Sub-processors
Last updated: 21 July 2026
A sub-processor is a third party we engage that may process personal data contained in Customer Data on your behalf. This page is the authoritative list referenced by Section 6 and Annex III of our Data Processing Addendum and Section 5.1 of our Privacy Policy.
Our commitments
- We give at least 10 days' notice before a new sub-processor begins processing customer personal data. Subscribe to that notice by emailing privacy@bitmodern.com.
- Every sub-processor is subject to security and privacy review before engagement, and is bound by data protection obligations no less protective than those in our DPA.
- We remain fully liable to you for each sub-processor's performance.
- If you reasonably object to a new sub-processor on data protection grounds within the notice period, we will work with you in good faith to provide an alternative; if we cannot, you may terminate the affected subscription without penalty and receive a pro-rata refund. See DPA §6.
- No sub-processor is permitted to train models on Customer Data. Our AI sub-processors are contractually bound to a no-training basis.
Infrastructure
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| Amazon Web Services, Inc. | Primary hosting and storage — compute (EKS), managed PostgreSQL (Aurora), object storage for attachments (S3), content delivery (CloudFront), container registry (ECR), and application logging and monitoring (CloudWatch) | All Customer Data and account data | United States |
AI and model providers — optional
These sub-processors are optional. They are engaged only when you use an AI feature of the Services. If your workspace does not invoke AI features, no model provider receives your Customer Data. Which provider is engaged depends on the model your workspace is configured to use, and you can change or disable that configuration at any time.
All AI sub-processors are contractually bound to process Customer Data on a no-training basis.
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| Google LLC (Gemini API) | Model inference and text embeddings, where your workspace is configured to use Gemini | Prompts and the Customer Data included in them | United States |
| OpenRouter, Inc. | Model routing, where your workspace is configured to use a model reached through OpenRouter | Prompts and the Customer Data included in them | United States |
Models reached through OpenRouter are operated by their own providers, and each is engaged only if you or your workspace configuration select that model. The models currently reachable are Gemini, Llama, DeepSeek, Qwen, and Kimi.
You can explicitly disable any of these models. Model selection is workspace-scoped: your workspace administrator can override the default set and deactivate any model your organization does not permit, or decline to use AI features altogether — in which case no model provider receives your Customer Data at all. You may also supply your own provider credentials so that inference runs under your own agreement with that provider rather than ours. Contact privacy@bitmodern.com if you would like help applying a restriction across your workspace.
Communications and billing
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| Mailgun Technologies, Inc. | Transactional email — verification, password reset, invitations, notifications | Name, email address, and message content | United States |
| Stripe, Inc. | Payment processing and subscription billing | Billing contact, billing address, tax identifiers, subscription and transaction records. Card numbers go to Stripe directly and are never stored by us. | United States |
Product operations
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| Google LLC (reCAPTCHA) | Bot and abuse protection on public forms such as sign-up | IP address, device and browser signals. Subject to the Google Privacy Policy and Terms | United States |
| PostHog, Inc. | Product analytics — feature usage and performance | Usage events and pseudonymous user identifiers | United States |
| Automattic, Inc. (Gravatar) | Resolving a profile image from a user's email address | A hash of the email address — plaintext email is never sent, though a hash of an email remains pseudonymous rather than anonymous | United States |
| DiceBear | Generating a fallback avatar when no profile image exists | Display name or initials used as the image seed | European Union |
Marketing website only
These operate on levr.one and process website-visitor data. They have no access to Customer Data or to any Levr or Qinetic workspace. The analytics tools below are optional: in the EEA, UK, and Switzerland they load only after a visitor accepts them; elsewhere they are on by default with opt-out available on first visit. That choice can be changed at any time from the Cookie preferences link in the site footer.
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| ClickRank | Search-optimization analytics on the marketing site | Visitor page views and device signals | United States |
| SiteBehaviour | Marketing-site behavior analytics and heatmaps | Visitor page views, interactions, and device signals | United States |
| jsDelivr / Google Fonts | Delivering fonts on the marketing site and in exported HTML documents | IP address, as inherent in any request for a hosted asset | Global CDN |
Integrations you choose to connect
The following are not sub-processors. They are third-party services you connect at your own initiative, under your own agreement with the provider. We exchange data with them only in the scope you authorize, and you can disconnect them at any time. See Section 7 of the Terms.
This includes GitHub, Atlassian/Jira, Slack, CI providers, and any coding agent or harness you connect over MCP — including Claude Code, Codex, and Cursor, which communicate with their own model providers under your agreement with them, not ours.
Self-hosted components
The following run on infrastructure we operate inside our own AWS environment and are not third-party sub-processors: PostgreSQL, ClickHouse (analytics), Redis (cache), NATS (messaging), and Qdrant (vector search). Data in these components never leaves the AWS environment described above.
Questions
Email privacy@bitmodern.com. For a countersigned DPA or a completed security questionnaire, the same address.
See also Terms of Service, Privacy Policy and Data Processing Addendum. Questions? Email legal@bitmodern.com.
