App Subprocessors
Effective Date: August 3, 2026
This page lists the third-party service providers (“subprocessors”) that BLOS Platforms Inc. (“Maura,” “we,” “us,” or “our”) engages to process personal data on our behalf in connection with our mobile application and related backend Services (together, the “App Services” for purposes of this page).
This list supplements our App Privacy Policy. Capitalized terms used but not defined here have the meanings given in that Privacy Policy.
We may update this list from time to time as we add, replace, or remove service providers. The “Effective Date” above reflects the most recent update. Please check this page periodically for changes.
For subprocessors used in connection with our marketing website and Partner-facing web app, see our Website & Web App Subprocessors page.
Scope
This list covers subprocessors used to operate, host, authenticate users of, store data for, deliver push notifications from, monitor, and provide AI-powered features within the App Services.
It does not cover:
- Subprocessors used solely in connection with our marketing website (see Website & Web App Subprocessors).
- Independent third parties that process personal data as separate controllers (for example, social media platforms when you interact with them outside the App Services), except where they act as our service providers.
- Service providers that may be configured only in a vendor dashboard and are not evidenced as direct application dependencies (for example, an SMTP or email provider configured in Supabase Auth for transactional auth emails). If engaged, those providers may process personal data and will be reflected here when identified.
Our Subprocessors
| Subprocessor | Service | Purpose of processing | Categories of personal data (typical) | Location |
| Supabase, Inc. | Authentication, Postgres database, Realtime, and database webhooks | Authenticates users; stores and serves application data; enables realtime updates and server-side database events | Account credentials and identifiers; profile and account information; content and activity you submit or generate in the app; technical logs related to auth and database access | United States |
| Cloudflare, Inc. | Application hosting (Workers), R2 object storage, KV, Images, Workflows, Observability, and AI Gateway | Hosts and runs application backends and workflows; stores and delivers media; caches/configures data; routes AI requests; collects operational logs and metrics | Internet and network activity information; media files and associated metadata; application request/log data; prompts, embeddings-related inputs, and model outputs routed through the AI gateway where applicable | United States and Cloudflare’s global edge network |
| Google LLC | Generative AI (Gemini via AI Gateway), Vertex AI embeddings, and Search grounding | Powers AI features such as content analysis, embeddings, and grounded search (for example, on receipts or similar user-submitted materials) | User-submitted content and derived inputs provided to AI features; embeddings and model outputs; related technical metadata | United States |
| Functional Software, Inc. (Sentry) | Error and performance monitoring | Captures application errors, performance traces, and diagnostic data to help us maintain and improve the App Services | Device/app diagnostic data; stack traces; performance metrics; and limited contextual data that may appear in error reports (which we configure to minimize personal data where practicable) | United States |
| Expo (Expo Application Services / related Expo entities) | Mobile push notification delivery | Sends push notifications to user devices via Expo’s push API | Push tokens; notification payloads; device/platform identifiers needed for delivery | United States |
| Apple Inc. | App distribution (App Store / TestFlight) and Apple Push Notification service (APNs), including delivery routed via Expo | Distributes the iOS app; delivers push notifications to Apple devices | Apple account/distribution-related identifiers as applicable; push tokens and notification delivery data for iOS devices | United States |
| Google LLC | Firebase SDK (Google Analytics for Firebase) | Collects app usage analytics, event tracking, and related diagnostics to help us understand how the App Services are used and improve them | App usage events and interactions; device and app identifiers; crash and performance data associated with analytics events | United States |
| Google LLC | Google Fonts | Serves web fonts used in certain app web surfaces (for example, Outfit and Source Serif 4) | Internet and network activity information associated with font requests (such as IP address and user agent) when fonts are loaded from Google’s servers | United States |
How We Use These Providers
- Authentication and data platform. Supabase provides user authentication, primary database storage, realtime functionality, and related database webhooks for the App Services.
- Hosting, media, and infrastructure. Cloudflare hosts application backends and workflows, stores and processes media, and provides edge infrastructure, observability, and AI request routing.
- AI features. Google Cloud / Google AI services (including Gemini, Vertex embeddings, and Search grounding) process inputs you provide when AI features are used, to generate embeddings, grounded results, and other model outputs.
- Reliability and diagnostics. Sentry helps us detect, diagnose, and resolve errors and performance issues.
- Push notifications. Expo delivers mobile push notifications, with Apple (APNs) performing platform-level delivery to iOS devices.
- Analytics. Google Analytics for Firebase (via the Firebase SDK) collects app usage events and diagnostics to help us understand usage patterns and improve the App Services.
- Presentation. Google Fonts may be used to load fonts on certain web-rendered surfaces of the App Services.
Transfers
Some of our subprocessors are located in, or process personal data in, the United States and other countries that may not provide the same level of data protection as your country of residence. Where required, we rely on appropriate transfer mechanisms and contractual protections with our providers. See Section 6 and Section 7 of our App Privacy Policy for more information.
Updates to This List
We may update this Subprocessors list to reflect changes to our service providers or the App Services. Material changes will be indicated by updating the Effective Date on this page. Continued use of the App Services after an update constitutes acknowledgment of the revised list to the extent permitted by applicable law.
If you are a Partner with a written agreement that requires advance notice of subprocessor changes, that agreement controls to the extent of any conflict with this page.
Contact Us
If you have questions about this Subprocessors list or how we process personal data, please contact us at privacy@maurainc.com.
For broader information about our privacy practices, please see our App Privacy Policy.