The following companies receive specific data to operate Grace. Each is contractually bound to use that data only to deliver their service to us.
- Clerk
- Authentication, sign-in, and session management. Receives your email, name, password hash, and (if enabled) MFA factors.
- Stripe
- Subscription billing and payment processing. Receives your billing email, payment method details (collected by Stripe directly, never by us), and tax/billing address.
- Resend
- Outbound email delivery (call sheets, invitations, vault shares, verification codes). Receives recipient addresses and email body content.
- Cloudflare R2
- File storage for scripts, photos, screeners, dailies, and call-sheet PDFs. Files are stored encrypted at rest.
- Cloudflare
- DNS, network edge, and the marketing-site CDN. Receives standard request metadata (IP, user agent, URL path).
- Neon
- Managed PostgreSQL hosting for the Grace application database. Receives all structured app data described above.
- Railway
- Application hosting and compute. Receives all data passing through Grace's servers.
- Sentry
- Error monitoring and diagnostics (operated by Functional Software, Inc.). Receives error messages and stack traces, the page or route where an error occurred (with sensitive tokens and query parameters redacted), browser/device/OS type, and a pseudonymous account identifier. Does not receive your name, email address, or production content.
- Anthropic
- AI processing of script content (Claude). Script text or PDF is sent for breakdown extraction. Anthropic does not retain user-API data beyond standard operational logs and does not use it for model training.
- Google
- Fallback AI processing of script content (Gemini), used when Claude is unavailable. Google does not use API content for model training when accessed via the paid API tier.
- Open-Meteo
- Weather data for shoot-day forecasts on call sheets. Receives latitude/longitude only, no production identity.
- Google Maps Platform (Places API)
- Address-to-coordinates geocoding for production locations and nearest-hospital lookups on call sheets. Receives the address string or coordinates only, no production identity. Operated by Google under its API-tier terms; content is not used to train Google's general models.
- OpenStreetMap (Nominatim)
- City-level coordinates lookup for weather forecasts on call sheets. Receives the city string only, no production identity.
- Thy Dark Hour Systems (OPC) Pvt Ltd
- Software development, technical operations, and customer-support engineering for Grace. Personnel acting under TDH's engagement may access the production database for engineering and support purposes, subject to an intercompany data-processing addendum with Obelisk Studios LLC. TDH is based in India; cross-border transfers are described under "International data transfers" below.