Subprocessors (Public List)

Last updated on September 10, 2025

Contact: [email protected]

This page discloses third‑party service providers that process personal data on behalf of Documentation.AI to deliver, secure, and support our Services. We require each subprocessor to use personal data only to provide contracted services, implement appropriate security measures, and comply with applicable law.

Change management: We will update this page and, where required, provide prior notice (typically 30 days) before adding or replacing a subprocessor, except for emergency replacements (we will notify promptly thereafter). To raise an objection where permitted by contract, email [email protected] with “Subprocessor Objection” in the subject.

Current subprocessors

VendorPurposeCategories of dataData location(s)Key safeguards
Render.comApplication hosting & runtimeAccount/workspace data processed by the app; logs; service metadataRegion as configured (e.g., USA/EU)Encryption in transit; access controls; isolation
Vercel, Inc.Front‑end hosting, serverless/edge functions, CDNIP addresses; request headers; logs; static/app content in transit (transient)Global POPs and selected regionsTLS; isolation; access controls
SupabaseManaged Postgres DB & object storageAccount profiles; workspace content; metadata; access tokens (as configured)Region as configured (e.g., USA/EU)Encryption at rest/in transit; role‑based access
MeiliSearchApplication search indexing & querySearch indices built from workspace content (as configured); search queries; pseudonymous IDsRegion as configured (e.g., USA/EU)Encryption at rest/in transit; access controls
Cloudflare, Inc.CDN, DDoS protection, edge cachingIP addresses; request headers; content in transit (transient)Global POPsTLS; DDoS mitigation
Clerk.comAuthentication & identity managementNames; emails; auth factors; session/device metadataUSA/EU (per service configuration)Access controls; encryption in transit
IntercomCustomer support & in‑app messagingName; email; support messages; usage/ticket metadataUSA/EUAccess controls; encryption in transit
Stripe, Inc.Payment processing & invoicingBilling name; email; payment method token; last 4 digits; transaction metadataUSA/EUPCI DSS Level 1; tokenization (we do not store full card numbers)
PostHogProduct analytics (events)Event data (feature usage, clicks); pseudonymous IDs; coarse IPUSA/EU (cloud region as selected)PII filters configurable; opt‑out controls
Framer.comMarketing website hosting/CMSSite visitor telemetry; contact form submissions (if enabled)USA/EUEncryption in transit; access controls
Trigger.devBackground jobs & workflow orchestrationJob payload

Notes

  • Marketing vs product: Framer processes website visitor/contact data; the rest primarily support the product.
  • Regionality: Where supported, we select regions to align with our hosting footprint; exact regions may change as we scale.
  • AI models: We use model providers as configured to fulfill user requests. By default, we do not permit model providers to train on customer content.