Subprocessors
AEO Explorer uses the following subprocessors to provide the service. Each processes personal data only under a data processing agreement and only to the extent described below. Entries marked are placeholders that must be verified before launch.
| Provider | Purpose | Region | Data |
|---|---|---|---|
| Vercel | Application hosting, serverless compute, CDN | EU-preferred (Frankfurt) | Application traffic in transit (all categories), request logs |
| Turso | Primary database (libSQL) | EU, region pinned | All tenant data at rest: accounts, workspace content (notes, chat), jobs, usage metering |
| Cloudflare R2 | File storage | EU jurisdiction | Uploaded files (org-scoped prefixes), data-export archives |
| Stripe | Payments and subscription billing | US / global (EU SCCs) | Billing contact, VAT ID, tokenized payment method, invoices |
| Resend | Transactional email | Not specified | Recipient name and email address, message content |
| Anthropic | AI inference (LLM) | US | Prompts and outputs derived from workspace content |
| OpenRouter | AI inference (model routing) | US / global, routes to downstream model providers | Prompts and outputs derived from workspace content |
AI providers
Retention and no-training settings for Anthropic and OpenRouter must be verified and configured before launch: customer content is not used for model training and is retained only transiently for inference. OpenRouter routes requests to downstream model providers — restrict the allowed provider list and verify each downstream provider's policy.
Changes to this list
We will notify customers at least 30 days before adding or replacing a subprocessor, via [email / changelog]. Where data lives, how it is retained, and how it is deleted is documented in our data map and privacy policy.
DPA
A data processing agreement (DPA / AVV) per Art. 28 GDPR covering these subprocessors is available at [link / contact email]. See also our privacy policy.
Last updated: .