How to read this provider list
The providers below cover the current production architecture and protected optional routes. A provider may be a processor, subprocessor, independent controller, or another service role depending on the contract and feature.
- Core means the service supports the current product. Optional means a user chooses the integration.
- Evidence-gated means the route stays disabled for private or sensitive content until its legal/vendor record passes.
- The public list names recipients and purposes without publishing contracts, credentials, account identifiers, or internal evidence files.
Fly.io
Purpose — Application hosting, database infrastructure, logs, metrics transport, and backups.
- Data categories — Account, workspace, content, operational, and security data.
- Availability — core.
- Evidence registry id — hosting_database.
Tigris Data
Purpose — Private object storage and backup copies.
- Data categories — Uploads, source assets, export artifacts, object metadata, and access logs.
- Availability — core.
- Evidence registry id — object_storage.
Resend and Namescheap Private Email
Purpose — Transactional, opted-in, support, privacy, security, copyright, and legal email.
- Data categories — Email addresses, messages, delivery events, and suppression metadata.
- Availability — core.
- Evidence registry id — email.
Cloudflare Turnstile
Purpose — Signup and authentication abuse prevention.
- Data categories — IP address, browser or device signals, challenge token, and security metadata.
- Availability — core.
- Evidence registry id — security_abuse.
Sentry
Purpose — Redacted error monitoring and incident response.
- Data categories — Redacted exception, normalized route, release, request, and operational identifiers.
- Availability — core.
- Evidence registry id — error_monitoring.
Google OAuth
Purpose — Optional Google account authentication.
- Data categories — Email, Google subject identifier, OAuth tokens, and callback metadata.
- Availability — optional, user-selected.
- Evidence registry id — identity_provider.
Fly Managed Prometheus and Grafana Cloud
Purpose — Service metrics, dashboards, and operational alerts.
- Data categories — Service metrics, machine identifiers, and redacted operational labels.
- Availability — core.
- Evidence registry id — infrastructure_monitoring.
OpenRouter and approved downstream model endpoints
Purpose — AI routing, generation, extraction, summarization, verification, and embeddings.
- Data categories — Prompts, outputs, selected context, embeddings input, and request metadata.
- Availability — disabled for private or sensitive processing pending evidence.
- Evidence registry id — ai_provider.
OpenAI
Purpose — Private media transcription.
- Data categories — Selected audio or video, transcript output, and request metadata.
- Availability — disabled for private or sensitive processing pending evidence.
- Evidence registry id — transcription_provider.
Namescheap
Purpose — Domain registration, DNS, and role-inbox control plane.
- Data categories — Corporate account, registrant, DNS, mailbox configuration, and control-plane logs.
- Availability — core.
- Evidence registry id — domain_registrar_dns.
Provider changes
FactNot reviews provider and subprocessor changes against the approved inventory before enabling a new processing route.
- Material changes are reflected in this public disclosure and, where appropriate, a versioned Privacy Notice update.
- Privacy questions and requests for applicable transfer safeguards can be sent to privacy@factnot.com.
- FactNot does not claim EU-only processing, fixed provider retention, no training, or GDPR compliance without current supporting evidence.