Loading…
𓂀[DRAFT — confirm before publishing] The list below is verified from our codebase. The exact contracting legal entity and data region for each [NEEDS MATTHEW] before this is published.
| Sub-processor | Purpose | Data processed |
|---|---|---|
| Vercel | Application hosting / serverless compute + product analytics | All application data in transit; aggregate usage/page-view analytics |
| MongoDB Atlas | Primary database (system of record for all application data) | All application data at rest — account, business records, customer PII (identity fields encrypted at rest) |
| Stripe | Payment processing (subscriptions + Connect) | Billing contact + payment details (card data tokenized by Stripe; never stored by ThothOS) |
| Anthropic | AI/LLM provider for in-app AI features | Prompt / conversation content submitted to AI features |
| Mailgun | Transactional & customer-facing email delivery | Recipient email addresses + email message content |
| Twilio | SMS phone-number verification (Twilio Verify) | Phone numbers + one-time SMS verification codes |
| EasyPost | Shipping rates, labels, and tracking | Shipping / recipient addresses + parcel details |
| Cloudflare (R2 + Images) | Audit-log archive storage + tenant image hosting/CDN | Audit-log archive files (R2) + uploaded images (Images/CDN) |
| Google Analytics (marketing + portals when GA ID configured) + Google Calendar sync (customer-enabled OAuth) | Page-view / usage analytics; calendar event titles and attendee metadata when connected | |
| Microsoft | Outlook / Microsoft 365 calendar sync (customer-enabled OAuth) | Calendar event titles and attendee metadata when connected |
| Apple | Apple Calendar connect (customer-enabled OAuth; connect-only) | Calendar account identity tokens when connected |
| Intuit QuickBooks | QuickBooks Online accounting sync (customer-enabled OAuth) | Customer names/refs + invoice line descriptions when connected |
Google, Microsoft, Apple, and Intuit QuickBooks (listed above) process data only when a customer explicitly connects them or configures a measurement ID. Calendar and QBO sync are off unless enabled; Google Analytics loads only when a measurement ID is present.
See our DPA and Privacy Policy.