TribeROI

Sub-processors

This is the canonical list of third parties involved in processing data held in TribeROI, referenced by our data processing agreement. Last updated 2026-07-30.

Sub-processors

Vendors TribeROI sends data to, or stores it with, in order to run the service.

ProviderPurposePersonal data involvedHosting region
Google Cloud PlatformAll hosting and storage: application runtime (Cloud Run), database (Cloud SQL), control plane (Firestore), secrets (Secret Manager), operational logs (Cloud Logging).All customer and community data, as the infrastructure it lives on.United States (us-central1)
Google Firebase AuthenticationWorkspace sign-in identity.Workspace users’ email addresses and login credentials.United States
AnthropicAI narration: insights, action drafts, and inline explanations, generated only when a workspace user asks.Aggregate metrics, event titles and venues, community profile text, and the question you type. Never community members’ names, email addresses, or survey text — enforced by an automated test on every change.United States
ResendTransactional email: waitlist confirmation and approval notices.Recipient name and email address for those notices only. No email is ever sent to community members.United States

Connected platforms

Platforms TribeROI reads from on your instruction, using a credential you supply and can revoke. Data flows into TribeROI from these platforms; they receive nothing from TribeROI beyond your credential and the queries needed to sync. They appear here for completeness, not because TribeROI discloses data to them.

ProviderPurposePersonal data involvedHosting region
LumaEvent, registration and attendance sync.Nothing beyond your API key and query parameters; guest data flows inbound.United States
Discourse (your own forum)Forum topics, posts and reactions sync.Nothing beyond your admin API key and query parameters; member data flows inbound. Post bodies are read for mention extraction and not stored.Wherever your forum is hosted
GitHubRepository issues, releases and contributor activity sync.Nothing beyond your read-only token and repo paths; activity data flows inbound.United States
DEV.toArticle and comment activity sync.Nothing beyond your API key and query parameters; activity data flows inbound (DEV.to exposes no member emails).United States

Questions about this list: privacy@triberoi.com.