This is a superseded version. It is kept at a permanent address so the text in force on a past date can be produced. It is not the current policy — read the current sub-processors instead.

Sub-processors — version 1.12
In effect from 2026-09-25. Supersedes version 1.11. Previous versions remain available at /legal/subprocessors/versions/.

Sub-processors

Version 1.12 · In effect from 25 September 2026 · supersedes 1.11

Aporta Systems, LLC uses the providers below to deliver the Service and to run this website. Each is engaged under a written data processing agreement, and we remain responsible to our customers for what each of them does, with three qualifications:

  • Google, for answering a question through its Gemini model. This runs on Google Cloud, under the Google Cloud terms, which include Google’s Cloud Data Processing Addendum. Google also offers an explicit acceptance of that addendum in its console, and we have not yet confirmed it is recorded on our account.
  • Google, for the demo on this website. The demo uses a different Google service, whose terms describe an agreement that takes effect when it is accepted or written into a contract, not simply by using the service. We have not yet confirmed that either has happened on our account.
  • Google and Microsoft, for delivering your sealed export into your own storage. We have not yet read which of each provider’s terms govern our application’s calls into your storage, or whether a data processing agreement reaches them.
  • Formspree, for this website’s beta sign-up form. We have not found a data processing agreement that Formspree offers. Its terms of service describe its customers as independent controllers of the personal data they collect through it.

The Gemini answer and the export delivery are switched off for every customer. We list providers before we turn a feature on, so that you can see the change coming and object before it starts. The demo and the sign-up form are live on this website.

We give customers at least thirty days’ notice before we add or replace a provider, and a right to object on reasonable data protection grounds.

Provider What it does for us What personal data it can reach Location
Cloudflare, Inc. Edge compute; storage of audit records; DNS and email routing; cookieless analytics on this website and in the Aporta dashboard Encrypted audit records; tokenized content in transit. Prompt text is present unencrypted at the edge while detection runs. Analytics are aggregate only, with no cookie and no visitor identifier. United States for storage; edge processing runs at the location nearest the user, including outside the United States, and is not stored there
Modal Labs, Inc. Second-tier detection Prompt text and extracted attachment text, in the clear, at the moment of detection. Processed in memory and not retained. A customer can turn this tier off. United States
Turso (ChiselStrike, Inc.) Per-customer vault and metadata databases Encrypted token-to-value mappings; account metadata; and, where a customer connects an export destination, the encrypted credential for it United States
WorkOS, Inc. Sign-in, directory and role assignment Names, work email addresses, role assignments. No prompt content. United States
Resend (Plus Five Five, Inc.) Delivers the email our system sends. Two messages go to your organisation: a notice to your administrators that browsers are waiting to be enrolled, and a notice to your Super Users that your directory removed your organisation’s only Super User and we did not remove their access. The rest go to Aporta’s own alert mailbox, never to you: our copy of that second notice, and alerts about our own systems. The email addresses each message goes to: your administrators or Super Users, which also tells this provider your domain, and our own alert mailbox. What each message carries: the enrolment notice gives a count of browsers waiting and how long the oldest has waited, and names nobody. The Super User notice names the email address your directory removed and the directory’s identifier for that event, so you can match it to your audit record. Our copy of it carries our identifier for your organisation (an opaque account ID, not its name) and that event identifier, and names no person. Our alerts about our own systems name the affected AI tool and carry counts of browsers and organisations and details of our own test browsers; they carry no organisation name, user identifier or email address of yours. None of these messages carries prompt content, token mappings or audit records. The provider holds delivery metadata under its own terms. United States
Microsoft Corporation Business email, document storage and support correspondence. Separately: delivering your sealed export into your own OneDrive, when you connect it, into one app folder, at your direction, using a credential we hold. We ask for Files.ReadWrite.AppFolder, which reaches that one folder and nothing else in your OneDrive, with offline_access so the connection outlasts the hour an access token lives. Built, switched off for every customer, and no request has been made to Microsoft for it for any customer. Email and documents: contact details, and anything personal included in correspondence, contracts or support requests. No prompt content, token maps or audit records. Export delivery: see Your sealed export below. Email and documents: United States. Export delivery: wherever Microsoft stores your OneDrive, which your agreement with Microsoft and your account settings decide, not us.
Stripe, LLC Payment processing and billing Billing contact name and email, subscription and invoice records. Card details go to Stripe directly and are never held by us. No prompt content. Stripe also uses payment data on its own account for fraud prevention and regulatory compliance, as its own terms describe. United States
Twilio Inc. Text-message alerts to our own staff when an internal check needs attention. We send one kind today: part of our browser extension has stopped working on the site of one of the AI tools we support, and a follow-up when it clears. The messages go to our staff and never to you, and carry no part of the Service you use. The mobile numbers of the Aporta staff who receive the alerts (one person today), and the provider’s own message log of who was messaged and when. What a message says: which supported AI tool is affected, which part of our extension stopped working, and counts of the browsers and customer organisations that reported it. It carries no organisation name, user identifier, email address or page content. That is a statement about what our code puts in the message, and our tests check it; it is not a statement about what the provider records beyond the message and its log. We send from a toll-free number whose verification by the carriers was pending on 25 September 2026, so we do not state that any message has been delivered. United States (Twilio US1 Region), confirmed in the Twilio Console for each of our keys, most recently on 25 September 2026. Twilio’s data protection terms name no processing location; it depends on the region an account uses.
Google LLC Answering a question for you when our protection for an AI tool has broken. Aporta supports five named AI tools and blocks or redirects the rest. When our support for one of them breaks and the extension blocks that tool rather than let it run unprotected, we can answer through Google’s Gemini model on Google Cloud (Agent Platform), on our own account, not yours. It takes our switch for the Service as a whole and your organisation’s own setting, which is off unless a Super User turns it on, and even then it is offered to a person only while one of the five tools is blocked for them that way. It is not offered because an AI provider’s own service is down. This is the one place where we would send your text to an AI provider ourselves; everywhere else your text goes from your browser to the tool you chose, under your account with it. Switched off for every customer. It has never been on in the service our customers use, and nothing from any customer has been sent to Google. It is on in our own test environment, which holds no customer content. Separately: delivering your sealed export into your own Google Drive, when you connect it, at your direction, using a credential we hold. We ask for drive.file, which reaches only files our application created. Built, switched off for every customer, and no request has been made to Google for it for any customer. Separately: the demo on this website. Text a visitor sends from aportasystems.com/demo goes to Gemini under our own Google account, and the answer is shown to the visitor. This is our website, not the Service: for it we are the controller and Google is our processor. The Gemini answer, when on: the text of that one question after the values we detected have been replaced with placeholders in your browser, and after we check it again on our own infrastructure and refuse to send anything if we still find a value. Those checks match fixed-format values and your employer’s own terms; they do not detect names, places or organisations, which are sent as typed. We do not claim the text contains no personal data, only that our detectors found none; detection is not perfect, and this dramatically reduces inadvertent exposure rather than preventing it. The answer comes back to us with the placeholders still in it, and your browser puts the values back. We send the text twice per answer (once to measure it against a spending cap, once to answer it) with a fixed instruction of ours that contains nothing of yours. We do not send attachments, earlier messages in the conversation, token mappings, audit records, your name, your employer or any account identifier; the request goes on our key. What Google keeps. Google’s Cloud terms say that, unless we instruct otherwise, it will not keep the text outside our account for longer than it needs to produce the answer, will not keep the answer there at all, and will not use either to train its models. Two exceptions are Google’s own. If Google’s automated safety checks flag a request, it may log that text for up to 90 days, in the same location it was processed, to check it against its usage rules, and authorised Google staff may read it; Google lets a customer ask to be excluded from this logging, and we have not yet asked. Google also holds recent requests in memory for up to 24 hours to answer faster; a customer can switch that off, and we have not yet decided whether to. Whether Google keeps a technical record of each call on its own account, as the service the demo uses does, we have not established. The website demo: the text a visitor sends, up to 2,000 characters, after the demo has replaced the values it detected in the visitor’s browser. Anything the demo does not detect is sent as typed, and our server does not check the text again. A fixed instruction of ours goes with it, and no identifier of the visitor. We store neither the text nor the answer. What Google keeps of the demo’s text is not established for our account. Google’s published policy for the service the demo uses says it keeps the prompt, anything sent with it and the answer for fifty-five days, to check its usage rules, whether or not anything is flagged, and that authorised Google staff may read anything flagged. That is not a setting we can turn off, and we do not say Google keeps it for less, or that it keeps nothing. Google also keeps the technical record of each demo call (words charged, the network address it came from) on its own account rather than ours. Export delivery: none of the above applies; see Your sealed export below. The Gemini answer: configured for the United States; confirmed by test before we switch it on. We send it to Google’s United States endpoint, where Google’s Cloud terms commit it to carry out the processing in the United States only. The website demo: not restricted to any country, and not something we can set. The terms of the service the demo uses, read on 23 September 2026, allow processing in any country where Google or its own providers have facilities, and that service has no region setting. Export delivery: wherever Google stores your Drive, which your agreement with Google and your account settings decide, not us.
Formspree, Inc. Receives the beta sign-up form on this website and makes each submission available to us. It does not run the Service. What a visitor enters in the form: full name, work email, business name, role, and free text about how their team uses AI. The visitor’s browser sends it to Formspree directly, so Formspree also receives the visitor’s network address and browser details. Formspree keeps the submission in our account with it; its terms state no retention period for submissions. No customer content from the Service reaches it. United States, by Formspree’s own statement that its service is hosted there. Its privacy policy also says it may use information in any country where it operates, and one of the providers on its own published list is in Germany.
Amazon Web Services, Inc. Key management. It holds the key that wraps each customer’s data keys, which protect the vault, the audit record and the credential for your export destination. It holds none of the data those keys protect. In use in production since 24 September 2026. Key material, and one identifier. The wrapping key is generated inside the provider’s hardware and cannot be exported. We send a data key to wrap or unwrap and nothing else: no prompt content, token mappings, audit records, names or email addresses. Each request carries our identifier for your organisation (an opaque account ID, not its name), the key’s purpose and its version. So the provider can see which customer’s keys are used and how often. One purpose tells it your organisation has connected an export destination, and the call pattern shows how often exports run; it does not say which storage service you use. These identifiers appear in the call records kept on our own account with the provider. United States (us-east-1)

Your sealed export, delivered to your own storage

Switched off for every customer, and nothing has been sent. Your sealed export, the copy of your record that opens without us, is meant to arrive on a schedule rather than only when you ask for it. The destination is your own Google Drive or Microsoft OneDrive, connected and disconnectable by you, under your agreement with that provider.

We treat Google and Microsoft as our sub-processors for this delivery. Your export passes through the provider’s interface, on a connection we hold, into storage the provider keeps for you. That is our own determination, not a conclusion from counsel.

What the file lets the provider reach. Its contents (your audit record, your token map and any tokenized file copies you chose to keep) are encrypted before the file leaves us. It opens with your recovery code, and the provider is given no key that opens it. If your organisation has left its vault key with us rather than holding it itself, we can open the file, and the file says so in its own header. Some of it is not encrypted, because a reader needs it before a key is typed:

  • the file name, which carries our identifier for your organisation and the dates the export covers;
  • a short header on each part: that identifier, your organisation’s name as it appears on your Aporta account, the period, when the part was sealed, and internal storage references that include a device identifier and delivery times;
  • a list of the parts with their sizes, fingerprints and record counts.

The provider also sees the file’s size and when it arrives.

The credential we hold. To put a file in your storage we hold a credential that can write there, for as long as you leave the connection on. We read nothing else there, and we ask for the narrowest permission each provider offers: with Google, only files our application created; with Microsoft, one app folder. We hold one refresh token per connected provider, encrypted under a key specific to you that is wrapped by the key-management provider above. Where we record the account name you connected with, it is encrypted too. Which provider, when it was connected, by whom (an identifier, not an email address) and when it was last renewed are stored unencrypted.

Ending it. Disconnecting deletes our copy of the token; leaving Aporta destroys the key that opens it. When you disconnect Google we also ask Google to revoke the permission, and we tell you it was revoked only when Google confirms it. Microsoft gives applications no way to revoke this permission, so you remove it in your Microsoft account. Destroying the key when you leave does not revoke the permission at either provider; you remove it in that account.

We have registered our applications with both providers. The code is written, it is switched off, and no request has been made to either provider for any customer.

Before we turn on the Gemini answer

We have decided to turn it on and have not turned it on for any customer. We list Google now so that you can object before your text starts going to it. If you sign with us after today, Google is already on the list you were given. If you are already a customer when we turn it on, you get at least thirty days’ notice and a right to object first.

Still to do before we turn it on: confirm our acceptance of Google’s Cloud Data Processing Addendum is recorded on our account, confirm by test that Google’s United States endpoint answers, and decide whether to ask Google to exclude our account from its abuse logging.

When it is on, your text, the part our detectors did not flag, leaves Aporta and goes to Google under our account. The Google row above describes it in full, including what Google may keep if its safety checks flag a request.

Providers that do not run the Service

Microsoft holds our email and documents, Stripe our billing, Twilio carries alerts to our own staff, and Formspree receives this website’s beta sign-up form. Personal data reaches all four, so they are on this list: a provider holding your correspondence or invoices is handling your personal data as surely as one running our servers. Once the export delivery is switched on, Microsoft would also carry that part of the Service for anyone who connects OneDrive.

Google also answers the demo on this website. For the demo and the sign-up form we are the controller, and Google and Formspree are our processors.

Their vendors

Each provider engages its own vendors under its own terms. Two limits are worth stating:

  • Our second-tier detection provider operates no physical infrastructure of its own. It schedules work across a pool of cloud providers it publishes. Our configuration fixes the country that work runs in. It does not fix which provider runs it.
  • The mobile carriers that deliver a text message are outside the chain we watch. Our messaging provider’s terms state that the telecommunications providers it uses are not its sub-processors, so they are not on its list and it owes us no notice if they change.

Notice we receive, compared with notice we give

We promise our customers thirty days. Six of these providers give us less.

Provider Notice we receive
Microsoft Six months for customer data; thirty days for sub-processors supporting AI features
Amazon Web Services Thirty days
Stripe Thirty days
Cloudflare Thirty days
Google Thirty days, in advance, sent to us by email rather than published on a page, to the contact we set in Google Cloud. If we object, our only option is to leave
WorkOS Fourteen days, by updating a page we are responsible for checking
Turso Ten days, by email, and silence for ten days counts as agreement
Modal Thirty days in its current terms, but it may replace a provider urgently and tell us afterwards. An earlier version of its data processing terms, which it still publishes, names no period
Resend Fourteen days, in writing, and silence for fourteen days counts as agreement
Twilio No fixed period. Its terms commit only to telling us as soon as is reasonably practicable. It offers a way to subscribe to those notices. Our right to object runs during that undefined period, and silence before it ends counts as agreement
Formspree No advance notice. Its sub-processor page says only that it updates the page from time to time. We have found no right to object

For a change that starts in one of those six chains, we cannot give you the thirty days we promise. We would give you what we have, as soon as we have it. For two of them we cannot tell you in advance how much that will be.

A good number in one column does not make a provider good in the others. Google’s notice term is the strongest here after Microsoft’s, but its objection right is exit rather than refusal, and it commits to no fixed period for telling us about a security incident, only “promptly and without undue delay”.

The Google entry above was read for the Gemini answer, under the Google Cloud terms; the demo on this website uses a different Google service, whose terms the Google row describes. The Microsoft entry was read for our own email and documents. Neither entry has been read for the export delivery, and we do not assume the same terms govern it.

Not on this list

Software stores. Our extension is distributed through the Chrome Web Store and Microsoft Edge Add-ons. They host a package and report install counts. No prompt content, token map or audit record reaches either, and the relationship each has with someone installing the extension is its own, not one we direct. They are not sub-processors.

Google and Microsoft each appear both here, as extension stores, and in the list above, for different things. Neither role softens the other.

Questions

privacy@aportasystems.com


Changelog

1.12, 25 September 2026. The Gemini answer path now runs on Google Cloud (Agent Platform), under the Google Cloud terms and data processing addendum, configured for processing in the United States. Cloudflare’s location names edge processing outside the United States.

1.11, 25 September 2026. Resend now delivers a second message to customers (the notice that a directory removed an organisation’s only Super User, which names the removed address) and alerts to Aporta’s own mailbox; its row says what each message carries. Modal’s notice entry corrected to its current terms. Twilio’s region confirmed for each of our keys. Page rewritten in shorter form. Added Formspree, Inc., for this website’s beta sign-up form. Google’s row adds the demo on this website. The Gemini answer runs on Google Cloud (Agent Platform) under the Cloud Data Processing Addendum, configured for the United States.

1.10, 25 September 2026. Twilio set up to send staff alerts; the row says what they carry.

1.9, 24 September 2026. AWS in production; export delivery added as a purpose for Google and Microsoft; Turso row names the export credential; corrections to 1.8.

1.8, 23 September 2026. Added Amazon Web Services, Inc. and Google LLC.

1.6 and 1.7. Prepared and replaced before publication.

1.5, 16 September 2026. Twilio location filled.

1.4, 14 September 2026. Added Twilio Inc.

1.3. Prepared and replaced before publication; its correction of Stripe’s legal name to Stripe, LLC first appeared in 1.4.

1.2, 10 September 2026. Added Resend (Plus Five Five, Inc.).

1.1, 4 September 2026. Added Stripe and Microsoft; recorded cookieless analytics; added the notice comparison.

1.0, 4 September 2026. First version; the first version published here was 1.1.

Generated from docs/governance/legal/subprocessors.md. The source of truth is the governance register in the application repository, not this page.