Trust
Sub-processors
Every third party we let touch your data, why, and where it processes. This list is incorporated by reference into our Data Processing Agreement, which commits us to give at least 14 days' notice before adding a new one.
Last updated 2026-09-08
In use today
Polar
Payment processing and billing, as merchant of record. Receives your organisation's billing contact, payment method, and billing address; issues receipts and handles tax. We never receive your full card number.
Where: United States.
Resend
Delivery of transactional email — sign-in and verification links, password resets, receipts, and billing and security notices. Never used for marketing.
Where: United States.
Cloudflare
Our network edge: TLS termination, DDoS protection, and routing for all website and application traffic, plus object storage for macOS app downloads. Sees visitor connections (including IP addresses) as our processor for this.
Where: Global edge network — a request is served from whichever of Cloudflare's points of presence is nearest the visitor, which may be inside or outside the EEA/UK.
Sentry
Application error tracking, where enabled — app or browser version, an error's stack trace, and a request id. We scrub identifiable information from these reports where practical.
Where: United States.
Application and database hosting
Operator confirmation neededRuns the web application, background workers, and the primary Postgres database — where every row described in our Privacy Policy and this page ultimately lives, and where encrypted backups are taken.
Where: Needs operator confirmation. Deployment is orchestrated through a self-hosted Coolify instance the operator administers directly; the underlying compute/hosting provider and its region are an operator decision this codebase does not record, and should be added here — with the transfer safeguard from our Data Processing Agreement — before this page is treated as final.
Only if you choose them, or if we turn them on
These process data only in the specific circumstance named below — never for every visitor or every account.
Sign-in, only if you choose "Continue with Google". We receive your verified email; we never receive your Google password. Also used for domain-verified Workspace sign-in on the Team plan, where an organisation has claimed its domain.
Where: United States.
Apple
Sign-in, only if you choose "Continue with Apple". We receive your verified email (or Apple's private relay address); we never receive your Apple password.
Where: United States.
Advertising measurement (Meta, Google, TikTok, LinkedIn, X, Pinterest, Snap, or Reddit)
Off unless we turn one on, and — where consent is required — loaded only after you agree. If Meta measurement is enabled, we may send it a limited, mostly hashed event record (such as a hashed email address) together with your IP address and user-agent, to match a conversion.
Where: United States, and wherever else the specific provider processes conversion events.
Not a sub-processor: our analytics
Website and app analytics are our own, first-party system, running on our own infrastructure (the hosting row above) — not a third-party analytics vendor. We do not use Google Analytics or any comparable third-party tool. See our Privacy Policy for exactly what that system records.
What each of your organisation's members controls
Nothing above ever receives the content of a note, a Vault secret's value, or a Thread's board: those are encrypted on a member's own device under a key none of these providers, and we ourselves, ever hold. See how we secure your data for the full boundary.
Questions
Write to [email protected] about this list, or to request the underlying Standard Contractual Clauses referenced in our Data Processing Agreement.