Sub-processors
Last updated — 2 September 2026
What this page is
These are the third parties that process data on our behalf. Our Privacy Policy points here, and we publish a change on this page before a new sub-processor begins processing rather than after.
For each one: what it actually receives, where it is, and whether you can refuse it. Where the honest answer is that refusing means not using a feature, or not using the service, it says so.
Hetzner — hosting
Runs the application and both databases. It therefore holds all stored telemetry at rest.
Germany (EU).
Cannot be declined: it is where the platform runs.
Cloudflare — network, bot check, and backup storage
Every request reaches us through Cloudflare, so it sees telemetry in transit. It is the only inbound path.
Turnstile, the bot check on the registration form, receives a visitor’s IP address and the browser signals its widget collects — on that page only, and not for anyone already signed in.
Backups are being moved to Cloudflare R2, in a bucket restricted to the European Union. A backup is a dump of both databases, so it is the largest single quantity of customer data any party here holds — and it is sealed before it leaves our host, so what Cloudflare receives is ciphertext it holds no key for. We are naming it here before the first backup is written rather than afterwards.
Global edge; the backup bucket is restricted to the EU.
Cannot be declined: it is the only inbound path.
Anthropic — AI investigations
Receives a deliberately minimised subset of a single issue: exception type, message, stack trace, culprit, counts and the correlated release. Never end-user identifiers, never raw attribute bags, never whole events.
Separately, and only where an organisation switches it on, it receives the code change a customer’s own build pipeline posts for review — their source code, for that request, unstored.
United States.
Can be declined, twice over: the feature is off unless the deployment configures a key, an organisation may refuse the sub-processor outright, and sending source code is a second permission that starts off.
Resend — transactional email
The delivery path for alert and digest email, where a customer has configured an email destination. It receives the subject and body of those messages — an issue title, service name, counts, and a link back — plus the recipient address the customer chose, which is their own staff rather than their users. Never an event body and never an end-user identifier.
Ireland (EU). Resend runs on Amazon SES, so AWS is the infrastructure underneath and is in the same region.
Cannot be declined while using email delivery, because delivery needs a relay. A customer who wants no third party in that path can use a webhook to their own endpoint instead, which is the honest alternative.
GeniusPay — payment collection
Hosted checkout and the webhook reporting the outcome, for buying a plan.
It receives no personal data and no telemetry: an amount, a currency, a plan description, two opaque identifiers, and the two URLs to return the browser to. Their API has a customer object for name, email, phone and country; we never populate it.
Côte d’Ivoire.
Not applicable to what we send — but paying at all means using them, so declining means not buying a plan.
How to be told when this changes
Write to [email protected] and ask to be notified of sub-processor changes, and we will tell you before the next one starts processing.