Subprocessors
Latest Update: August 2026
This page lists the third-party service providers (“Subprocessors”) that Dollar Diary uses to deliver, secure, and operate the Services. We share the minimum data necessary with each provider for the purpose described. Our use of these providers is governed by our Privacy Policy and Terms of Service.
What is a Subprocessor. A subprocessor is a third party that processes personal or account data on our behalf to provide a specific component of the Services (for example, payment processing, hosting, or transactional email). We remain responsible for the data we share and select providers with appropriate security and compliance practices.
Current Subprocessors.
(a) Stripe (Banking & Payments). Stripe Financial Connections provides bank account linking and transaction syncing. Stripe authenticates directly with your financial institution, so Dollar Diary never sees or stores your bank login credentials. We receive bank account metadata, transaction data, and an encrypted access token used for ongoing sync. Stripe also processes subscription payments; payment card details are entered directly into Stripe and never touch our servers. Subject to Stripe’s terms and Privacy Policy.
(b) Google (Sign-In). Google OAuth is used for account authentication. When you sign in, Google shares your name, email address, and profile picture with Dollar Diary. We do not receive your Google password. Subject to Google’s Privacy Policy.
(c) PlanetScale (Database). Hosts our primary application database, including your account, workspace, transaction, tag, budget, and configuration data. Data is encrypted in transit and at rest. Subject to PlanetScale’s Privacy Policy.
(d) Cloudflare (Edge & Infrastructure). Provides our application hosting (Workers), DNS, DDoS protection, caching, and object storage (R2/KV). Cloudflare processes requests to and from the Services and stores certain operational data (cached responses, session keys, uploaded assets such as custom icons). Subject to Cloudflare’s Privacy Policy.
(e) Fly.io (SQL Execution). Runs the per-workspace DuckDB execution server that powers the SQL editor and DuckDB exports. When you run a query, the relevant workspace’s transaction data is loaded into a DuckDB instance on Fly.io infrastructure for the duration of the query. Subject to Fly.io’s Privacy Policy.
(f) Tigris (Durable Cache). Stores the per-workspace DuckDB database file used by the SQL editor as a durable cache, so cold machines can re-attach without re-bootstrapping from the primary database. Files are scoped per workspace and refreshed when underlying data changes. Subject to Tigris’s Privacy Policy.
(g) OpenAI (AI Features & Error Triage). Powers merchant identification, tag keyword suggestions, SQL query generation, custom icon image generation, related content moderation, and Codex-assisted incident response. Depending on the feature, we send limited context such as a raw bank descriptor, tag names, query prompts and workspace schema metadata, icon descriptions, reference images you provide, or redacted error logs and relevant source files. We do not send transaction amounts, dates, annotations, financial account details, bank credentials, or your full transaction dataset. Subject to OpenAI’s Privacy Policy.
(h) Resend (Transactional Email). Delivers transactional emails such as workspace invitations, identity-link confirmations, and farewell data exports. Your email address and display name are shared with Resend to send these messages. Subject to Resend’s Privacy Policy.
(i) BetterStack (Logging). Receives server-side application logs used for operations and incident response. Logs may include user identifiers, workspace identifiers, and request metadata; sensitive fields (tokens, secrets, payment data) are stripped before logging. Subject to BetterStack’s Privacy Policy.
(j) Airtable (Feedback). If you submit feedback through the application, your feedback message, your account email address, and a user identifier are stored in Airtable. Subject to Airtable’s Privacy Policy.
(k) Brandfetch and Logo.dev (Merchant Logos). Merchant logos shown alongside your transactions are looked up by merchant domain (for example, “chipotle.com”). Transaction amounts, account details, and personal data are never sent to these providers. Logos from Logo.dev and Brandfetch are hotlinked, as their terms require: your browser requests the image from their CDN directly, so they receive your IP address, your browser user agent, and the merchant domain being displayed. Subject to Logo.dev’s Privacy Policy and Brandfetch’s Privacy Policy.
Data Locations. Subprocessors may store and process data in the United States and other regions where they operate infrastructure. By using the Services, you consent to such international transfers as necessary to deliver the Services.
Updates to This List. We may add, remove, or replace subprocessors as the Services evolve. Material changes will be reflected on this page, and the “Latest Update” date above will be revised. For significant changes, we will also provide notice through the Site, an in-app notification, or email.
Contact. For questions about our subprocessors or data handling, contact us at info@dollardiary.com.