Subprocessors
1. What this page is
A subprocessor is a third party that processes personal data on our behalf in order for our services to work. Vagary Labs LLP publishes the list so that customers — particularly those with GDPR obligations of their own — can see who is in the chain before they sign.
This is the corporate-level list covering infrastructure common to our products. Where a product uses an additional subprocessor specific to it, that product's own privacy policy names it.
2. Infrastructure and hosting
| Subprocessor | Purpose | Primary location |
|---|---|---|
| Hostinger International | Virtual private servers — the compute and storage our services run on | United States (Boston) / India (Mumbai) |
| Cloudflare, Inc. | DNS, CDN, WAF, DDoS protection, identity-aware access proxy, object storage | Global edge / US |
| Backblaze, Inc. | Encrypted off-site backup storage | US |
| Google LLC | Cloud object storage used as one backup destination | US / global |
3. Analytics and product telemetry
| Subprocessor | Purpose | Primary location |
|---|---|---|
| Google LLC (Analytics) | Website analytics — loaded only after you consent to analytics cookies | US |
| PostHog, Inc. | Product analytics, feature flags and session replay | US |
4. AI and machine-learning providers
Our AI features route requests through a provider gateway. The providers below are grouped by whether they are active by default or only become active when specifically configured — because the difference decides whether your data actually reaches them.
4.1 Active providers
These are wired into the gateway and can handle a request whenever the service is running.
| Subprocessor | Purpose | Primary location |
|---|---|---|
| OpenAI, L.L.C. | Language-model and embedding inference; image generation and understanding | US |
| Anthropic, PBC | Language-model inference | US |
| Google LLC (Gemini) | Language-model and embedding inference; image generation and understanding | US / global |
| Moondream | Dedicated image-understanding model | US |
4.2 Supported but not enabled
The gateway can additionally route to the providers below through an OpenAI-compatible interface. Each is inactive unless its API credential has been configured, and an unconfigured provider cannot receive a request at all. We list them anyway: telling you what the system can be pointed at is more useful than a list that silently grows.
Cerebras · DeepSeek · Fireworks · Groq · Inception · Mistral · Nebius · Novita · NVIDIA · OpenRouter · Perplexity · Qwen · SambaNova · Sarvam · Together · xAI.
If we enable one of these for a service you use, it moves into section 4.1 before it begins processing.
4.3 Self-hosted inference
Some inference runs on infrastructure we operate ourselves rather than being sent to a vendor. There is no third party in that path and therefore no subprocessor to name for it.
4.4 Bring-your-own-key changes who the processor is
Where you supply your own API key for a provider (BYOK), your requests are sent to that provider under your own account and your own agreement with them. In that arrangement the provider is not our subprocessor — you are their customer directly, and their terms and privacy policy govern that processing. We pass the request through; we do not add ourselves as an intermediary controller.
Where you use our platform keys instead, the provider handling your request is our subprocessor and this page is the disclosure for it.
This distinction is worth checking before you assume either position: it changes who your data-processing agreement is with, and who you approach to exercise rights over data held by that provider.
5. Communications
| Subprocessor | Purpose | Primary location |
|---|---|---|
| Slack Technologies | Internal operational alerting, which may reference an account identifier | US |
Transactional email — receipts, password resets, notifications — is sent from mail infrastructure we operate ourselves. It is not handed to a third-party email provider, so there is no subprocessor to name for it.
6. Payments
Payment processing is performed by regulated payment providers. Card details are entered directly with the provider and are never transmitted through or stored on our systems; we hold only the metadata needed to reconcile a payment and issue an invoice.
For self-serve subscriptions we use a merchant of record, which is a stronger arrangement than an ordinary processor: that company is the legal seller of the transaction and is responsible for charging and remitting sales tax, VAT or GST in your jurisdiction. It therefore acts as an independent controller for that payment relationship and its own tax and anti-fraud obligations — not purely as our processor. Its privacy policy governs what it does with the payment data you give it.
For business invoices and Indian customers, Vagary Labs LLP is the seller and the payment provider acts in the ordinary processor role. The provider in use is shown at checkout.
7. International transfers
Several subprocessors are located in the United States — including the virtual-private-server hosting our services run on, which is split between the United States and India — and we are established in India. Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on the appropriate safeguard for that transfer — Standard Contractual Clauses, with the UK Addendum where the transfer is from the UK — together with an assessment of the destination and technical measures including encryption. Our Privacy Policy sets out the detail.
8. Changes to this list
We update this page when a subprocessor is added or removed. Customers with a data-processing agreement who want advance notice of a new subprocessor can request it by writing to [email protected] with the subject Subprocessor Notifications, and we will give notice before the new subprocessor begins processing.
9. Requesting a DPA
A data-processing agreement, including Standard Contractual Clauses where required, is available on request at [email protected].