Controller: Operator details will be published here, at Operator details will be published here. This recipient inventory supports the Privacy Policy. Optional providers are identified as such.
Effective 27 September 2026. This schedule forms part of the Privacy Policy. Optional providers are used only when the corresponding feature is enabled. App stores and user-chosen connection providers operate their own services.
| Name | Purpose | Data potentially received | Region and status |
| Google Cloud Platform, including Vertex AI/Gemini and Google Cloud Text-to-Speech | Cloud infrastructure, generative AI, optional speech synthesis | Service data on the hosted VM; prompts, retrieved context, images in approved AI routes; text submitted for speech | Vertex is the configured default AI route; speech is a separate optional provider. Active region requires verification. |
| MinIO (self-hosted object-storage software, not a separate external recipient by itself) | Exercise media and account avatar objects | Exercise media and user-uploaded avatar images | Same deployment as the service unless separately configured. |
| PostgreSQL and Redis (self-hosted infrastructure) | Account and feature records, sessions, queues, rate limiting | Account, health, finance, social, chat, transaction and operational records as relevant to each service | Same deployment as the service unless separately configured. |
| Google Firebase Cloud Messaging | Deliver push notifications | Device registration token and notification content/metadata | Native FCM route is configured when enabled; avoid sensitive content in push payloads. |
| Account email provider | Necessary verification, account and security messages | Email address, message and delivery metadata | The provider and location depend on the account-email service in use. |
| Sentry (conditional SDK) | Error and performance diagnostics when configured | Error events, stack traces, context and device/runtime data that the SDK sends | Conditional; project region and production use require verification. |
| Anthropic and OpenAI (conditional AI routes) | Alternative model inference if configured and selected | Prompts, retrieved context, approved inline images, generated responses | Used only when the optional model route is enabled. |
| Voyage AI (conditional embedder) | Semantic embeddings if separately enabled | Text submitted for embedding | The default embedding route is local. |
| Open Food Facts (independent API recipient) | Requested barcode lookup | Scanned numeric barcode and request metadata; no account ID in constructed URL | Server queries the product API and caches the result; barcode may reveal food choice. |
| Expo Push (conditional superseded fallback) | Push if FCM wholly absent and Expo configured | Push token, payload, delivery metadata | Used only where an older client and enabled configuration require it. |
| Affiliate partner (independent referral recipient) | Attribution and commission status | Stable pseudonym, join date, plan type, status and commission end; internal user-ID join | Referring partner may reidentify; pseudonym remains personal data. |
| Google Play and Apple App Store (independent store operators, not Ascendia subprocessors for payment) | Purchase, renewal, refund and subscription verification | Store account/payment information held by store; Ascendia receives transaction, product and entitlement data | Store policies govern payment and refund processing. |
| Google and Microsoft calendar services (user-directed connected services) | Optional calendar OAuth connection and sync | Authorization tokens and calendar events within granted scope | Per connected provider; disconnect and revocation path must be checked. |
| User-chosen private ICS/webcal feed host (independent external recipient unless actual terms establish another role; may be Google, Microsoft or another host) | Fetch optional calendar feed at connection, on request and on schedule | Private feed URL (possibly a standing read secret), request metadata and conditional-fetch validators; the host supplies event data to Ascendia | Depends on the link and host; no fixed country or processor can be assigned. Disconnect/account purge removes active source copies in code. |
| OpenWeather (conditional) | Current weather and forecast for a saved location | Latitude and longitude, request metadata | Selected only if configured; region and active use require verification. |
| Google Places (conditional or legacy route) | Nearby place search when its route is used | Search location and request metadata | Active use requires verification. |
Backups cover the database and MinIO objects. The local script keeps seven daily and four weekly copies; its offsite Cloud Storage leg is documented as blocked pending setup, so this schedule does not claim completed offsite backup.
Additional recipients: speech input and account sign-in
These rows cover optional speech input and sign-in. They are separate from speech output, app-store purchases and calendar access. Provider processing varies by device and selected sign-in route.
| Name | Purpose | Data potentially received | Region and status |
| Apple iOS and Google/Android speech recognition | Optional speech-to-text input before a user submits a transcript | Microphone audio and recognition hypotheses may reach the OS provider; Ascendia does not configure persistent audio recording | Local or provider-operated processing depends on device and language; OS permission is required. |
| Apple Sign in with Apple | Optional federated login and account linking | Identity token, provider subject, verified email or private relay email, optional name | Independent identity provider; separate from App Store billing. |
| Google Sign-In | Optional federated login and account linking | Identity token, provider subject, verified email and optional name | Independent identity provider; separate from Google Play billing and calendar. |