Subprocessors
Last updated: July 2026
LitAgent OS uses the third-party services listed below (subprocessors) to provide the product. Each entry describes what the service does for us and what customer data it receives. We update this list before enabling a new provider that processes customer data.
Payments
Stripe
Subscription billing and payment processing.
Data received: Billing contact (name, email), country, selected plan and billing interval, your organization or agency name and internal account identifiers attached as subscription metadata, payment method details entered directly into Stripe-hosted fields (LitAgent OS never stores card numbers), and subscription and trial state.
Hosting & infrastructure
Railway
Backend application hosting, PostgreSQL database, and Redis.
Data received: All application data at rest — authors/clients, projects, submissions, deals, contract tracking, finance tracking records, and support tickets — plus queue and cache state.
Vercel
Frontend hosting and Vercel Web Analytics.
Data received: Page requests and privacy-friendly, aggregated usage analytics.
Cloudflare R2
Primary object and file storage for the application.
Data received: Uploaded files: manuscripts, contract documents, migration import files, support screenshots, and generated exports. Files live in private buckets, encrypted at rest, and are accessed through short-lived signed URLs.
Backups & disaster recovery
Cloudflare R2 (off-site database backups)
Encrypted off-site database backups for disaster recovery, held in a separate account and region from the primary file storage above.
Data received: A nightly full backup of the application database. Each backup is encrypted on our own servers before it is uploaded, so this provider stores only ciphertext. Because it is a whole-database snapshot, it can contain any record kept in the product — authors and clients, projects, submissions, deals, contract-tracking, finance-tracking records, and support tickets.
Backblaze B2 (off-site file backups)
Encrypted off-site backup mirror of uploaded files for disaster recovery, on a different storage provider from the primary file storage above.
Data received: A nightly copy of every uploaded file in our primary object store — manuscripts, contract documents, migration import files, support screenshots, and generated exports. Each file is encrypted on our own servers before it is uploaded, so this provider stores only ciphertext, and copies are written under an immutability lock so they cannot be altered or deleted for a fixed retention window.
Email & communications
Resend
Transactional platform email delivery.
Data received: Recipient email addresses and message content for account and product notifications (invitations, password resets, account lifecycle notices).
Google (Gmail API)
Customer-initiated submission email sending.
Data received: Only when you connect Gmail: the submission emails you compose (recipients, subject, body, attachments, and message-routing headers that link replies back to the originating submission), sent through your own Google account via the send-only gmail.send scope under the Google API Services User Data Policy, including its Limited Use requirements. LitAgent OS does not read, store, or index your mailbox.
Google Workspace
Support mailbox hosting for support@litagentos.com.
Data received: Emails you send to support, and internal support ticket notification copies (ticket number, organization, severity, reporter contact).
Monitoring
Sentry
Error and performance monitoring.
Data received: Error reports and performance telemetry, including request metadata and account/organization identifiers needed to diagnose failures. Limited diagnostic context in error events (such as error messages and request details) may incidentally include fragments of customer content. Session replay is disabled.
AI processing
Anthropic (Claude API)
AI-assisted migration analysis, the in-app support assistant, and support ticket analysis.
Data received: Uploaded migration file contents (a pre-flight step masks detected personal identifiers in structured fields; free-text fields, document bodies, PDFs, and images are sent in full — and two migration features work with actual values rather than masked ones: duplicate-merge evaluation sends the field values being compared, and the migration planning chat can retrieve actual rows and column values when you ask it to inspect your data), support chat messages and conversation history, screenshots you explicitly attach, the page you are viewing (URL and title), browser and device context (user agent, language, platform, and screen/viewport details), your role and timezone, recent client-side error messages, and support ticket text used for triage and same-organization duplicate detection.
Not sent: billing data, finance ledger entries, contract files, or e-sign envelopes. Anthropic does not train its models on API inputs under its default API terms. We do not currently offer a contractual data-residency commitment for AI processing unless separately agreed in writing.
OpenAI (DALL-E)
Optional AI avatar image generation.
Data received: Only the avatar prompt text you type. No user identity, email, organization data, or uploaded files are sent.
OpenAI does not use API inputs to train its models under its default API terms. We do not currently offer a contractual data-residency commitment for AI processing unless separately agreed in writing.
What is not listed
Internal operational tools that do not receive customer data (for example, on-call paging and alerting) are not listed here. Some features that would introduce additional subprocessors are turned off at launch — inbound email processing and electronic signature — and this list is updated to name those providers before either feature is enabled. Questions about this list can be sent to support@litagentos.com.