Skip to content

Sub-processors

Vendors that help us run the planner. Last updated 19 September 2026.

End of Life Planner uses selected third parties (“sub-processors”) to operate the website and planner. This list is part of our Privacy Policy. Use of the Service is also governed by the Terms & Conditions.

Our approach

  1. Data minimization. Each vendor receives only what it needs to do its job. Vault files go to object storage as ciphertext. Optional assist sends only the text you type in that box.
  2. Security. We look for TLS in transit and encryption at rest where the vendor offers it. No vendor holds your passphrase.
  3. Contracts. Where a vendor processes personal information for us, we use written terms that require appropriate protection, including a DPA and transfer safeguards where required by law. Polar may act as an independent controller for checkout; each provider’s role is determined by the contract and privacy terms applicable to that processing.
  4. Least privilege. Access to production systems is limited to services and people who need it.
  5. Transparency. We keep this page current. Material changes are also reflected in the Privacy Policy.

Notification of changes

We will update this page when we add or replace sub-processors. For material changes, we aim to give at least 30 days’ notice by posting here and, where we have an email on your account, by email. Continued use after that notice period is governed by the Terms and does not replace any consent required by privacy law.

Current sub-processors

  • Hetzner (EU) Hosting and infrastructure (application servers). The website and planner application; account and operational metadata needed to run the server.
  • MongoDB (EU (self-managed on Hetzner)) Application database. Account email, entitlements, encrypted plan envelopes, invite and check-in metadata. Not vault file bytes.
  • Cloudflare R2 (US) Object storage for the encrypted vault. Vault objects as ciphertext only. We do not store vault plaintext there.
  • Polar.sh (EU (Sweden)) Checkout and payment processing. Customer, checkout, and order identifiers needed to unlock or revoke access. Polar handles card data and may act as an independent controller for checkout.
  • Resend (US) Transactional and consented email. Recipient email and the message content we send (sign-in links, invites, check-in notices, purchase notices, and marketing only if you opted in).
  • PostHog (US) Product analytics and error diagnostics. Page views, in-app events, error reports, and an identified user id and email when you are signed in. Event properties do not include plan field contents or vault files. We do not currently record session videos.
  • OpenAI (US) Optional “Tell it your way” assist. Only the text you type in that box, for a single extraction request. We do not send your saved plan or vault files. OpenAI may act as an independent controller for that request.

Polar handles card data. Vault objects on Cloudflare R2 are ciphertext, as described on the document vault page. We may use ancillary providers (for example DNS or error delivery) under the same limits. We do not sell personal information.

Contact

Questions about sub-processors: [email protected]. Refunds are in the refund policy.