Tore

Legal

Subprocessors

Every third party that processes data on our behalf, what each one does, what it actually receives, and where it runs.

Draft, not yet reviewed by a lawyer

This document is published so its structure and facts can be checked. It has not been through legal review and should not be relied upon as a binding agreement until this banner is gone.

Last updated: 4 August 2026

Codas Labs, LLC uses the providers below to run Tore. Each has access only to what it needs to do its job, and each is bound by written contract to confidentiality and security obligations at least as protective as those in our Data Processing Addendum. We remain liable to you for what they do with your data.

This page is the authoritative list. It is also reproduced as Annex III of the DPA; if the two ever differ, this page is the one that counts.

The current list

The What it receives column is the one worth reading. A provider being on this list does not mean it sees everything, and the difference matters when you are working out your own exposure.

Infrastructure

ProviderWhat it doesWhat it receivesWhere
Amazon Web ServicesObject storage for attachments, bug-capture artifacts and inbound email; sending and receiving email; bounce and complaint notificationsAttachments, redacted capture artifacts, raw inbound email including sender address and body, outbound email including recipient address and bodyUnited States (us-east-1)
NeonThe managed Postgres database holding your conversations, contacts, knowledge base, feedback and settingsAll structured customer data. This is the primary store, so assume everything except blobs and queue payloadsUnited States
Fly.ioRuns the Tore API and background workersEverything in transit through the application, held in memory during a request. Fly is compute, not a storeUnited States (iad)
VercelServes the Tore web application and this websiteRequest metadata and whatever a signed-in browser renders. No customer database of its ownGlobal edge network
UpstashRedis queue that schedules background work such as indexing, redaction and investigationsJob payloads, which carry record identifiers and an organization id rather than message contentUnited States

AI models

ProviderWhat it doesWhat it receivesWhere
AnthropicAI models used for triage, drafting replies and investigating bugsThe specific conversation, capture or code context sent with a request, for the duration of that requestUnited States
OpenAIAI models, and the embeddings that make your knowledge base searchableRequest context as above, plus knowledge base text submitted for embeddingUnited States
GoogleAI models used for summarizing long stack traces; also an optional sign-in providerRequest context as above. Where a user signs in with Google, the sign-in identifiers for that userUnited States

Development

ProviderWhat it doesWhat it receivesWhere
GitHubRepository access for investigations and fixes, via a GitHub App you install and can revokeThe branch, commit and pull request we create on your repository, and the investigation context we put in the pull request descriptionUnited States

Billing

ProviderWhat it doesWhat it receivesWhere
PayKickstartSubscription billing and payment processingThe billing contact for your account and your subscription history. No end-customer support dataUnited States

Transfers out of the UK and the EEA

Every provider above processes in the United States, so if you are in the United Kingdom or the European Economic Area, your data leaves. That transfer is covered by the mechanism set out in clause 11 of the Data Processing Addendum: the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss adaptations, with the annexes completed in that document.

We contract with each provider on terms that carry that transfer mechanism through to them, so the chain does not break at the second link. We have not appointed an Article 27 representative in the EU or the UK. The DPA says the same thing, in the same words, rather than leaving the slot blank.

About the AI providers

Three of the providers above are AI model vendors. Which one handles a given piece of work depends on the task: a cheap model triages the queue, a stronger one investigates code, and a different vendor reviews the result so that no single vendor both writes and checks its own work.

We use these vendors through their paid business interfaces, under terms where your content is not used to train their models. We do not use free or consumer tiers, because those generally do allow training. If that ever changes for a vendor we use, we will move off it or tell you before it takes effect. We also do not train models of our own on your content.

Content is sent per request and is not retained by us at the vendor beyond what that vendor holds for abuse monitoring under its own business terms.

On the Free plan, and optionally on the Scale and Enterprise plans, you can connect your own AI provider key. In that case your content goes to your own account with that vendor, under your own agreement with them, and our terms with that vendor do not apply to it. That is a customer-directed flow, so it is not covered by this list.

What is not on this list, and why

  • Systems you connect yourself. A repository you give the GitHub App access to, a tool you push data into, or a provider key you supply, is directed by you. GitHub appears above because we hold the App credential and act on it; a destination you configure on your own side does not.
  • Our own internal tools. Anything we use that never touches customer data is not a subprocessor and does not belong here. If one of them ever starts touching customer data, it gets a row.
  • Sub-subprocessors. The providers above use their own infrastructure suppliers. We require each of them, by contract, to hold its own suppliers to obligations at least as protective as ours, and to stay responsible to us for them. We do not republish their supplier lists here, because theirs change on their schedule and a stale copy is worse than a pointer. Each provider publishes its own.

Changes to this list

We publish an intended addition or replacement here at least 30 days before that provider starts handling customer data.

  • Getting the notice. Email legal@codaslabs.com with the subject “Subprocessor notifications” and we will add you to the list that gets the same notice by email, so you are not relying on checking this page.
  • Objecting. You may object on reasonable data protection grounds within 30 days of the notice. Tell us what the ground is and we will work with you in good faith on an alternative, which may include not routing your data through that provider.
  • If we cannot resolve it. You may terminate the affected part of the Service and we will refund prepaid fees covering the period after termination, on a pro rata basis. That refund is your only remedy for the objection, which is a real limit on your rights and we would rather you read it here than find it in clause 10.
  • Urgent replacements. If a provider has to be replaced faster than 30 days for security or continuity reasons, we will tell you as soon as we can and your rights above still apply after the fact.

Change history

Tore has not launched, so there have been no changes to notify. This section exists so that the first change has somewhere to go, rather than being a silent edit to the table above. Each future entry will record the date, the provider, and whether it was an addition, a replacement or a removal.

Contact

Questions about a provider on this list, or about the DPA: legal@codaslabs.com. Privacy questions: privacy@codaslabs.com. Security reports: security@codaslabs.com.