The following companies receive specific data to operate Grace. Each is contractually bound to use that data only to deliver their service to us.
- Clerk
- Authentication, sign-in, and session management. Receives your email, name, password hash, and (if enabled) MFA factors.
- Stripe
- Subscription billing and payment processing. Receives your billing email, payment method details (collected by Stripe directly, never by us), and tax/billing address.
- Resend
- Outbound email delivery (call sheets, invitations, vault shares, verification codes, and signature requests, reminders, and completed-document notifications). Receives recipient addresses and email body content.
- Cloudflare R2
- File storage for scripts, photos, screeners, dailies, and call-sheet PDFs. Files are stored encrypted at rest.
- Cloudflare
- DNS, network edge, and the marketing-site CDN. Receives standard request metadata (IP, user agent, URL path).
- Neon
- Managed PostgreSQL hosting for the Grace application database, and a separate database for our self-hosted document-signing service. Receives all structured app data described above, plus signing records and audit logs for documents sent for e-signature.
- Railway
- Application hosting and compute, both for Grace's web/server tier and for our self-hosted document-signing service. Receives all data passing through those servers.
- Sentry
- Error monitoring and diagnostics (operated by Functional Software, Inc.). Receives error messages and stack traces, the page or route where an error occurred (with sensitive tokens and query parameters redacted), browser/device/OS type, and a pseudonymous account identifier. Does not receive your name, email address, or production content.
- PostHog
- Product analytics. Receives a fixed set of explicit events — page views (recording the in-app route visited, with sensitive tokens and query parameters redacted from the path), how long a screen was open, and lifecycle actions such as sign-up, production created, or call sheet sent — carrying non-identifying counts and category labels, a pseudonymous account identifier, and pseudonymous organization and production identifiers along with a few non-identifying group attributes (the organization's subscription plan, and the production's union status, shoot-day count, and status). Sets a first-party cookie and uses browser local storage to hold the pseudonymous identifier. We do not enable session replay, autocapture, or heatmaps. Does not receive your name, email address, scripts, budgets, or other production content, and is not used to train any models. Processes this data in the United States.
- Amazon Web Services (Amazon Bedrock)
- Primary AI processing — script breakdown extraction, the Grace AI assistant panel, and VFX-shot suggestions (Anthropic Claude and related models, hosted within AWS). Receives script text/PDF and the production data needed for a request. Amazon Bedrock does not store prompts or completions, does not train models on them, and does not share them with the model providers.
- Anthropic
- Failover AI processing (Claude, direct API), used only if Amazon Bedrock is unavailable. Anthropic does not retain user-API data beyond standard operational logs and does not use it for model training.
- Google
- Secondary fallback AI processing of script content via Google Cloud Vertex AI (Gemini); Google AI Studio serves this role during the direct-API failover. Google does not use paid-tier content for model training. (Google also provides geocoding — see below.)
- Open-Meteo
- Weather data for shoot-day forecasts on call sheets. Receives latitude/longitude only, no production identity.
- Google Maps Platform (Geocoding API and Places API)
- Address-to-coordinates geocoding for production locations and nearest-hospital lookups on call sheets. Receives the address string or coordinates only, no production identity. Operated by Google under its API-tier terms; content is not used to train Google's general models.
- OpenStreetMap (Nominatim)
- City-level coordinates lookup for weather forecasts on call sheets. Receives the city string only, no production identity.
- Thy Dark Hour Systems (OPC) Pvt Ltd
- Software development, technical operations, and customer-support engineering for Grace. Personnel acting under TDH's engagement may access the production database for engineering and support purposes, under confidentiality and data-protection obligations to Obelisk Studio LLC. TDH is based in India; cross-border transfers are described under "International data transfers" below.