store. This page is kept current — any material change is reflected here and, for changes affecting existing users, notified per the Privacy Policy.
The following providers process personal data on SLP Command's behalf, under a data processing agreement requiring appropriate technical and organisational safeguards, for the purposes and data categories described below.
| Provider | Purpose | Data processed | Location | Transfer safeguard |
|---|---|---|---|---|
| Supabase | Application database, user authentication, audio file storage | Email, password hash, learning progress, scores, Speaking audio | EU/US depending on project region | SCC (Art. 46 GDPR) where applicable |
| Render | Backend application hosting | Technical logs, hashed IP addresses, API traffic | United States | Standard Contractual Clauses |
| Provider | Purpose | Data processed | Location | Transfer safeguard |
|---|---|---|---|---|
| OpenAI | Speech-to-text transcription (Whisper) and AI evaluation (GPT) | Speaking audio, Speaking/Writing text, exercise prompts | United States | Standard Contractual Clauses |
| ElevenLabs | Text-to-speech generation for Listening exercises | Exercise text only — no personal data | United States | Standard Contractual Clauses |
| Provider | Purpose | Data processed | Location | Transfer safeguard |
|---|---|---|---|---|
| Sentry | Application error and crash diagnostics | Technical error data, stripped of request bodies and authorization headers — never personal content or audio | United States/EU depending on project configuration | Standard Contractual Clauses |
| PostHog | Pseudonymous product usage analytics (feature/screen usage, app version) | Pseudonymous user identifier and usage events only — never written answers, audio, transcripts, or account email | United States | Standard Contractual Clauses |
| Provider | Purpose | Data processed | Location | Transfer safeguard |
|---|---|---|---|---|
| RevenueCat | Validates App Store purchases with Apple, keeps track of subscription status (active, renewed, expired, cancelled) and synchronises it with your account, so the app can grant or withdraw Professional-plan access accordingly | A technical subscriber identifier linked to your account, App Store product identifier, App Store transaction identifiers, subscription status, and purchase/renewal/expiration dates. RevenueCat does not receive your card number or other full payment credentials — those are held by Apple. | United States | Standard Contractual Clauses, per RevenueCat's Data Processing Addendum |
SLP Command engages RevenueCat as a processor of subscriber data for this specific purpose, on the basis of RevenueCat's published Data Processing Addendum. This does not exclude that RevenueCat, like most technology providers, may also process certain data for its own operational purposes (e.g. service security, aggregated product metrics) under its own privacy policy, to the extent disclosed there.
Apple Inc. operates the App Store, through which the app is distributed and through which any purchase of SLP Command Professional is made. Apple is not a processor acting on SLP Command's instructions for this purpose: Apple determines its own purposes and means for operating the App Store, collecting payment, and administering your Apple ID and subscription, under Apple's own terms and privacy policy.
| Provider | Role | What SLP Command receives | What Apple handles independently |
|---|---|---|---|
| Apple Inc. (App Store) | Independent party for app distribution and payment — not SLP Command's processor | Only the technical information necessary to recognise a valid purchase, grant Professional-plan access, process a restore, and provide support — received via RevenueCat, not directly from Apple, and never including your card number. | Your Apple ID account, payment instrument and full payment details, purchase history across all your apps, subscription billing and renewal, and refunds — all governed by Apple's own Privacy Policy and App Store terms. |
To be notified when this list changes, contact privacy@slpcommand.com.