Subprocessors

Every vendor that processes data on our behalf, with purpose and region.

Effective date: August 25, 2026. For a transfer assessment, regions marked “Available on request” are confirmed by emailing support@hiveintelligence.xyz.

Hive Intelligence engages the vendors below to operate Hive Intelligence. This page is referenced by our Privacy Policy and by our Data Processing Addendum, and it is the authoritative list for both.

Infrastructure and platform

VendorPurposeData receivedProcessing region
VercelHosting and edge delivery for hiveintelligence.xyz and the dashboardIP address, request metadata, user agentUnited States, served from a global edge network
Google Cloud Platform (Cloud Run, Artifact Registry, Cloud Logging)Hosting the MCP server and the CLI backend, and its operational logsIP address, request metadata, tool-call telemetry, application logsasia-southeast1 (Singapore)
SupabaseManaged Postgres, account authentication, and delivery of sign-in emailsAccount email address, account identifier, plan and billing state, sign-in emailsap-south-1 (Mumbai, India)
UnkeyAPI key issuance and verificationKey identifier, key prefix, key metadata, account identifier. Not a recoverable copy of the keyAvailable on request
Managed RedisOAuth state, distributed rate limiting, and durable canary historyShort-lived tokens, rate-limit counters keyed by principal or IPAvailable on request

Payments

Both payment processors act as independent controllers for the payment itself. What each one receives is described in section 5 of the Privacy Policy.

VendorPurposeData receivedProcessing region
StripeCard payment processing and subscription managementAccount email address, account identifier, plan; card and billing details you give Stripe directlyAvailable on request
LlamaPayCrypto payment checkoutAccount identifier, plan, billing cycle, charge amount, account email address where available; wallet connection handled by LlamaPayAvailable on request

Analytics

VendorPurposeData receivedProcessing region
Google (Google Analytics 4)Status-page visit measurement, plus server-side service telemetry sent from the MCP backend over the GA4 Measurement ProtocolStatus page: page-view data and the visitor's IP address. Measurement Protocol: tool name, outcome, duration, cache and runtime status, provider, client profile and version, server version; and on one activation event only, pseudonymous hashes derived from the account identifier. No IP address is sent on the Measurement Protocol pathAvailable on request

Google receives data on two independent paths. The second one runs on our servers rather than in your browser, so no browser setting reaches it.

Browser script

A Google Analytics tag is served on the status page at mcp.hiveintelligence.xyz/status. It reports a page view and, like any browser request to Google, the visitor's IP address. No account identifier is attached to a visit to that page. That tag is under review for removal.

No analytics script is served on hiveintelligence.xyz or in the dashboard. Pages on this site do preconnect to Google's two analytics hosts, which opens a connection to Google on page load and so exposes your IP address to Google even though no analytics script is loaded.

Server-side Measurement Protocol

The MCP server sends telemetry directly to Google from our backend, by POST to www.google-analytics.com/mp/collect. It carries four events:

  • tool_call: one per tool call. Sends the tool name, whether the call succeeded, how long it took, and whether the answer came from cache. The identifier attached to these events is one fixed constant shared by every call on the whole server, so they are not linked to an account, a session, or an IP address.
  • server_start: server lifecycle only. Sends the listening port under a fixed server identifier. No user data.
  • cli_command: sent only if you switch CLI telemetry on yourself with hive telemetry enable. Sends the command name, its duration, an error code, the CLI version, your operating system, and your Node.js version, under a freshly random identifier generated per event so two commands cannot be tied to each other.
  • oauth_first_material_receipt: this one is account-linked. It fires once per account and client pair, on the first material result that pair receives, and is then suppressed for that pair for the next 400 days. It sends pseudonymous SHA-256 hashes of your account identifier, of the client identifier, and of the pair, alongside the client profile and version, the tool name, the provider, the category, the runtime and cache status, our server version, and how long it had been since you approved consent. Those hashes are stable, so the same account always produces the same value.

On none of these paths do we send tool arguments, response payloads, wallet or token addresses, your account email address, or an API key value. Your IP address is never sent over the Measurement Protocol.

Two server credentials must both be configured for the Measurement Protocol path to send anything; when either is absent the calls are skipped. This page describes what that path sends when it is switched on, rather than reporting a server setting a published page cannot verify.

The site also ships Vercel Web Analytics, which activates only when the site is built on Vercel itself. Our releases are built elsewhere and uploaded, so no Vercel Analytics script is served today.

Upstream data providers

These are the sources Hive queries to answer a tool call. They are recipients of query content, not subprocessors of your account data: they receive the subject of a query (for example a token address, a contract, or a wallet address) and never receive your account email, your account identifier, or your API key. Requests are made with Hive-managed provider keys.

ProviderContributes
AlchemyEVM wallet, token, NFT, transfer, simulation, gas, and network RPC data
CoinGeckoMarket data, OHLC, trending coins, exchange data
DeFiLlamaTVL, yields, fees, stablecoins, chain analytics
GoPlusToken, NFT, dApp, and wallet security and risk analysis
CodexDEX analytics, prediction markets, on-chain trade flow
CCXTCentralized exchange spot, derivatives, and funding rates
HeliusSolana RPC, Digital Asset Standard, priority fees, parsed transactions
HyperliquidPerpetual DEX volume, funding, candles, open interest, builder DEX discovery
MoralisWallet, token, and NFT analytics across EVM and Solana
TenderlyEVM transaction simulation, gas estimation, calldata decoding
Open Data FetchAllowlisted, size-capped access to long-tail public crypto APIs
Hive ArchiveHive's own derivatives history store. No third party involved
RWA PerpsHive's own tokenized real-world-asset perp snapshots. No third party involved

Changes to this list

We will update this page before a new subprocessor starts processing data. Customers with a signed Data Processing Addendum may object to a new subprocessor on the terms set out there. To be notified of changes, email support@hiveintelligence.xyz and ask to be added to the subprocessor notification list.