Twellie policy
Sub-Processors
Plain-English terms for using Twellie's buyer-side property reports, valuation logic, privacy controls, and support policies.
Last Updated: July 10, 2026
This page lists the third-party Sub-processors EnglishAidol LLC engages to operate the Twellie service. EnglishAidol LLC is the Processor under the Data Processing Addendum; Twellie is the name of the Service, not a separate legal entity. This page also supplements the Privacy Policy.
Enterprise customers with executed DPAs will receive notice of new Sub-processors at least fifteen (15) days before they begin Processing Personal Data. Consumer users are notified by an update to this page and, where feasible, by email.
Current Sub-Processors
| Provider | Purpose | Data Handled | Location | Certifications |
|---|---|---|---|---|
| Supabase, Inc. | Authentication (Supabase Auth), relational database (Postgres), file/object storage, realtime, row-level security | Account credentials (hashed), profile data, Reports, usage counters, subscription metadata, uploaded files | United States (primary), with regional replicas where elected | SOC 2 Type II (Supabase parent), underlying AWS infrastructure |
| Vercel, Inc. | Hosts the static web application and proxies same-origin /api requests to the API service |
Request metadata; API request/response payloads in transit, which can include account, property-address, and buyer-brief data | United States / global edge network | Vercel-published security and compliance attestations |
| Fly.io, Inc. | Hosts the Twellie Python API | Request metadata and submitted account, property, buyer-brief, report, and billing-reference data processed by the API | United States / selected deployment region | Fly.io-published security and privacy commitments |
| Stripe, Inc. | Payment processing, invoicing, tax calculation (Stripe Tax), fraud screening (Radar), subscription management, Billing Portal, Checkout | Cardholder data (processed by Stripe; we see only last 4 + brand), billing name/address, subscription status, transaction history | United States, EU | PCI-DSS Level 1, SOC 1/2/3, ISO 27001 |
| AI business API providers | AI model providers for vision (photo analysis), report synthesis, scoring, and fallback processing | Property addresses, photos (base64), listing text, buyer-profile inputs. Business-API data is processed under commercial data-protection commitments and is not used to train foundation models. | United States (global for model inference) | Enterprise-grade security and compliance programs, including SOC 2 / ISO-aligned controls where applicable |
| Resend Inc. | Transactional email (welcome, report-ready, deletion confirmation, win-back) | Email address, subject, body; bounce/complaint metadata | United States | SOC 2 Type II (in progress), GDPR-aligned DPA |
| Sentry | Error monitoring, performance tracing, release-health tracking | Stack traces, request metadata (URL, method, status), user ID tag, sanitised event payloads (credentials and PII scrubbed client-side before transmission) | United States | SOC 2 Type II, ISO 27001 |
| Meta Platforms, Inc. — Pixel + App Events + Conversions API | Ad attribution, conversion measurement, remarketing | Hashed email and phone (where user identified), event names, timestamps; subject to user opt-in / GPC / ATT | United States | ISO 27001 (underlying infra) |
| Google LLC — Analytics 4 + Google Ads | Product analytics, attribution, conversion tracking | Pseudonymous device identifier, IP (truncated), page path, event parameters | United States / EU region where selected | ISO 27001, SOC 2 |
| Cloudflare, Inc. | DNS, CDN, DDoS protection, TLS termination at the edge (if/when enabled) | Request metadata (IP, user-agent, request path, response status) | United States with global edge PoPs | SOC 2 Type II, ISO 27001 |
| Shorebird | Over-the-air Flutter updates for the mobile apps | App version metadata, device identifier (Shorebird-generated, not the OS ad ID), optional crash metadata | United States | Standard commercial contract, no PII shared |
| Apple Inc. | iOS app distribution, in-app purchase where used, push-notification service (APNs) | Account email (for iCloud Family Sharing if enabled), purchase receipts (when IAP used), device token for push | United States, EU | Apple published privacy commitments |
| Google LLC — Play Services | Android app distribution, optional in-app billing, Firebase Cloud Messaging for push | Account email (Play account), purchase receipts, FCM device token | United States, EU | SOC 2, ISO 27001 |
| FEMA (federal agency) | Flood-zone data (public records) | Property latitude/longitude (not Personal Data about users) | United States | Not applicable (federal agency) |
| U.S. Census Bureau, FRED (Federal Reserve), USGS, EPA | Public demographic, macro-financial, seismic, environmental data | None (user data is not transmitted to these sources) | United States | Not applicable |
| Fortnoff Financial LLC (RentCast) | Supplies provider-reported property, listing, tax/assessment, and comparable-sale records for report generation and coverage testing | Property addresses submitted for a report or canary; returned property/listing records; request and response metadata | United States | Provider-published privacy and security safeguards; no independent certification claimed by Twellie |
RentCast is the designated production property-data provider. Paid report checkout is configured to fail closed unless a documented provider-rights review has been completed and PAID_REPORT_DATA_RIGHTS_CONFIRMED=true is deliberately enabled. Adding or replacing a production property-data vendor requires an update to this register before activation.
Historical Sub-Processors
| Provider | Relationship Ended | Notes |
|---|---|---|
| Apify Technologies s.r.o. | July 10, 2026 | Used only for pre-launch Zillow-derived collection testing. It is not a production source or automatic fallback. This historical disclosure will remain listed for at least 12 months. |
Upcoming Sub-Processors (Notice Period)
| Provider | Purpose | Earliest Date | Status |
|---|---|---|---|
| (announcements will be listed here at least 15 days before activation, giving DPA'd customers time to object) |
Changes Log
- 2026-04-19 — Initial publication of this page.
- 2026-07-10 — Disclosed Apify pre-launch testing use and removed hypothetical property-data licensees from the current-provider list.
- 2026-07-10 — Named RentCast as the designated production property-data processor and moved Apify to historical testing; Apify is not a production fallback.
Contact
To object to a new Sub-processor (customers with an executed DPA): legal@twellie.com with subject line "Sub-processor objection — [vendor]".
General questions: privacy@twellie.com.
© 2026 EnglishAidol LLC. Twellie is a service operated by EnglishAidol LLC.