Legal

Service Provider Disclosure

The service providers in FactNot's current production architecture, the data categories they may receive, and which routes remain evidence-gated.

01

How to read this provider list

The providers below cover the current production architecture and protected optional routes. A provider may be a processor, subprocessor, independent controller, or another service role depending on the contract and feature.

  • Core means the service supports the current product. Optional means a user chooses the integration.
  • Evidence-gated means the route stays disabled for private or sensitive content until its legal/vendor record passes.
  • The public list names recipients and purposes without publishing contracts, credentials, account identifiers, or internal evidence files.
02

Fly.io

Purpose — Application hosting, database infrastructure, logs, metrics transport, and backups.

  • Data categories — Account, workspace, content, operational, and security data.
  • Availability — core.
  • Evidence registry id — hosting_database.
03

Tigris Data

Purpose — Private object storage and backup copies.

  • Data categories — Uploads, source assets, export artifacts, object metadata, and access logs.
  • Availability — core.
  • Evidence registry id — object_storage.
04

Resend and Namescheap Private Email

Purpose — Transactional, opted-in, support, privacy, security, copyright, and legal email.

  • Data categories — Email addresses, messages, delivery events, and suppression metadata.
  • Availability — core.
  • Evidence registry id — email.
05

Cloudflare Turnstile

Purpose — Signup and authentication abuse prevention.

  • Data categories — IP address, browser or device signals, challenge token, and security metadata.
  • Availability — core.
  • Evidence registry id — security_abuse.
06

Sentry

Purpose — Redacted error monitoring and incident response.

  • Data categories — Redacted exception, normalized route, release, request, and operational identifiers.
  • Availability — core.
  • Evidence registry id — error_monitoring.
07

Google OAuth

Purpose — Optional Google account authentication.

  • Data categories — Email, Google subject identifier, OAuth tokens, and callback metadata.
  • Availability — optional, user-selected.
  • Evidence registry id — identity_provider.
08

Fly Managed Prometheus and Grafana Cloud

Purpose — Service metrics, dashboards, and operational alerts.

  • Data categories — Service metrics, machine identifiers, and redacted operational labels.
  • Availability — core.
  • Evidence registry id — infrastructure_monitoring.
09

OpenRouter and approved downstream model endpoints

Purpose — AI routing, generation, extraction, summarization, verification, and embeddings.

  • Data categories — Prompts, outputs, selected context, embeddings input, and request metadata.
  • Availability — disabled for private or sensitive processing pending evidence.
  • Evidence registry id — ai_provider.
10

OpenAI

Purpose — Private media transcription.

  • Data categories — Selected audio or video, transcript output, and request metadata.
  • Availability — disabled for private or sensitive processing pending evidence.
  • Evidence registry id — transcription_provider.
11

Namescheap

Purpose — Domain registration, DNS, and role-inbox control plane.

  • Data categories — Corporate account, registrant, DNS, mailbox configuration, and control-plane logs.
  • Availability — core.
  • Evidence registry id — domain_registrar_dns.
12

Provider changes

FactNot reviews provider and subprocessor changes against the approved inventory before enabling a new processing route.

  • Material changes are reflected in this public disclosure and, where appropriate, a versioned Privacy Notice update.
  • Privacy questions and requests for applicable transfer safeguards can be sent to privacy@factnot.com.
  • FactNot does not claim EU-only processing, fixed provider retention, no training, or GDPR compliance without current supporting evidence.