Trust Center

Subprocessors

Last updated: 16 August 2026

The providers Securely actually uses for hosting, AI analysis, payments and email — and what each one processes.

UK GDPR alignedTLS in transit · provider encryption at restUK-builtPlain-English policies

1. Overview

Securely is operated by Ashley Evans, a sole trader in the United Kingdom. To run the service we rely on a small number of third-party providers. This page lists the providers actually in use, what each processes, and why. It supplements Section 12 of our Privacy Policy. We do not sell personal data, and we do not currently use a third-party product-analytics or advertising provider. Each provider below acts on our instructions and is bound by data-processing terms; none is permitted to use your data for its own purposes. Because Google Play’s Data Safety section treats any transfer to a third party as “sharing” — including transfers to a processor — the transfers described here are what our Play Store listing declares as shared data.

2. Current providers

ProviderPurposeData processed
SupabaseDatabase, authentication, file storage, realtimeAccount data, scan history, uploaded evidence, cases, alerts, preferences
LovableApplication hosting, build and deployment of the web app and server functionsRequest traffic and infrastructure/diagnostic logs
OpenAIAI analysis of submitted content (scanners, scam checkers, OCR, case summaries)Message text, link details, transcripts, uploaded screenshots/documents and extracted text
StripeWebsite subscription payments, invoicing and receiptsEmail address, payment method (held by Stripe), subscription and invoice metadata
Google Play Billing / Google Play servicesAndroid app distribution and in-app subscription paymentsGoogle account payment data (held by Google), purchase and order identifiers
RevenueCatAndroid subscription entitlement managementSecurely user identifier, purchase and subscription identifiers, entitlement status
Email delivery providerTransactional and opted-in email, unsubscribe and bounce handlingEmail address, message content, delivery and open status
Google FontsWeb font delivery for securelyapp.co.ukYour IP address and user-agent, sent by your browser when a page loads fonts

3. A note on AI processing

Content you submit to an AI-powered feature is sent to OpenAI's API over TLS so it can be analysed and a result returned. Under the OpenAI API data terms in force at the time of writing, API content is not used to train OpenAI's models by default and may be retained for a limited period for abuse monitoring before deletion. Those terms are set by OpenAI and may change. Avoid pasting passwords, PINs or one-time codes into any scan.

3a. How these providers map to the Google Play “Data shared” label

  • OpenAI — receives the content you submit for analysis: message and listing text, links, call transcripts, case notes, and uploaded screenshots, photos and documents. Declared on Play as sharing of “Other in-app messages”, “Photos” and “Files and docs”.
  • RevenueCat and Stripe — receive your Securely user identifier and subscription/purchase identifiers so your entitlement matches your account. Declared on Play as sharing of “User IDs”. Stripe also receives your email address for receipts and invoicing.
  • Supabase and Lovable — host the database, storage and application. They hold data on our behalf as infrastructure rather than receiving an onward transfer for their own use.
  • Payment card details — never pass through Securely. Stripe and Google Play Billing collect them directly on their own checkout surfaces, so “Payment info” is declared as not collected by us.
  • Your stored IP address — the IP captured in your legal acceptance record stays in our own database and is not transferred to OpenAI, Stripe, RevenueCat or Google.

“Shared” in the Play sense does not mean sold, rented or traded. Securely does none of those things.

4. International transfers

Several providers are based outside the UK, including in the United States. Where personal data is transferred internationally we rely on the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision, as offered by the provider.

5. Changes to this list

We will update this page when we add or remove a provider that processes personal data. Questions: privacy@securelyapp.co.uk.