Service Provider List

Last updated: August 9, 2026

kumaaa LLC uses the following service providers to deliver loopkeep. This list shows each provider's role and whether it handles relayed event bodies or metadata.

Read this list together with our Privacy Policy.

Current service providers

loopkeep service providers and the data they handle
ProviderRoleData handled
ClerkSign-in and account managementDoes not handle relayed event bodies. Handles email addresses, basic profiles, and authentication and session data.
SentryError monitoring for the gateway onlyRelayed event bodies are not sent. Handles gateway error and performance data, such as request URLs, stack traces, and traces. Hook tokens are redacted before data is sent.
VercelHosting for the website, docs, Console, and control-plane APIsDoes not handle relayed event bodies. Handles account, device, integration, workflow, webhook, run-request, and similar information processed through the Console and APIs, plus operational request metadata.
CloudflareGateway and event relay through Workers, Durable Objects, and KVHandles relayed event bodies and delivery metadata. Event bodies are used only to evaluate triggers and deliver them to devices, and may be held for up to 24 hours while undelivered. They are deleted after delivery or expiry.
SupabasePostgres database hosting for the control planeDoes not store relayed event bodies. Stores account, device-pairing, integration, workflow-name and trigger-condition, webhook, and Console run-request records. Slack access tokens are encrypted; device and webhook tokens are stored as hashes. GitHub tokens are not stored.

Contact

kumaaa LLC — legal@kumaaa.co.jp