DevShot's external vendors and contractually confidential service categories, what they process, and where to find their compliance evidence. Last updated . Material changes are announced 30 days in advance to active customers via the email address on file.
Vendors
Supabase
Postgres database, authentication, object storage
Data accessed
All customer data (RLS-isolated; AES-256 at rest with vendor-managed KMS).
Region
EU (Frankfurt) — primary; configurable per project.
AI generation, review, computer-use reasoning, and optional speech synthesis requested in Studio.
Data accessed
Prompts, selected project context or source files, tool results and screenshots, generated outputs, and generated reply text sent for optional voice synthesis. Voice audit logs contain character count and consent version, not the voice text.
Region
United States; EEA transfer safeguards are required before personal-data production use.
Trust center
Provider identity and compliance evidence are available to business customers on request, subject to contractual confidentiality.
DPA
Provider data terms, transfer safeguards, and enterprise DPA status are available on request.
Per-VM qcow2 / raw overlay storage. The customer chooses and connects the provider.
Data accessed
Full VM disk images. The customer is the data controller for these buckets — DevShot only processes the connection metadata (provider URL, bucket name, masked credentials).