Provider Disclosure & Processing Contexts
This page describes the current external providers, self-hosted processing contexts, and offline suppliers used to operate Mineral Wild. It groups external providers by legal entity and explains the services, data categories, purposes, regions, and conditions that apply.
Where an external provider receives personal data from us to process on our behalf, it is engaged under a written data processing agreement that requires the same or equal protection described in our Privacy Policy, limits processing to the purposes described on this page, and, where applicable, requires compliance with service-provider obligations under the CCPA. Where a cross-border transfer is subject to the GDPR, we rely on an adequacy mechanism or Standard Contractual Clauses; if neither is yet in place for a specific provider, the transitional fallback described in our Privacy Policy applies.
Listing a provider identifies a current data flow; it does not by itself characterize that provider's role under privacy law. User-initiated services apply only under the condition stated below. The self-hosted and offline sections describe processing contexts and do not identify additional third-party recipients.
This page is also referred to as the Subprocessors page in our Privacy Policy and Terms of Service.
This is a current service-wide disclosure. Conditional services apply when the described feature or interaction is used; this is not a per-user historical recipient ledger.
Current external providers
Amazon Web Services (AWS)
- Legal entity
- Amazon Web Services, Inc.
Application hosting and managed data services
- Available on
- App
- Website
- Support
- Infrastructure
- Applies when
- Generally applicable to the listed surface(s)
- Regions
- United States (AWS us-east-1)
- Data categories
- Account, profile, collection, social, messaging, and support data
- Pseudonymized email-derived verification throttle keys and other authentication, security, request, and operational metadata
- Background-job arguments that can include a sender, seller, or owner username and specimen or mineral name
- Cached collection statistics, public profile data, specimen locality and address details, and reverse-geocoding responses
- Purpose
- Run the application, APIs, databases, caches, Celery broker and result state, security controls, and operational logging.
Object storage, backups, and content delivery
- Available on
- App
- Website
- Support
- Infrastructure
- Applies when
- Generally applicable to the listed surface(s)
- Regions
- United States (AWS us-east-1; disaster-recovery copies in us-west-2)
- CloudFront global edge network
- Data categories
- User-uploaded media and generated derivatives
- Public collection media (specimen photos and videos, avatars, and cover images) delivered without signed links and cached at the edge for up to about 30 days; public atlas reference images may be cached for up to one year
- Private chat attachments and data exports, and mineral-suggestion photos uploaded since that path moved behind signed delivery, delivered through expiring signed links
- Export archives, backups, and content-delivery request metadata
- Purpose
- Store, back up, recover, and deliver application content and user-requested exports.
Transactional email and delivery events
- Applies when
- Applies when the service sends a transactional or support email.
- Regions
- United States (AWS us-east-1)
- Data categories
- Recipient email address, message subject, and message body
- Delivery, bounce, complaint, and notification metadata
- Purpose
- Send account, security, support, and privacy-request messages and observe delivery outcomes.
Media safety screening
- Applies when
- Applies when a user submits media through a feature that performs safety screening.
- Regions
- United States (AWS us-east-1)
- Data categories
- User-uploaded images and selected video cover frames
- Moderation labels and confidence scores
- Purpose
- Screen user-selected media for configured safety categories.
Apple
- Legal entity
- Apple Inc.
Sign in with Apple
- Applies when
- Applies when a user chooses Sign in with Apple.
- Regions
- Apple global service infrastructure
- Data categories
- Apple account identifier, authentication tokens, and user-shared email or name
- Purpose
- Authenticate accounts and maintain an optional Apple sign-in connection.
Apple Push Notification service (APNs)
- Applies when
- Applies when the App initializes push messaging on an Apple device; notification delivery depends on operating-system permission and account preferences.
- Regions
- Apple global service infrastructure
- Data categories
- Device push token, notification payload, and delivery metadata
- Purpose
- Deliver notifications to Apple devices.
Apple Maps and MapKit
- Applies when
- Applies when a user opens a feature that displays an Apple map or map snapshot.
- Regions
- Apple global service infrastructure
- Data categories
- Map coordinates, map requests, and device or network metadata
- Purpose
- Display interactive maps and map snapshots for collection locations.
Declared Age Range
- Applies when
- Applies when the App starts on a supported Apple platform and checks age-feature eligibility or required regulatory features, and whenever the App makes an age-range request as part of account-access handling.
- Regions
- Apple global service infrastructure
- Data categories
- Age-feature eligibility and required regulatory-feature signals returned during startup checks
- Age-range declaration, declaration-source, and coarse age-bound signals returned after a user responds
- Purpose
- Determine whether age-access handling is required and apply it from the coarse signals returned by Apple's framework.
Google
- Legal entity
- Google LLC
Google Sign-In
- Applies when
- Applies when a user chooses Google Sign-In.
- Regions
- Google global service infrastructure
- Data categories
- Google account identifier, authentication tokens, email address, and profile name
- Purpose
- Authenticate accounts and maintain an optional Google sign-in connection.
Firebase Cloud Messaging
- Applies when
- Applies when the App initializes or registers push messaging on a device; notification delivery depends on operating-system permission and account preferences.
- Regions
- Google global service infrastructure
- Data categories
- Device registration token, notification payload, and delivery metadata
- Purpose
- Route application notifications to registered devices.
Gmail
- Applies when
- Applies when a person contacts a Mineral Wild email address routed to the support mailbox.
- Regions
- Google global service infrastructure
- Data categories
- Sender and recipient addresses, email headers, message body, attachments, and routing metadata
- Purpose
- Receive and respond to support, legal, and privacy-request correspondence.
Google Search
- Applies when
- Applies when a user chooses Search on Google from a mineral detail page.
- Regions
- Google global service infrastructure
- Data categories
- Mineral English name, search query suffix, IP address, browser or device data, and request metadata
- Purpose
- Open an optional external web search for additional mineral information.
Cloudflare
- Legal entity
- Cloudflare, Inc.
Authoritative DNS
- Available on
- App
- Website
- Support
- Infrastructure
- Applies when
- Generally applicable to the listed surface(s)
- Regions
- Cloudflare global network
- Data categories
- DNS query, resolver, network, and request metadata
- Purpose
- Resolve Mineral Wild domains to the configured service endpoints.
Cloudflare Web Analytics
- Applies when
- Applies when a person visits a page carrying the analytics beacon.
- Regions
- Cloudflare global network
- Data categories
- Page request, browser, referrer, coarse network, and performance-event data
- Purpose
- Measure website usage and performance.
Cloudflare Turnstile
- Applies when
- Applies when a person visits or interacts with a /r/ referral landing page that sends an event.
- Regions
- Cloudflare global network
- Data categories
- Challenge token, IP address, browser or device signals, hostname, action, and request metadata
- Pseudonymous anonymous-session identifier and short share-token-derived binding value sent as customer data (cData)
- Purpose
- Protect anonymous referral landing events from automated abuse and preserve analytics integrity.
Cloudflare Email Routing
- Applies when
- Applies when a person sends email to a routed Mineral Wild address.
- Regions
- Cloudflare global network
- Data categories
- Sender and recipient addresses, email headers, message body, attachments, and routing metadata
- Purpose
- Route incoming support, legal, and privacy-request email to the configured mailbox.
Sentry
- Legal entity
- Functional Software, Inc. d/b/a Sentry
Error and performance monitoring
- Available on
- App
- Website
- Support
- Infrastructure
- Applies when
- Applies when monitored software records an error, diagnostic event, or sampled performance event.
- Regions
- United States (Sentry US region)
- Data categories
- Pseudonymous internal account identifier on server-side events
- Error context, request paths that may contain a public username, other request metadata, and app, browser, device, or server diagnostics
- Purpose
- Detect, investigate, and remediate application and service failures.
LocationIQ
- Legal entity
- Unwired Labs (India) Private Limited
Geocoding and reverse geocoding
- Applies when
- Applies when a user searches for a place or requests reverse geocoding. Geocoding requests go through Mineral Wild's backend; the App does not call LocationIQ directly.
- Regions
- Requests use the United States API endpoint; LocationIQ does not publish an exclusive processing location
- Data categories
- Place search text, coordinates, language preference, and request metadata
- Purpose
- Convert place searches to coordinates and coordinates to locality labels.
Discord
- Legal entity
- Discord Inc.
Discord community and support
- Applies when
- Applies when a person chooses the Discord link and interacts with Discord.
- Regions
- United States and other Discord service locations
- Data categories
- Network and device data and, after joining, Discord account and community content
- Purpose
- Open the optional Mineral Wild community and support channel hosted by Discord.
Self-hosted processing contexts
Self-hosted Nginx edge and reverse proxy
- Available on
- App
- Website
- Support
- Infrastructure
- Applies when
- Generally applicable to the listed surface(s)
- Regions
- United States (Mineral Wild AWS hosts)
- Data categories
- IP address, request path, headers, response status, timing, and security metadata
- Purpose
- Terminate and route web traffic, enforce request controls, and retain operational access logs.
Self-hosted Centrifugo realtime service
- Applies when
- Applies while a user uses a realtime-enabled app feature.
- Regions
- United States (Mineral Wild AWS hosts)
- Data categories
- Pseudonymous connection identity, channel subscriptions, realtime events, and connection metadata
- Purpose
- Authorize and deliver realtime messaging and application events.
Offline suppliers
MaxMind GeoLite2 Country database
- Applies when
- Applies when the service evaluates a request using the locally installed country database.
- Regions
- United States (local database on Mineral Wild AWS hosts)
- Data categories
- Request IP processed locally to derive a country code; neither value is sent to MaxMind, and the GeoLite lookup does not persist an additional raw-IP copy
- Purpose
- Derive a coarse country signal locally for account registration metadata and anonymous landing-page acquisition analytics.
Changes to this disclosure
We update this page when a disclosed provider, service, or processing context changes. Material changes involving a new external provider that processes a new category of user data will be announced in-App via Settings → What's New at least 30 days before taking effect, where reasonably possible.
If you have questions about a specific provider or processing context, or wish to object to our use of one, please contact mineralwild@gmail.com.
Related documents