Subprocessors
Third-party services that process data on your behalf. If a service isn't listed here, your data is not sent to it. Any change to this list is made through a code change — not hidden admin settings.
Operator contact for privacy questions: sarvesh@bwcubesmart.com. Last updated when this page was deployed — check the site footer for the current deploy date.
Active — currently receiving your data
Some are opt-in: you only share data with them if you explicitly connect that integration.
| Service | Purpose | Region | Data sent |
|---|---|---|---|
| Zoho Mail | Transactional email (verification, password reset, beta approvals) | India | Email address, user's name, message content |
| Google Gemini | AI assistant responses | US / multi-region | Chat message text; routines, reminders, life areas, goals, completion logs and a monthly finance summary (totals, top category, net worth); mood, health and journal data only if you allow it |
| Razorpay | Subscription payments and invoices | India | Name, email, phone, payment method fingerprint, billing history |
| Telegram | Chat bot link for reminders and quick capture (opt-in) | Multi-region | Message text, Telegram user/chat ID — only if you link your account |
| Google (OAuth) | Sign-in with Google (optional auth provider) | US / multi-region | Email, public profile — only if you choose Google sign-in |
| Apple (OAuth) | Sign-in with Apple (optional auth provider) | US | Email (may be relay), public profile — only if you choose Apple sign-in |
| Google Calendar | Two-way calendar sync (opt-in) | US / multi-region | Calendar events you choose to sync |
| Google Fit | Activity and sleep data sync (opt-in) | US / multi-region | Steps, heart rate, sleep sessions — only if you connect Google Fit |
| Zerodha / Groww / INDMoney | Investment balance sync (opt-in) | India | Holdings snapshots — only if you connect each account |
| PostHog | Product analytics and session replay for debugging (anonymous where possible) | EU or self-hosted | Page views, feature interactions, session recordings (with PII masking) |
| Sentry | Application error tracking | EU | Stack traces, request metadata, user id (no request body) |
| BetterStack | Uptime monitoring of the /status/ page | EU | Public status-page metadata only — no user data |
| ElevenLabs | Voice synthesis (text-to-speech) for voice replies (opt-in) | US | Text we convert to speech — only when voice output is enabled |
| Typesense | Full-text search indexing of your content (for ⌘K) | Self-hosted / EU | Indexable strings from your own entries — searchable only by you |
| GrowthBook | Feature flag service (rollout decisions) | Self-hosted | Non-user: flag configuration only |
| hCaptcha | Bot protection on public forms | Multi-region | IP, browser fingerprint — only on signup/login |
Wired but dormant — no data flowing today
Integration code exists for these but the service is gated off (awaiting credentials, domain verification, or a feature flag). Listed here so you know what could activate in the future without another code change — only a configuration flip. When that happens this page is updated in the same release.
| Service | Purpose (when enabled) | Region | Data that would flow |
|---|---|---|---|
| MSG91 | Transactional SMS (wired but currently unused) | India | Phone, message text — when SMS is sent (currently off) |
| WhatsApp (Meta) | Chat bot link (wired but currently disabled) | Multi-region | Phone, message text — when enabled |
| Cloudflare R2 | Object storage for avatars and chat images (wired, awaiting credentials) | Multi-region | Images you upload — filenames and content |
| Resend | Transactional email (wired as drop-in SMTP alternative; awaiting domain verification) | US | Email address, user's name, message content — when activated |
Retention policy
- Mood, journal, gratitude entries — kept while your account is active; hard-deleted 30 days after you close your account.
- AI conversation history — rolling 90 days, then purged automatically.
- Privacy and login audit logs — rolling 180 days, then purged automatically.
- Finance transactions — retained for 7 years (Indian tax compliance), then eligible for deletion.
- Health data — deleted immediately on request; otherwise kept while your account is active.
- Backups — rotated every 30 days.
You can export a copy of your data or request deletion at any time from Privacy & Data.
Trifini is operated as an independent project and is not yet incorporated as a company. Contact sarvesh@bwcubesmart.com for privacy questions, data requests, or suspected incidents. We aim to respond within 72 hours.