← Back to policies

Service Providers and Subprocessors

Last updated: September 9, 2026

This register identifies providers used to operate Vesperion Gate, Thicket, and LensCherry. Roles depend on the processing involved. When we process customer-controlled personal information as a processor, providers handling that information on our behalf are subprocessors. Providers may also process account-administration information for us or act independently for their own billing, fraud prevention, or legal obligations. Installed software alone is not a separate service provider.

Primary application data, object storage, and backups are in the United States. A storage location is not a promise that a provider's network, support, or other processing is confined to that location. The links below describe the providers' services and data-protection arrangements.

Hosting, storage, and delivery

  • Hetzner Online GmbH: all products. Application hosting and PostgreSQL databases in Ashburn, Virginia, US. Processes account content and operational data necessary to host the Services. Active content and backups follow our retention policy. Hetzner privacy information.
  • Cloudflare, Inc.: all products. Network security, CDN, selected form verification through Turnstile, US R2 object storage, and encrypted database/configuration backup storage. Ordinary customer-content database backups use a 28-day maximum window with no monthly or annual tier; configuration backups rotate after 90 days. Processes stored content and technical traffic data such as IP addresses and request metadata. Network and security processing can occur globally. Cloudflare DPA and privacy policy.
  • Backblaze, Inc.: Thicket and LensCherry. Offsite file replicas and version backups in the US. Receives uploaded and generated files and object metadata. Removed or replaced file versions expire 28 days after the daily replica archives them; version-aware verification confirms cleanup. Backblaze privacy information.

AI generation and safety screening

  • Google: LensCherry Gemini API. Image generation, editing, and prompt assistance using prompts, reference images, outputs, and technical request information. Our operating standard requires paid-service terms for customer content and prohibits free-tier customer-content processing. Paid-service terms prohibit using prompts and responses to improve Google's products. They permit safety and legal processing, with a published 55-day abuse-monitoring period. New image-generation requests opt out of optional Interaction storage; earlier stored interactions may remain until deleted or their retention expires. Processing may take place in countries where Google or its agents maintain facilities. Gemini terms, abuse-monitoring retention, and Interaction storage controls.
  • Google Cloud: LensCherry Vision API. Automated image safety screening receives image data and returns classification results. LensCherry records outcomes for moderation and support. This is a different service and processing purpose from Gemini generation. Vision data-use information and Google Cloud DPA.

Thicket does not use these providers to generate or summarize workspace content. A customer's use of an external AI tool has a separate data flow, described below. Provider retention and legal preservation can continue after we remove our own copy.

Public website analytics

  • Plausible Insights OÜ: Thicket public website. Measures public page visits and visits to the signup page. Receives public page URLs, standard campaign labels, referring website origins and technical browser and network information. Our integration excludes private workspace and token-bearing pages, removes other query parameters and fragments before transmission, and sends no account identities, form contents or customer conversion events. Plausible processes website visitor data on European-owned infrastructure in the EU. It uses rotating daily identifiers to count visitors without analytics cookies or persistent identifiers; its policy states that raw IP addresses and User-Agent strings are not stored. We can delete our site and collected statistics; Plausible documents 30-day backup retention. Plausible DPA, visitor data policy, and security and backup information.

Payments, communications, and diagnostics

  • Stripe: Thicket and LensCherry billing. Payment details, billing addresses, transaction and subscription information, and fraud-prevention signals. Stripe processes some data independently for payment-network and legal obligations; required financial records can outlast account closure. Stripe privacy policy.
  • Resend, Inc.: product and company email. Recipient and sender addresses, message bodies, delivery status, and related metadata for authentication, notifications, billing, and support communications. Messages can contain account activity and content previews. Resend DPA and privacy policy.
  • Microsoft: company email and support correspondence. Microsoft 365 mailboxes receive customer correspondence and support notifications, including contact details and the information supplied in those messages. Microsoft Products and Services DPA.
  • Functional Software, Inc. (Sentry): Thicket and LensCherry diagnostics. Error reports, traces, logs, technical context, and account identifiers used to investigate reliability and security. LensCherry diagnostic events can include an account email address. These records are not all anonymous and their retention is separate from account-content deletion. Sentry DPA and privacy information.
  • Expo: Thicket mobile push notifications. Device push tokens, notification payloads, and delivery information. Delivery also uses Apple Push Notification service or Google Firebase Cloud Messaging according to the device platform. Payloads can contain activity and message previews. Expo privacy information.
  • Apple and Google: optional sign-in, mobile delivery, and app-store services where used. These services receive the identity, device, or transaction information needed for the feature you choose and may act independently under their platform terms. Apple privacy information and Google privacy information.

Communications, payment, and diagnostic providers may process information internationally. Their service-specific retention and legally required records differ from our application-content schedules. Contact [email protected] for processing details relevant to your account or help with an erasure request involving a provider we engage.

Customer-selected apps and staff tools

Compatible AI apps, including tools offered by OpenAI, Anthropic, Google, or other providers, are not automatically our subprocessors when you select and authorize them independently. Their handling follows your agreement and settings with them. Compatibility depends on the interface, client, account, and workspace restrictions. See connected-tool data handling.

Staff AI tools are a separate category. Our staff use assistant tools from Anthropic (Claude) and OpenAI (ChatGPT and Codex) for software development and internal work, with training on our conversations disabled in each account. Private customer content, support correspondence, and identifiable production records stay out of them, so they are not subprocessors and are not listed above. A staff AI provider later approved to process customer data on our behalf would be added here first and handled under the Data Processing Addendum's subprocessor process.

Changes and questions

The Data Processing Addendum provides the authorization, notice, and objection process for new or replacement subprocessors. We record register changes in the policy update history. Publication of this register does not retrospectively establish a transfer mechanism or replace a required contractual agreement.