Skip to content

Subprocessors

Last updated: July 2026

LitAgent OS uses the third-party services listed below (subprocessors) to provide the product. Each entry describes what the service does for us and what customer data it receives. We update this list before enabling a new provider that processes customer data.

Payments

Stripe

Subscription billing and payment processing.

Data received: Billing contact (name, email), country, selected plan and billing interval, your organization or agency name and internal account identifiers attached as subscription metadata, payment method details entered directly into Stripe-hosted fields (LitAgent OS never stores card numbers), and subscription and trial state.

Stripe privacy policy

Hosting & infrastructure

Railway

Backend application hosting, PostgreSQL database, and Redis.

Data received: All application data at rest — authors/clients, projects, submissions, deals, contract tracking, finance tracking records, and support tickets — plus queue and cache state.

Railway privacy policy

Vercel

Frontend hosting and Vercel Web Analytics.

Data received: Page requests and privacy-friendly, aggregated usage analytics.

Vercel privacy policy

Cloudflare R2

Primary object and file storage for the application.

Data received: Uploaded files: manuscripts, contract documents, migration import files, support screenshots, and generated exports. Files live in private buckets, encrypted at rest, and are accessed through short-lived signed URLs.

Cloudflare R2 privacy policy

Backups & disaster recovery

Cloudflare R2 (off-site database backups)

Encrypted off-site database backups for disaster recovery, held in a separate account and region from the primary file storage above.

Data received: A nightly full backup of the application database. Each backup is encrypted on our own servers before it is uploaded, so this provider stores only ciphertext. Because it is a whole-database snapshot, it can contain any record kept in the product — authors and clients, projects, submissions, deals, contract-tracking, finance-tracking records, and support tickets.

Cloudflare R2 (off-site database backups) privacy policy

Backblaze B2 (off-site file backups)

Encrypted off-site backup mirror of uploaded files for disaster recovery, on a different storage provider from the primary file storage above.

Data received: A nightly copy of every uploaded file in our primary object store — manuscripts, contract documents, migration import files, support screenshots, and generated exports. Each file is encrypted on our own servers before it is uploaded, so this provider stores only ciphertext, and copies are written under an immutability lock so they cannot be altered or deleted for a fixed retention window.

Backblaze B2 (off-site file backups) privacy policy

Email & communications

Resend

Transactional platform email delivery.

Data received: Recipient email addresses and message content for account and product notifications (invitations, password resets, account lifecycle notices).

Resend privacy policy

Google (Gmail API)

Customer-initiated submission email sending.

Data received: Only when you connect Gmail: the submission emails you compose (recipients, subject, body, attachments, and message-routing headers that link replies back to the originating submission), sent through your own Google account via the send-only gmail.send scope under the Google API Services User Data Policy, including its Limited Use requirements. LitAgent OS does not read, store, or index your mailbox.

Google (Gmail API) privacy policy

Google Workspace

Support mailbox hosting for support@litagentos.com.

Data received: Emails you send to support, and internal support ticket notification copies (ticket number, organization, severity, reporter contact).

Google Workspace privacy policy

Monitoring

Sentry

Error and performance monitoring.

Data received: Error reports and performance telemetry, including request metadata and account/organization identifiers needed to diagnose failures. Limited diagnostic context in error events (such as error messages and request details) may incidentally include fragments of customer content. Session replay is disabled.

Sentry privacy policy

AI processing

Anthropic (Claude API)

AI-assisted migration analysis, royalty-statement PDF data extraction, the in-app support assistant, and support ticket analysis.

Data received: Uploaded migration file contents (a pre-flight step masks detected personal identifiers in structured fields; free-text fields, document bodies, PDFs, and images are sent in full — and two migration features work with actual values rather than masked ones: duplicate-merge evaluation sends the field values being compared, and the migration planning chat can retrieve actual rows and column values when you ask it to inspect your data), royalty-statement PDFs you upload for automated data extraction, support chat messages and conversation history, screenshots you explicitly attach, the page you are viewing (URL and title), browser and device context (user agent, language, platform, and screen/viewport details), your role and timezone, recent client-side error messages, and support ticket text used for triage and same-organization duplicate detection.

Sent for royalty extraction only after an organization owner explicitly enables the feature: the original bounded royalty-statement PDFs you upload (these are financial documents), as native PDF document blocks. The feature is off by default for every organization and can be turned off again at any time. Anthropic states that commercial API inputs are not used to train its models by default and may be retained for up to 30 days under its standard API terms, subject to limited safety, abuse-prevention, and legal exceptions. Not sent: billing/card data, finance ledger entries, contract files, or e-sign envelopes. We do not currently offer a contractual data-residency or zero-data-retention commitment for AI processing unless separately agreed in writing.

Anthropic (Claude API) privacy policy

OpenAI (GPT Image)

Optional AI avatar image generation.

Data received: Only the avatar prompt text you type. No user identity, email, organization data, or uploaded files are sent.

OpenAI does not use API inputs or outputs to train its models by default. Standard API abuse-monitoring logs may retain prompts and outputs for up to 30 days unless approved data-retention controls apply; LitAgent OS does not currently promise zero-data retention or a specific processing region.

OpenAI (GPT Image) privacy policy

What is not listed

Internal operational tools that do not receive customer data (for example, on-call paging and alerting) are not listed here. Some capabilities that would introduce additional subprocessors are not part of the current product — inbound email processing and electronic-signature execution. Introducing either would require a completed product, security, privacy, and legal review; this list would be updated before deployment. We are not committing to their future availability. Questions about this list can be sent to support@litagentos.com.