Loading…
Loading…
Third parties that process customer data on our behalf. This page is Annex III to our data processing addendum. When the list changes we update it here and record the change on /changelog, and customers have 30 days from publication to object. Last updated: 2026-08-14.
Current subprocessors
| Subprocessor | Purpose | Region |
|---|---|---|
| Neon | Primary Postgres data store for account, chat, and application data. | United States |
| Clerk | Authentication, session, and user identity management. | United States |
| Vercel | Hosting and edge delivery for the web surface (agiworkforce.com). | Global edge |
| Fly.io | Runtime for the real-time signaling server used by collaborative and multi-device sessions. | United States (San Jose) |
| Stripe | Payment processing for paid tiers. | United States |
| Cloudflare | Two roles. (1) Cloudflare R2 object storage: files you upload and files the model generates are stored here. AGI serves catalogued files through a signed-in, active-workspace-scoped app route and does not return raw storage URLs in normal responses. Generated videos use a private bucket; images and other non-video files remain in a public bucket and can be opened without AGI sign-in if their underlying URL is obtained. (2) Edge delivery and DDoS protection for the marketing site. | Global edge |
| Sentry | Error and performance monitoring. Receives crash reports and diagnostic context from the web surface and server routes. | United States |
| E2B | Managed sandbox runtime. Executes code and processes files you supply during a Managed Cloud session. Sandbox execution is gated behind an explicit operator flag and is off by default; while it is off, nothing is sent here. | United States |
| Google Analytics | Product analytics for the marketing site. Receives page views and device/browser metadata. | United States |
| Model providers (Managed Cloud) | Inference for Managed Cloud chat: Anthropic, OpenAI, Google, xAI, DeepSeek, Moonshot and Perplexity. Your prompt and any attached content are sent to the provider serving the model you select. This applies to Managed Cloud only — in Local Mode nothing is sent, and under BYOK you contract with the provider directly. | United States and other regions, per provider |
| OpenRouter | Inference routing on Managed Cloud, in two situations. (1) Always, for the MiniMax, Qwen and Zhipu models — prompt content for those passes through OpenRouter on its way to the model provider. (2) As a failover for any other catalogued chat model when the direct route to its provider fails. That second case means prompt content for a model you selected from any provider can pass through OpenRouter, and we would rather say so than let the narrower first case imply otherwise. | United States |
| MiniMax, Qwen and Zhipu | Inference for their own models on Managed Cloud, reached through OpenRouter rather than directly. | Outside the United States, per provider |
| Upstash | Rate limiting and ephemeral request state. | Global edge |
| Expo | Two roles for the iOS and Android apps. (1) Push delivery: notification titles and bodies (including the names you give scheduled tasks) are relayed through Expo on their way to Apple and Google. (2) Over-the-air updates: every app launch requests an update manifest from Expo, which sees the device IP and build fingerprint. | United States |
| Resend | Transactional email, in three narrow paths and no others. (1) Support escalation: when a live-support session is escalated, the conversation transcript and the contact email you gave are emailed to our support address (lib/support/handoff/escalation-email.ts). (2) Scheduled-task notifications: if you enable them in Settings, the task name and your email address are used to tell you a run finished — the body carries no task output (lib/services/notification-email-service.ts). (3) Operational alerts to us, carrying user-linked job identifiers (lib/services/video-incident-alert-service.ts). There is no account-lifecycle email: no signup, deletion-confirmation, breach or policy-change mail is sent by anything. | United States |
| Runway | Video generation. The prompt text you type is sent to Runway when you generate a video with one of its models (app/api/media/video/generate/route.ts). Only reachable when an operator has configured a Runway key; otherwise the route refuses rather than silently choosing another provider. | United States |
| Perplexity | Two distinct roles, and the second was previously undisclosed. (1) Inference for its own models on Managed Cloud, as listed in the model-provider row above. (2) The backend for the platform web-search tool: when the assistant searches the web for you, your search query is sent to Perplexity (lib/web-search/web-search-tool.ts). That happens on the model’s initiative during a conversation, not only when you visit a search box. | United States |
| Google (Play Android Publisher) | Verifying Android in-app purchases. The purchase token from your device is sent to Google to confirm a subscription is genuine and current (lib/server/mobile-iap-store-verification.ts). Apple is deliberately NOT listed for the equivalent iOS path: Apple’s signed notifications are verified locally against bundled root certificates, so nothing is sent back to Apple. | United States |
| OpenStreetMap Foundation (Nominatim) | Geocoding for the maps tool. A place name or location you ask about is sent to Nominatim to resolve it to coordinates (lib/services/map-geocoding-service.ts). Nominatim’s usage policy requires an identifying User-Agent, so the request is attributable to AGI rather than to you. | European Union |
| GitHub | The GitHub connector. When you install it, repository content and metadata you authorise are read through the GitHub API on your behalf (lib/github-app.ts). Nothing is read until you install the app and grant it access, and you can revoke it at GitHub at any time. | United States |
How you find out about a change
Additions and replacements are published on this page and recorded on /changelog, which you can subscribe to. We do not promise emailed notice. The product can send email in three narrow paths (support escalation, scheduled-task notifications, and operational alerts to us) and none of them can mail an arbitrary list of customers. Until something can, a commitment to email you about a subprocessor change is one we could not perform. To object to a new subprocessor on reasonable data protection grounds, write to us within 30 days of publication. The objection and termination route is in section 05 of the DPA.
Corrections made on 2026-08-14
A review of what actually leaves this product found this page had been wrong in both directions, and we would rather publish the correction than quietly reissue the list.
Resend, Runway, Perplexity’s web-search role, Google’s Play verification API, OpenStreetMap’s Nominatim and GitHub were all receiving data while absent from this page. They are listed above with what each one receives.
It was delisted because no email package appeared in our dependencies. It does not use one: it calls the provider’s HTTP API directly, so the check that justified the removal could not have found it. Support transcripts were being emailed the whole time. That is the most serious thing this review found, and it is fixed above.
It named three model families. OpenRouter is also the failover for every other catalogued chat model, so prompt content for a model from any provider can pass through it. The row now says so.
Apple was reported as receiving purchase identifiers alongside Google. It does not: Apple’s signed receipts are verified on our own servers against bundled certificates, and nothing is sent back. We checked rather than adding the row, and we are noting the near-miss because a list padded with recipients that receive nothing is unreliable in the same way as one with gaps.
What about LLM providers?
When you BYOK against Anthropic, OpenAI, Google, or any other provider, that provider becomes a processor of your data, on your contract, not ours. We do not process those prompts; the request goes from your client to the provider you targeted, and no row in the table above is in that path.
Which surface that applies to, precisely. BYOK is a capability of the desktop app, the CLI and the VS Code extension. The web app at agiworkforce.com is cloud-only: it has no user-supplied-key path at all. Every model request you make in a browser is a Managed Cloud request on our keys, through the recipients listed above. We used to state the BYOK posture here without naming the surface, which invited exactly the wrong inference on the one surface where it does not hold. See BYOK for the full posture.