Legal

Subprocessors

The companies we rely on to run the platform, and what each one does with customer data. This is the list Annex 3 of the Data Processing Addendum refers to.

Last updated 24 September 2026

We use as few providers as we can. Each of these processes customer data only to do the job listed, under a contract with data protection terms at least as protective as our DPA.

SubprocessorWhat it does for the ServiceData it seesLocation
Cloudflare, Inc.
San Francisco, USA
Hosting and the edge network. Runs the edge that authenticates every request, the applications themselves (Workers and containers), their storage (files, databases, container images), the dashboard and the API, and the queue that carries audit events. Everything that passes through the platform: request metadata, identity tokens, application code and data, the audit stream in transit. Requests are served from Cloudflare's global edge, at the location nearest the person making them. Account data is stored in the United States.
Neon, Inc.
Delaware, USA
The control-plane database (Postgres): accounts, workspaces, members, app configuration, access rules, encrypted secrets, billing status, the audit log. Account emails, sign-in metadata, app metadata, the audit log, secrets in encrypted form. AWS us-east-2 (Ohio), United States.
Resend, Inc.
San Francisco, USA
Transactional email, and nothing else: sign-in codes; invitations to a workspace or an app; notices to a workspace's owners about its billing, its request allowance, a suspension, audit-log entries due to be deleted, or a change to the Service; notices about a workspace's database limit and database rows; notice of new limits before they take effect; and alerts to our own staff when part of the platform goes down or comes back, when audit-log entries aren't being delivered, when mail fails to send, when a deleted app is still on Cloudflare an hour later, or when Cloudflare won't let us read apps' logs. The recipient's email address and the content of the message. eu-west-1 (Ireland).
Stripe, Inc.
South San Francisco, USA
Payments: subscriptions, cards, invoices, receipts, tax calculation, and the customer portal where a card is updated, an invoice is read or a plan is cancelled. The workspace owner's email address and the workspace name, which we give Stripe as the customer's email and name; the hourly request counts we report for metering; and what you give Stripe yourself: billing name and address, card details (which we never receive), tax identifiers, invoice history. The workspace identifier is in the customer's metadata. United States.
Proton AG
Geneva, Switzerland
Our own mailboxes: support, privacy and security. It holds the email you send us, replies to the platform's emails included, and our answers. Whatever you write to us: your email address and name, and anything you include, such as a workspace or app name, the address an app was shared with, or lines from the audit log. Kept 2 years after the last message in the thread. Switzerland, Germany or Norway, where Proton stores mail (proton.me/mail/privacy-policy, checked 23 September 2026).

When the list changes

We email every workspace owner at least 30 days before we add or replace a subprocessor, saying what it will do and where. If you object on reasonable data protection grounds, section 7 of the DPA says what happens next. Removing a subprocessor needs no notice; the table is updated when it happens.

The date at the top of this page is the date of the last change to the list.

What is not on the list

There is no analytics provider, no advertising network, no customer-relationship tool holding your data, and no service that reads your content for any purpose of its own. GitHub hosts the open-source SDKs and the CLI's releases, but no customer data goes there. The providers your apps call are your own subprocessors, not ours, even where the platform holds their credentials for you.