| Fulfillment: invoices and receipts | Paid order | Financial records, personal data | S3 | Dedicated bucket per document class; presigned URLs, 1-hour TTL |
| Fulfillment: file benefits | Merchant upload | Merchant content | S3 | Presigned URLs, 1-hour TTL |
| Fulfillment: Discord and GitHub benefits | Benefit grant | End-customer OAuth identity, including access and refresh tokens | Postgres, Discord, GitHub | Scoped to the granting organization |
| Fulfillment: license keys | Benefit grant | Key, per-device activations | Postgres | Scoped to the granting organization |
| Fulfillment: email | Platform event | Recipient address, subject, rendered body | Resend | Sends recorded in email_logs; marketing audience keyed by users.resend_id |
| Usage events and metering | Merchant API or SDK | Customer and member references plus arbitrary merchant-supplied metadata; the Tinybird row also carries customer email and name | Postgres, Tinybird | Scoped to the ingesting organization; per-environment Tinybird tokens; metadata treated as untrusted |
| Outbound webhooks | Platform event | The same objects the API returns, including customer email and billing address | Merchant endpoint | Payload signing; 10 retries; failing endpoints disabled; events deleted after 90 days |
| Payouts | Paid orders | Balance transactions, payout records, payout invoice PDFs; Connect account ID, country, currency, capability flags | Postgres, S3, Stripe | Held until a minimum balance and delay elapse; payout invoices in a separate bucket from customer invoices |
| Disputes and chargebacks | Stripe, ChargebackStop | Card transaction identifiers, dispute records | Postgres | Both signature-verified; payloads stored raw in external_events and processed asynchronously |
| Support | Buyer or merchant | Support threads, chat transcripts, attachments; context cards looked up by email address | Plain | Plain’s requests signature-verified; cards return only triage fields |
| Telemetry | API, workers, browser | Traces, metrics, product analytics, error reports | Logfire, Sentry, PostHog, Grafana, S3 | Browser analytics and errors proxied through polar.sh; session replay disabled; health-check and token-usage spans dropped at the sampler |
| Audit logs and span archive | Trace spans | Gzipped JSONL, the Audit Logs asset | S3 | Sensitive attribute keys redacted before the object is written |
| Backups | Render Postgres | Everything in this document, in one object | S3 | Object Lock in COMPLIANCE mode means a backup cannot be deleted before retention elapses, by anyone, including root; deletion reaches backups by expiry rather than erasure |
| Staff access | Polar admin via backoffice | Any production record; impersonation renders the merchant dashboard | Postgres | Impersonation restricted to READ_ONLY_SCOPES and one organization |
| AI: organization review | Merchant signup | Products, website text, Stripe-verified identity (name, date of birth, address country), payout-account details, payment totals and risk scores, user history | Pydantic AI Gateway → OpenAI, Anthropic | ADR-0012 |
| AI: Compass | Merchant question | Merchant metrics; buyer personal data only when asked about that person | Pydantic AI Gateway → OpenAI, Anthropic | ADR-0012 |
| AI: Plain subject lines | Support message | The customer’s message | Pydantic AI Gateway → OpenAI, Anthropic | ADR-0012 |
| Workspace assistant | Meetings, calendar, Slack, Google Workspace, GitHub | Meeting audio and transcripts, internal communications, documents, source code | Stilla | Zero-data-retention agreements with the underlying LLM providers; contractual bar on training |