Mnemia
Sign InTry Mnemia

Sub-processors

Last updated: 23 August 2026

This is the current list of third-party providers Mnemia uses to deliver the service. It distinguishes durable storage from transient processing and avoids treating a provider's incorporation, data-centre region, support access, and network delivery as the same thing. The controller gives general authorisation for this list under the Data Processing Agreement.

Supabase, Inc.

  • Purpose: PostgreSQL database, authentication, storage, and protected Edge Functions used for encryption and processing orchestration.
  • Data: account identities; controller and relationship records; encrypted session content; permissions and audit evidence; and plaintext content in memory while an authorised Edge Function performs its task.
  • Configured locations: the project database is on AWS in Zürich, Switzerland (eu-central-2). Sensitive Edge Function execution is pinned to the same Zürich region. Network ingress and authorised provider support can involve other locations under Supabase's contractual safeguards.

Microsoft Corporation — Azure OpenAI

  • Purpose: speech-to-text transcription and selected text, document, image, continuity, and coach-reflection analysis.
  • Data: only source material selected for an action that has passed the relevant permission and authority gates, plus the minimum context needed for that action.
  • Required deployment configuration:single-region Standard transcription in Switzerland North and single-region Standard analysis in Sweden Central. Global and Data Zone deployment types are not accepted by Mnemia's release policy for client content.
  • Training and provider retention:Microsoft states that submitted prompts and outputs are not used to train its foundation models without permission. A blanket “provider never retains content” statement would be inaccurate: Azure's abuse monitoring can retain flagged content for authorised review unless the applicable modified monitoring and content-logging controls are approved and configured. Mnemia treats those settings as a release control and keeps AI unavailable when the required configuration has not been attested.

Vercel Inc.

  • Purpose: web application hosting, server functions, and delivery.
  • Data: account and service requests in transit, including protected content only where a server action needs it to perform the requested task.
  • Configured locations: dynamic server functions are pinned to Frankfurt, Germany (fra1). Static assets and network delivery use Vercel's global edge network, and authorised provider support may involve other locations under contractual safeguards.

Resend, Inc.

  • Purpose: invitations and other transactional service emails.
  • Data: recipient name and email address, delivery metadata, and the service message. Coaching notes, transcripts, and AI output are not intentionally placed in email.
  • Location: the verified Mnemia domain dispatches mail from Ireland (eu-west-1). Resend documents that account data, email metadata, logs, and API records remain in the United States regardless of the sending region; delivery also traverses the systems needed to reach the recipient. Contractual transfer safeguards apply.

PostHog, Inc.

  • Purpose: limited, cookieless measurement on the public site and during account creation only.
  • Data: a short-lived pseudonymous identifier, sanitised page path, language, landing version, broad device category, selected call-to-action source, anonymous sign-up step, and network data needed to deliver the event. Names, email addresses, query strings, invitation tokens, client identifiers, free text, form answers, session content, automatic capture, and replay are excluded.
  • Location: PostHog EU Cloud.

Stripe group companies

  • Purpose: coach subscription, payment, invoicing, and fraud prevention.
  • Data: coach/practice billing identity, payment and subscription details, billing events, and limited usage quantities needed for the selected plan. Stripe does not receive client names or coaching content for billing.
  • Location: Stripe uses regional and global infrastructure and entities as described in its services agreement and privacy documentation, with transfer mechanisms appropriate to the relevant Stripe entity.

Controller-selected external services

A coach may add an external scheduling link, such as Cal.com. That service is selected and controlled by the coach and is not used by Mnemia to process coaching content. Opening or embedding it can disclose network and booking data to that provider under the coach's and provider's notices. It is not included in Mnemia's sub-processor authorisation merely because a coach links to it.

Changes and objections

We will update this page and give reasonable advance notice before a material new or replacement sub-processor begins handling controller data. A controller may object on documented, reasonable data-protection grounds under the DPA. Removing a provider from code does not erase historical evidence about the provider version used for an earlier action.

Contact

Questions or objections can be sent to privacy@mnemia.ch.

Review version 2026-08-23-review-v1. Provider facts and operational controls are checked again before the optional AI path is enabled in each production environment.

Mnemia

Continuity in your practice.

Product
How it worksPricingChangelogTry Mnemia
Company
AboutFAQContactSign in
Legal
Privacy NoticeTerms of ServiceData Processing AgreementSub-processorsLegal notice
© 2026 Mnemia
ENFRDE
Designed and built by 0xCreativeMind