Sub-processors
A sub-processor is a company we use to run Underlayer that processes personal data on our behalf. This page lists all of them, what each one receives, and why.
It is the list the Privacy Policy refers to, published rather than sent on request. Every entry corresponds to a service this application is configured to call, or the platform it runs on — there is no sixth integration waiting in a drawer.
1. Supabase
Supabase, Inc. provides the Postgres database, the authentication service, and the file storage behind Underlayer. It holds everything the product stores: workspaces and their members, courses and their content, themes, the identities you provision, the progress and answers recorded against those identities, and issued certificates.
It also sends the sign-in link when an Authorized User signs in by email. Supabase is a processor acting on our instructions, under its own data processing agreement.
- Receives: everything above.
- Purpose: database, authentication, and storage — the infrastructure the Services run on.
2. Stripe
Stripe, Inc. processes subscription payments. Card details are entered on Stripe's own form and never reach our servers; we store a customer reference, a subscription reference, and the plan they resolve to.
Stripe receives a billing email address and the billing details a customer types into its form. It does not receive course content, learner identities, progress, or anything else about what a workspace has built.
- Receives: billing email address, payment details entered on Stripe's form, subscription and invoice records.
- Purpose: taking payment, issuing invoices, and managing subscriptions.
3. Resend
Resend delivers the transactional email the product sends on your instruction — a course-completion notice, a confirmation that somebody accepted a team invitation, and the test certificate you send yourself from the certificate designer.
It receives the recipient address and the contents of that message, which can include a learner's name and a course title where the message is about a completion.
- Receives: recipient email address and the contents of the message being sent.
- Purpose: delivering email you asked the product to send.
4. Anthropic
Anthropic, PBC generates course drafts. It receives only the brief and source material an author explicitly submits for generation, and the draft it returns. It never receives learner identities, progress, answers, or anything from a course it was not asked to write.
Your content is not used to train any model — see the AI section of the Privacy Policy, which states that commitment and how it is held in place.
- Receives: the brief and source material submitted for generation, and nothing else.
- Purpose: drafting course content on an author's explicit instruction.
5. Vercel
Vercel Inc. hosts and serves Underlayer. Every request — to this site, the dashboard, the REST API and the embedded player — passes through its infrastructure, so it processes in transit whatever that request carries, course content and learner activity included, on the way to and from the database. It stores none of that: persistence is Supabase's job. What its infrastructure does keep is the ordinary request log, which records IP addresses and the paths requested.
Vercel also provides the Web Analytics that counts page views on these public pages: the path visited, the referring URL, and coarse device, browser and country information derived from the request. That part sets no cookie, assigns no identifier that could follow a visitor to another site, and is loaded on the public marketing pages only — not in the dashboard, and not in the embedded course player.
Vercel is a processor acting on our instructions, under its own data processing agreement.
- Receives: every request to the Services in transit, and the request logs that come with it, including IP address and path.
- Also receives: page path, referrer, and coarse device, browser and country for visits to these public pages, through Web Analytics.
- Purpose: running and serving the application, and counting page views on the marketing site.
6. Marsad — our own
Marsad records errors and counts page views for the marketing site and the dashboard. It is not another company: it is another service of Outworx for Web-Design, the establishment that operates Underlayer, and it is on this page because where your data goes is the question this page answers — and “to another of our own servers” is an answer to it, not a reason to leave it out.
When something breaks it receives the error: the message, the stack trace, the page it happened on, and the recent navigation and network activity leading up to it. That is so a fault somebody hits at three in the morning is a report we can read rather than a line in a log nobody is watching.
An error carries whatever was in flight when the failure happened, which on an authoring screen can include the title of the course being edited. It is not sent course content, learner identities, progress or answers, and screenshots on error are switched off precisely because they would reach into all of that.
Its page-view counting is cookieless. No cookie is set and nothing is stored in the browser that could follow a visitor to another site.
It is not loaded in the embedded player. See Section 7.
It runs on our own infrastructure in Tokyo, Japan. Outworx for Web-Design is licensed in Dubai, so that is a transfer outside the UAE and the transfer section of the Privacy Policy applies to it exactly as it does to the five companies above — our owning the server changes who holds the data, not which rules the transfer follows.
- Receives: errors and their surrounding context — message, stack trace, page, and recent navigation and requests — plus page views and Web Vitals timings.
- Does not receive: course content, learner identities, progress, answers, or screenshots.
- Purpose: knowing when the product breaks, and counting visits.
- Where: the marketing site and the dashboard. Not the embedded player.
- Operated by: Outworx for Web-Design — the same establishment as Underlayer. No data processing agreement is named because there is no third party to have one with.
- Hosted in: Tokyo, Japan.
7. What is not on this list
There is no advertising network, no session-recording tool, and no customer-data platform. The analytics is page-view counting and nothing more — Sections 5 and 6 — with no cookie and no identifier that could follow anybody to another site.
Neither underlayerhq.com nor the embedded player sets an advertising or analytics cookie, and the embedded player — the part your learners actually see — loads no third-party script at all. That last claim is the reason the error monitoring in Section 6 runs on our own site and dashboard and stops at the player: an embed reporting your learners' traffic to a vendor you never chose is the one thing an embeddable player must not do.
One exception worth naming, because a blanket claim would be untrue: the demo course on this site contains an embed block pointing at a third-party map, so opening it loads that third party's page in a frame and lets it set its own cookies. That is the embed block doing exactly what it does for your learners when you point one at somebody else's page — not something we collect.
If that changes, this page changes with it, and Section 8 says what notice you get first.
8. Changes to this list
We will update this page before a new sub-processor begins processing personal data, and customers on a signed Data Processing Addendum can ask to be notified by email when it does. Where the DPA gives you a right to object to a new sub-processor, that right runs from the date this page changes.
Questions, or a request to be added to the notification list, go to privacy@underlayerhq.com.