We use cookies

Cookies keep Tryall working, remember preferences, and — only when you consent — help us measure usage and ad performance. choices anytime or review the cookie policy.

tryall.ai

Subprocessors and Service Providers

Effective: May 28, 2026. Updated: July 18, 2026.

1. Overview

This page lists vendors that help Tryall provide, secure, monitor, bill, and support the service. It includes active providers and conditional providers that are present in the product architecture or configuration but may only run when a feature or environment setting is enabled.

Some AI, payment, fraud-prevention, search, or platform providers may act as processors, service providers, independent controllers, or mixed-role providers depending on the feature, route, law, and contract. We use this page as a practical transparency list, not as a final legal classification for every provider role.

2. Current List

Tryall subprocessors and service providers
VendorPurposeDataStatusRole note
VercelApplication hosting, serverless/runtime execution, deployment infrastructure, and platform logs.Request metadata, runtime logs, deployment metadata, and data processed by the application during service delivery.ActiveProcessor/service provider for hosting and app delivery.
ClerkAuthentication, account identity, session management, and user profile services.Account identifiers, email, name/avatar where provided, auth/session metadata, and security events.ActiveProcessor/service provider for auth; some fraud/security roles may require legal classification.
StripeCheckout, billing, subscription administration, invoices, payment status, and fraud prevention.Billing contact data, Stripe customer ids, subscription metadata, checkout events, invoices, and payment status.ActivePayment provider; processor/controller role can vary for regulated payment and fraud obligations.
Google (Google Ads)Advertising conversion measurement via the Google tag (gtag.js) with Consent Mode: cookieless consent-flagged pings before marketing consent; advertising cookies and conversion identifiers only after consent.IP address, user agent, page URL, and ad-click identifiers; after marketing consent also _gcl_* cookies and conversion transaction identifiers (checkout session id, account id for sign-up conversions).ConditionalAdvertising measurement provider, active only when the Google tag is configured; CPRA sharing position and opt-out path are documented in the Privacy Policy.
OpenRouterAI gateway and routing for chat, compare, model access, image generation, search-enabled model calls, and transcription when enabled.Prompts, messages, supported attachments, generated content, model ids, usage metadata, provider request ids, and user/session routing identifiers.ActiveAI gateway/provider. Downstream provider role and retention vary by route and model.
Downstream AI model providersAI inference selected through OpenRouter or product routing, including text, multimodal, image, search-backed, and transcription-capable models.Prompts, messages, attachments, source images, generated outputs, provider metadata, and usage metadata depending on model and feature.Under reviewProvider set can vary by model, route, fallback, and plan. Tryall does not claim ZDR/no-training unless the route and terms enforce it.
SentryOperational error monitoring, diagnostics, reliability, security investigation, and incident response.Error data, stack traces, sanitized request context, route metadata, and operational diagnostics.ActiveProcessor/service provider for operational telemetry under the Sentry LIA controls.
PostHogConsent-gated product analytics using reviewed events only.Reviewed analytics events/properties, minimal identifiers, timestamps, and product metadata after analytics consent.ActiveProcessor/service provider for optional analytics. Autocapture, heatmaps, pageview/pageleave capture, and replay are disabled for the MVP.
ResendTransactional email delivery and email delivery metadata when enabled.Email address, message metadata, delivery/bounce/suppression data, and service email content.ConditionalConditional processor/service provider; production use and retention settings need final review.
SupabaseDatabase and managed storage for attachments, project sources, support files, and generated artifacts when enabled.Account/product records, uploaded files, project/source data, generated assets, support screenshots, and object metadata.ConditionalConditional processor/service provider; production storage use and retention settings need final review.
UpstashRate limits, cache, quota/admission control, Redis-like counters, and short-lived operational data when enabled.Short-lived cache keys, counters, rate-limit metadata, account/session identifiers, and operational workflow metadata.ConditionalConditional processor/service provider; TTL and production-use settings need final review.
InngestBackground workflow execution, retries, asynchronous events, and job metadata when enabled.Workflow payloads, run metadata, event identifiers, retry state, and feature-specific job data.ConditionalConditional processor/service provider; event retention and production-use settings need final review.
TavilyOptional web search and grounding when Tavily search is enabled.Search queries, search policy metadata, retrieved source metadata, snippets, and web content used for grounding.ConditionalConditional search provider; DPA, retention, transfer, and production enablement need final review.
PerplexityOptional direct search and retrieval when a Perplexity-backed search path is enabled.Search prompts or queries, generated answers, citations, source metadata, status metadata, and usage metadata.ConditionalConditional search/retrieval provider; direct Perplexity paths are not covered by OpenRouter routing controls.
LangfuseAI observability, model-call trace metadata, feedback scores, quality review, and incident debugging when enabled.Trace identifiers, model/function names, route/status/timing/token or cost-style metadata, feedback scores, and prompt/response content only if a separate capture policy allows it.ConditionalConditional AI observability provider. Disabled by default; metadata-only by default when enabled. Project region, retention, access, and DPA review are required before production enablement.
OpenAI direct APINative image mask editing when enabled; direct transcription adapter exists but was not found wired in this audit.Source images, masks, image-edit prompts, generated image outputs, and audio files if direct transcription is wired later.ConditionalConditional direct provider path. OpenRouter routing controls do not apply.

3. AI Provider Routing

Tryall is a multi-provider AI product. A selected model, Auto routing, fallback behavior, search mode, image mode, or attachment mode can change which downstream provider processes a request. Provider privacy settings, logging, retention, training controls, and availability can vary by model, route, feature, and plan.

We do not claim zero data retention, no training, or provider-side deletion unless the specific route, configuration, and vendor terms support that claim.

4. Changes

We may update vendors as the service changes. Before adding or materially changing a provider that can process personal data, Tryall should review the provider purpose, data categories, security posture, retention, transfer mechanism, DPA or equivalent terms, public notice impact, and any customer notice or objection commitments that apply.

For privacy or vendor questions, contact privacy@tryall.ai or legal@tryall.ai.