Subprocessors
Every vendor that processes data on our behalf, with purpose and region.
Effective date: August 25, 2026. For a transfer assessment, regions marked “Available on request” are confirmed by emailing support@hiveintelligence.xyz.
Hive Intelligence engages the vendors below to operate Hive Intelligence. This page is referenced by our Privacy Policy and by our Data Processing Addendum, and it is the authoritative list for both.
Infrastructure and platform
| Vendor | Purpose | Data received | Processing region |
|---|---|---|---|
| Vercel | Hosting and edge delivery for hiveintelligence.xyz and the dashboard | IP address, request metadata, user agent | United States, served from a global edge network |
| Google Cloud Platform (Cloud Run, Artifact Registry, Cloud Logging) | Hosting the MCP server and the CLI backend, and its operational logs | IP address, request metadata, tool-call telemetry, application logs | asia-southeast1 (Singapore) |
| Supabase | Managed Postgres, account authentication, and delivery of sign-in emails | Account email address, account identifier, plan and billing state, sign-in emails | ap-south-1 (Mumbai, India) |
| Unkey | API key issuance and verification | Key identifier, key prefix, key metadata, account identifier. Not a recoverable copy of the key | Available on request |
| Managed Redis | OAuth state, distributed rate limiting, and durable canary history | Short-lived tokens, rate-limit counters keyed by principal or IP | Available on request |
Payments
Both payment processors act as independent controllers for the payment itself. What each one receives is described in section 5 of the Privacy Policy.
| Vendor | Purpose | Data received | Processing region |
|---|---|---|---|
| Stripe | Card payment processing and subscription management | Account email address, account identifier, plan; card and billing details you give Stripe directly | Available on request |
| LlamaPay | Crypto payment checkout | Account identifier, plan, billing cycle, charge amount, account email address where available; wallet connection handled by LlamaPay | Available on request |
Analytics
| Vendor | Purpose | Data received | Processing region |
|---|---|---|---|
| Google (Google Analytics 4) | Status-page visit measurement, plus server-side service telemetry sent from the MCP backend over the GA4 Measurement Protocol | Status page: page-view data and the visitor's IP address. Measurement Protocol: tool name, outcome, duration, cache and runtime status, provider, client profile and version, server version; and on one activation event only, pseudonymous hashes derived from the account identifier. No IP address is sent on the Measurement Protocol path | Available on request |
Google receives data on two independent paths. The second one runs on our servers rather than in your browser, so no browser setting reaches it.
Browser script
A Google Analytics tag is served on the status page at mcp.hiveintelligence.xyz/status. It reports a page view and, like any browser request to Google, the visitor's IP address. No account identifier is attached to a visit to that page. That tag is under review for removal.
No analytics script is served on hiveintelligence.xyz or in the dashboard. Pages on this site do preconnect to Google's two analytics hosts, which opens a connection to Google on page load and so exposes your IP address to Google even though no analytics script is loaded.
Server-side Measurement Protocol
The MCP server sends telemetry directly to Google from our backend, by POST to www.google-analytics.com/mp/collect. It carries four events:
tool_call: one per tool call. Sends the tool name, whether the call succeeded, how long it took, and whether the answer came from cache. The identifier attached to these events is one fixed constant shared by every call on the whole server, so they are not linked to an account, a session, or an IP address.server_start: server lifecycle only. Sends the listening port under a fixed server identifier. No user data.cli_command: sent only if you switch CLI telemetry on yourself withhive telemetry enable. Sends the command name, its duration, an error code, the CLI version, your operating system, and your Node.js version, under a freshly random identifier generated per event so two commands cannot be tied to each other.oauth_first_material_receipt: this one is account-linked. It fires once per account and client pair, on the first material result that pair receives, and is then suppressed for that pair for the next 400 days. It sends pseudonymous SHA-256 hashes of your account identifier, of the client identifier, and of the pair, alongside the client profile and version, the tool name, the provider, the category, the runtime and cache status, our server version, and how long it had been since you approved consent. Those hashes are stable, so the same account always produces the same value.
On none of these paths do we send tool arguments, response payloads, wallet or token addresses, your account email address, or an API key value. Your IP address is never sent over the Measurement Protocol.
Two server credentials must both be configured for the Measurement Protocol path to send anything; when either is absent the calls are skipped. This page describes what that path sends when it is switched on, rather than reporting a server setting a published page cannot verify.
The site also ships Vercel Web Analytics, which activates only when the site is built on Vercel itself. Our releases are built elsewhere and uploaded, so no Vercel Analytics script is served today.
Upstream data providers
These are the sources Hive queries to answer a tool call. They are recipients of query content, not subprocessors of your account data: they receive the subject of a query (for example a token address, a contract, or a wallet address) and never receive your account email, your account identifier, or your API key. Requests are made with Hive-managed provider keys.
| Provider | Contributes |
|---|---|
| Alchemy | EVM wallet, token, NFT, transfer, simulation, gas, and network RPC data |
| CoinGecko | Market data, OHLC, trending coins, exchange data |
| DeFiLlama | TVL, yields, fees, stablecoins, chain analytics |
| GoPlus | Token, NFT, dApp, and wallet security and risk analysis |
| Codex | DEX analytics, prediction markets, on-chain trade flow |
| CCXT | Centralized exchange spot, derivatives, and funding rates |
| Helius | Solana RPC, Digital Asset Standard, priority fees, parsed transactions |
| Hyperliquid | Perpetual DEX volume, funding, candles, open interest, builder DEX discovery |
| Moralis | Wallet, token, and NFT analytics across EVM and Solana |
| Tenderly | EVM transaction simulation, gas estimation, calldata decoding |
| Open Data Fetch | Allowlisted, size-capped access to long-tail public crypto APIs |
| Hive Archive | Hive's own derivatives history store. No third party involved |
| RWA Perps | Hive's own tokenized real-world-asset perp snapshots. No third party involved |
Changes to this list
We will update this page before a new subprocessor starts processing data. Customers with a signed Data Processing Addendum may object to a new subprocessor on the terms set out there. To be notified of changes, email support@hiveintelligence.xyz and ask to be added to the subprocessor notification list.