TribeROI
Sub-processors
This is the canonical list of third parties involved in processing data held in TribeROI, referenced by our data processing agreement. Last updated 2026-07-30.
Sub-processors
Vendors TribeROI sends data to, or stores it with, in order to run the service.
| Provider | Purpose | Personal data involved | Hosting region |
|---|---|---|---|
| Google Cloud Platform | All hosting and storage: application runtime (Cloud Run), database (Cloud SQL), control plane (Firestore), secrets (Secret Manager), operational logs (Cloud Logging). | All customer and community data, as the infrastructure it lives on. | United States (us-central1) |
| Google Firebase Authentication | Workspace sign-in identity. | Workspace users’ email addresses and login credentials. | United States |
| Anthropic | AI narration: insights, action drafts, and inline explanations, generated only when a workspace user asks. | Aggregate metrics, event titles and venues, community profile text, and the question you type. Never community members’ names, email addresses, or survey text — enforced by an automated test on every change. | United States |
| Resend | Transactional email: waitlist confirmation and approval notices. | Recipient name and email address for those notices only. No email is ever sent to community members. | United States |
Connected platforms
Platforms TribeROI reads from on your instruction, using a credential you supply and can revoke. Data flows into TribeROI from these platforms; they receive nothing from TribeROI beyond your credential and the queries needed to sync. They appear here for completeness, not because TribeROI discloses data to them.
| Provider | Purpose | Personal data involved | Hosting region |
|---|---|---|---|
| Luma | Event, registration and attendance sync. | Nothing beyond your API key and query parameters; guest data flows inbound. | United States |
| Discourse (your own forum) | Forum topics, posts and reactions sync. | Nothing beyond your admin API key and query parameters; member data flows inbound. Post bodies are read for mention extraction and not stored. | Wherever your forum is hosted |
| GitHub | Repository issues, releases and contributor activity sync. | Nothing beyond your read-only token and repo paths; activity data flows inbound. | United States |
| DEV.to | Article and comment activity sync. | Nothing beyond your API key and query parameters; activity data flows inbound (DEV.to exposes no member emails). | United States |
Questions about this list: privacy@triberoi.com.