Subprocessors
Effective 8 August 2026 · Last updated 8 August 2026
The third parties that handle information on our behalf so CrowFlo can run. This page is the current record of who they are and what each one does.
1. What this page is
A subprocessor is a third party that processes information on our behalf so that CrowFlo can work. This page lists them, says what each one does, and is referenced by our Privacy Policy and Terms of Service.
This list is the authoritative record of who processes your information. Where the Privacy Policy names providers in prose, it does so illustratively; this page is what to rely on.
We give notice of a change by updating this page, and the last-updated date at the top shows when that happened. We do not currently send individual notifications or offer a right to object to a particular subprocessor under standard terms. If the identity of our subprocessors matters to you, please check this page, or raise it before signing so it can be dealt with in a negotiated agreement.
2. Infrastructure
These run the Service itself. All customer data is stored in the United States.
- Application hosting and compute. United States. Single region; there is no multi-region deployment.
- Neon - managed PostgreSQL database. Stores account, project and register data. Region: us-east-1, United States.
- Cloudflare - DNS, edge delivery and network protection. Traffic passes through Cloudflare’s global network.
3. AI providers
These receive prompts and the relevant project context when you use an AI feature. Requests may be routed to a different provider automatically if one is unavailable - see clause 7 of the Privacy Policy.
- Anthropic - AI model inference.
- OpenAI - AI model inference.
- Google (Gemini) - AI model inference.
- xAI (Grok) - AI model inference.
Not every provider is used for every feature, and which one is active is a platform configuration that can change, including automatically on failover. We use each under its standard published API terms: we have not negotiated bespoke data-processing terms and have not enabled zero-retention or enterprise configurations, so retention of inputs and outputs follows each provider’s own terms rather than an agreement specific to CrowFlo. Their processing locations are determined by the provider and are not restricted by us.
Where you configure your own provider credentials (Bring Your Own AI), that provider is not our subprocessor: you contract with it directly and its terms govern. It will not appear on this list.
4. Identity, payments and communications
- WorkOS - single sign-on and directory synchronization. Used only by organizations that enable SSO or SCIM; processes identity attributes sent by your identity provider.
- Stripe - payment processing and subscription billing. Handles card data directly; we do not receive or store full card numbers.
- Resend - transactional email delivery. Sends account, invitation, security and billing notifications; processes recipient email addresses and message content.
5. What this list does not yet say
Stated plainly rather than left to be discovered:
- Each subprocessor is engaged under its own standard published terms. We have not separately negotiated or executed data processing agreements with them, and we do not rely on bespoke commitments from any of them.
- Several of these providers hold security certifications and publish audit reports. We do not verify or audit them, and we make no representation about them; if a certification matters to you, check it with the provider directly.
- This list was compiled from the CrowFlo codebase and reflects the third parties the product actually calls. It does not include tools used internally that never receive customer content.
Questions about this list: [email protected].