⚠️ Draft placeholder. This document is pending review by legal counsel and is not yet binding.

Subprocessor List

Version: Draft (pending counsel review) Last updated: 2026-06-14

This list discloses every third-party subprocessor that may Process Customer Personal Data in support of the Blueprint Service. Material changes (additions, replacements) are announced at least 30 days in advance via this list and email to the account address of paying customers.


1. Core platform subprocessors

These are required to deliver the core Service. Removing or substituting any of these would constitute a material change to the Service.

1.1 Google Cloud Platform (GCP)

RoleCompute, object storage, managed databases — production hosting
ProviderGoogle LLC
Address1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
Data processedAll Customer Content; account data; service logs
Regionus-east1 (Moncks Corner, SC, USA)
RetentionPer Customer's account lifecycle + 30 days
CertificationsSOC 1/2/3, ISO 27001/27017/27018/27701, PCI DSS, FedRAMP Moderate (selected services), HIPAA-eligible
Privacy noticehttps://cloud.google.com/terms/data-processing-addendum
DPA / SCCsExecuted

1.2 Clerk

RoleAuthentication, session management, user identity
ProviderClerk, Inc.
Address660 King St, Unit 345, San Francisco, CA 94107, USA
Data processedAccount data (email, user ID, sign-in events); session cookies
RegionUnited States
RetentionLifecycle of the user account
CertificationsSOC 2 Type II
Privacy noticehttps://clerk.com/privacy
DPA / SCCsPer Clerk standard DPA

1.3 Stripe

RolePayment processing; subscription + one-shot Top-Up billing; customer portal
ProviderStripe, Inc.
Address354 Oyster Point Boulevard, South San Francisco, CA 94080, USA
Data processedPayment card information (Stripe-hosted; we do not see); billing address; Stripe customer ID; charge / invoice records
RegionUnited States (with global edge for card networks)
RetentionPer financial regulations (typically 7 years)
CertificationsPCI DSS Level 1, SOC 1/2, ISO 27001
Privacy noticehttps://stripe.com/privacy
DPA / SCCsPer Stripe Services Agreement and DPA

1.4 SendGrid (Twilio)

RoleTransactional email delivery (welcome, run-complete, billing, heads-up)
ProviderTwilio Inc. (SendGrid product)
Address101 Spear Street, 5th Floor, San Francisco, CA 94105, USA
Data processedRecipient email, subject, body (transactional content), delivery + open events
RegionUnited States
Retention30 days for event data; longer for unsubscribe records (statutory)
CertificationsSOC 2 Type II, ISO 27001, HIPAA (with BAA — not signed for our use)
Privacy noticehttps://www.twilio.com/legal/privacy
DPA / SCCsPer Twilio DPA

1.5 Cloudflare

RoleDNS, edge proxy, Zero Trust Access (authentication gating), TLS termination, DDoS mitigation
ProviderCloudflare, Inc.
Address101 Townsend Street, San Francisco, CA 94107, USA
Data processedRequest metadata (IP, user agent, URL, timing); Zero Trust authentication events
RegionGlobal anycast edge
Retention30 days for access logs
CertificationsSOC 2 Type II, ISO 27001/27018, PCI DSS, FedRAMP Moderate
Privacy noticehttps://www.cloudflare.com/privacypolicy/
DPA / SCCsPer Cloudflare DPA

2. AI / LLM subprocessors

Each Brief is processed by one or more of the following providers to generate Artifacts. We have configured each provider's data-handling settings to maximize Customer privacy where supported.

2.1 DeepSeek

RoleStandard-tier LLM provider for Unrestricted content
ProviderHangzhou DeepSeek Artificial Intelligence Co., Ltd.
AddressHangzhou, People's Republic of China
Data processedBrief content + pipeline prompts (transient); generated Artifact text
RegionChina
RetentionPer DeepSeek API policy (subject to change); we treat all DeepSeek inputs as logged for ≤ 30 days
Training opt-outConfigured per DeepSeek API options where supported
Privacy noticehttps://platform.deepseek.com/privacy
⚠ NotesDeepSeek's PRC jurisdiction creates legal exposure if Customer submits ITAR/EAR or CUI content. The AUP prohibits such submissions, but Customer is responsible for the classification of their own content. EU and UK Customers should consider this transfer when assessing GDPR Art 44–49 compliance.

2.2 Google (Gemini API)

RoleEmbedding generation; fallback LLM for refusals and Confidential tier
ProviderGoogle LLC
Address1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
Data processedBrief content (for embeddings); pipeline prompts for fallback generation
RegionUnited States (specific Gemini API region depends on model)
RetentionPer Google AI API Additional Terms; production-paid APIs are not used for training by default
Training opt-outDefault for paid API tier
Privacy noticehttps://policies.google.com/privacy; Gemini API Additional Terms at https://ai.google.dev/gemini-api/terms
DPA / SCCsCovered by Google Cloud's GDPR DPA where applicable

2.3 OpenAI

RolePremium-tier LLM provider; fallback for refusals
ProviderOpenAI, LLC
Address3180 18th Street, San Francisco, CA 94110, USA
Data processedBrief content + pipeline prompts; generated Artifact text
RegionUnited States
RetentionAPI inputs retained for up to 30 days for safety + abuse monitoring; not used for training when Customer is on a Zero Data Retention (ZDR) enrolled account
Training opt-outDefault for API tier; Customer may not opt into training even by request
Privacy noticehttps://openai.com/policies/privacy-policy/
DPA / SCCsPer OpenAI DPA

3. Observability subprocessors

These do not Process Customer Content, only operational telemetry.

3.1 Sentry

RoleError tracking + performance monitoring (backend + frontend)
ProviderFunctional Software, Inc. d/b/a Sentry
Address132 Hawthorne Street, San Francisco, CA 94107, USA
Data processedError stack traces, scrubbed request metadata, browser console errors. Customer Content fields are scrubbed before transmission (see Privacy Policy §3.2).
RegionUnited States
Retention90 days for free tier (default); errors auto-purge after this
CertificationsSOC 2 Type II
Privacy noticehttps://sentry.io/privacy/
DPA / SCCsPer Sentry DPA

3.2 BetterStack (Better Stack)

RoleUptime monitoring; SMS / email alerts to founder on incident
ProviderBetter Stack Inc.
Address750 9th Avenue, San Francisco, CA 94109, USA
Data processedPublic health check responses (no Customer Content); founder contact (phone, email) for paging
RegionMulti-region edge (probes from US, EU, Asia)
RetentionIncident history per plan terms
CertificationsSOC 2 in progress
Privacy noticehttps://betterstack.com/policies/privacy-policy
DPA / SCCsPer Better Stack DPA

4. Change history

DateChange
2026-06-14Initial Subprocessor List drafted

5. Notice mechanism

To receive 30-day-in-advance notice of subprocessor additions:


6. Contact

NeuronKite LLC Attn: Privacy 4539 N 22nd St #6544, Phoenix, AZ 85016 [email protected]