How to read this page
This page identifies third parties that may process personal data in connection with MedaStaré. Depending on the service and applicable law, a provider may act as MedaStaré's processor/subprocessor, as an independent controller for part of its processing, or in more than one role.
The list is based on the current production architecture and enabled integrations known to MedaStaré as of the effective date. A provider is not listed as active merely because MedaStaré has considered or configured it for future use.
Processing locations shown below describe the current MedaStaré configuration or the provider information MedaStaré has verified. They do not mean that a provider's support, security or downstream subprocessors are limited to a single country.
1. Scope and terminology
MedaStaré uses third-party infrastructure and specialist services to provide the application and website. These services can include hosting, authentication, database storage, media storage, AI processing, creator identity verification and payouts, weather information, geocoding and optional user-experience analytics.
For this page, processor/subprocessor means a provider processing personal data on behalf of MedaStaré for an authorized service purpose. Some providers may also determine certain processing purposes independently and therefore act as an independent controller for that limited processing. The provider's own terms and privacy notice apply to its independent-controller activities.
Downstream vendors used internally by a provider are not all repeated here. Major providers maintain their own subprocessor lists and data-processing terms, which may change independently of MedaStaré.
2. Core infrastructure providers
| Provider | Purpose | Data that may be processed | Current location / note |
|---|---|---|---|
| Google Cloud / Firebase | Firebase Authentication, Firestore database, Firebase Cloud Storage, cloud infrastructure and selected moderation/safety services. | Account and authentication data, profile data, wardrobe/style data, body-related styling data, photos and videos, MedAI records stored by MedaStaré, social interactions, consent records, coarse location fields, subscription/entitlement records and technical metadata. | Firestore: nam5 U.S. multi-region. Object storage: US-CENTRAL1. Provider support and subprocessors may operate in additional locations under Google's applicable terms. |
| Vercel | Application hosting, server/runtime execution, deployment, scheduled jobs and runtime logging. | Requests handled by the application, network and device metadata, limited application data needed to execute a request, server-side processing context and runtime logs. | Current MedaStaré application region: iad1 / U.S. East. Current MedaStaré technical inventory records approximately one-day retention for Vercel runtime logs under the production plan. Vercel may use global subprocessors under its DPA. |
MedaStaré's current Firestore configuration does not use a separate production backup as a second active copy of the database. Cloud Storage currently uses a provider soft-delete recovery layer of approximately seven days. These technical facts may change as MedaStaré improves resilience, in which case the Privacy, Security and Account Deletion disclosures will be updated.
3. AI and creative providers
| Provider | Purpose | Data that may be processed | Current location / note |
|---|---|---|---|
| OpenAI | MedAI chat/text processing, text-to-speech, realtime voice and image-input processing where used. | Prompts, chat context, user-selected images, style/wardrobe context, personalization inputs, limited body or cycle context where required by the requested feature, voice/audio during an active realtime session, generated outputs and technical request metadata. | Provider-managed API infrastructure. MedaStaré does not state one fixed processing country unless verified for the active OpenAI account and endpoint. OpenAI's business/API terms state that business/API inputs and outputs are not used for model training by default unless the customer opts in. |
| Google Gemini | Chat, visual/image-related AI processing and text-to-speech where used. | Prompts, conversation context, selected images, wardrobe/style context and other feature-specific information required for the request. | Provider-managed endpoints. The current MedaStaré technical inventory does not verify one fixed Gemini processing country. Provider-side retention and logging depend on the Gemini product, plan and feature configuration. |
| Kling AI | AI video generation and related video-processing requests. | User-selected media or generation inputs, prompts and technical request information required to generate the requested video. | Current MedaStaré implementation uses a Singapore endpoint. Provider-side retention and training are governed by the active Kling configuration and terms and are not represented by MedaStaré as zero-retention unless verified. |
| Meshy | AI-assisted 3D generation and related 3D asset processing. | Prompts, user-selected reference material and generated 3D assets or related technical metadata as required by the feature. | Meshy publicly states that its data storage uses AWS in the United States. Retention and training rules can differ by account/plan. MedaStaré therefore does not publish a universal Meshy retention or training guarantee unless verified for the active production plan. |
Not every data category is transmitted to every AI provider. MedaStaré limits each AI request to information reasonably necessary for the selected function and uses additional consent controls where required. See the AI Data Processing Notice for provider-specific consent, retention and training information.
4. Creator payout provider
| Provider | Purpose | Data that may be processed | Role / location note |
|---|---|---|---|
| Stripe / Stripe Connect | Eligible creator onboarding, identity/business verification, financial-account setup, transfers, payouts, payout status, fraud prevention and related compliance. | Creator identity and contact information, business or tax information where required, verification information/documents, connected-account identifiers, payout status, transfer records and bank/card information submitted to Stripe. MedaStaré may receive limited or masked financial-account metadata and status information made available by Stripe. | Stripe operates globally and may process data in multiple jurisdictions depending on the connected account, Stripe entity and service. Stripe may act as MedaStaré's processor for some activities and as an independent controller for regulatory, fraud, KYC/AML and other Stripe-determined processing. |
Stripe Connect is used for creator payout infrastructure. It is not the processor for ordinary MedaStaré mobile subscription purchases made through Apple App Store or Google Play billing.
Creators enter sensitive financial and identity information through Stripe-supported onboarding components. MedaStaré is designed not to store complete payment-card numbers, CVC/security codes or online-banking passwords in its own application database. Stripe may retain KYC, AML, transaction, payout or verification records when required or permitted by law.
5. Weather and location providers
| Provider | Purpose | Data that may be processed | Location / note |
|---|---|---|---|
| MET Norway (Norwegian Meteorological Institute) | Locationforecast 2.0 weather data for weather-aware styling. | Approximate coordinates needed for the forecast request and technical request metadata. Depending on request architecture, the provider may also receive an IP address associated with the request. | Norwegian public weather service. MET states that its services log technical traffic information, including IP addresses, for operations and security. MedaStaré uses coarse location of approximately one-kilometer granularity rather than a continuous precise-location history for this feature. |
| OpenStreetMap Nominatim / OpenStreetMap Foundation service | City/place resolution and geocoding for location-aware features. | Place-name queries or coordinates needed to resolve city/location information, plus normal network/request metadata. | Provider-managed public infrastructure. OSMF instructs users not to submit unrelated personal or confidential material to Nominatim. MedaStaré uses it for location resolution rather than for user profiling. |
MedaStaré currently stores coarse location context at approximately one-kilometer granularity together with city and country information where the feature is enabled. Users may disable the location feature, and account deletion removes the corresponding MedaStaré account fields subject to the limited exceptions described in the Privacy Policy.
6. Analytics and session-experience providers
Contentsquare is disclosed conditionally and should be treated as active only after the Contentsquare tag or SDK is actually deployed and begins collecting data.
| Provider | Status / purpose | Data that may be processed if enabled | Location / protection note |
|---|---|---|---|
| Contentsquare | Conditional website/app user-experience analytics, navigation analysis, performance diagnostics and Session Replay where enabled. | Page/screen views, clicks/taps, navigation events, URLs, device/browser information, session identifiers and performance information. MedaStaré has selected a Full Masking configuration for replay content. | Hosting region depends on the customer/account configuration. Contentsquare states that EU customer data is stored in the EU by default and U.S. customer data in the U.S. by default, with global support/subprocessor access subject to its DPA and transfer safeguards. |
MedaStaré does not treat configuration or account creation alone as data collection. If Contentsquare is not technically deployed, it does not receive MedaStaré visitor data merely because an account exists. Before non-essential analytics is activated in a jurisdiction requiring consent, MedaStaré will implement the applicable consent control.
7. Platforms that may act independently
Some major platforms interact with MedaStaré but are not accurately described solely as MedaStaré subprocessors because they determine significant processing purposes under their own terms:
- Apple. App Store distribution, StoreKit billing, Sign in with Apple and related platform functions. Apple processes App Store and Apple Account data under Apple's own terms and privacy rules.
- Google. Google Play distribution/billing when enabled and Google sign-in/platform services. Google may act independently for store, account and platform processing, while Google Cloud/Firebase services used by MedaStaré are separately described above as infrastructure services.
- Stripe. As described above, Stripe can act as a processor for platform-directed services and as an independent controller for certain regulatory, fraud, KYC/AML and Stripe-account processing.
MedaStaré does not receive a user's full payment-card details for subscriptions processed through the Apple App Store or Google Play.
8. International transfers
MedaStaré is a United States company and the current primary application, database and storage configuration is U.S.-based. As a result, personal data from users outside the United States may be transferred to or processed in the United States.
Feature-specific processing can also occur elsewhere. The current implementation verifies Kling processing through a Singapore endpoint, while other providers may use provider-managed global infrastructure and subprocessors.
Where applicable law requires a transfer mechanism, MedaStaré will rely on an available lawful mechanism appropriate to the transfer, such as adequacy decisions, standard contractual clauses, approved contractual safeguards, recognized certification frameworks or another legally permitted mechanism.
A provider's own subprocessor list may identify additional processing locations that MedaStaré does not directly select. MedaStaré reviews provider terms and will update this page when a material production change affects the provider, processing purpose or location disclosure.
9. Provider changes
MedaStaré may add, replace or remove providers as the architecture evolves. A provider will not be represented as active on this page solely because it is being evaluated, contracted or configured for future use.
Where a new provider will process personal data in a way that materially changes MedaStaré's privacy disclosures or requires consent, MedaStaré will update the relevant legal notice and obtain any consent required by applicable law before the new processing begins.
Changes to a provider's own downstream subprocessors are governed by that provider's applicable DPA, subprocessor notice process and contract.
10. Questions
Questions about a provider, processing purpose, international transfer or this list may be sent to support@medastare.com.
For information about personal-data rights and requests, see the Privacy Policy and Privacy Choices page.