Legal
Every third party that processes data on our behalf, what each one does, what it actually receives, and where it runs.
Draft, not yet reviewed by a lawyer
This document is published so its structure and facts can be checked. It has not been through legal review and should not be relied upon as a binding agreement until this banner is gone.
Last updated: 4 August 2026
Codas Labs, LLC uses the providers below to run Tore. Each has access only to what it needs to do its job, and each is bound by written contract to confidentiality and security obligations at least as protective as those in our Data Processing Addendum. We remain liable to you for what they do with your data.
This page is the authoritative list. It is also reproduced as Annex III of the DPA; if the two ever differ, this page is the one that counts.
The What it receives column is the one worth reading. A provider being on this list does not mean it sees everything, and the difference matters when you are working out your own exposure.
| Provider | What it does | What it receives | Where |
|---|---|---|---|
| Amazon Web Services | Object storage for attachments, bug-capture artifacts and inbound email; sending and receiving email; bounce and complaint notifications | Attachments, redacted capture artifacts, raw inbound email including sender address and body, outbound email including recipient address and body | United States (us-east-1) |
| Neon | The managed Postgres database holding your conversations, contacts, knowledge base, feedback and settings | All structured customer data. This is the primary store, so assume everything except blobs and queue payloads | United States |
| Fly.io | Runs the Tore API and background workers | Everything in transit through the application, held in memory during a request. Fly is compute, not a store | United States (iad) |
| Vercel | Serves the Tore web application and this website | Request metadata and whatever a signed-in browser renders. No customer database of its own | Global edge network |
| Upstash | Redis queue that schedules background work such as indexing, redaction and investigations | Job payloads, which carry record identifiers and an organization id rather than message content | United States |
| Provider | What it does | What it receives | Where |
|---|---|---|---|
| Anthropic | AI models used for triage, drafting replies and investigating bugs | The specific conversation, capture or code context sent with a request, for the duration of that request | United States |
| OpenAI | AI models, and the embeddings that make your knowledge base searchable | Request context as above, plus knowledge base text submitted for embedding | United States |
| AI models used for summarizing long stack traces; also an optional sign-in provider | Request context as above. Where a user signs in with Google, the sign-in identifiers for that user | United States |
| Provider | What it does | What it receives | Where |
|---|---|---|---|
| GitHub | Repository access for investigations and fixes, via a GitHub App you install and can revoke | The branch, commit and pull request we create on your repository, and the investigation context we put in the pull request description | United States |
| Provider | What it does | What it receives | Where |
|---|---|---|---|
| PayKickstart | Subscription billing and payment processing | The billing contact for your account and your subscription history. No end-customer support data | United States |
Every provider above processes in the United States, so if you are in the United Kingdom or the European Economic Area, your data leaves. That transfer is covered by the mechanism set out in clause 11 of the Data Processing Addendum: the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss adaptations, with the annexes completed in that document.
We contract with each provider on terms that carry that transfer mechanism through to them, so the chain does not break at the second link. We have not appointed an Article 27 representative in the EU or the UK. The DPA says the same thing, in the same words, rather than leaving the slot blank.
Three of the providers above are AI model vendors. Which one handles a given piece of work depends on the task: a cheap model triages the queue, a stronger one investigates code, and a different vendor reviews the result so that no single vendor both writes and checks its own work.
We use these vendors through their paid business interfaces, under terms where your content is not used to train their models. We do not use free or consumer tiers, because those generally do allow training. If that ever changes for a vendor we use, we will move off it or tell you before it takes effect. We also do not train models of our own on your content.
Content is sent per request and is not retained by us at the vendor beyond what that vendor holds for abuse monitoring under its own business terms.
On the Free plan, and optionally on the Scale and Enterprise plans, you can connect your own AI provider key. In that case your content goes to your own account with that vendor, under your own agreement with them, and our terms with that vendor do not apply to it. That is a customer-directed flow, so it is not covered by this list.
We publish an intended addition or replacement here at least 30 days before that provider starts handling customer data.
Tore has not launched, so there have been no changes to notify. This section exists so that the first change has somewhere to go, rather than being a silent edit to the table above. Each future entry will record the date, the provider, and whether it was an addition, a replacement or a removal.
Questions about a provider on this list, or about the DPA: legal@codaslabs.com. Privacy questions: privacy@codaslabs.com. Security reports: security@codaslabs.com.