Sub-processors
A sub-processor is a company we use to run EAuth that, in doing so, processes personal data of your end users. The terms authorise the ones listed here (8.5, Annex B.8). Before one is added, every developer is told by mail and on the changelog, 30 days ahead; whoever objects on data protection grounds within those days and cannot be accommodated may end their account and export their data.
The list
Since 3 October 2026 EAuth runs on our own cluster: eight servers at five providers in Switzerland, Germany, the Netherlands and France. These companies were added on that day without the 30 days' notice, because every application registered with EAuth then belonged to Elchi Studios and nobody else had an account (terms, clause 8.6).
| Company | What it does | What it sees | Where |
|---|---|---|---|
| Infomaniak Network SA | Runs an application server, the object storage for uploaded pictures, and the server that watches the others | Everything EAuth stores, encrypted at rest as Annex C describes; profile pictures and logos | Geneva, Switzerland |
| Tavuru | Runs the primary database server | Everything EAuth stores, as above | Frankfurt, Germany |
| Hetzner Online GmbH | Runs a database replica and one of the two edge proxies, where TLS ends | Everything EAuth stores, as above; every request in transit | Nuremberg and Falkenstein, Germany |
| Scaleway SAS | Runs an application server, a database replica and the nightly copy of the pictures | Everything EAuth stores, as above | Amsterdam, Netherlands and Paris, France |
| UpCloud Oy | Runs the second edge proxy, where TLS ends | Every request in transit | Amsterdam, Netherlands |
| ClouDNS Ltd. | Answers the one DNS name behind every host with the edges that are healthy | DNS queries only, no request or account content | Sofia, Bulgaria (EU) |
| Resend, Inc. | Sends the mails EAuth sends: address confirmations, password resets, invitations | The recipient's address, the subject and the text of each mail, for as long as its logs keep them | Sent from the European Union region |
Every server is in the European Union or Switzerland, and no third party's proxy sits in front of them: a request is encrypted from the browser to our own edge proxy, and from there onward over our own encrypted network between the servers.
That is the whole list. In particular, nobody else sees sign-in data: there is no analytics, no error reporting service and no support tool outside our own.
Two services see something that is not personal data and are listed for completeness: Cloudflare holds the DNS zones of our domains and answers name lookups only, so it never sees a request or a sign-in; and when a password is checked against known breaches, only the first five characters of its SHA-1 digest are sent to Have I Been Pwned, from which neither the password nor the person can be recovered.
Changes
Every addition is a notice on the changelog, with the day it takes effect. A company removed from the list stops processing your data on the day named there.