The following third-party services process data on our behalf to operate Product Analyst AI. We contractually require each sub-processor to protect your data with appropriate security measures.
Last updated March 2026
| Sub-processor | Location | Purpose | Data processed |
|---|---|---|---|
| Anthropic | USA | AI-powered analysis (LLM) | Anonymized analytics context, user questions. Zero data retention — nothing stored after processing. |
| Supabase | USA (AWS) | Database and authentication | Account information, hashed event data, authentication credentials. |
| Slack | USA | Message delivery and app platform | Workspace ID, bot token, messages that @mention the bot. |
| Vercel | USA (AWS) | Application hosting | Standard server logs (IP, browser type, timestamps). |
| Resend | USA | Transactional email | Email address, email content for account notifications. |
| Hetzner | EU (Germany/Finland) | Infrastructure hosting (Docker) | Application runtime data, encrypted at rest and in transit. |
Anthropic (zero retention): Our AI provider does not store, log, or retain any data sent via the API. Prompts and responses are processed in memory only and discarded immediately. Anthropic is contractually prohibited from using customer data to train models.
PII handling: User identifiers are cryptographically hashed on ingestion before reaching any sub-processor. Raw PII is not stored in our systems.
Questions about our sub-processors? [email protected]