Legal
Subprocessors
Effective 2026-09-29
These are the third parties that handle personal data on behalf of Nisatsu. Material changes to this list are announced in the app and take effect on the updated effective date above. See our Privacy Policy for the broader context.
| Provider | Purpose | Data categories | Location |
|---|---|---|---|
| Stytch | Passwordless authentication (email magic links, SMS OTP, OAuth). | Email, phone number, OAuth identity assertions, auth session tokens, IP. | United States |
| RevenueCat | Subscription management across web and mobile. Aggregates Apple, Google, and Stripe purchases into a single entitlement and dispatches webhook events back to us. | RevenueCat app user ID (equal to our internal user ID), product identifiers, subscription state. | United States |
| Stripe | Payment processing for web purchases (invoked by RevenueCat under the hood; we do not integrate with Stripe directly). | Subscription state, card data (held by Stripe, not us), billing contact info. | United States |
| Apple | In-app purchase payment processing for iOS subscriptions, reported to Nisatsu through RevenueCat. | Apple subscription transaction identifiers, product identifiers, billing/payment records held by Apple. | Global / United States |
| Google (Play Billing) | In-app purchase payment processing for Android subscriptions, reported to Nisatsu through RevenueCat. | Google Play subscription transaction identifiers, product identifiers, billing/payment records held by Google. | Global / United States |
| OpenAI | AI-generated stories, content moderation of user topics and generated output, profile-field moderation, manually entered vocabulary moderation and enrichment, in-reader press-and-drag selection translation, complete translated-story generation, automatic English translation of story titles after generation (to build the library search index) and on-request title translation into your native language, uncached text-to-speech input moderation, and answers for the Pro in-reader "Ask Nisatsu AI" explain chat. | The learner's full known-vocabulary list (up to 5,000 words), the titles of the learner's recent stories (so a new story avoids repeating them), and the chosen native/target language for story generation; user-supplied topic prose and generated story output; interest tags and learning goal when used to derive a topic; display name, username, bio, and interest tags for profile moderation; manually entered vocabulary fields for intake or edit moderation; selected phrases from stories you read (including stories shared by other learners) plus the source/target language pair when you press-and-drag to translate inside the reader; a complete story title and sentences plus the destination language for complete translated-story generation; the story title and target language for title translation (automatic to English after generation, and on request into your native language); the target-language word and its meaning for part-of-speech lookups; uncached text-to-speech input and any supplied reading for moderation before Azure synthesis; the questions you type in the "Ask Nisatsu AI" explain chat together with the word or phrase they ask about, its sentence, and the recent turns of the same conversation. No account identifiers (email, phone, name, IP, internal user ID) are forwarded. | United States |
| Microsoft Azure Speech | Text-to-speech audio generation. | The word, highlighted text, or sentence being spoken, plus the target language/voice. No account identifiers (email, phone, name, IP, internal user ID) are forwarded. | Configurable Azure region |
| Amazon Web Services (S3 / CloudFront) | Content-addressed cache for text-to-speech MP3 audio: a public cache of single-word files and a non-enumerable cache of sentence/phrase audio. | MP3 audio files stored under opaque deterministic object keys derived from cache version, language, voice, and a cryptographic hash of the exact text. Sentence/phrase audio can include sentences from stories (including stories written from your topics); keys carry no account identifiers, and cached audio may persist after the source story or account is deleted until the cache entry expires. | Configurable AWS region / CloudFront edge locations |
| Neon (Postgres hosting) | Primary application database. | All account, learning, subscription, and analytics data at rest. | Configurable region; default United States or EU |
| Upstash | Redis-backed rate limiting and abuse controls, plus QStash delivery of durable story-generation jobs. | Hashed/prefixed rate-limit keys (for example user ID, IP, or phone) and counters, plus short-lived operational caches: your known-vocabulary word list keyed by internal user ID (held for about a minute), recently translated selections with their language pair (held up to 4 hours), and single-use, short-lived sign-in handoff state (account linking and the PKCE-bound OAuth mobile handoff), deleted when used or expired, which can include the email address being linked. QStash receives an opaque story-job ID, delivery metadata, and the Nisatsu callback URL. Story topics, known vocabulary, account identifiers, and story text are loaded from our database by the signed callback and do not cross QStash. | Configurable region; default United States |
| Sentry | Server-side and client-side error monitoring. | Stack traces and request paths, scrubbed of free-form content and account identifiers before send; events carry no stable account identifier. | United States |
| PostHog | Product analytics, funnels, retention cohorts, and feature-usage dashboards. | Internal user ID, event names, story IDs, language/screen metadata. No email, phone number, raw story prose, or vocab prose. | United States |
| Expo (EAS) + Apple APNs + Google FCM | Mobile push notification delivery. | Expo push tokens and notification payloads (e.g. "Today's word: 猫"). | United States |
| Resend | Transactional account and legal-policy email delivery, plus marketing email for users who opt in. EU data residency is available for EU/EEA recipients. | Email address, email content, first name when needed to address the message, and marketing opt-in status where relevant. No phone number, story text, or vocab prose. | United States (with EU data-residency option) |
| Vercel | Hosting the Nisatsu web app and API. | Request metadata and logs as part of normal hosting. | Global edge; storage primarily United States |
| Fly.io | Hosting the story-generation guardrail service that validates and assembles story requests before they reach OpenAI and returns the generated story, tokenizes complete story sentences into reader segments with readings, and checks saved vocabulary words against its built-in dictionary during vocabulary maintenance. | The learner's full known-vocabulary list (up to 5,000 words), story topic text, the titles of the learner's recent stories (so a new story avoids repeating them), the chosen native/target language and story settings (genre, difficulty, reading stage), the generated story text, complete story sentences submitted for tokenization and reading assignment, and saved vocabulary words submitted for dictionary checks. No account identifiers (email, phone, name, IP, internal user ID) are forwarded. | Configurable region; default United States |
Advertising partners (only with your consent)
When we run ad campaigns for Nisatsu, the following partners can set cookies on our public pages to measure ad performance, only if you accept the consent banner, and never by default. They act as independent controllers of the measurement data they receive (not subprocessors handling data on our behalf); declining the banner, or a Global Privacy Control signal, keeps them entirely out. See the Privacy Policy ("Advertising cookies") and Cookies pages for the full picture.
- Google (Google Ads) performs ad-click conversion measurement via the Google tag with Consent Mode v2.
- Meta (Facebook/Instagram) performs ad-click conversion measurement via the Meta Pixel.
- TikTok performs ad-click conversion measurement via the TikTok Pixel.
International transfers rely on standard contractual clauses or equivalent safeguards provided by each subprocessor.
Questions about our subprocessors? Email contact@nisatsu.com.