trust center · data + privacy · GDPR

every system that touches your data, listed.

respira is one person and a short list of carefully picked vendors. here is exactly who they are, what they do, where they store things, and whether there is a DPA on file.

last updated Aug 5, 2026

at a glance

where respira stands on GDPR

respira is built and run from Brașov, Romania. that makes the EU the home jurisdiction rather than a market to comply into, and the GDPR the baseline every visitor gets, not a regional variant.

one thing stated plainly, because trust pages that only say flattering things are not worth reading: "GDPR compliant" is not a certificate anyone issues. there is no audit behind that phrase the way there is behind SOC 2 or ISO 27001. what is on this page is the actual posture, vendor by vendor, with dates, so you can judge it rather than take a badge on faith.

sub-processors

15 vendors. add or swap one and this page updates from a single typed source.

vendor purpose region cookies category DPA
Supabase Auth, primary Postgres, file storage, edge functions. Email, hashed password, user metadata (preferences), license records, telemetry events. No payment data (handled by LemonSqueezy / Polar). EU (Frankfurt, eu-central-1) sb-*-auth-token essentials DPA → DPA signed · Nov 14, 2025 + SCCs
Vercel Hosting, edge network, serverless function execution. Request headers (IP, UA, country), routing metadata. No request bodies stored beyond function log retention (24h on the hobby tier, 7d on Pro). EU + global server-side only essentials DPA → standard terms accepted · Nov 14, 2025 + SCCs
Google Analytics 4 Aggregate page-view + event analytics. Truncated IP, user agent, anonymised client id, page path, event name, optional user_id (Supabase UUID) when logged in. Global (with EU IP truncation) _ga, _ga_F55E0B1KNX analytics DPA → standard terms accepted · Nov 14, 2025 + SCCs
PostHog Product analytics inside the dashboard. Distinct id = Supabase user UUID, email, plan tier, is_trial. Inputs masked in session replays. No payment data, no chat content. EU (eu.i.posthog.com) ph_* analytics DPA → DPA signed · Jan 12, 2026 + SCCs
Customer.io In-app messaging and journeys. Anonymous visitor id (cookie-bound) or email when logged in. Message impressions, clicks. No content payloads beyond what is needed for delivery. EU _cio* messaging DPA → DPA signed · Dec 20, 2025 + SCCs
Chatwoot Live chat support widget. Visitor identifier, chat transcript, optional email if you start a conversation. Inactive sessions purge. EU (Chatwoot self-hosted) cw_* messaging DPA → standard terms accepted · Jan 5, 2026 + SCCs
Resend Transactional and broadcast email delivery. Recipient email, subject, body, delivery + open + click events. Bodies retained 14 days. EU server-side only essentials DPA → DPA signed · Nov 25, 2025 + SCCs
LemonSqueezy retired Retired. Legacy payment and subscription billing. Historic records only: billing email, name, billing address, and payment method tokens from orders placed before the move to Polar. No new data is sent. Raw card numbers were never held here. Global server-side only essentials DPA → standard terms accepted · Nov 14, 2025 + SCCs
Polar Payment + subscription billing. Billing email, billing address, payment method tokens. No browser cookies on respira.press. EU server-side only essentials DPA → standard terms accepted · Feb 8, 2026 + SCCs
Anthropic Marketing copy generation, plus AI-assisted engineering and support. Marketing generation sends product and release text only, with no user identifiers. Support and engineering sessions see only the records needed for the ticket in hand: typically an account email, plan, site list, and error detail. No payment card data, and no content from your WordPress site unless you send it in a ticket yourself. US (with EU SCCs) server-side only essentials DPA → DPA signed · Dec 1, 2025 + SCCs
Google (Gemini API) Image generation for social and marketing visuals. A text prompt describing the visual, plus brand assets. No user identifiers, no customer data. Global (with EU SCCs) server-side only essentials DPA → standard terms accepted · Nov 14, 2025 + SCCs
OpenAI Fallback image generation for social and marketing visuals. A text prompt describing the visual. No user identifiers, no customer data. US (with EU SCCs) server-side only essentials DPA → standard terms accepted + SCCs
ElevenLabs Sage, the support agent on the website and dashboard. On the dashboard: account email and display name, plus the page you are on and the versions you run. On public pages: no identifiers. Whatever you type into the conversation. No payment data, and no content from your WordPress site. US (with EU SCCs) server-side only essentials DPA → standard terms accepted + SCCs
Sentry Error tracing and reliability monitoring. Stack traces, breadcrumbs, request metadata (path, status). Email + user_id only when explicitly attached to a captured exception. EU (de.sentry.io) server-side only essentials DPA → DPA signed · Dec 2, 2025 + SCCs
Frankfurter (ECB) USD → EUR FX rate for the Earn page. None. Server-side only, requests a public exchange-rate JSON. EU server-side only essentials no DPA needed no DPA needed

lawful basis varies per vendor (contract performance, consent, legitimate interest). per-vendor basis is documented in src/data/sub-processors.ts and surfaced via the cookie widget tune panel.

your rights

plain-english version of GDPR articles 15 through 22. response within 30 days, usually same week.

security posture

questions, requests, or just want to talk through how a workflow uses your data? word@respira.press.

privacy policy terms