Legal · Plain language
Sub-processors
Seven providers touch PAPI data, and each one gets only what its job requires. This is the canonical list — the same one referenced from our Privacy Policy, Trust & Security page, and our data processing agreement.
Last updated · 15 September 2026
| Service | What they handle |
|---|---|
| Netcup | EU VPS infrastructure for the dashboard, MCP server, database, sign-in, and storage. |
| Supabase (self-hosted, open-source) | The database/auth/storage software itself, running on Netcup above — not a Supabase Inc. account or cloud service. No production data ever reaches Supabase Inc.’s own infrastructure. |
| Stripe | Billing. Your card goes straight to Stripe; we only ever see subscription status. |
| Resend | Transactional email (signup, reset, magic links). |
| Anthropic | Brief text during import, and project context for AI-assisted intelligence calls, run through Anthropic’s commercial API. No training on your content. |
| GitHub | Sign-in identity and public-repo access, only if you connect it. |
| Sign-in identity (email and profile), only if you use it. |
That is the whole list. There are no advertising or tracking networks behind it.
How we notify you of changes
We’ll update the “last updated” date above whenever this list changes. For a new sub-processor, or a new category of data reaching an existing one, we’ll also email registered users before the change takes effect — the same commitment made in our Privacy Policy.
Questions? Contact us.