Sub-processors

Last updated: 25 May 2026

Codex uses the following sub-processors to operate the service. Each is bound by a Data Processing Agreement (DPA) with Standard Contractual Clauses (SCCs) where transfers leave the EEA. We notify customers via this page at least 30 days before adding a new sub-processor.

VendorPurposeData sharedRegionSafeguard
Supabase (Lovable Cloud)Database, auth, storageAccount, bookings, messages, contentEU (Frankfurt)DPA, EU hosting
CloudflareCDN, DDoS protection, edge runtimeIP, request metadataGlobal (EU edge)DPA, SCCs
StripePayments, fraud detectionName, email, payment method, billing addressEU + USDPA, SCCs, PCI-DSS L1
ResendTransactional email deliveryEmail, name, message contentEU + USDPA, SCCs
KlaviyoMarketing email (opt-in only)Email, name, engagement eventsEU + USDPA, SCCs
Google (OAuth)Sign-in with GoogleEmail, name, avatar (only if you choose Google)GlobalDPA, SCCs
OpenAI / Google AIAI chat & recommendationsPrompt text (no PII appended by us)USDPA, zero-retention API tier

Data Processing Agreement

B2B customers (studios, employers) can request our DPA — including the full SCCs for international transfers — by emailing privacy@thecodex.world. We countersign within 5 business days.

Your rights

Under GDPR you can request access, rectification, deletion, restriction, or portability of your data. Logged-in users can self-serve at /account/privacy. Otherwise email privacy@thecodex.world — we respond within 30 days.

Changes

We post the change date at the top of this page. Material changes are also announced via email to active customers.