Subprocessors
Last updated 1 September 2026.
Every third party that can receive personal data through VibeMyExpt. If a service is not on this list, it does not get your data.
Rows marked study data can receive data derived from participant responses. The rest handle only account, traffic or payment information.
| Provider | Purpose | Data | Processed in |
|---|---|---|---|
| Amazon Web Services (S3, SES) study data | File storage, stimuli, recordings, exports, outbound email | Experiment files, participant recordings, generated exports, email addresses | India (ap-south-1) |
| MongoDB Atlas study data | Primary database | Accounts, studies, sessions, trial data, payments | India |
| Cloudflare | DNS, TLS termination, DDoS protection | Traffic metadata, IP addresses in transit | Global edge network |
| Google Cloud (Vertex AI) study data | AI experiment building and analysis assistance | Researcher prompts, experiment code, dataset structure and summary statistics | United States |
| Anthropic study data | AI experiment building and analysis assistance | Researcher prompts, experiment code, dataset structure and summary statistics | United States |
| Google (OAuth sign-in) | Optional "Sign in with Google" | Email address, name, profile picture | United States |
| Google Analytics | Website usage statistics on marketing pages only | Page views, IP address, browser | United States |
| Razorpay / RazorpayX | Payments in, participant reward payouts | Payer identity, amounts, payout bank or UPI details | India |
Where data is stored
| Files, stimuli, recordings and exports (AWS S3) | India (AWS ap-south-1, Mumbai) |
| Outbound email (AWS SES) | India (AWS ap-south-1, Mumbai) |
| Application servers | India |
| Database (MongoDB Atlas) | India |
A note on the AI providers
Google Cloud and Anthropic are marked as receiving study data, which deserves an explanation rather than a footnote. When a researcher uses the analysis assistant, the dataset itself stays in their browser — but a structural description of it is sent to the model, including summary statistics and, for columns with fewer than 25 distinct values, the actual list of those values. Free-text responses are described, never quoted.
Both providers process this in the United States, and both state in their published terms that data submitted through their business APIs is not used to train their models. The full account is in the privacy policy.
Changes to this list
We will update this page before a new subprocessor starts handling personal data. Institutions with a signed data processing agreement can ask to be notified of changes in advance — email [email protected] and we will add you to the list.