Subprocessors & Data Retention
Last updated: August 12, 2026
Overview
To operate BoardRecord, we rely on a small number of trusted third-party service providers ("sub-processors") that process data on our behalf. Each is bound by a data processing agreement and is permitted to use data only to provide their service to us. We do not sell your data, and we do not use your content to train AI models.
This page is maintained as our sub-processors change. Questions? Contact privacy@boardrecord.com.
Current Sub-processors
| Provider | Purpose | Data processed | Location |
|---|---|---|---|
| Supabase | Managed PostgreSQL database and authentication | Account data, workspace content, emails, invoices, audit logs | United States |
| Amazon Web Services (AWS) | Object storage (S3), inbound/outbound email (SES), document processing (Lambda) | Uploaded documents, email content and attachments | United States (us-east-1) |
| Vercel | Application hosting and edge network | Request metadata, access logs | United States |
| Stripe | Subscription billing, ACH funding, Connect payouts, 1099-K tax reporting | Billing details, tokenized bank accounts, vendor tax IDs (held by Stripe) | United States |
| OpenAI | AI extraction of invoices and structured data from documents and email | Email and document content submitted for extraction | United States |
| Mailgun | Inbound email routing and delivery | Email content and attachments | United States |
| Sentry | Application error monitoring | Diagnostic and error data (configured without PII capture) | United States |
| Upstash | Rate limiting | IP addresses and request identifiers | United States |
| Segment | Product analytics | Usage events and device information | United States |
Payment card and bank account numbers are tokenized and stored by Stripe — BoardRecord never stores raw card or bank account numbers. Vendor tax identifiers (EIN/SSN) for 1099 reporting are collected and held by Stripe, not in our database.
Regions above reflect each provider's default region for our current configuration. Contact privacy@boardrecord.com to confirm the exact processing region for any provider.
Data Retention
- Workspace content (projects, documents, emails, invoices, vendors, payments, audit logs) is retained for as long as the board's account is active.
- Deletion: an owner can permanently delete a board and all of its database records at any time from Settings → Danger Zone. Corresponding copies in provider backups roll off on our providers' schedules, generally within 30 days.
- Sub-processor copies: data processed by the providers above is retained under each provider's own data processing agreement and retention schedule, which we do not control. Notably, Stripe retains payment and tax records to meet its own legal and financial-reporting obligations, and content sent to OpenAI is retained briefly for abuse monitoring and is not used to train models.
- Logs and diagnostics (access logs, error monitoring) are retained for a limited period for security and reliability, then purged.
- Export: admins can download a machine-readable copy of a board's data at any time from Settings → Data & Privacy.
Related Policies
See our Privacy Policy for how we collect and use data, and our Security Protocol for how we protect it.