Legal
Subprocessors
The companies we rely on to run the platform, and what each one does with customer data. This is the list Annex 3 of the Data Processing Addendum refers to.
We use as few providers as we can. Each of these processes customer data only to do the job listed, under a contract with data protection terms at least as protective as our DPA.
| Subprocessor | What it does for the Service | Data it sees | Location |
|---|---|---|---|
| Cloudflare, Inc. San Francisco, USA |
Hosting and the edge network. Runs the edge that authenticates every request, the applications themselves (Workers and containers), their storage (files, databases, container images), the dashboard and the API, and the queue that carries audit events. | Everything that passes through the platform: request metadata, identity tokens, application code and data, the audit stream in transit. | Requests are served from Cloudflare's global edge, at the location nearest the person making them. Account data is stored in the United States. |
| Neon, Inc. Delaware, USA |
The control-plane database (Postgres): accounts, workspaces, members, app configuration, access rules, encrypted secrets, billing status, the audit log. | Account emails, sign-in metadata, app metadata, the audit log, secrets in encrypted form. | AWS us-east-2 (Ohio), United States. |
| Resend, Inc. San Francisco, USA |
Transactional email, and nothing else: sign-in codes; invitations to a workspace or an app; notices to a workspace's owners about its billing, its request allowance, a suspension, audit-log entries due to be deleted, or a change to the Service; notices about a workspace's database limit and database rows; notice of new limits before they take effect; and alerts to our own staff when part of the platform goes down or comes back, when audit-log entries aren't being delivered, when mail fails to send, when a deleted app is still on Cloudflare an hour later, or when Cloudflare won't let us read apps' logs. | The recipient's email address and the content of the message. | eu-west-1 (Ireland). |
| Stripe, Inc. South San Francisco, USA |
Payments: subscriptions, cards, invoices, receipts, tax calculation, and the customer portal where a card is updated, an invoice is read or a plan is cancelled. | The workspace owner's email address and the workspace name, which we give Stripe as the customer's email and name; the hourly request counts we report for metering; and what you give Stripe yourself: billing name and address, card details (which we never receive), tax identifiers, invoice history. The workspace identifier is in the customer's metadata. | United States. |
| Proton AG Geneva, Switzerland |
Our own mailboxes: support, privacy and security. It holds the email you send us, replies to the platform's emails included, and our answers. | Whatever you write to us: your email address and name, and anything you include, such as a workspace or app name, the address an app was shared with, or lines from the audit log. Kept 2 years after the last message in the thread. | Switzerland, Germany or Norway, where Proton stores mail (proton.me/mail/privacy-policy, checked 23 September 2026). |
When the list changes
We email every workspace owner at least 30 days before we add or replace a subprocessor, saying what it will do and where. If you object on reasonable data protection grounds, section 7 of the DPA says what happens next. Removing a subprocessor needs no notice; the table is updated when it happens.
The date at the top of this page is the date of the last change to the list.
What is not on the list
There is no analytics provider, no advertising network, no customer-relationship tool holding your data, and no service that reads your content for any purpose of its own. GitHub hosts the open-source SDKs and the CLI's releases, but no customer data goes there. The providers your apps call are your own subprocessors, not ours, even where the platform holds their credentials for you.