Subprocessors
What this page is
A subprocessor is a third-party service we use to run Norrith that may process your personal information on our behalf. We share data with each one only as needed to operate the service, under a data-processing agreement that limits them to processing on our instructions: no advertising, no profiling, and no training their own models on your data. We do not sell your data.
Core account, financial, and authentication data is stored encrypted in a Canadian region. The subprocessors below that operate outside Canada, primarily in the United States, are listed with the specific data they touch. See Privacy Policy §5 and §9 for the full detail.
Always active
These services are needed to run the app.
Supabase (hosted on AWS)
CanadaPurpose. Authentication, encrypted database, file storage, and serverless functions.
Data processed. Account, financial, and authentication data, isolated per user at the database with Row-Level Security.
Plaid
United States / CanadaPurpose. Bank connection and read-only account and transaction aggregation.
Data processed. Bank account, balance, and transaction data. Your bank password is entered in Plaid and never reaches Norrith.
Apple
United StatesPurpose. Push notifications (APNs) and device attestation (App Attest).
Data processed. Device push token; app-integrity attestation signal.
Resend
United StatesPurpose. Transactional email: verification, household invites, security alerts (new-device sign-in, password or MFA change, bank reconnect), and welcome messages.
Data processed. Your email address and the content of that notification.
Sign-in providers
Used only when you choose to sign in that way.
Sign in with Apple
United StatesPurpose. Federated sign-in.
Data processed. The identifier Apple returns (Apple may relay a private email address).
Sign in with Google
United StatesPurpose. Federated sign-in.
Data processed. The identifier Google returns (name, email).
Consent-gated (off by default)
These run only if you opt in, in Settings → Privacy.
Google Gemini API
United StatesPurpose. AI Insights and Ask Norrith. Off until you consent in Settings → Privacy.
Data processed. AI Insights sends category-level aggregates (no merchant names). Ask Norrith adds your top merchants by recent spend. Detailed mode, a separate opt-in, adds balances by type, itemized recent transactions, holdings, and split-partner names. Account numbers are never sent, and health or medical merchant names are always withheld. Paid API tier: your inputs are not used to train Google's models.
Sentry
United StatesPurpose. Crash and error diagnostics. Off until you enable Analytics in Settings → Privacy.
Data processed. Stack traces plus device and OS metadata. Personal information is scrubbed; no balances, transactions, or account identifiers.
Marketing website
These touch only norrith.com website behaviour. None of them receive any in-app financial data.
Vercel
United StatesPurpose. Website hosting and Vercel Analytics (anonymous, cookieless page views).
Data processed. Page-view and performance metrics. No cookies and no individual identification.
Google Tag Manager
United StatesPurpose. Loads our website tags (currently just Google Analytics 4). Off until you accept cookies.
Data processed. The container itself sets no cookies and stores no data; it only delivers the tags below on consent.
Google Analytics 4
United StatesPurpose. Website traffic and waitlist-conversion measurement, deployed via Google Tag Manager.
Data processed. First-party cookies and a persistent client ID, with IP anonymized and no Google Signals or ads features. Opt-out instructions are in Privacy Policy §3.
Changes to this list
If we add or replace a subprocessor that handles personal information, we will update this page and, where the change is material, give notice as described in the Privacy Policy before the new subprocessor begins processing your data.
Questions
Questions about this list? Email hello@norrith.com.