Skip to content

Subprocessors

Last updated: October 5, 2026 (draft).

We use a small number of third-party subprocessors — cloud infrastructure and service providers — to run ProofQL. This page lists every one that processes personal data, as described in our Privacy policy. [PLACEHOLDER: confirm a data processing agreement is in place with each, and link it.]

Subprocessor What it does for ProofQL Data it processes Location
Cloudflare, Inc. Runs our API, dashboard, snippet CDN and docs (Workers); caches query results (Workers Cache API, KV); stores uploaded review exports (R2); queues indexing work (Queues); computes embeddings and sentiment labels (Workers AI); pools database connections (Hyperdrive); rate limiting and logs (Workers Logs) Review content and derived data, request metadata including IP addresses at the edge, account and project records in transit Global edge network; [PLACEHOLDER: confirm storage locations for R2 and KV, and Workers AI inference locations]
Neon, Inc. Hosted Postgres database holding accounts, projects, hashed API keys, reviews, excerpts, embeddings, encrypted Google tokens and usage counts All stored Service data United States (AWS us-east-2, Ohio)
Clerk, Inc. Customer sign-in, sessions and workspace membership; may use Cloudflare Turnstile for bot protection at sign-up Customer names, email addresses, sign-in credentials, session and device data United States
Google LLC Only when a customer uses them: the Business Profile API (reading the customer’s own reviews through its Google connection) and the Places API (looking up a business and its public reviews) Business Profile account and location details, review content, search terms typed into the business lookup United States
Subprocessor What it will do Data it will process Location
Stripe, Inc. Payment processing, once self-serve billing opens (not yet in use) Billing name, email, address and payment card details (sent directly to Stripe) United States

We will update this page before a new subprocessor starts processing personal data, and email account owners about additions. You can follow every change in the project’s public repository history. Questions: support@proofql.dev.


The structure of this page is adapted from the 37signals policies (Basecamp subprocessors), © 37signals LLC, used under the Creative Commons Attribution 4.0 International license (CC BY 4.0), with changes; 37signals does not endorse ProofQL.