Sub-processors
Last updated 6 August 2026
This is the complete register of third parties that can process customer data on our behalf, rendered from the same source file our engineering checks run against — an integration cannot ship without appearing here. Optional processors receive data only when their credential is configured: a deployment with no API keys sends data to none of them; the built-in fallback (demo engines, template briefs, mock checkout, console email) runs in their place.
Always on
| Provider | Purpose | Data shared | Location |
|---|---|---|---|
| Vercel | Application hosting, serverless functions, request logs; optional portal-domain provisioning via the Vercel API | All application traffic (IP addresses, request metadata); custom portal hostnames | United States (global edge) |
| Neon | Managed Postgres — the application database | All application data (accounts, client workspaces, sweep results) | United States (region fixed at project creation) |
| Cloudflare | DNS and domain registration | DNS queries only — no customer content | Global |
Optional — active only when configured
| Provider | Purpose | Data shared | Location | Keyless fallback |
|---|---|---|---|---|
| Anthropic | Claude engine sweeps; mention extraction, remediation briefs, prompt suggestions, fact-checking | Tracked prompts, brand and competitor names, engine answer text | United States | Demo personas, heuristic extraction, template briefs and suggestions, deterministic pricing matcher |
| OpenAI | ChatGPT engine sweeps | Tracked prompts (brand names appear only in the answers it returns) | United States | Demo persona |
| Perplexity | Perplexity engine sweeps | Tracked prompts | United States | Demo persona |
| Google (Gemini API) | Gemini engine sweeps | Tracked prompts | United States | Demo persona |
| SerpAPI | Google AI Overviews capture (live results-page queries) | Tracked prompts as Google queries | United States | Demo persona with simulated absence rate |
| DataForSEO | Keyword search-volume lookups for measured prompt demand | Extracted head terms from tracked prompts, sent in a flat batch with no client, workspace or account identifier attached — a term may itself contain a brand name if the prompt does | United States / EU | Deterministic demand estimates, labelled as such |
| Stripe | Subscription billing and checkout | Agency billing details (name, email, payment method — card data never touches us) | United States / EU | Mock checkout (test/demo deployments only — no real billing occurs) |
| Resend | Transactional email (alerts, reports, invites, resets) | Recipient email addresses and message content | United States | Console/outbox delivery — mail never leaves the deployment |
| Google (OAuth) | Optional "Sign in with Google" | OAuth profile (name, email) of users who choose it | United States | Email + password sign-in |
| Google Search Console | Optional per-client Search Console connect (Slice D.1): read a client's own organic search performance for reporting and the first-party demand overlay | The client's OAuth authorization for their Search Console property; we read that property's search-performance figures back from Google (top queries, pages, clicks, impressions and average position) | United States | Seed-stable sample data served by the built-in fixture (the keyless demo connect) |
Advance notice
We give customers 14days’ email notice before a new sub-processor begins processing customer data, so you can object under your DPA before anything changes. The change log below is the record.
Change log
- 2026-08-19 — Added Google Search Console (optional per-client organic-search connect).
- 2026-08-06 — Added DataForSEO (optional keyword-volume lookups) alongside the initial register.
- 2026-08-06 — Initial published register.