Levr

Sub-processors

Last updated: 21 July 2026

A sub-processor is a third party we engage that may process personal data contained in Customer Data on your behalf. This page is the authoritative list referenced by Section 6 and Annex III of our Data Processing Addendum and Section 5.1 of our Privacy Policy.

Our commitments


Infrastructure

Sub-processorPurposeData processedLocation
Amazon Web Services, Inc.Primary hosting and storage — compute (EKS), managed PostgreSQL (Aurora), object storage for attachments (S3), content delivery (CloudFront), container registry (ECR), and application logging and monitoring (CloudWatch)All Customer Data and account dataUnited States

AI and model providers — optional

These sub-processors are optional. They are engaged only when you use an AI feature of the Services. If your workspace does not invoke AI features, no model provider receives your Customer Data. Which provider is engaged depends on the model your workspace is configured to use, and you can change or disable that configuration at any time.

All AI sub-processors are contractually bound to process Customer Data on a no-training basis.

Sub-processorPurposeData processedLocation
Google LLC (Gemini API)Model inference and text embeddings, where your workspace is configured to use GeminiPrompts and the Customer Data included in themUnited States
OpenRouter, Inc.Model routing, where your workspace is configured to use a model reached through OpenRouterPrompts and the Customer Data included in themUnited States

Models reached through OpenRouter are operated by their own providers, and each is engaged only if you or your workspace configuration select that model. The models currently reachable are Gemini, Llama, DeepSeek, Qwen, and Kimi.

You can explicitly disable any of these models. Model selection is workspace-scoped: your workspace administrator can override the default set and deactivate any model your organization does not permit, or decline to use AI features altogether — in which case no model provider receives your Customer Data at all. You may also supply your own provider credentials so that inference runs under your own agreement with that provider rather than ours. Contact privacy@bitmodern.com if you would like help applying a restriction across your workspace.

Communications and billing

Sub-processorPurposeData processedLocation
Mailgun Technologies, Inc.Transactional email — verification, password reset, invitations, notificationsName, email address, and message contentUnited States
Stripe, Inc.Payment processing and subscription billingBilling contact, billing address, tax identifiers, subscription and transaction records. Card numbers go to Stripe directly and are never stored by us.United States

Product operations

Sub-processorPurposeData processedLocation
Google LLC (reCAPTCHA)Bot and abuse protection on public forms such as sign-upIP address, device and browser signals. Subject to the Google Privacy Policy and TermsUnited States
PostHog, Inc.Product analytics — feature usage and performanceUsage events and pseudonymous user identifiersUnited States
Automattic, Inc. (Gravatar)Resolving a profile image from a user's email addressA hash of the email address — plaintext email is never sent, though a hash of an email remains pseudonymous rather than anonymousUnited States
DiceBearGenerating a fallback avatar when no profile image existsDisplay name or initials used as the image seedEuropean Union

Marketing website only

These operate on levr.one and process website-visitor data. They have no access to Customer Data or to any Levr or Qinetic workspace. The analytics tools below are optional: in the EEA, UK, and Switzerland they load only after a visitor accepts them; elsewhere they are on by default with opt-out available on first visit. That choice can be changed at any time from the Cookie preferences link in the site footer.

Sub-processorPurposeData processedLocation
ClickRankSearch-optimization analytics on the marketing siteVisitor page views and device signalsUnited States
SiteBehaviourMarketing-site behavior analytics and heatmapsVisitor page views, interactions, and device signalsUnited States
jsDelivr / Google FontsDelivering fonts on the marketing site and in exported HTML documentsIP address, as inherent in any request for a hosted assetGlobal CDN

Integrations you choose to connect

The following are not sub-processors. They are third-party services you connect at your own initiative, under your own agreement with the provider. We exchange data with them only in the scope you authorize, and you can disconnect them at any time. See Section 7 of the Terms.

This includes GitHub, Atlassian/Jira, Slack, CI providers, and any coding agent or harness you connect over MCP — including Claude Code, Codex, and Cursor, which communicate with their own model providers under your agreement with them, not ours.


Self-hosted components

The following run on infrastructure we operate inside our own AWS environment and are not third-party sub-processors: PostgreSQL, ClickHouse (analytics), Redis (cache), NATS (messaging), and Qdrant (vector search). Data in these components never leaves the AWS environment described above.


Questions

Email privacy@bitmodern.com. For a countersigned DPA or a completed security questionnaire, the same address.

See also Terms of Service, Privacy Policy and Data Processing Addendum. Questions? Email legal@bitmodern.com.