ValueinValuein
Back to home

Subprocessors

Effective 2026-10-01 · Version 2026-10-01

What changed in this version

  • First published list of the companies that process personal information for Valuein.
  • Adds Google as the host of our email mailboxes.
  • Separates destinations you choose and vendors that receive no personal information.
  • Explains how to subscribe to 30 days' notice of changes.

In short: these companies process personal information for Valuein (as identified in the Terms) so we can run the Service. Each may use it only to provide its service to us. Separately we list (a) companies you choose to send data to, which are not our subprocessors, and (b) data and service vendors that receive no personal information. We give subscribed customers 30 days' notice before adding or replacing a subprocessor. How we handle personal information is described in our Privacy Policy. This summary is not a substitute for the lists below.

1.Subprocessors

EntityService to ValueinPersonal information it processesLocationTransfer safeguard (EEA/UK/CH data)
Cloudflare, Inc.Hosting of the website, Workspace, API, MCP Server and background workers; databases (D1), key-value storage (KV), object storage (R2), Durable Objects; network security and DDoS protection; bot checks (Turnstile); cookieless web analytics; usage analytics; inbound email routing for our intake mailbox; platform logsEverything the Service stores (Account data, User Content, chats, uploads, sealed model keys, usage, billing projections); IP addresses, user agents and request metadata in transit and in short-lived logsUnited States (company); data processed on Cloudflare's global network, with no location restriction setEU-U.S. Data Privacy Framework where the vendor is certified; otherwise Standard Contractual Clauses
Stripe, Inc.Payments, subscriptions, invoices, customer portal, card-funded balance top-ups, pay-per-call chargesName, email, billing address, payment-card details (collected directly by Stripe), transaction history, customer identifierUnited StatesEU-U.S. Data Privacy Framework where the vendor is certified; otherwise Standard Contractual Clauses
Resend, Inc.Delivery of transactional email (sign-in codes, receipts, Agent deliverables, alerts), product email and our outbound business email; contact-form delivery to our teamRecipient email address, message content, delivery and bounce events; for contact-form messages, sender name, email, message and IP addressUnited StatesEU-U.S. Data Privacy Framework where the vendor is certified; otherwise Standard Contractual Clauses
Anthropic, PBCAI model for Valuein-managed AI (managed chat and scheduled Agents without a vaulted key); classification of inbound support and intake emailPrompts, conversation context, attached-document text, tool results and outputs on the managed lane; up to 8,000 characters of each inbound support message. Anthropic's commercial terms with Valuein prohibit training on this contentUnited StatesEU-U.S. Data Privacy Framework where the vendor is certified; otherwise Standard Contractual Clauses
GitHub, Inc.Internal issue tracker for support routing and service healthRouting record of support email: subject, classification, one-line summary, redacted excerpt (≤300 characters), hash of sender's email domain. No names or email addressesUnited StatesEU-U.S. Data Privacy Framework where the vendor is certified; otherwise Standard Contractual Clauses
Slack Technologies, LLCInternal operational alerts to ValueinAlert text, which may include a customer's email address and Plan (billing events), a reporter's IP address (data-issue reports), customer identifiers (failed-deletion alerts), and support subject lines and classificationsUnited StatesEU-U.S. Data Privacy Framework where the vendor is certified; otherwise Standard Contractual Clauses
Google LLCEmail hosting (Gmail) for our mailboxes, including legal@valuein.biz and support@valuein.bizContent of emails you send us and our replies, and the sender and recipient addressesUnited StatesEU-U.S. Data Privacy Framework where the vendor is certified; otherwise Standard Contractual Clauses

Conditional: if we route Valuein-managed AI traffic through Cloudflare AI Gateway (configured but not enabled today), Cloudflare would also process managed-lane prompts and outputs; we will update this page before enabling it. A Seat holder's own Anthropic key is never routed through it.

2.Sign-in providers (independent controllers)

EntityRoleWhat happens
Google LLC"Sign in with Google"Google authenticates you and sends us your name, email and a profile-photo link (which we do not store). Google processes your sign-in under its own privacy policy.
LinkedIn Corporation"Sign in with LinkedIn"As above, under LinkedIn's privacy policy.

For sign-in they are not our subprocessors: they act as controllers of your account with them. (Google separately hosts our mailboxes, as listed in section 1.) We send them nothing about your use of Valuein.

3.Destinations you choose (not subprocessors)

When you connect your own AI key or configure a delivery channel, you choose the recipient and the relationship is between you and that company, under your own account and its terms.

DestinationWhen data goes thereNote
Anthropic, PBC (with your own key)Chat and scheduled Agents when you connect an Anthropic keySame company as our managed lane, but under your account and terms. The request includes a Valuein credential so the model can call Valuein's read-only tools for you.
OpenAIChat and scheduled Agents when you connect an OpenAI keyUnder your OpenAI account and terms.
OpenRouter, Inc.Chat and scheduled Agents when you connect an OpenRouter keyOpenRouter forwards each request to the vendor of the model you pick (for example Anthropic, Google, OpenAI or xAI), which receives it under OpenRouter's arrangements. Set data-collection preferences in your OpenRouter account.
Your Slack workspace, webhook URLs, email addressesWhen a signal or Agent you configured delivers a resultYou control the destination.

We do not send provider-side retention settings for these destinations; configure them in your own account.

4.Vendors that receive no personal information

EntityWhat it providesWhy no personal information
Logo.devCompany logosOur logo cache (logos.valuein.biz, on Cloudflare) requests a logo from Logo.dev only the first time a ticker is needed, server-to-server, sending only the ticker, theme and our API key. Your browser never contacts Logo.dev; your IP address and identity are not sent.

We also obtain data from licensed market-data providers and from public sources (SEC EDGAR, FINRA IAPD, public index and fund disclosures, security-identifier services). We download from them, or look up by ticker or security identifier only, and send them nothing about you. Because they receive no personal information they are not subprocessors, and this page does not list them by name.

5.Changes and notifications

  • Subscribe. Customers can subscribe to subprocessor changes by emailing legal@valuein.biz with the subject "Subprocessor updates". If you sign a Data Processing Addendum with us, the Account owner's email is added to the list when it is signed.
  • 30 days' notice. We email subscribers at least 30 days before a new or replacement subprocessor starts processing personal information, describing the vendor, the service, the data and the location, and we update this page and its date at the same time.
  • Objections. Customers with a Data Processing Addendum may object within those 30 days as set out in section 6.3 of that addendum.
  • Urgent replacement. If a subprocessor must be replaced urgently to keep the Service secure or available, we will notify subscribers as soon as possible and no later than when the change takes effect, and the 30-day objection right still applies.

Questions: legal@valuein.biz.