Subprocessors
Last updated: 2026-08-21
These are the third parties myAI engages to process personal data on customers' behalf for the hosted surfaces only — account/billing, optional hosted brain remotes, and support. In the default self-hosted configuration none of them touch your data, because your working context never leaves your machine (see Security & Data Locality). This page is the maintained list referenced by Section 5 of the Data Processing Addendum; the change log at the bottom is the advance-notice record.
Current subprocessors
| Subprocessor | Purpose | Data processed | Location & transfer mechanism | Terms |
|---|---|---|---|---|
| Stripe, Inc. | Payment processing, subscriptions, invoices, marketplace payouts | Billing contact details, payment method (held by Stripe, never by the Vendor), transaction history | United States / global (SCCs + Stripe DPA) | Stripe DPA |
| MongoDB, Inc. (Atlas) | Hosted brain remotes — only for tenants that explicitly provision one | The brain content the customer’s instance syncs (session atoms, compiled briefs) | Region selected by the customer at provisioning; not moved without notice | MongoDB DPA |
| Vercel, Inc. | Hosting of the public marketing/dashboard site | Standard web server request logs (IP address, user agent) processed transiently to serve the site | United States / global edge (SCCs + Vercel DPA) | Vercel DPA |
| GitHub, Inc. | Source hosting, release distribution, and the support channel (issues/private threads) | Support correspondence and any details a customer includes in it | United States (SCCs + GitHub DPA) | GitHub DPA |
Not subprocessors: integrations you configure yourself
The software you self-host contacts an external service only when you supply the corresponding credential in your own .env. Those are your own vendors under your own accounts — the Vendor is not in the data path and they are deliberately absent from the table above:
- LLM providers (Anthropic, OpenAI, Moonshot, DeepSeek) — your API keys, your calls.
- Messaging channels (Telegram, Discord) — your bot tokens.
- Error tracking (Sentry) — only if you set a DSN.
- Your own MongoDB Atlas cluster — if you point your database URI at Atlas yourself.
- GitHub/git remotes for your repositories — your credentials, your pushes.
Change notice & objections
- Additions or replacements are posted here at least 30 days before the new subprocessor handles customer data, as a dated change-log row.
- To be notified actively, watch the repository — this page is version-controlled, so every change is a reviewable commit.
- Objections: raise a reasonable data-protection objection via the repository or the maintainer email before the effective date; unresolved objections carry the termination right in DPA Section 5.
Change log
| Date | Change |
|---|---|
| 2026-08-21 | Initial published list: Stripe, MongoDB Atlas, Vercel, GitHub. |