This list is published by Derive Notes Pty Ltd (ACN 696 859 597), 2/290 Boundary Street, Spring Hill QLD 4000, Australia, and is the list the Privacy Policy refers to. We update it when a provider is added, changed or removed. Questions go to matt@derivenotes.com.
Unless a row says otherwise, "United States" means the provider runs the service from there and your data is transferred there to be processed. Where a provider publishes a data processing agreement, we link it beside its privacy page.
Where your notebooks live
| Provider | What it does | What it receives | Where it processes | Its privacy or DPA page |
|---|---|---|---|---|
| Supabase | Sign in, database, file storage, and all our server logic | Account details, notebooks, page images, uploaded files, recognised text, billing state, email records | Australia (AWS Sydney, ap-southeast-2) | supabase.com/privacy, supabase.com/legal/dpa |
| Cloudflare | Runs the network edge in front of Supabase's API gateway, so every request from the app passes through it | IP address, connection metadata, and request contents in transit | Global edge network | cloudflare.com/trust-hub/gdpr |
| Vercel | Hosts the Derive web app shell and the marketing website, and answers the app's country lookup | IP address, request logs, pages requested | United States and Vercel's global edge network. We do not pin a region | vercel.com/legal/privacy-policy, vercel.com/legal/dpa |
AI providers
These providers receive an image of the part of the page you wrote on, the recognised text around it, and, on a practice page, the question you are working on. They do not receive your name, your email address or your account id. The AI disclosure explains which feature sends what.
| Provider | What it does | What it receives | Where it processes | Its privacy or DPA page |
|---|---|---|---|---|
| OpenRouter | Routes handwriting recognition requests to the three model hosts below, in the order Relace, Modal, DeepInfra | Rendered image of your handwriting, surrounding page text | United States | openrouter.ai/privacy |
| Relace | Runs the recognition model | Rendered image of your handwriting, surrounding page text | United States | relace.ai |
| Modal | Runs the recognition model | Rendered image of your handwriting, surrounding page text | United States | modal.com/legal/privacy-policy |
| DeepInfra | Runs the recognition model | Rendered image of your handwriting, surrounding page text | United States | deepinfra.com/privacy |
| Recognition fallback, tutoring, page and image reading, and the search index | Rendered image of your handwriting, page text, page titles, images you add, typed questions | Google's global service endpoint. We use the "global" location rather than a named region, so Google may serve the request from any of its regions | cloud.google.com/terms/cloud-privacy-notice, cloud.google.com/terms/data-processing-addendum | |
| OpenAI | Summaries, page titles, practice questions, diagrams, image and code extraction, assistant chat, and a last fallback for recognition | Recognised handwriting, typed page text, page titles, your questions, source code | United States | openai.com/policies/privacy-policy, openai.com/policies/data-processing-addendum |
| Judge0, reached through RapidAPI | Runs code you write in the app and choose to run | Your source code and any input you supply with it | United States | rapidapi.com/privacy |
Retention at AI providers. On the handwriting recognition path we send an instruction with every request telling OpenRouter to refuse any model host that would keep or train on the request, and to use only the three hosts named above. Other requests that may be routed through OpenRouter, such as reading a photo you add or choosing which lines of the page are relevant, do not currently carry that instruction. Nothing in our code requests zero data retention from OpenAI or from Google, so those two run on their standard API terms.
If you connect Derive to Claude
| Provider | What it does | What it receives | Where it processes | Its privacy or DPA page |
|---|---|---|---|---|
| Anthropic | If you connect Derive to claude.ai or Claude Desktop as a connector, Claude can search your notes, list your recent pages, read a page and download a page image | Recognised page text, page titles and structure, rendered page images | United States | anthropic.com/legal/privacy, anthropic.com/legal/commercial-terms |
This only happens if you set the connector up yourself. Nothing is sent to Anthropic otherwise. Once your notes reach Claude, Anthropic's terms govern what happens to them, not ours.
Setting up your account
| Provider | What it does | What it receives | Where it processes | Its privacy or DPA page |
|---|---|---|---|---|
| Research Organization Registry (ROR) | Looks up your university when you type its name during setup | The text you type into the institution box, and your IP address, sent directly from your browser | United States | ror.org |
This request goes from your browser to ROR directly, so ROR sees your IP address. It only happens if you are asked for an institution and you start typing.
Analytics, diagnostics, payments and email
| Provider | What it does | What it receives | Where it processes | Its privacy or DPA page |
|---|---|---|---|---|
| PostHog | Usage analytics for the app. The app also contains a screen recording capability that is not currently enabled for anyone | A random device identifier and which features you used. Never your name, email or account id. If screen recording were ever enabled it would send a recording of your screen including the canvas you write on; it is switched off today and there is no control that turns it on. Your IP address is removed by our own servers before the data reaches PostHog | European Union | posthog.com/privacy, posthog.com/dpa |
| PostHog | Usage analytics for the marketing website, only after you say yes to the cookie banner, plus the home page headline test | Pages viewed, clicks, scroll depth, campaign tags, and on waitlist signup your email address. A random visitor identifier for the headline test | United States | posthog.com/privacy, posthog.com/dpa |
| Sentry | Crash reports and performance diagnostics | Error details, your Derive account id, app version, platform, and a fully masked recording of the screen at the moment of an error. The canvas you write on is deliberately excluded. Your IP address is removed by our own servers before the data reaches Sentry | United States | sentry.io/privacy, sentry.io/legal/dpa |
| Amazon Web Services (SES) | Sends all of our email, from the app and from this website, and handles bounces and complaints | Your email address, the subject and body of the message, and delivery, bounce, complaint and open events | Australia (Sydney, ap-southeast-2) | aws.amazon.com/privacy, aws.amazon.com/compliance/gdpr-center |
| Stripe | Takes payment on the web, Mac and Windows. Under Stripe's managed payments, Stripe is the merchant of record and handles tax | Your email address, billing address, card details (we never see the card number), your Derive account id, and your subscription record | United States and Ireland | stripe.com/privacy, stripe.com/legal/dpa |
| Apple | Takes payment for subscriptions bought inside the iPhone and iPad app. Apple is the seller for those purchases | Purchase records. We receive no card details | United States | apple.com/legal/privacy |
| RevenueCat | Manages App Store subscription state for the iPhone and iPad app | Your Derive account id, purchase and subscription records, device and app metadata | United States | revenuecat.com/privacy, revenuecat.com/dpa |
| Meta Platforms | Measures whether our adverts work. Only on the Derive web app, only for accounts created from 7 September 2026, and only if you accept analytics | That a page was viewed, an account was created, a trial was started or a payment succeeded, with the amount. A one way hash of your email address, and only for accounts we know to be 18 or over. Never your notes, and never any identifier for a user under 18 or of unknown age | United States | meta.com/privacy/policy, meta.com/legal/business-tools-terms |
What Sentry can see in a diagnostic trail. Sentry is described above as receiving error details. In a small number of places our diagnostic log also carries an AI generated page title, the raw text of a maths expression being repaired, and the text you typed into search, so a crash report can include those fragments.
What is not on this list
- No ad exchange, no data broker, and no advertising network other than Meta. Meta is listed above and receives only what that row describes: we do not sell personal data, and the sharing we do for advertising measurement is limited to adults who have accepted analytics and whose accounts were created from 7 September 2026. Privacy policy section 13.6 sets it out, and B2.9 explains the Global Privacy Control signal we honour.
- No school, university or teacher. Derive has no institutional accounts and discloses no student's work to an institution. See Children and students.
- Apple is not asked for your age range. That integration is not used.
Related documents
Privacy Policy, Terms of Service, Cookies, Children and students, AI disclosure, Data processing addendum.