Subprocessors

Last updated: 2026-08-21

These are the third parties myAI engages to process personal data on customers' behalf for the hosted surfaces only — account/billing, optional hosted brain remotes, and support. In the default self-hosted configuration none of them touch your data, because your working context never leaves your machine (see Security & Data Locality). This page is the maintained list referenced by Section 5 of the Data Processing Addendum; the change log at the bottom is the advance-notice record.

Current subprocessors

SubprocessorPurposeData processedLocation & transfer mechanismTerms
Stripe, Inc.Payment processing, subscriptions, invoices, marketplace payoutsBilling contact details, payment method (held by Stripe, never by the Vendor), transaction historyUnited States / global (SCCs + Stripe DPA)Stripe DPA
MongoDB, Inc. (Atlas)Hosted brain remotes — only for tenants that explicitly provision oneThe brain content the customer’s instance syncs (session atoms, compiled briefs)Region selected by the customer at provisioning; not moved without noticeMongoDB DPA
Vercel, Inc.Hosting of the public marketing/dashboard siteStandard web server request logs (IP address, user agent) processed transiently to serve the siteUnited States / global edge (SCCs + Vercel DPA)Vercel DPA
GitHub, Inc.Source hosting, release distribution, and the support channel (issues/private threads)Support correspondence and any details a customer includes in itUnited States (SCCs + GitHub DPA)GitHub DPA

Not subprocessors: integrations you configure yourself

The software you self-host contacts an external service only when you supply the corresponding credential in your own .env. Those are your own vendors under your own accounts — the Vendor is not in the data path and they are deliberately absent from the table above:

  • LLM providers (Anthropic, OpenAI, Moonshot, DeepSeek) — your API keys, your calls.
  • Messaging channels (Telegram, Discord) — your bot tokens.
  • Error tracking (Sentry) — only if you set a DSN.
  • Your own MongoDB Atlas cluster — if you point your database URI at Atlas yourself.
  • GitHub/git remotes for your repositories — your credentials, your pushes.

Change notice & objections

  • Additions or replacements are posted here at least 30 days before the new subprocessor handles customer data, as a dated change-log row.
  • To be notified actively, watch the repository — this page is version-controlled, so every change is a reviewable commit.
  • Objections: raise a reasonable data-protection objection via the repository or the maintainer email before the effective date; unresolved objections carry the termination right in DPA Section 5.

Change log

DateChange
2026-08-21Initial published list: Stripe, MongoDB Atlas, Vercel, GitHub.
Subprocessors — myAI