Moche-AIBack to site

Legal Center

  • Overview
  • Terms of Service
  • Privacy Policy
  • Refund & Billing
  • Data Processing Addendum
  • Master Service Agreement
  • Security
  • Subprocessors
  • Acceptable Use
  • AI Policy
  • Open-Source Notices
  • Cookies
  • Support & Data Rights

Subprocessors

Version 1.3.0 · Last updated August 3, 2026

We use the third-party service providers (“subprocessors”) below to deliver the Service. Each processes personal data only under a data-processing agreement and only for the stated purpose. This same list backs Schedule 3 of our Data Processing Addendum.

VendorPurposeData processedRegionTransferRetentionStatus
SupabasePrimary application database (Postgres + pgvector), authentication, file storageHost account & profile data, property/brain content, guest identities (hashed contacts), embeddingsEU (Frankfurt) / US — project-dependentSCCsFor the life of the account; deleted on erasure request (billing/legal records retained)Active
VercelApplication hosting, edge network, serverless computeRequest metadata, IP addresses, logsUS / global edgeSCCsTransient; logs per Vercel retention policyActive
StripePayment processing and subscription billingHost billing contact, payment card data (held by Stripe, never by us), invoicesUS / EUSCCsPer Stripe policy and tax/accounting law (typically 7+ years for financial records)Active
OpenAIAI subprocessor — text embeddings (text-embedding-3-small), guest-intent classification, and the fallback path for all chat completions if model routing is unavailableGuest questions and property knowledge context (PII redacted before external routing where applicable)USSCCsAPI inputs/outputs retained up to 30 days for abuse monitoring, then deleted (no training on API data)Active
OpenRouterAI model router — directs completion requests to a task-appropriate model (currently Google Gemini 2.5 Flash for guest answers, OpenAI GPT-4o-mini and Meta Llama 3.1 for background extraction/classification) with automatic failover between modelsPrompt content only, with personal data programmatically redacted before the request leaves our infrastructure: guest questions and the relevant property knowledge context. A post-redaction check blocks the external request entirely if personal data is still detected. No guest identity, contact details, or account data are sent.US (routes to model providers in the US/EU)SCCsZero-Data-Retention enforced on every request: prompts and responses are not logged or retained by OpenRouter, and any downstream model provider that would collect or train on the data is refused (the request fails closed and falls back to our primary provider instead)Active
ResendTransactional email delivery (host notifications, escalations)Host email address, notification contentUSSCCsDelivery logs per Resend policyActive
TwilioSMS delivery for guest verification one-time codesGuest phone number, one-time verification codeUS / globalSCCsMessage logs per Twilio policyActive
FirecrawlHost-initiated URL ingestion (fetch & extract public listing/content pages)URLs submitted by the host and the fetched page contentUSSCCsTransient; extracted content stored in the host’s Property BrainActive
SentryApplication error monitoring and performance tracingError events, stack traces, request metadata (PII scrubbed where feasible)US / EUSCCsPer Sentry retention settings (typically 90 days)Active
CloudflareBot mitigation (Turnstile) on guest verification and edge protectionIP address, challenge token, request metadataGlobal edgeSCCsTransient challenge dataActive
MapboxAddress autocomplete/geocoding, nearby place discovery, and static map images on the host dashboardProperty address strings and coordinates entered by the host, plus the host browser’s request metadata (IP, referrer) when a static map image loads. No guest identity or guest message content is sent.USSCCsQuery logs per Mapbox policy; results cached in the host’s own property recordsActive
PostHogProduct analytics (host-side usage; no guest PII sent)Pseudonymous host user id, product events, page viewsUS / EU (cloud region dependent)SCCsPer PostHog project retention settingsActive
Trigger.devBackground job orchestration (async task execution and retries outside the request/response cycle)Task payloads we choose to send. Jobs are designed to carry row/record ids only, never guest PII directly — the job re-reads any needed data from Supabase using the service role at execution time.USSCCsRun logs and payloads retained per Trigger.dev account settingsActive
Amazon Web Services (S3)Private object storage for host-uploaded files and images, accessed only via short-lived presigned URLs so bytes never transit our app serversProperty-related images and documents the host uploads. Objects are stored under a per-property key prefix; no object is publicly accessible (all public access blocked, TLS-only bucket policy, server-side encryption at rest).US (us-east-2)SCCsObjects retained until deleted by the host or removed per bucket lifecycle policy (noncurrent versions expire after 90 days)Active

AI model providers are reached through our model router (OpenRouter) under a zero-data-retention configuration; see the AI Policy for which models handle which task and the safeguards applied before any content leaves our infrastructure.

Terms of ServicePrivacy PolicyRefund & BillingData Processing AddendumMaster Service AgreementSecuritySubprocessorsAcceptable UseAI PolicyOpen-Source NoticesCookiesSupport & Data Rights

Built in Somerville, MA