tryall.ai
Subprocessors and Service Providers
Effective: May 28, 2026. Updated: July 18, 2026.
1. Overview
This page lists vendors that help Tryall provide, secure, monitor, bill, and support the service. It includes active providers and conditional providers that are present in the product architecture or configuration but may only run when a feature or environment setting is enabled.
Some AI, payment, fraud-prevention, search, or platform providers may act as processors, service providers, independent controllers, or mixed-role providers depending on the feature, route, law, and contract. We use this page as a practical transparency list, not as a final legal classification for every provider role.
2. Current List
| Vendor | Purpose | Data | Status | Role note |
|---|---|---|---|---|
| Vercel | Application hosting, serverless/runtime execution, deployment infrastructure, and platform logs. | Request metadata, runtime logs, deployment metadata, and data processed by the application during service delivery. | Active | Processor/service provider for hosting and app delivery. |
| Clerk | Authentication, account identity, session management, and user profile services. | Account identifiers, email, name/avatar where provided, auth/session metadata, and security events. | Active | Processor/service provider for auth; some fraud/security roles may require legal classification. |
| Stripe | Checkout, billing, subscription administration, invoices, payment status, and fraud prevention. | Billing contact data, Stripe customer ids, subscription metadata, checkout events, invoices, and payment status. | Active | Payment provider; processor/controller role can vary for regulated payment and fraud obligations. |
| Google (Google Ads) | Advertising conversion measurement via the Google tag (gtag.js) with Consent Mode: cookieless consent-flagged pings before marketing consent; advertising cookies and conversion identifiers only after consent. | IP address, user agent, page URL, and ad-click identifiers; after marketing consent also _gcl_* cookies and conversion transaction identifiers (checkout session id, account id for sign-up conversions). | Conditional | Advertising measurement provider, active only when the Google tag is configured; CPRA sharing position and opt-out path are documented in the Privacy Policy. |
| OpenRouter | AI gateway and routing for chat, compare, model access, image generation, search-enabled model calls, and transcription when enabled. | Prompts, messages, supported attachments, generated content, model ids, usage metadata, provider request ids, and user/session routing identifiers. | Active | AI gateway/provider. Downstream provider role and retention vary by route and model. |
| Downstream AI model providers | AI inference selected through OpenRouter or product routing, including text, multimodal, image, search-backed, and transcription-capable models. | Prompts, messages, attachments, source images, generated outputs, provider metadata, and usage metadata depending on model and feature. | Under review | Provider set can vary by model, route, fallback, and plan. Tryall does not claim ZDR/no-training unless the route and terms enforce it. |
| Sentry | Operational error monitoring, diagnostics, reliability, security investigation, and incident response. | Error data, stack traces, sanitized request context, route metadata, and operational diagnostics. | Active | Processor/service provider for operational telemetry under the Sentry LIA controls. |
| PostHog | Consent-gated product analytics using reviewed events only. | Reviewed analytics events/properties, minimal identifiers, timestamps, and product metadata after analytics consent. | Active | Processor/service provider for optional analytics. Autocapture, heatmaps, pageview/pageleave capture, and replay are disabled for the MVP. |
| Resend | Transactional email delivery and email delivery metadata when enabled. | Email address, message metadata, delivery/bounce/suppression data, and service email content. | Conditional | Conditional processor/service provider; production use and retention settings need final review. |
| Supabase | Database and managed storage for attachments, project sources, support files, and generated artifacts when enabled. | Account/product records, uploaded files, project/source data, generated assets, support screenshots, and object metadata. | Conditional | Conditional processor/service provider; production storage use and retention settings need final review. |
| Upstash | Rate limits, cache, quota/admission control, Redis-like counters, and short-lived operational data when enabled. | Short-lived cache keys, counters, rate-limit metadata, account/session identifiers, and operational workflow metadata. | Conditional | Conditional processor/service provider; TTL and production-use settings need final review. |
| Inngest | Background workflow execution, retries, asynchronous events, and job metadata when enabled. | Workflow payloads, run metadata, event identifiers, retry state, and feature-specific job data. | Conditional | Conditional processor/service provider; event retention and production-use settings need final review. |
| Tavily | Optional web search and grounding when Tavily search is enabled. | Search queries, search policy metadata, retrieved source metadata, snippets, and web content used for grounding. | Conditional | Conditional search provider; DPA, retention, transfer, and production enablement need final review. |
| Perplexity | Optional direct search and retrieval when a Perplexity-backed search path is enabled. | Search prompts or queries, generated answers, citations, source metadata, status metadata, and usage metadata. | Conditional | Conditional search/retrieval provider; direct Perplexity paths are not covered by OpenRouter routing controls. |
| Langfuse | AI observability, model-call trace metadata, feedback scores, quality review, and incident debugging when enabled. | Trace identifiers, model/function names, route/status/timing/token or cost-style metadata, feedback scores, and prompt/response content only if a separate capture policy allows it. | Conditional | Conditional AI observability provider. Disabled by default; metadata-only by default when enabled. Project region, retention, access, and DPA review are required before production enablement. |
| OpenAI direct API | Native image mask editing when enabled; direct transcription adapter exists but was not found wired in this audit. | Source images, masks, image-edit prompts, generated image outputs, and audio files if direct transcription is wired later. | Conditional | Conditional direct provider path. OpenRouter routing controls do not apply. |
3. AI Provider Routing
Tryall is a multi-provider AI product. A selected model, Auto routing, fallback behavior, search mode, image mode, or attachment mode can change which downstream provider processes a request. Provider privacy settings, logging, retention, training controls, and availability can vary by model, route, feature, and plan.
We do not claim zero data retention, no training, or provider-side deletion unless the specific route, configuration, and vendor terms support that claim.
4. Changes
We may update vendors as the service changes. Before adding or materially changing a provider that can process personal data, Tryall should review the provider purpose, data categories, security posture, retention, transfer mechanism, DPA or equivalent terms, public notice impact, and any customer notice or objection commitments that apply.
For privacy or vendor questions, contact privacy@tryall.ai or legal@tryall.ai.