Legal
Subprocessors
The third parties that process data on our behalf. We would rather this list be accurate and short than impressive.
Draft — awaiting legal review
This document has not yet been reviewed by counsel and should not be relied upon. It is published so the structure can be checked, not as a binding agreement.
Last updated: 4 August 2026
A subprocessor is a company we use to help run MeshTale that may handle data on our behalf. This page lists them, what each does, and what kind of data reaches it.
Service subprocessors
These are involved in running the product itself.
| Provider | What it does | Data involved |
|---|---|---|
| Neon | Managed Postgres database — the primary store for accounts, content metadata and audit records | All application data |
| Fly.io | Application hosting for the API, the connection server, the model-routing proxy and the redaction service | All data in transit and in process |
| Vercel | Hosting and content delivery for the web application and this website | Request metadata, session cookies |
| Tigris | Object storage for uploaded files and exports | Uploaded documents and generated exports |
| Qdrant | Vector database used for search across your content | Embeddings and chunk metadata |
| OpenAI | Embedding generation and, where selected, chat responses | Content submitted for embedding or included in a prompt |
| Anthropic | Chat responses where selected as the model provider | Content included in a prompt |
| Chat responses where selected as the model provider, and connector access to Google services you authorize | Content included in a prompt; content from connected Google sources | |
| Resend | Transactional email — sign-in, notifications and account messages | Email address, message content |
| Sentry | Error monitoring | Error traces and request metadata |
Website only
These are used by this marketing website and are not part of the product. If you never visit this site, they never see anything about you.
| Provider | What it does | Data involved |
|---|---|---|
| logo.dev | Displays third-party product logos on this website | None — logos are fetched by domain name, no visitor data is sent |
| GoHighLevel | Receives contact form submissions from this website | Name, email, company and message you choose to submit |
Still to confirm
The following are open questions on this document rather than statements. They are listed because leaving them out would make the page look more finished than it is.
- Whether the vector database is self-hosted or vendor-managed, which determines whether it belongs on the list above at all.
- Which model provider is the effective default for chat, and whether responses are excluded from provider training by contract.
- The hosting arrangement for our own monitoring and analytics, and whether that introduces a further provider.
- Processing locations and data residency for each provider above.
Changes
We will update this page when a provider is added or removed. Once we have customers on paid plans we will give advance notice of additions, and the notice period will be set out in the data processing terms.
Questions
If you need this in a particular format for a security review, ask us and we will fill it in properly rather than sending you this page.