Subprocessors
These are the third parties we engage to process personal data on our behalf, as referenced in our Privacy Policy. We publish this because you should be able to see who touches your data, not because we are contractually required to.
Service providers
| Provider | Purpose | Data processed |
|---|---|---|
| Cloudflare | Application hosting, edge delivery, per-account sync storage, billing database | Account identifiers, all synced user content, request logs, IP addresses |
| Clerk | Identity, authentication and session management | Name, email address, authentication events |
| PayPal | Subscription payment processing | Billing contact and transaction records. Full card numbers are handled by PayPal and never reach us |
| Amazon Web Services | Transactional email delivery for billing notices and reminders | Email address, message content |
| Sentry | Error and crash reporting | Diagnostic data, stack traces, app and OS version, account identifier |
| PostHog | Product analytics and feature flags, with person profiles disabled | Pseudonymous usage events and feature-flag evaluations. Never email bodies, contact source text, generated content or assistant transcripts |
| Apple | Weather context in Journal | A coarse location or place reference for the requested forecast |
| Wise | Currency exchange rates in Money | Rate lookups only. No personal or transaction data is sent |
| Adobe | Web font delivery on superplanner.ai, through Adobe Fonts | IP address, browser and device characteristics, and which fonts were served |
These providers operate globally and process data in the United States and other countries. Where that involves transferring personal data out of the EEA or the UK, the safeguards described in our Privacy Policy apply.
AI model providers
Draft translation and subscription extraction may be routed to any of the providers below. AI Runtime chooses one per request, so this is the complete set of providers we permit rather than a fixed assignment. Personal information is redacted before the text is sent, and every provider here is engaged under a contract that prohibits using your text to train their models. The privacy filter works differently: it runs on a model we host ourselves, on the compute providers listed further down this page, and the text it sees is never sent to a third-party model API.
| Provider | Service |
|---|---|
| OpenAI | OpenAI API |
| Anthropic | Claude API |
| Microsoft | Azure OpenAI and Azure AI Foundry |
| Gemini API | |
| Amazon | Bedrock |
| Cloudflare | Workers AI |
| OpenRouter | OpenRouter API |
How a provider is selected
Superplanner does not send every request to the same provider. AI Runtime, our own platform, selects one of the providers listed above for each request, based on factors such as response speed, real-time availability and cost. The provider handling any particular request is therefore not fixed, and may change over time.
One of those providers, OpenRouter, is itself a routing service. Where a request is routed through OpenRouter, OpenRouter forwards it to a downstream model provider on our behalf, which may be a provider not individually named in the table above.
We contractually require these providers to maintain appropriate data protection safeguards and prohibit them from using your data for generalized AI model training.
Infrastructure that runs our own models
Not every AI feature calls a third-party model API. Some run on models Grid Heap hosts itself. Hosting a model still requires computing infrastructure, and those providers process the data for as long as the model is running, so they are listed here for completeness.
| Provider | Purpose | Data processed |
|---|---|---|
| Modal | On-demand GPU compute for models we host ourselves | The text or file submitted to the model, for the duration of the request |
| Google Cloud | On-demand GPU compute, plus supporting database and messaging services | The text or file submitted to the model, for the duration of the request |
| Amazon Web Services | On-demand GPU compute, in addition to the transactional email delivery listed above | The text or file submitted to the model, for the duration of the request |
| Microsoft Azure | On-demand container compute for model serving | The text or file submitted to the model, for the duration of the request |
These providers supply computing capacity only. They are not model vendors, and they do not retain your content after a request completes. Google, Amazon and Microsoft appear both here and in the tables above, because we use different services from each for different purposes.
Our own infrastructure is not a subprocessor
Hosted AI and email capabilities are routed through AI Runtime, our own platform, operated by Grid Heap, Inc. under the same legal entity that provides Superplanner. AI Runtime is our infrastructure rather than an independent third party, so it is not itself listed as a subprocessor — but the model providers it calls, and the compute providers it runs on, are third parties and are listed above.
That platform enforces a closed list of permitted operations for Superplanner. It cannot invoke models or services outside that list.
What is absent from this list, on purpose
- No advertising network of any kind
- No website analytics — our product analytics run inside the app, not on superplanner.ai
- No data brokers, enrichment services, or marketing-attribution vendors
Changes
We will update this page when we add or replace a subprocessor, with a revised date at the top.
Contact
Questions about anything on this page:
Grid Heap, Inc.
1111B S Governors Ave Ste 51059
Dover, DE 19904, United States
legal@gridheap.com