Subprocessors

Third-party services GenID uses to run the product, what each one is for, and what data it sees. See our Privacy Policy and Data Processing Agreement for the full picture.

Supabase

United States (AWS-hosted)

Primary database and file storage — session/step/certificate records, uploaded and generated images, certificate PDFs.

Data shared: Account and session data, uploaded/generated images, certificates.

Stripe (Identity)

United States

Government ID and selfie identity verification at registration, and the one-time verification fee.

Data shared: Name, email, government ID document, selfie — handled directly by Stripe; GenID stores only the verification result and Stripe's own session/verification identifiers, never the ID document or selfie image itself.

Resend

United States

Transactional email delivery — sign-in magic links and registration confirmation links.

Data shared: Email address, email content.

OpenAI

United States

Text-to-image generation (gpt-image-1) for the "generate from a prompt" step of the certification pipeline.

Data shared: Your text prompt. Uploaded/externally-sourced images are never sent to OpenAI — only prompts for images GenID itself generates.

Alchemy

United States

Polygon blockchain RPC access, used to anchor a session's root hash on-chain and to look up anchor transactions during verification.

Data shared: The session root hash (a cryptographic digest, not the image itself) submitted as transaction calldata — which, once submitted, is itself public on the Polygon blockchain, outside GenID's control.

This list reflects what the product actually calls as of this writing. We'll update it if that changes. Questions: privacy@genid.app.