Last updated: July 22, 2026
This page lists the third-party providers involved in operating EzCoder, grouped by their role. Locations show each provider's primary place of business; processing locations can vary, and details are available on request. We will give notice of material additions to the platform subprocessor list through the platform or by email. See our Privacy Policy for how we handle your data and our Data Processing Addendum for the terms that apply when we process data on your behalf.
Providers EzCoder appoints to help run the platform. "When configured" means the provider is used only where the related infrastructure is enabled.
| Provider | Purpose | Data handled | Location |
|---|---|---|---|
| Anthropic | AI code and chat generation | Prompts, code, project content | United States |
| OpenAI | Image generation, embeddings, audio transcription | Prompts, code snippets, media inputs | United States |
| AI processing for lightweight tasks; sign-in | Prompts, conversation summaries; sign-in profile | United States | |
| OpenRouter | AI request routing to model providers (when enabled; otherwise requests go directly to the provider) | Prompts, code, project content (same as the underlying model) | United States |
| Voyage AI | Code-search embeddings and reranking | Code and document snippets (secret-scanned) | United States |
| Supabase | Primary database, authentication, and file storage | Account data, projects, conversations, customer records, uploads | United States |
| Neon | Per-project application databases and sign-in for the apps you build | Your app's data and your app end-users' records and credentials | United States |
| Fly.io | Application hosting for previews and deployed sites | Project code and running applications | United States |
| Cloudflare | Content delivery, DNS, traffic routing, object storage (R2), and domain registration | Site traffic metadata (visitor IP, hostname, request data), stored files, and domain/registration metadata | United States |
| Upstash | Caching, job scheduling (QStash), and search/vector indexes | Session state, queued job data (may include code for indexing) | United States |
| Amazon Web Services (S3) | Audit-log archive storage (when configured) | Security/audit event records | United States (us-east-1) |
| Stripe | Payment processing and seller payment accounts (Connect) | Email, name, payment and subscription data | United States |
| Resend | Transactional and campaign email delivery | Recipient email addresses and message content | United States |
| GitHub | Sign-in and repository import | Sign-in profile; repository contents you import | United States |
| Sentry | Error monitoring | Error reports and request context (scrubbed of known personal data; may include pseudonymous identifiers) | United States |
| Slack | Internal operational and security alerting (when configured) | Alert context (may include account, project, and IP identifiers) | United States |
| Grafana Cloud | Operational metrics monitoring (when configured) | Aggregated performance metrics — no personal content | United States |
| ip-api.com | IP-based sign-in security checks (location and risk signals for account protection) | Sign-in IP addresses (until our licensed HTTPS endpoint is enabled, lookups use the provider’s standard endpoint, which is not encrypted in transit) | Varies |
Appointed by EzCoder, but active only when you use the related feature.
| Provider | Purpose | Data handled | Location |
|---|---|---|---|
| Twilio | SMS delivery for campaigns and alerts | Recipient phone numbers and message content | United States |
| fal.ai | Image and video generation model hosting | Generation prompts and reference media | United States |
| Runway | Video generation | Video prompts and reference media | United States |
| Luma | Video generation | Video prompts and reference media | United States |
| Replicate | Image and video model hosting | Generation prompts and reference media | United States |
| Stability AI | Image generation model hosting | Generation prompts and reference media | United States |
| HeyGen | Avatar video generation | Scripts and avatar selections | United States |
| D-ID | Avatar video generation | Scripts and source images | Israel |
| Ideogram | Image and logo generation | Generation prompts | Canada |
| Pexels | Stock image search | Search query terms | United States |
| Pixabay | Stock image search | Search query terms | Germany |
| Brave Search | Web search for research features | Search query terms | United States |
| SerpAPI | Web search (alternate engine) | Search query terms | United States |
| Google Custom Search | Web and image search | Search query terms | United States |
| Google Ads, Meta, TikTok (marketing APIs) | Ad campaign management and audiences, when you connect your ad accounts | Campaign content; audience identifiers in hashed form | United States |
| X, Facebook/Instagram, TikTok (publishing) | Social publishing, when you connect your social accounts | The posts and media you choose to publish | United States |
Third-party data APIs that the applications you build call through EzCoder's runtime gateway. The data here belongs to your app and its visitors, and you are responsible for disclosing these in your own site's privacy notice. This is a representative list.
| Provider | Purpose | Data handled | Location |
|---|---|---|---|
| OpenWeatherMap | Weather data for apps that request it | Location terms your app sends | Varies |
| LocationIQ | Geocoding and maps for apps that request it | Address/location terms your app sends | Varies |
| ip-api.com | IP geolocation for apps that request it (called over the provider’s standard endpoint, which is not encrypted in transit) | Visitor IP addresses your app sends | Varies |
| Finnhub, CoinGecko, ExchangeRate-API | Market, crypto, and currency data for apps that request it | Query terms your app sends | Varies |
| NewsAPI, RestCountries, and other public data APIs | Reference data for apps that request it (a representative set; your app may call others you configure) | Query terms your app sends | Varies |
When you connect your own account or supply your own API key for a third-party service — for example SendGrid, ElevenLabs, QuickBooks, HubSpot, Salesforce, or another integration — that service is used only at your direction and is governed by your agreement with the provider. That provider is not an EzCoder-appointed subprocessor, and these services are not included in the platform subprocessor list above.
Questions about this list can be sent to [email protected].