launch week Respira for WordPress is live on DevHunt until Monday. Live on DevHunt this week. See the launch

trust center · data + privacy · GDPR

every system that touches your data, listed.

respira is one person and a short list of carefully picked vendors. here is exactly who they are, what they do, where they store things, and whether there is a DPA on file.

last updated Oct 3, 2026

at a glance

where respira stands on GDPR

respira is built and run from Brașov, Romania. that makes the EU the home jurisdiction rather than a market to comply into, and the GDPR the baseline every visitor gets, not a regional variant.

one thing stated plainly, because trust pages that only say flattering things are not worth reading: "GDPR compliant" is not a certificate anyone issues. there is no audit behind that phrase the way there is behind SOC 2 or ISO 27001. what is on this page is the actual posture, vendor by vendor, with dates, so you can judge it rather than take a badge on faith.

sub-processors

17 vendors. add or swap one and this page updates from a single typed source.

vendor purpose region cookies category DPA
Supabase Auth, primary Postgres, file storage, edge functions. Email, hashed password, user metadata, license records, telemetry events, and the AER workspace data a user chooses to store. No payment data (handled by Polar). EU (Ireland, eu-west-1) sb-*-auth-token essentials DPA → DPA signed · Nov 14, 2025 + SCCs
Vercel Hosting, edge network, serverless function execution. Request headers (IP, UA, country), routing metadata. No request bodies stored beyond function log retention (24h on the hobby tier, 7d on Pro). EU + global server-side only essentials DPA → standard terms accepted · Nov 14, 2025 + SCCs
Google Analytics 4 Aggregate page-view + event analytics. Truncated IP, user agent, anonymised client id, page path, event name, optional user_id (Supabase UUID) when logged in. Global (with EU IP truncation) _ga, _ga_F55E0B1KNX analytics DPA → standard terms accepted · Nov 14, 2025 + SCCs
Reddit Ads Ad conversion measurement for Respira's Reddit campaigns. Page URL and browser details from the pixel. For a sign-up or purchase: a SHA-256 hash of the email address and of the account id, the IP address, the browser user agent, the Reddit click id when the visit came from an ad, and for a purchase its value and currency. No site content. US _rdt_uuid, rdt_cid attribution standard terms accepted standard terms accepted
PostHog Product analytics inside the dashboard. Distinct id = Supabase user UUID, email, plan tier, is_trial. Inputs masked in session replays. No payment data, no chat content. EU (eu.i.posthog.com) ph_* analytics DPA → DPA signed · Jan 12, 2026 + SCCs
Customer.io In-app messaging and journeys. Anonymous visitor id (cookie-bound) or email when logged in. Message impressions, clicks. No content payloads beyond what is needed for delivery. EU _cio* messaging DPA → DPA signed · Dec 20, 2025 + SCCs
Chatwoot Live chat support widget. Visitor identifier, chat transcript, optional email if you start a conversation. Inactive sessions purge. EU (Chatwoot self-hosted) cw_* messaging DPA → standard terms accepted · Jan 5, 2026 + SCCs
Resend Transactional and broadcast email delivery. Recipient email, subject, body, delivery + open + click events. Bodies retained 14 days. EU server-side only essentials DPA → DPA signed · Nov 25, 2025 + SCCs
LemonSqueezy retired Retired. Legacy payment and subscription billing. Historic records only: billing email, name, billing address, and payment method tokens from orders placed before the move to Polar. No new data is sent. Raw card numbers were never held here. Global server-side only essentials DPA → standard terms accepted · Nov 14, 2025 + SCCs
Polar Payment + subscription billing. Billing email, billing address, payment method tokens. No browser cookies on respira.press. EU server-side only essentials DPA → standard terms accepted · Feb 8, 2026 + SCCs
Anthropic Customer-selected AER inference, marketing generation, and AI-assisted engineering and support. AER sends the selected thread messages and site context needed to complete the run. Marketing generation sends product and release text only. Support and engineering sessions see only the account and error details needed for the ticket. No payment card data. US (with EU SCCs) server-side only essentials DPA → DPA signed · Dec 1, 2025 + SCCs
Google (Gemini API) Customer-selected AER inference and image generation for social and marketing visuals. AER sends the selected thread messages and site context needed to complete the run. Marketing generation sends only a visual prompt and brand assets. No payment card data. Global (with EU SCCs) server-side only essentials DPA → standard terms accepted · Nov 14, 2025 + SCCs
OpenAI Customer-selected AER inference and fallback image generation for social and marketing visuals. AER sends the selected thread messages and site context needed to complete the run. Marketing generation sends only a visual prompt. No payment card data. US (with EU SCCs) server-side only essentials DPA → standard terms accepted + SCCs
OpenRouter Optional customer-selected routing for AER model inference. The selected thread messages and site context needed to complete the AER run, plus request metadata such as model, token count and latency. No payment card data. Global (EU-only routing is an enterprise option) server-side only essentials DPA → standard terms accepted + SCCs
ElevenLabs Sage, the support agent on the website and dashboard. On the dashboard: account email and display name, plus the page you are on and the versions you run. On public pages: no identifiers. Whatever you type into the conversation. No payment data, and no content from your WordPress site. US (with EU SCCs) server-side only essentials DPA → standard terms accepted + SCCs
Sentry Error tracing and reliability monitoring. Stack traces, breadcrumbs, request metadata (path, status). Email + user_id only when explicitly attached to a captured exception. EU (de.sentry.io) server-side only essentials DPA → DPA signed · Dec 2, 2025 + SCCs
Frankfurter (ECB) USD → EUR FX rate for the Earn page. None. Server-side only, requests a public exchange-rate JSON. EU server-side only essentials no DPA needed no DPA needed

lawful basis varies per vendor (contract performance, consent, legitimate interest). per-vendor basis is documented in src/data/sub-processors.ts and surfaced via the cookie widget tune panel.

your rights

plain-english version of GDPR articles 15 through 22. response within 30 days, usually same week.

security posture

questions, requests, or just want to talk through how a workflow uses your data? word@respira.press.

privacy policy terms