Sub-processors
Last updated: May 30, 2026
A sub-processor is a third-party service we use to run sprintrr. Some of these services have technical access to your data in order to provide their service to us — for example, our database provider hosts the customer projects you create, and our AI provider receives the prompts you submit to AI features.
We choose sub-processors carefully (see our Trust page for our vendor-assessment process), and we require them to apply security and privacy controls at least as strong as our own.
Change notification. We notify customers at least 30 days before adding a new sub-processor that processes customer data, where feasible. Emergency additions during a vendor incident may be notified retroactively. To subscribe to changes, email support@sprintrr.ai.
Current sub-processors
- Critical
- Service
- Database, authentication, file storage
- Data shared
- All customer-account data, project content, authentication records, uploaded files
- Location
- United States (primary region)
- Certifications
- SOC 2 Type II
- HIPAA-eligible
- Critical
- Service
- Application hosting, edge network
- Data shared
- Request metadata, response logs, deployment artifacts (no customer content at rest)
- Location
- Global edge network
- Certifications
- SOC 2 Type II
- ISO 27001
- Critical
- Service
- Claude AI inference for AI-generated content
- Data shared
- AI prompts you submit to Sprintrr AI features
- Location
- United States
- Certifications
- SOC 2 Type II
- Important
- Service
- GPT inference (only when you Bring Your Own Key)
- Data shared
- Prompts you submit — only when you have configured a personal OpenAI key (BYOK)
- Location
- United States
- Certifications
- SOC 2 Type II
- Important
- Service
- Gemini inference (only when you Bring Your Own Key)
- Data shared
- Prompts you submit — only when configured with a personal Google AI key
- Location
- United States / global Google Cloud
- Certifications
- SOC 2 Type II
- ISO 27001
- ISO 27017
- ISO 27018
- Important
- Service
- Sign-in provider when you choose "Continue with Google"
- Data shared
- Your Google account email, name, and profile picture
- Location
- United States / global
- Certifications
- SOC 2 Type II
- ISO 27001
- Critical
- Service
- Subscription billing and payments
- Data shared
- Customer email, plan, subscription identifiers (no payment-card numbers — those stay with Polar)
- Location
- United States
- Certifications
- PCI DSS (via Stripe)
- Important
- Service
- Transactional email delivery (account emails and customer-published status updates)
- Data shared
- Recipient email and message content (transactional only — no marketing)
- Location
- United States
- Certifications
- SOC 2 Type II
- Important
- Service
- Optional channel for delivering customer-published status updates (OAuth-based, customer-initiated)
- Data shared
- Customer-authored status update content; workspace ID and channel ID chosen by the customer
- Location
- United States
- Certifications
- SOC 2 Type II
- ISO 27001
- ISO 27017
- ISO 27018
- Important
- Service
- Optional one-way import of issues from a customer-supplied Jira Cloud workspace (customer-initiated, API-token-based)
- Data shared
- Customer's Atlassian email + API token (encrypted at rest); read-only access to the chosen Jira project's issue fields
- Location
- United States / EU / AU
- Certifications
- SOC 2 Type II
- ISO 27001
- ISO 27017
- ISO 27018
- Important
- Service
- Bot protection (Turnstile) and edge security
- Data shared
- IP address, browser fingerprint, request metadata
- Location
- Global edge
- Certifications
- SOC 2 Type II
- ISO 27001
- Important
- Service
- Rate-limiting state store (Redis)
- Data shared
- Anonymous counters keyed by user ID or IP
- Location
- AWS regions (US/EU)
- Certifications
- SOC 2 Type II
- ISO 27001
- Important
- Service
- Error monitoring (enabled when Sentry DSN is configured)
- Data shared
- Stack traces and request metadata — cookies, authorization headers, and known PII are scrubbed before send
- Location
- United States / EU options
- Certifications
- SOC 2 Type II
- ISO 27001
- Important
- Service
- Application log aggregation (enabled when AXIOM credentials are configured)
- Data shared
- Application log lines
- Location
- United States / EU
- Certifications
- SOC 2 Type II
- Critical
- Service
- Source code hosting and CI/CD
- Data shared
- Application source code, deployment metadata (no customer content)
- Location
- United States
- Certifications
- SOC 2 Type II
- ISO 27001
- FedRAMP
- Important
- Service
- Advertising conversion measurement (Meta Pixel) on public marketing pages
- Data shared
- Page-view and signup-conversion events, IP address, browser/cookie identifiers — marketing visitors only. No project content, task data, or AI prompts.
- Location
- United States
- Certifications
- ISO 27001
- ISO 27018
| Vendor | Service | Data shared | Location | Certifications | Tier |
|---|---|---|---|---|---|
| Supabase | Database, authentication, file storage | All customer-account data, project content, authentication records, uploaded files | United States (primary region) |
| Critical |
| Vercel | Application hosting, edge network | Request metadata, response logs, deployment artifacts (no customer content at rest) | Global edge network |
| Critical |
| Anthropic | Claude AI inference for AI-generated content | AI prompts you submit to Sprintrr AI features | United States |
| Critical |
| OpenAI | GPT inference (only when you Bring Your Own Key) | Prompts you submit — only when you have configured a personal OpenAI key (BYOK) | United States |
| Important |
| Google (Gemini API) | Gemini inference (only when you Bring Your Own Key) | Prompts you submit — only when configured with a personal Google AI key | United States / global Google Cloud |
| Important |
| Google (OAuth) | Sign-in provider when you choose "Continue with Google" | Your Google account email, name, and profile picture | United States / global |
| Important |
| Polar.sh | Subscription billing and payments | Customer email, plan, subscription identifiers (no payment-card numbers — those stay with Polar) | United States |
| Critical |
| Resend | Transactional email delivery (account emails and customer-published status updates) | Recipient email and message content (transactional only — no marketing) | United States |
| Important |
| Slack (Salesforce) | Optional channel for delivering customer-published status updates (OAuth-based, customer-initiated) | Customer-authored status update content; workspace ID and channel ID chosen by the customer | United States |
| Important |
| Atlassian (Jira Cloud) | Optional one-way import of issues from a customer-supplied Jira Cloud workspace (customer-initiated, API-token-based) | Customer's Atlassian email + API token (encrypted at rest); read-only access to the chosen Jira project's issue fields | United States / EU / AU |
| Important |
| Cloudflare | Bot protection (Turnstile) and edge security | IP address, browser fingerprint, request metadata | Global edge |
| Important |
| Upstash | Rate-limiting state store (Redis) | Anonymous counters keyed by user ID or IP | AWS regions (US/EU) |
| Important |
| Sentry | Error monitoring (enabled when Sentry DSN is configured) | Stack traces and request metadata — cookies, authorization headers, and known PII are scrubbed before send | United States / EU options |
| Important |
| Axiom | Application log aggregation (enabled when AXIOM credentials are configured) | Application log lines | United States / EU |
| Important |
| GitHub | Source code hosting and CI/CD | Application source code, deployment metadata (no customer content) | United States |
| Critical |
| Meta Platforms | Advertising conversion measurement (Meta Pixel) on public marketing pages | Page-view and signup-conversion events, IP address, browser/cookie identifiers — marketing visitors only. No project content, task data, or AI prompts. | United States |
| Important |
About this list
“Critical” sub-processors are services whose failure or breach would materially affect the sprintrr service or customer-data confidentiality. “Important” sub-processors process some customer data but their failure degrades a non-core feature.
For each Critical and Important sub-processor we maintain an internal vendor-assessment record covering the security certifications listed above, our Data Processing Agreement on file, and the residual risk we accept. Customers under contract may request a redacted assessment.
See our Privacy Policy for the rights you have over your personal data, and our Trust page for the overall security program.