Subprocessors

Last updated 1 September 2026.

Every third party that can receive personal data through VibeMyExpt. If a service is not on this list, it does not get your data.

Rows marked study data can receive data derived from participant responses. The rest handle only account, traffic or payment information.

ProviderPurposeDataProcessed in
Amazon Web Services (S3, SES) study data File storage, stimuli, recordings, exports, outbound emailExperiment files, participant recordings, generated exports, email addressesIndia (ap-south-1)
MongoDB Atlas study data Primary databaseAccounts, studies, sessions, trial data, paymentsIndia
CloudflareDNS, TLS termination, DDoS protectionTraffic metadata, IP addresses in transitGlobal edge network
Google Cloud (Vertex AI) study data AI experiment building and analysis assistanceResearcher prompts, experiment code, dataset structure and summary statisticsUnited States
Anthropic study data AI experiment building and analysis assistanceResearcher prompts, experiment code, dataset structure and summary statisticsUnited States
Google (OAuth sign-in)Optional "Sign in with Google"Email address, name, profile pictureUnited States
Google AnalyticsWebsite usage statistics on marketing pages onlyPage views, IP address, browserUnited States
Razorpay / RazorpayXPayments in, participant reward payoutsPayer identity, amounts, payout bank or UPI detailsIndia

Where data is stored

Files, stimuli, recordings and exports (AWS S3)India (AWS ap-south-1, Mumbai)
Outbound email (AWS SES)India (AWS ap-south-1, Mumbai)
Application serversIndia
Database (MongoDB Atlas)India

A note on the AI providers

Google Cloud and Anthropic are marked as receiving study data, which deserves an explanation rather than a footnote. When a researcher uses the analysis assistant, the dataset itself stays in their browser — but a structural description of it is sent to the model, including summary statistics and, for columns with fewer than 25 distinct values, the actual list of those values. Free-text responses are described, never quoted.

Both providers process this in the United States, and both state in their published terms that data submitted through their business APIs is not used to train their models. The full account is in the privacy policy.

Changes to this list

We will update this page before a new subprocessor starts handling personal data. Institutions with a signed data processing agreement can ask to be notified of changes in advance — email [email protected] and we will add you to the list.