Skip to content

Service Providers & International Transfers

Effective date:

Last updated:

About This List

This list supplements our Privacy Policy and identifies the principal third parties Voyager uses to process personal information or support transactions and online services.

This list does not attempt to enumerate every external service or AI provider that you independently choose to connect to Voyager. Those providers process information under the permissions you choose and their own terms and privacy notices. Where a provider below acts independently for part of a transaction, rather than solely on Voyager’s instructions, we identify that role.

Processing locations describe the primary or current processing location known to Voyager. Distributed infrastructure and provider subprocessors may involve additional authorized locations. We update this list when a principal provider or material international-transfer arrangement changes.

Supabase, Inc. — Authentication and Application Data

Role and purpose: authentication, account and session services, and application database infrastructure used for account-linked Voyager functions.

Information: account and provider identifiers, email address, session and authentication information, device and entitlement records, transaction references, and connection or operational records where applicable.

Processing location: Voyager’s production Supabase project is hosted in the United States, Ohio (AWS us-east-2). Supabase or its authorized subprocessors may perform support or service operations from other locations subject to the applicable contractual safeguards.

Transfer timing and method: over encrypted network connections when you sign in, use an account-linked feature, or when Voyager’s backend stores or retrieves the related application data.

Retention: according to the category-specific periods in our Privacy Policy. Account-linked data is retained while needed for the account or entitlement and applicable recovery periods; separately retained transaction or security records follow their own schedules.

Availability: required for account-linked and server-backed functions, but not for Free’s core local file-browsing functionality.

Cloudflare, Inc. — Network, Hosting, API, and Security Infrastructure

Role and purpose: DNS, content delivery, network security, API and Worker infrastructure, rate limiting, and related online-service operations.

Information: IP address, network and request metadata, request identifiers, security signals, and information carried by the specific online or API function being used.

Processing locations: Cloudflare operates a distributed global network. Requests can be processed in the United States and other countries in which Cloudflare or its authorized infrastructure operates.

Transfer timing and method: automatically over the network when you access the Site or use a Voyager online or API function.

Retention: Voyager-controlled general operational logs are kept for 30 days and security, fraud-prevention, or abuse-investigation logs for 90 days under our standard policy. Cloudflare may retain its own platform and security records according to its applicable terms and legal obligations.

Availability: required for the affected Site, account, and online-service functions. Local-only app functionality does not depend on every Cloudflare-backed function.

Polar Software, Inc. — Merchant of Record and Billing

Role and purpose: merchant of record and authorized reseller for purchases, including checkout, payment handling, tax, receipts, refunds, and chargebacks. Polar also acts independently for portions of the buyer transaction under its own buyer terms and privacy policy.

Information: billing email, customer and order identifiers, purchased product, payment and refund status, tax and receipt information, payment-method metadata, and chargeback information. Voyager does not intentionally receive full payment-card numbers through its app or website.

Processing locations: United States and other locations used by Polar and its payment or infrastructure partners under Polar’s applicable transfer arrangements.

Transfer timing and method: over encrypted network connections when you start or complete checkout, when Polar sends transaction updates to Voyager, or when a refund or billing-support action is processed.

Retention: Polar retains information according to its independent legal, tax, accounting, payment, and dispute obligations. Voyager separately retains its transaction records for the periods stated in the Privacy Policy, including up to 5 years for applicable order, payment, refund, tax, and supply records.

Availability: used only when you make or manage a purchase or related billing request.

Plus Five Five, Inc. (Resend) — Email Delivery and Contact Management

Role and purpose: sending service emails, account or purchase notices, and optional marketing or product communications to users who have the applicable subscription or consent status; managing email contacts and delivery status.

Information: email address, message content, subscription or suppression status, delivery and interaction metadata, and authentication, recovery, purchase, or support information included in a message where applicable.

Processing location: United States. Resend and its subprocessors may use additional locations under the applicable data-processing arrangements.

Transfer timing and method: over encrypted network connections when Voyager creates or checks a contact or sends and processes an email.

Retention: on Resend’s standard plans, email and log data is retained for 30 days and backups for 7 days; remaining customer data is deleted within 90 days after termination of the Resend service. Contact data can remain while the service relationship is active. Voyager separately retains marketing-consent records and suppression information according to the Privacy Policy.

Availability: service communications are used when needed for the requested account or transaction. Optional marketing and product communications are separate and subject to the applicable opt-in and unsubscribe controls.

PostHog, Inc. — Product Analytics and Attribution

Role and purpose: product and website analytics, source attribution, conversion measurement, and analysis of account, purchase, and product-use events.

Information: persistent browser or device identifiers, internal account-related identifiers where associated, page or route information, referrer or campaign source, event time, browser and device information, and selected product, plan, purchase, checkout, and error-event properties.

Processing location: United States. Voyager currently uses PostHog’s US Cloud endpoint.

Transfer timing and method: over encrypted network connections when analytics is enabled and browser, server, account, checkout, purchase, or product events are captured.

Retention: identifiable analytics events are retained for 90 days under Voyager’s standard policy. Irreversibly anonymized aggregate information can be retained longer.

Availability and choice: analytics and attribution are optional processing where applicable law requires a choice. Voyager provides the consent, objection, or privacy controls required for the user’s jurisdiction before relying on the applicable optional processing.

Functional Software, Inc. (Sentry) — Diagnostics and Reliability

Role and purpose: crash, error, app-hang, and performance diagnostics used to investigate reliability and operational issues.

Information: diagnostic installation identifier, filtered error codes and stack traces, app and operating-system versions, component or environment tags, and performance information. Voyager’s policy is to prevent automated diagnostic telemetry from transmitting local file contents, file names, file paths, prompts, user-entered content, or private work context.

Processing location: United States. Voyager’s production app currently uses Sentry’s US ingest region.

Transfer timing and method: over encrypted network connections when enabled diagnostics generate an event.

Retention: diagnostic crash, error, and performance records are retained for 30 days under Voyager’s standard policy.

Availability: used for operational diagnostics and reliability. Diagnostic collection is configured and minimized separately from files or content you voluntarily submit to customer support.

User-Selected External Services

Voyager can let you connect external AI, productivity, storage, or other services. We do not list every such service on this page merely because Voyager supports a connection to it. When you choose a connection, the external provider receives information needed for the connection or action you request and processes it under its own terms and privacy notice. Feature-specific information can be provided when you configure the connection.

Changes and Questions

We update this list when we add, remove, or materially change a principal provider or international-transfer arrangement. A provider change does not by itself authorize a new use of personal information beyond the purposes described in the Privacy Policy.

Questions about a provider, processing location, international transfer, or available privacy choice can be sent to privacy@voyager.fm.