trust center · data + privacy · GDPR
every system that touches your data, listed.
respira is one person and a short list of carefully picked vendors. here is exactly who they are, what they do, where they store things, and whether there is a DPA on file.
last updated Oct 3, 2026
at a glance
- data residency EU (Ireland) Supabase Pro · primary region
- encryption TLS 1.3 in transit AES-256 at rest
- cookie taxonomy 4 categories essentials always on · 3 opt-in
- breach notification 72 hours GDPR Art. 33
where respira stands on GDPR
respira is built and run from Brașov, Romania. that makes the EU the home jurisdiction rather than a market to comply into, and the GDPR the baseline every visitor gets, not a regional variant.
- establishment EU-established controller (Romania). GDPR applies directly, not by extension.
- residency accounts, sites, licences, telemetry and audit logs live in Supabase EU (Ireland). transfers outside the EEA are covered by Standard Contractual Clauses (2021/914).
- lawful basis recorded per vendor in the table below: contract performance for the ones that make the product work, consent for anything analytics or messaging, legitimate interest for error tracing.
- consent (art. 7) EU, EEA and UK visitors are geo-detected and asked before any non-essential category fires. "essentials only" carries the same visual weight as "okay". every choice is logged server-side so consent is demonstrable, and withdrawal is one click from the footer.
- rights (art. 15-22) access, rectification, erasure, portability, restriction and objection, detailed below. 30 days, usually the same week.
- breach (art. 33) 72 hours, by email to every potentially affected account and posted on this page.
- processors (art. 28) every sub-processor below has a signed DPA or accepted standard terms on file, with the date. if your organisation needs a data processing agreement with respira itself, the article 28 DPA is published in full and takes effect on one email, with a counter-signed copy on request.
one thing stated plainly, because trust pages that only say flattering things are not worth reading: "GDPR compliant" is not a certificate anyone issues. there is no audit behind that phrase the way there is behind SOC 2 or ISO 27001. what is on this page is the actual posture, vendor by vendor, with dates, so you can judge it rather than take a badge on faith.
sub-processors
17 vendors. add or swap one and this page updates from a single typed source.
| vendor | purpose | region | cookies | category | DPA |
|---|---|---|---|---|---|
| Supabase | Auth, primary Postgres, file storage, edge functions. Email, hashed password, user metadata, license records, telemetry events, and the AER workspace data a user chooses to store. No payment data (handled by Polar). | EU (Ireland, eu-west-1) | sb-*-auth-token | essentials | DPA → DPA signed · Nov 14, 2025 + SCCs |
| Vercel | Hosting, edge network, serverless function execution. Request headers (IP, UA, country), routing metadata. No request bodies stored beyond function log retention (24h on the hobby tier, 7d on Pro). | EU + global | server-side only | essentials | DPA → standard terms accepted · Nov 14, 2025 + SCCs |
| Google Analytics 4 | Aggregate page-view + event analytics. Truncated IP, user agent, anonymised client id, page path, event name, optional user_id (Supabase UUID) when logged in. | Global (with EU IP truncation) | _ga, _ga_F55E0B1KNX | analytics | DPA → standard terms accepted · Nov 14, 2025 + SCCs |
| Reddit Ads | Ad conversion measurement for Respira's Reddit campaigns. Page URL and browser details from the pixel. For a sign-up or purchase: a SHA-256 hash of the email address and of the account id, the IP address, the browser user agent, the Reddit click id when the visit came from an ad, and for a purchase its value and currency. No site content. | US | _rdt_uuid, rdt_cid | attribution | standard terms accepted standard terms accepted |
| PostHog | Product analytics inside the dashboard. Distinct id = Supabase user UUID, email, plan tier, is_trial. Inputs masked in session replays. No payment data, no chat content. | EU (eu.i.posthog.com) | ph_* | analytics | DPA → DPA signed · Jan 12, 2026 + SCCs |
| Customer.io | In-app messaging and journeys. Anonymous visitor id (cookie-bound) or email when logged in. Message impressions, clicks. No content payloads beyond what is needed for delivery. | EU | _cio* | messaging | DPA → DPA signed · Dec 20, 2025 + SCCs |
| Chatwoot | Live chat support widget. Visitor identifier, chat transcript, optional email if you start a conversation. Inactive sessions purge. | EU (Chatwoot self-hosted) | cw_* | messaging | DPA → standard terms accepted · Jan 5, 2026 + SCCs |
| Resend | Transactional and broadcast email delivery. Recipient email, subject, body, delivery + open + click events. Bodies retained 14 days. | EU | server-side only | essentials | DPA → DPA signed · Nov 25, 2025 + SCCs |
| LemonSqueezy retired | Retired. Legacy payment and subscription billing. Historic records only: billing email, name, billing address, and payment method tokens from orders placed before the move to Polar. No new data is sent. Raw card numbers were never held here. | Global | server-side only | essentials | DPA → standard terms accepted · Nov 14, 2025 + SCCs |
| Polar | Payment + subscription billing. Billing email, billing address, payment method tokens. No browser cookies on respira.press. | EU | server-side only | essentials | DPA → standard terms accepted · Feb 8, 2026 + SCCs |
| Anthropic | Customer-selected AER inference, marketing generation, and AI-assisted engineering and support. AER sends the selected thread messages and site context needed to complete the run. Marketing generation sends product and release text only. Support and engineering sessions see only the account and error details needed for the ticket. No payment card data. | US (with EU SCCs) | server-side only | essentials | DPA → DPA signed · Dec 1, 2025 + SCCs |
| Google (Gemini API) | Customer-selected AER inference and image generation for social and marketing visuals. AER sends the selected thread messages and site context needed to complete the run. Marketing generation sends only a visual prompt and brand assets. No payment card data. | Global (with EU SCCs) | server-side only | essentials | DPA → standard terms accepted · Nov 14, 2025 + SCCs |
| OpenAI | Customer-selected AER inference and fallback image generation for social and marketing visuals. AER sends the selected thread messages and site context needed to complete the run. Marketing generation sends only a visual prompt. No payment card data. | US (with EU SCCs) | server-side only | essentials | DPA → standard terms accepted + SCCs |
| OpenRouter | Optional customer-selected routing for AER model inference. The selected thread messages and site context needed to complete the AER run, plus request metadata such as model, token count and latency. No payment card data. | Global (EU-only routing is an enterprise option) | server-side only | essentials | DPA → standard terms accepted + SCCs |
| ElevenLabs | Sage, the support agent on the website and dashboard. On the dashboard: account email and display name, plus the page you are on and the versions you run. On public pages: no identifiers. Whatever you type into the conversation. No payment data, and no content from your WordPress site. | US (with EU SCCs) | server-side only | essentials | DPA → standard terms accepted + SCCs |
| Sentry | Error tracing and reliability monitoring. Stack traces, breadcrumbs, request metadata (path, status). Email + user_id only when explicitly attached to a captured exception. | EU (de.sentry.io) | server-side only | essentials | DPA → DPA signed · Dec 2, 2025 + SCCs |
| Frankfurter (ECB) | USD → EUR FX rate for the Earn page. None. Server-side only, requests a public exchange-rate JSON. | EU | server-side only | essentials | no DPA needed no DPA needed |
lawful basis varies per vendor (contract performance, consent, legitimate interest). per-vendor basis is documented in src/data/sub-processors.ts and surfaced via the cookie widget tune panel.
your rights
plain-english version of GDPR articles 15 through 22. response within 30 days, usually same week.
- access ask for a copy of every personal data point on file. email word@respira.press.
- rectification fix anything that is wrong about you. most fields live in /dashboard/settings; the rest is one email away.
- erasure "right to be forgotten." closes the account, drops every row, and de-identifies retained transactional logs.
- portability JSON export of your account, sites, telemetry, and billing history. file a request via email; turnaround is days, not weeks.
- restriction pause processing without deleting (useful while you decide).
- objection opt out of any processing based on legitimate interest. the cookie widget covers the consent-based categories; this is the broader sibling.
- automated decisions no automated decisions with legal effect are made about you on respira.press today. if that ever changes, you will know first.
security posture
- authentication. Supabase Auth, magic link plus OAuth.
- authorization. Postgres Row-Level Security on every table. reads scoped to
auth.uid() = user_idunless an admin gate explicitly bypasses. - secrets. never in client bundles. rotated quarterly via Vercel env vars.
- backups. Supabase daily backups, kept for 7 days.
- breach notification. 72-hour commitment per GDPR Art. 33. notified via email + posted on this page.
- error tracing. Sentry EU region, PII scrubbing on by default.
questions, requests, or just want to talk through how a workflow uses your data? word@respira.press.