Security & Data Privacy

Sub-processors

The following third-party services process data on our behalf to operate Product Analyst AI. We contractually require each sub-processor to protect your data with appropriate security measures.

Last updated March 2026

Sub-processorLocationPurposeData processed
AnthropicUSAAI-powered analysis (LLM)Anonymized analytics context, user questions. Zero data retention — nothing stored after processing.
SupabaseUSA (AWS)Database and authenticationAccount information, hashed event data, authentication credentials.
SlackUSAMessage delivery and app platformWorkspace ID, bot token, messages that @mention the bot.
VercelUSA (AWS)Application hostingStandard server logs (IP, browser type, timestamps).
ResendUSATransactional emailEmail address, email content for account notifications.
HetznerEU (Germany/Finland)Infrastructure hosting (Docker)Application runtime data, encrypted at rest and in transit.

Anthropic (zero retention): Our AI provider does not store, log, or retain any data sent via the API. Prompts and responses are processed in memory only and discarded immediately. Anthropic is contractually prohibited from using customer data to train models.

PII handling: User identifiers are cryptographically hashed on ingestion before reaching any sub-processor. Raw PII is not stored in our systems.

Questions about our sub-processors? [email protected]

Sub-processors | Product Analyst AI