Sub-processors
Last updated 2026-09-26.
A sub-processor is any third party we use that processes personal data on our behalf in connection with the Locus service. This page lists every one we use today and the ones planned for billing, and what each one receives. It's the customer-facing version of the same list referenced in our DPA.
Current sub-processors
| Vendor | Status | Purpose | Data involved | Region | Role |
|---|---|---|---|---|---|
| Supabase | Active | Database, sign-in (Auth) and Realtime messaging for locus-web | Account data (stored): email, sign-in details (including Google or GitHub name, profile picture URL, account ID and GitHub username), plan, hashed API keys, usage records and relay request counts, feedback, deletion requests, organization membership, invites and audit log. Outreach contacts and drafts (stored): contact name, handle, email address and message for partnership outreach, sent only after a person approves it. Remote-connection relay messages via Realtime (in transit; we don't store them): search requests, excerpts and file text, file paths and lists, and account and setup status when an assistant asks for them. | Account data: ap-southeast-2 (Sydney, Australia). Realtime relay messages: in transit through Supabase's Realtime service, whose serving region is not pinned. | Sub-processor |
| Vercel | Active | Hosts locus-web and its API: embedding relay, remote-connection relay, relay sign-in, account status | Request logs (time, path, status, IP address). In transit, and we don't store it: chunk text and search queries for managed embeddings; search requests, excerpts and file text, file paths and lists, and account and setup status for remote connection. | United States (iad1, Washington, D.C.) | Sub-processor |
| Voyage AI | Active (managed plans only) | Computes embeddings for managed plans, under Locus's account | Chunk text and search queries from managed-plan users. Under Voyage AI's standard terms, Voyage may keep the text it receives and use it to train its models unless the account holder opts out; with the opt-out on, Voyage deletes the text once it has processed it. We have not yet confirmed that opt-out for Locus's account, so for now assume Voyage may keep chunk text and search queries sent through managed embeddings. If you use your own Voyage key, Voyage works for you directly and is not our sub-processor. | United States | Sub-processor |
| Resend | Active | Email delivery | Recipient name, email address and message content | United States | Sub-processor |
| Tranzila | When paid plans open | Card payments | Card details are entered with and held by Tranzila; Locus would keep only a payment token reference. | Israel | Sub-processor once billing is live |
| Yesh Heshbonit (יש חשבונית) | When paid plans open | Issues the receipts and invoices Israeli tax law requires | Name, email, country, amount, VAT line | Israel | Sub-processor once billing is live |
| Google (sign-in) | Active (if you choose it) | Sign in with Google | Confirms your identity and shares your name, email address, profile picture URL and account ID with us. Google sees that you signed in to Locus. | Global (Google's infrastructure) | Sign-in provider you choose (independent controller) |
| GitHub (sign-in) | Active (if you choose it) | Sign in with GitHub | Confirms your identity and shares your name, email address, profile picture URL, account ID and username with us. GitHub sees that you signed in to Locus. | United States | Sign-in provider you choose (independent controller) |
| GitHub (code hosting) | — | Source code hosting and CI for the Locus codebase | Source code; no customer data | N/A | Not a data sub-processor |
GitHub (code hosting) is listed for completeness (it holds our source code and CI) but does not process customer account data or content, so it isn't a data sub-processor in the GDPR Article 28 sense. Tranzila and Yesh Heshbonit become sub-processors only once billing is live; until then they receive no customer data from us. The rest of the table is live today.
Sign-in providers you choose (not sub-processors)
If you sign in with Google or GitHub, that provider confirms your identity and shares your name, email address, profile picture URL and account ID (and, for GitHub, your username) with us under your own account with them.
Explicitly not a sub-processor
Whatever AI assistant or MCP client you choose to connect Locus to — Claude Desktop, Claude Code, Cursor, ChatGPT, or any other — is your own tool choice, outside our control and outside any contractual relationship with us. Locus doesn't send anything to that assistant on its own; it only responds to tool calls your own chosen client initiates. That assistant's provider is not a Locus sub-processor.
The same goes for the embedding provider you use with your own key (Voyage or OpenAI); for Hugging Face, which serves the local embedding model and receives your IP address and the model name each time the local engine loads it while online, but no file content; and for Notion, which you connect with your own integration and which sends content straight to your computer.
How we notify you of changes
We update this page when we add or replace a sub-processor. If you have a signed DPA, its change-notice clause applies; see /dpa for that.
Questions
If you need more detail on any vendor above for your own vendor-risk review, contact yonilev2003@gmail.com.
Current-state, not a certification. This list reflects what is actually integrated today; it is not a target list or a generic template.