Active
Amazon Web Services (London · eu-west-2)
Primary infrastructure. Hosts our database (RDS Postgres), object storage (S3), authentication (Cognito), email ingestion (SES), application servers (ECS Fargate, Lambda), DNS (Route 53), encryption keys (KMS), and CDN (CloudFront).
Data location: United Kingdom (London). Basis: Sposa's data-processing addendum with AWS, governed by the AWS GDPR DPA.
Anthropic (via AWS Bedrock · eu-west-2)
All AI inference. Claude Haiku 4.5 reads simple email content; Claude Sonnet 4.6 reads PDF attachments, generates your checklist, and synthesises your mood-board fingerprint and Style Guide.
Data location: United Kingdom (London) via the AWS Bedrock service. Retention: zero — Anthropic does not store inputs after the inference
call. Training: Anthropic does not train on customer data submitted via
Bedrock. Guardrails: a configured Bedrock Guardrail (sposa-default)
filters for prompt injection, blocked PII categories (UK NI numbers, NHS numbers, payment
cards, AWS keys), and unsafe outputs.
Planned
The services below are planned for our public launch and will appear in the Active section once integrated. We'll notify subscribers by email at least 14 days before any new subprocessor begins processing their data.
Stripe (UK)
Payment processing for the £24/month subscription. Stripe receives your name, email, billing address, and card details — Sposa never sees or stores your full card number. Stripe processes payments in the UK.
Sentry (EU)
Error monitoring for the application. Stack traces, request metadata, and minimal user identifiers (your couple ID) are recorded when something goes wrong. PII is scrubbed before transmission.
Langfuse (EU)
LLM observability — we record prompts and responses to evaluate our AI's accuracy over time. PII redaction is applied at trace level before storage.
What we don't use
No US-only processors. No third-party analytics (no Google Analytics, no Mixpanel, no Segment). No advertising trackers. No social-media pixels. No data brokers.
How to know when this changes
This page is version-controlled in our repository. Material changes — adding a new subprocessor or changing the data-residency posture of an existing one — are announced by email at least 14 days in advance. If you object, you can cancel before the change takes effect.