Subprocessors
Last updated: 31 August 2026
This list is taken from the Othor Cloud application as it runs today — not from a vendor questionnaire. Legal entity names should match the signed contract (AWS, Stripe, OpenAI, Anthropic, Postmark). Processing regions below are where the product actually sends data.
To run Othor we use a small number of third parties. Every one that can process customer data is listed here, with what it does and where it runs.
We give at least 30 days’ notice before adding or replacing a subprocessor that processes customer data. Write to to be notified.security@othor.ai.
Applies to Othor Cloud. See the deployment table for Cloud + your keys and self-hosted.
Subprocessors that may process customer data
| Subprocessor | Entity (verify on contract) | Purpose | Data it can access | Processing region |
|---|---|---|---|---|
| Amazon Web Services | Amazon Web Services, Inc. / AWS EMEA (as on your invoice) | Hosting (ECS, ALB), PostgreSQL, Redis/ElastiCache, S3 (uploads, images, Drive extracts), CloudFront, SQS (SFTP intake), SES (website contact/bug/feature forms), CloudWatch logs and backups | Connection credentials (encrypted), column names and definitions, extracted file tables while a Drive/SFTP/document connection is active, analysis results, account data, form submissions | eu-north-1 (Stockholm). CloudFront edge locations may serve the app globally. Another AWS region only if we have agreed it for that customer. |
| OpenAI | OpenAI, L.L.C. (US) | Default LLM for analysis, discovery, chat, and document intelligence (via LiteLLM in-process — not a separate vendor) | Prompts and data submitted for analysis, generated outputs | US (default Cloud path) |
| Anthropic | Anthropic PBC (US) | Optional LLM when a workspace assigns a Claude model, or as a platform fallback | Same as OpenAI, for those requests | US (default Cloud path) |
| Postmark (ActiveCampaign) | ActiveCampaign, LLC (US) | Transactional product email: verify, invite, password reset, narrative/digest alerts | Recipient name and email; and any analysis content in the message body | US unless the Postmark server is set to their EU data centre |
| Amazon SES | (part of AWS) | Website contact, bug, and feature-request forms to the Othor team | Name, email, subject, message, optional company / page URL | eu-north-1 |
| Stripe | Stripe, Inc. / Stripe Payments Europe / Stripe India (as on your dashboard) | Payment and subscription billing | Billing name, email, address, transaction records. Card details are entered on Stripe and never stored by Othor. | US / EU / IN as determined by the Stripe account |
| Mixpanel | Mixpanel, Inc. (US) | In-product analytics | Usage events, page URL, user agent; email, workspace id and name, role, plan type | EU ingest (api-eu.mixpanel.com in the app). Confirm the Mixpanel project residency is also EU. |
| Mailchimp (Intuit) | The Rocket Science Group LLC | Account/marketing list at signup and verification | Email address, subscription status, tags (e.g. New User, Verified) | US (Mailchimp datacenter on the configured server prefix) |
| Google LLC / Google Ireland Limited | Sign-in with Google; optional Google Drive and Calendar connections | Sign-in: name, email, Google account id. Drive: files the user authorises Othor to read (extracted into our AWS database). Calendar: events if that OAuth path is used. | Global | |
| Slack | Slack Technologies, LLC (Salesforce), US | Optional customer notifications (OAuth to the customer’s workspace); also internal alerts for website forms | Customer Slack: channel id and any analysis content in the message. Internal: name, email, and message text from contact/bug/feature forms. | US |
Optional / path-specific
These run only when that product path is on.
| Subprocessor | Purpose | Data it can access | Processing region |
|---|---|---|---|
| Tavily | External news lookup used by narrative/context | Search query text (may be derived from the question or metric names) | US |
| Sugra | External market/series data | Provider symbol and date range — not source tables | As operated by Sugra |
| Terminalfeed | External news/series data | Same pattern as Sugra | As operated by Terminalfeed |
Public statistical APIs we call without sending customer records (World Bank, BIS, Open-Meteo, open.er-api for FX) are not listed as subprocessors. They receive a series id or currency code, not your tables.
What changes by deployment model
| Subprocessor | Othor Cloud | Cloud + your keys | Self-hosted |
|---|---|---|---|
| AWS | Yes | Yes | No — runs in your infrastructure |
| OpenAI / Anthropic | Yes, under our contracts | Replaced by your provider contract and keys | Only if you route to one |
| Postmark | Yes | Yes | Only if that build still uses our mail token; otherwise your mail |
| Amazon SES (website forms) | Yes | Yes | No (marketing site is ours) |
| Stripe | Yes | Yes | Yes — billing only, no analysis data |
| Mixpanel | Yes | Yes | Only if the shipped frontend still has a Mixpanel token |
| Mailchimp | Yes | Yes | No (Cloud signup list) |
| Google sign-in / Drive | Optional | Optional | Optional |
| Slack (customer alerts) | Optional | Optional | Optional |
| Tavily / Sugra / Terminalfeed | If those streams are enabled | Same | Only if you enable them |
What we checked and do not list
Taken from the running services (auth, narrative, metrics, chatbot, organizations, metric-discovery, frontend):
- No Sentry, Datadog, or similar APM. Application logs stay in AWS CloudWatch.
- No Vercel / Netlify for the product app. app.othor.ai is served from AWS (ALB / CloudFront).
- No separate vector database. Document intelligence uses OpenAI and tables in our Postgres.
- LiteLLM is a library, not a vendor. Tokens go to OpenAI or Anthropic (or your keys).
- Customer warehouses (Snowflake, BigQuery, Postgres, …) are the customer’s systems. We connect with credentials they provide; those vendors are not our subprocessors.
- Engineering: Cursor is used on the Othor codebase. It is not given production database credentials by the product. It is not a customer-data subprocessor unless an engineer pastes production data into it — that is forbidden by internal rule.
Internal systems that may hold personal data
These are not in the analysis path. Support and sales correspondence can still reach them.
| System | Entity | What reaches it |
|---|---|---|
| Slack (internal) | Slack Technologies, LLC | Website form submissions (name, email, message) and internal discussion of support issues |
| Notion | Notion Labs, Inc., US | Internal documentation and account notes (not wired in the product; used by the team) |
Staff are instructed not to paste customer source data, credentials, or analysis output into Slack or Notion. That instruction is a written internal rule.
Website only
The marketing site and app shell load fonts from Adobe Fonts (Typekit). Adobe may see the visitor’s IP address. It does not receive analysis data or account credentials.
Contact
Questions about this list: security@othor.ai