Legal

Subprocessors

Every provider that processes data for us, what each one receives, and when. Most are involved only if you use the feature that needs them.

Last updated 2026-10-02

Subprocessors

Cloudflare, Inc.
PurposeHosting, compute, storage, network delivery and DDoS protection for every part of the service
DataAll service data: account data, telemetry you send, configuration, request metadata
WhenAlways
Resend
PurposeTransactional email
DataRecipient address and message: sign-in and confirmation links, alert emails (issue title, culprit, level, environment, release), status-page notices
WhenWhenever we send email
Polar Software, Inc.
PurposePayments, as merchant of record
DataOrganization id, the purchasing person's email, plan or credit pack, usage counts for metered overage
WhenOrganizations billed through Polar (the default)
Stripe, Inc.
PurposePayments
DataOrganization id, the purchasing person's email, plan, invoice items, overage usage
WhenOrganizations billed through Stripe
Twilio Inc.
PurposeVoice calls for paging
DataThe phone number on a voice channel and a spoken summary of the alert (issue title and culprit)
WhenOnly if you add a voice channel
Apple Inc. (Apple Push Notification service)
PurposePush notifications to the iOS app
DataDevice push token, and a notification title and body (alert kind, issue title, culprit)
WhenOnly if you register an iOS device
Google LLC (Firebase Cloud Messaging)
PurposePush notifications to the Android app
DataDevice push token, and a notification title and body (alert kind, issue title, culprit)
WhenOnly if you register an Android device
Anthropic, PBC
PurposeAI fix suggestions and mobile chat
DataThe context of the issue you ask about: title, exception, stack frames with source lines, recent breadcrumbs, release; files from a repository you connected; your chat messages
WhenOnly when someone in your organization runs the fix agent or chat with an Anthropic model
OpenAI, L.L.C.
PurposeAI fix suggestions
DataThe same issue context as above
WhenOnly when someone runs the fix agent with an OpenAI model
Google LLC (Gemini API)
PurposeAI fix suggestions
DataThe same issue context as above
WhenOnly when someone runs the fix agent with a Gemini model

Services you choose to connect

These receive data because you choose to use them, and they act under their own terms, not as our subprocessors.

  • Google, GitHub or Microsoft sign-in: Their sign-in flow; we receive your account id, email, name and avatar.
  • GitHub repositories you connect: Files the fix agent reads; the branch, commit and pull request it opens when you ask for one.
  • Slack, Discord, Microsoft Teams, PagerDuty and webhooks: Alert contents you route there: kind, issue title, culprit, level, environment, release and a link.
  • Your browser's push service: Web push notifications, end-to-end encrypted so the push service cannot read them.

Changes

We update this page before a new subprocessor receives data, and we email organization owners when we add one. To object, write to privacy@bugwatch.io.