Legal
Subprocessors
Last updated: May 15, 2026
These are the companies that process data on our behalf when we run a virtual employee for a client. The list is kept in the product's own code and rendered here, so it cannot quietly fall out of date.
| Who | What for | Where | What they see |
|---|---|---|---|
| Anthropic | the language model that writes and reviews content | EU/US, depending on the endpoint in use | briefs, content drafts, memory used as context |
| Voyage AI | embeddings, so the employee can find what it already knows | US | memory entries, conversation summaries |
| Supabase | database, authentication and file storage | EU (eu-central-1) | all workspace data, account identities, generated images |
| Vercel | hosting for the portal | EU | request metadata |
| Railway | hosting for the service that does the actual work | EU | request metadata, job payloads in transit |
| Zernio | publishing to social networks and reading comments, when enabled | EU | published content, public comments under it |
| Microsoft | mailbox, Teams and files, when the client connects them | the client's own Microsoft 365 tenant | email the employee sends and receives, files it is given access to |
Changes to this list
We tell clients before adding a subprocessor that would see their content. Connections a client does not enable - social publishing, Microsoft 365 - never receive their data at all.