Last updated: August 13, 2026
This document is published in English only. We do not maintain a translated version, because two versions of a contract eventually disagree and only one of them can control.
1. What This Document Is
1.1 WebberUI (webberui.com) is operated by Teyra LLC ("we", "us", "our"). This page lists every third-party service provider that may process personal data on our behalf when you use webberui.com, plus a small number of third-party services we use that do not touch personal data of site users at all.
1.2 A "Subprocessor" is a third-party company that processes personal data on our behalf so that the service can run — for example, hosting our servers, storing our email list, or operating our sign-in system. Subprocessors act on our instructions; they are not free to use your data for their own purposes.
1.3 This list is deliberately short. We run WebberUI with as few data-touching vendors as we can, and the components you install from WebberUI never send data to us or to anyone on this list: installed components make no network calls to our servers, contain no telemetry or reporting mechanism, and are never remotely disabled. See the License Agreement at /license and the Privacy Policy at /privacy.
2. Our Commitments
2.1 We keep this list current. Before we add a Subprocessor, or materially change what an existing one does with personal data, we update this page and change the "Last updated" date above.
2.2 We tell you about changes that matter. Consistent with the Privacy Policy (/privacy): if a change affects how the early-access email list is used or who stores it, we notify list members by email. For other material changes, the updated date on this page (and on /privacy where relevant) is the notice mechanism.
2.3 We do not add trackers quietly. We will not silently introduce advertising pixels, data brokers, or cross-site tracking vendors. Those categories are already excluded by the Privacy Policy; a change of that magnitude would be a change to the Privacy Policy itself, with the notice obligations that entails.
3. Current Subprocessors and Third-Party Services
| Provider | Purpose | Personal data involved | Processing location |
|---|---|---|---|
| Cloudflare, Inc. | Hosting and delivery of webberui.com (Cloudflare Workers); storage of the early-access email list (Cloudflare D1 database); storage of Pro component source files (Cloudflare R2 — contains no personal data); standard access logs for debugging and abuse prevention; Cloudflare Web Analytics, a cookieless traffic and performance measurement beacon served on page loads | Early-access email list: email address, source page, and signup timestamp — nothing else (deliberately no IP address, no browser user agent). Access logs: request time, path, status code, and coarse region — not matched to any identity. Web Analytics: page load and performance measurements with no cookie and no identifier of any kind | Global edge network for content delivery. Email-list database: no jurisdiction restriction is configured, so Cloudflare assigns the primary location; we do not represent a specific data-residency guarantee |
| Clerk, Inc. | Sign-in, account and organization management, and subscription entitlements. Entirely optional — see Section 5 | Email address and sign-in identifiers (for example a Google or GitHub account identifier, depending on the sign-in method you choose), name, user and organization IDs, session cookies and tokens, and plan/entitlement flags | the United States |
| Transactional email provider — not yet selected | Transactional and notification email: the early-access launch notice, policy-change notices, renewal reminders, and breach notification. Clerk's built-in email covers only authentication flows (sign-in verification and similar), not these notices | Recipient email address and message metadata | Not applicable yet. We will name the provider and its processing location on this page before the first notification email is sent |
| PostHog, Inc. | Product analytics — which pages and components are used, so we know what to build next | An anonymous identifier stored in a cookie and localStorage; page views, referrer, a fixed code-defined list of product events (for example "component viewed", "install command copied"), and performance metrics (Web Vitals). Never linked to your account: we never call PostHog's identify function, so PostHog does not learn who you are. Like any web request, analytics requests carry your IP address to PostHog's servers as configured on 2026-08-13, "Discard client IP data" is not enabled for our project, so the IP is stored with the event | United States (PostHog US Cloud) |
| Payment provider — not yet active | Subscription billing for WebberUI Pro. Billing is not live yet; no payment data is collected today | None today. When billing launches: the data the chosen provider needs to process your payment. We will not see or store full card numbers ourselves | Paddle.com Market Limited, which acts as merchant of record and processes payment data in the United Kingdom and the United States |
| npm, Inc. / GitHub, Inc. | Public distribution of the @webberui/mcp npm package |
None. The package is a public download; distributing it involves no personal data of webberui.com users | Not applicable (no site-user personal data processed) |
4. Notes on the Table
4.1 Cloudflare is our infrastructure: the entire site runs on Cloudflare Workers behind Cloudflare DNS. The only personal data our application stores server-side is the early-access email list (email address, source page, timestamp) in a Cloudflare D1 database — we deliberately store no IP address and no user agent alongside it. Cloudflare also produces standard access logs (Workers Logs), retained under Cloudflare's own policy; we add no application-level logging of our own and do not match access logs to identities.
4.2 Clerk processes personal data only if you choose to create an account or sign in; the free tier never requires it (Section 5). What our application reads from Clerk is narrow: your user and organization IDs, your subscription entitlements, an administratively set "pro" flag where applicable, and your first name (shown in the account menu). Clerk sets its own session cookies when you sign in. During the current launch promotion, signing in grants Pro access; the account and email data involved is the same Clerk data described above and is disclosed in the Privacy Policy.
4.3 PostHog is configured with tracking features off wherever possible: session recording disabled, autocapture disabled, surveys disabled, dead-click capture disabled. Events are a fixed, code-defined list and carry only things like component names, page types, and document slugs — never your email address or account identity. If the analytics key is not configured in a deployment, no analytics code runs at all. Analytics can be blocked with a content blocker without breaking any site functionality. See the Cookie Policy at /cookies.
4.4 Payments. Until a payment provider goes live, the pricing page collects at most a voluntarily submitted email address for the early-access list. When billing launches, we will name the provider in the table above, update this page's date, and treat the addition as a material change under Section 2. Billing terms, including refunds, will be governed by the Refund & Billing Policy at /refunds and the Terms of Service at /terms.
4.5 npm / GitHub are distribution channels for a publicly downloadable package, not processors of site-user data. The package ships with our license terms; see /license.
5. Zero-Account Use
5.1 The free tier requires no account. You can browse the site and install all 274 free components without logging in, without giving an email address, and without any account data about you existing anywhere on our side. In that mode, the only processing that touches you is anonymous analytics (Section 4.3) and Cloudflare's standard access logs (Section 4.1).
5.2 Saved favorites, theme settings, and similar preferences live in your own browser's localStorage and are never uploaded to us or to any provider on this list. See the Cookie Policy at /cookies.
6. How You Learn of Changes
6.1 This page (/subprocessors) is the canonical list. The "Last updated" date changes whenever the list changes — we do not bury Subprocessor changes in a changelog.
6.2 Members of the early-access email list receive email notice of any change that affects how their email address is used or who stores it, consistent with the Privacy Policy (/privacy).
7. Related Documents
- Privacy Policy — /privacy
- Terms of Service — /terms
- License Agreement — /license
- Cookie Policy — /cookies
- Refund & Billing Policy — /refunds
8. Contact
Questions about this list or any provider on it: official@teyrallc.com. WebberUI is a service of Teyra LLC.