Subprocessors
Last updated: October 5, 2026 (draft).
We use a small number of third-party subprocessors — cloud infrastructure and service providers — to run ProofQL. This page lists every one that processes personal data, as described in our Privacy policy. [PLACEHOLDER: confirm a data processing agreement is in place with each, and link it.]
Current subprocessors
Section titled “Current subprocessors”| Subprocessor | What it does for ProofQL | Data it processes | Location |
|---|---|---|---|
| Cloudflare, Inc. | Runs our API, dashboard, snippet CDN and docs (Workers); caches query results (Workers Cache API, KV); stores uploaded review exports (R2); queues indexing work (Queues); computes embeddings and sentiment labels (Workers AI); pools database connections (Hyperdrive); rate limiting and logs (Workers Logs) | Review content and derived data, request metadata including IP addresses at the edge, account and project records in transit | Global edge network; [PLACEHOLDER: confirm storage locations for R2 and KV, and Workers AI inference locations] |
| Neon, Inc. | Hosted Postgres database holding accounts, projects, hashed API keys, reviews, excerpts, embeddings, encrypted Google tokens and usage counts | All stored Service data | United States (AWS us-east-2, Ohio) |
| Clerk, Inc. | Customer sign-in, sessions and workspace membership; may use Cloudflare Turnstile for bot protection at sign-up | Customer names, email addresses, sign-in credentials, session and device data | United States |
| Google LLC | Only when a customer uses them: the Business Profile API (reading the customer’s own reviews through its Google connection) and the Places API (looking up a business and its public reviews) | Business Profile account and location details, review content, search terms typed into the business lookup | United States |
Planned
Section titled “Planned”| Subprocessor | What it will do | Data it will process | Location |
|---|---|---|---|
| Stripe, Inc. | Payment processing, once self-serve billing opens (not yet in use) | Billing name, email, address and payment card details (sent directly to Stripe) | United States |
Changes
Section titled “Changes”We will update this page before a new subprocessor starts processing personal data, and email account owners about additions. You can follow every change in the project’s public repository history. Questions: support@proofql.dev.
The structure of this page is adapted from the 37signals policies (Basecamp subprocessors), © 37signals LLC, used under the Creative Commons Attribution 4.0 International license (CC BY 4.0), with changes; 37signals does not endorse ProofQL.