We do not sell your personal data. We do not share it for cross-context behavioral advertising. We do not trade, rent, or license it to data brokers.
We do use a small number of vendors to run the service, and your data passes through them because it has to. They process data under their applicable terms to provide and secure the assigned service. Counsel and operator verification of those terms remains a launch gate:
—
Supabase — database, authentication, and photo storage.
—
Cloudflare — website hosting and network security.
—
Stripe — Checkout, subscription billing, and the Customer Portal. Stripe receives your billing contact and payment details. We do not store your full card number or card security code.
—
Our configured AI provider — analyzes the scan photo, or a short-lived link to it, only to return the diagnosis you requested.
—
Sentry — receives scrubbed technical error reports when monitoring is configured; replay, request bodies, credentials, contact fields, and customer content are excluded.
—
Our email provider — delivers the messages you have asked for.
—
Open-Meteo — receives configured regional grid coordinates to return forecasts. Those approximate coordinates come from your ZIP code, not your name, email, street address, or device location.
If you submit a service request and we bring in an outside provider to do the work, the contact details and request summary you entered go to that provider so they can reach you. We will tell you that at the point you submit the request, before you send it — you will not find out afterward. These are independent local service providers, not ConcordiaPax employees, agents, or partners.
We may also disclose information if the law requires it, or to protect someone’s safety or our legal rights.