Provider Disclosure & Processing Contexts

This page describes the current external providers, self-hosted processing contexts, and offline suppliers used to operate Mineral Wild. It groups external providers by legal entity and explains the services, data categories, purposes, regions, and conditions that apply.

Where an external provider receives personal data from us to process on our behalf, it is engaged under a written data processing agreement that requires the same or equal protection described in our Privacy Policy, limits processing to the purposes described on this page, and, where applicable, requires compliance with service-provider obligations under the CCPA. Where a cross-border transfer is subject to the GDPR, we rely on an adequacy mechanism or Standard Contractual Clauses; if neither is yet in place for a specific provider, the transitional fallback described in our Privacy Policy applies.

Listing a provider identifies a current data flow; it does not by itself characterize that provider's role under privacy law. User-initiated services apply only under the condition stated below. The self-hosted and offline sections describe processing contexts and do not identify additional third-party recipients.

This page is also referred to as the Subprocessors page in our Privacy Policy and Terms of Service.


This is a current service-wide disclosure. Conditional services apply when the described feature or interaction is used; this is not a per-user historical recipient ledger.

Current external providers

Amazon Web Services (AWS)

Legal entity
Amazon Web Services, Inc.

Application hosting and managed data services

Available on
  • App
  • Website
  • Support
  • Infrastructure
Applies when
Generally applicable to the listed surface(s)
Regions
  • United States (AWS us-east-1)
Data categories
  • Account, profile, collection, social, messaging, and support data
  • Pseudonymized email-derived verification throttle keys and other authentication, security, request, and operational metadata
  • Background-job arguments that can include a sender, seller, or owner username and specimen or mineral name
  • Cached collection statistics, public profile data, specimen locality and address details, and reverse-geocoding responses
Purpose
Run the application, APIs, databases, caches, Celery broker and result state, security controls, and operational logging.

Object storage, backups, and content delivery

Available on
  • App
  • Website
  • Support
  • Infrastructure
Applies when
Generally applicable to the listed surface(s)
Regions
  • United States (AWS us-east-1; disaster-recovery copies in us-west-2)
  • CloudFront global edge network
Data categories
  • User-uploaded media and generated derivatives
  • Public collection media (specimen photos and videos, avatars, and cover images) delivered without signed links and cached at the edge for up to about 30 days; public atlas reference images may be cached for up to one year
  • Private chat attachments and data exports, and mineral-suggestion photos uploaded since that path moved behind signed delivery, delivered through expiring signed links
  • Export archives, backups, and content-delivery request metadata
Purpose
Store, back up, recover, and deliver application content and user-requested exports.

Transactional email and delivery events

Available on
  • App
  • Support
  • Infrastructure
Applies when
Applies when the service sends a transactional or support email.
Regions
  • United States (AWS us-east-1)
Data categories
  • Recipient email address, message subject, and message body
  • Delivery, bounce, complaint, and notification metadata
Purpose
Send account, security, support, and privacy-request messages and observe delivery outcomes.

Media safety screening

Available on
  • App
Applies when
Applies when a user submits media through a feature that performs safety screening.
Regions
  • United States (AWS us-east-1)
Data categories
  • User-uploaded images and selected video cover frames
  • Moderation labels and confidence scores
Purpose
Screen user-selected media for configured safety categories.

Apple

Legal entity
Apple Inc.

Sign in with Apple

Available on
  • App
Applies when
Applies when a user chooses Sign in with Apple.
Regions
  • Apple global service infrastructure
Data categories
  • Apple account identifier, authentication tokens, and user-shared email or name
Purpose
Authenticate accounts and maintain an optional Apple sign-in connection.

Apple Push Notification service (APNs)

Available on
  • App
Applies when
Applies when the App initializes push messaging on an Apple device; notification delivery depends on operating-system permission and account preferences.
Regions
  • Apple global service infrastructure
Data categories
  • Device push token, notification payload, and delivery metadata
Purpose
Deliver notifications to Apple devices.

Apple Maps and MapKit

Available on
  • App
Applies when
Applies when a user opens a feature that displays an Apple map or map snapshot.
Regions
  • Apple global service infrastructure
Data categories
  • Map coordinates, map requests, and device or network metadata
Purpose
Display interactive maps and map snapshots for collection locations.

Declared Age Range

Available on
  • App
Applies when
Applies when the App starts on a supported Apple platform and checks age-feature eligibility or required regulatory features, and whenever the App makes an age-range request as part of account-access handling.
Regions
  • Apple global service infrastructure
Data categories
  • Age-feature eligibility and required regulatory-feature signals returned during startup checks
  • Age-range declaration, declaration-source, and coarse age-bound signals returned after a user responds
Purpose
Determine whether age-access handling is required and apply it from the coarse signals returned by Apple's framework.

Google

Legal entity
Google LLC

Google Sign-In

Available on
  • App
Applies when
Applies when a user chooses Google Sign-In.
Regions
  • Google global service infrastructure
Data categories
  • Google account identifier, authentication tokens, email address, and profile name
Purpose
Authenticate accounts and maintain an optional Google sign-in connection.

Firebase Cloud Messaging

Available on
  • App
Applies when
Applies when the App initializes or registers push messaging on a device; notification delivery depends on operating-system permission and account preferences.
Regions
  • Google global service infrastructure
Data categories
  • Device registration token, notification payload, and delivery metadata
Purpose
Route application notifications to registered devices.

Gmail

Available on
  • Support
Applies when
Applies when a person contacts a Mineral Wild email address routed to the support mailbox.
Regions
  • Google global service infrastructure
Data categories
  • Sender and recipient addresses, email headers, message body, attachments, and routing metadata
Purpose
Receive and respond to support, legal, and privacy-request correspondence.

Google Search

Available on
  • App
Applies when
Applies when a user chooses Search on Google from a mineral detail page.
Regions
  • Google global service infrastructure
Data categories
  • Mineral English name, search query suffix, IP address, browser or device data, and request metadata
Purpose
Open an optional external web search for additional mineral information.

Cloudflare

Legal entity
Cloudflare, Inc.

Authoritative DNS

Available on
  • App
  • Website
  • Support
  • Infrastructure
Applies when
Generally applicable to the listed surface(s)
Regions
  • Cloudflare global network
Data categories
  • DNS query, resolver, network, and request metadata
Purpose
Resolve Mineral Wild domains to the configured service endpoints.

Cloudflare Web Analytics

Available on
  • Website
Applies when
Applies when a person visits a page carrying the analytics beacon.
Regions
  • Cloudflare global network
Data categories
  • Page request, browser, referrer, coarse network, and performance-event data
Purpose
Measure website usage and performance.

Cloudflare Turnstile

Available on
  • Website
Applies when
Applies when a person visits or interacts with a /r/ referral landing page that sends an event.
Regions
  • Cloudflare global network
Data categories
  • Challenge token, IP address, browser or device signals, hostname, action, and request metadata
  • Pseudonymous anonymous-session identifier and short share-token-derived binding value sent as customer data (cData)
Purpose
Protect anonymous referral landing events from automated abuse and preserve analytics integrity.

Cloudflare Email Routing

Available on
  • Support
Applies when
Applies when a person sends email to a routed Mineral Wild address.
Regions
  • Cloudflare global network
Data categories
  • Sender and recipient addresses, email headers, message body, attachments, and routing metadata
Purpose
Route incoming support, legal, and privacy-request email to the configured mailbox.

Sentry

Legal entity
Functional Software, Inc. d/b/a Sentry

Error and performance monitoring

Available on
  • App
  • Website
  • Support
  • Infrastructure
Applies when
Applies when monitored software records an error, diagnostic event, or sampled performance event.
Regions
  • United States (Sentry US region)
Data categories
  • Pseudonymous internal account identifier on server-side events
  • Error context, request paths that may contain a public username, other request metadata, and app, browser, device, or server diagnostics
Purpose
Detect, investigate, and remediate application and service failures.

LocationIQ

Legal entity
Unwired Labs (India) Private Limited

Geocoding and reverse geocoding

Available on
  • App
Applies when
Applies when a user searches for a place or requests reverse geocoding. Geocoding requests go through Mineral Wild's backend; the App does not call LocationIQ directly.
Regions
  • Requests use the United States API endpoint; LocationIQ does not publish an exclusive processing location
Data categories
  • Place search text, coordinates, language preference, and request metadata
Purpose
Convert place searches to coordinates and coordinates to locality labels.

Discord

Legal entity
Discord Inc.

Discord community and support

Available on
  • Support
Applies when
Applies when a person chooses the Discord link and interacts with Discord.
Regions
  • United States and other Discord service locations
Data categories
  • Network and device data and, after joining, Discord account and community content
Purpose
Open the optional Mineral Wild community and support channel hosted by Discord.

Self-hosted processing contexts

Self-hosted Nginx edge and reverse proxy

Available on
  • App
  • Website
  • Support
  • Infrastructure
Applies when
Generally applicable to the listed surface(s)
Regions
  • United States (Mineral Wild AWS hosts)
Data categories
  • IP address, request path, headers, response status, timing, and security metadata
Purpose
Terminate and route web traffic, enforce request controls, and retain operational access logs.

Self-hosted Centrifugo realtime service

Available on
  • App
  • Infrastructure
Applies when
Applies while a user uses a realtime-enabled app feature.
Regions
  • United States (Mineral Wild AWS hosts)
Data categories
  • Pseudonymous connection identity, channel subscriptions, realtime events, and connection metadata
Purpose
Authorize and deliver realtime messaging and application events.

Offline suppliers

MaxMind GeoLite2 Country database

Available on
  • App
  • Website
  • Infrastructure
Applies when
Applies when the service evaluates a request using the locally installed country database.
Regions
  • United States (local database on Mineral Wild AWS hosts)
Data categories
  • Request IP processed locally to derive a country code; neither value is sent to MaxMind, and the GeoLite lookup does not persist an additional raw-IP copy
Purpose
Derive a coarse country signal locally for account registration metadata and anonymous landing-page acquisition analytics.

Changes to this disclosure

We update this page when a disclosed provider, service, or processing context changes. Material changes involving a new external provider that processes a new category of user data will be announced in-App via Settings → What's New at least 30 days before taking effect, where reasonably possible.

If you have questions about a specific provider or processing context, or wish to object to our use of one, please contact mineralwild@gmail.com.


Related documents