Sub-processors

Every third party that touches data on our behalf, what it receives, and where it runs. This page forms part of our Data Processing Addendum.

Effective 21 July 2026Version v2026-07-21

Current sub-processors

Each of these operates under a written contract imposing obligations equivalent to our Data Processing Addendum. We remain fully liable to you for their performance. Last updated 21 July 2026.

Sub-processorPurposeData receivedLocation
Microsoft Azure (Virtual Machines, Container Apps)Hosts the API gateway, control-plane services, and every per-project engine container and its graph volume.All Customer Content; account identifiers.United States — East US
Microsoft Azure OpenAI ServiceFact extraction, compilation, and answer synthesis (gpt-4.1-mini).Memory content submitted for processing; query text.United States — East US
Microsoft Azure OpenAI Service (Speech-to-Text)Transcribing uploaded audio (whisper). Separate resource because the model has no deployable SKU in East US.Audio files you upload.United States — East US 2
Microsoft Azure Blob StorageEncrypted off-host backups of project graphs.All Customer Content, as periodic snapshots.United States
Neon (Postgres)Control-plane database: accounts, sessions, organisations, billing records, audit log, site analytics.Account and billing data. No Customer Content.United States — AWS us-east-1
VercelHosts the Console web application and proxies browser traffic to our API.Account data in transit; approximate visitor geography.United States / global edge
CloudflareTLS termination, DDoS protection, and reverse proxy for api.thinkingroot.com.All API traffic in transit, including IP addresses at the edge.Global edge network
StripePayment processing and hosted checkout.Billing email, subscription and invoice records, payment details you enter directly with Stripe.United States
ResendTransactional email: verification codes, password resets, service alerts.Email address and message content.United States
Google, GitHubOptional single sign-on, and optional connector authorisation you initiate.Profile email and username from the provider you choose to link.Per provider

“Customer Content” means the memories, documents and facts stored in your projects. Note that our control-plane database holds accounts and billing only — no Customer Content ever reaches it.

Who is deliberately not on this list

A sub-processor list is only useful if it is exhaustive, so it is worth naming the services we use that never receive your data — and why they are not listed.

  • No embedding or reranking vendor. These models run as local files inside our own engine. Every memory you store is embedded and ranked on our infrastructure, so no third party receives your memory text in order to index it.
  • Klavis AI. Our connector servers are built from their open-source images, but we host them ourselves on a private network. No data reaches Klavis the company.
  • Cloudflare AI Gateway. It is supported in our configuration but not enabled. Model requests go directly to Azure, so no prompt or completion transits it.

We do not use any sub-processor to train models on your data, and each AI sub-processor is contractually prohibited from training on data we send it.

Notice of changes

We give at least 30 days' notice before a new sub-processor begins processing customer data. To receive those notices, email [email protected] with the subject “Subscribe to sub-processor notices”. We will add you to the list and confirm.

We may engage a replacement sub-processor without the full notice period where an existing one becomes unavailable and continuity of service requires it. We will tell you as soon as we can, and your right to object is unaffected.

Objecting to a sub-processor

If you have reasonable data-protection grounds to object to a new sub-processor, tell us within the notice period. We will work with you in good faith to find an alternative. If we cannot, you may terminate the affected part of the service and receive a pro-rata refund of prepaid fees — you will not be held to a contract whose data flows you object to.

We keep every previous version of this document. If you need the text that was in force on a particular date, write to [email protected] and we will send it.