Sub-processor register

The sub-processor register.

Updated · 2026-08-22

Every service that may process data on our behalf, with what reaches it and in what form. This page is written for the person who has to evaluate us: a compliance lead, a privacy officer, counsel. Services marked optional run only when you enable the feature that uses them.

The register lists what it covers and says how the list was built: by tracing the outbound calls in our own code. It does not claim to cover everything. A processor reached only through a connector you configure yourself, or through a dependency of ours making its own call, would not surface that way and is not listed. If you find a flow that should be here, tell us and it goes on the register.

Two entries below are marked open: their privacy assessment has not been completed. They appear anyway, because a register that omits what it has not assessed would be hiding exactly the rows a reader most needs to see. For the other entries, an internal privacy impact assessment exists; counsel review of those internal assessments is pending, and we say so rather than imply otherwise.

This page renders directly from the machine-readable register the product carries, rather than being written beside it, so the page cannot drift from the register it presents.

Supabase

Postgres database, authentication, and encrypted file storage.

Region: Configured in a Canadian region (Montréal) for the primary database and uploaded files.

What reaches it: Application data at rest: client records, mission history, uploaded documents, and encrypted credentials.

In what form: Stored data, encrypted at rest; secrets are additionally encrypted at the application layer before they reach the database.

When it runs: Always; it is the primary datastore.

Assessment status: An internal privacy impact assessment is on file for this flow; counsel review of the internal assessments is pending.

Vercel

Application hosting and serverless compute, pinned to the Montréal region.

Region: Server functions pinned to the Montréal (yul1) region.

What reaches it: Request traffic in transit and provider-side operational logs.

In what form: Transient request processing and operational logs.

When it runs: Always; it serves the application.

Assessment status: An internal privacy impact assessment is on file for this flow; counsel review of the internal assessments is pending.

Google / Microsoft (the mailboxes and calendars you connect)

OAuth for the mailboxes and calendars you connect; tokens are limited-scope and revocable.

Region: Governed by your own Google or Microsoft account and its region settings.

What reaches it: Full email content and headers, and calendar data, read and sent through your own connected account.

In what form: Plain content, under your own account and its rules.

When it runs: Only when you connect a mailbox or calendar.

Assessment status: An internal privacy impact assessment is on file for this flow; counsel review of the internal assessments is pending.

Your connected model provider (bring-your-own-model)

Anthropic, OpenAI, Google, or another, running under your own API key. Invice routes selected mission context to that provider; its handling is governed by your contract and settings.

Region: Wherever your chosen provider processes; outside Invice's control and disclosed as such.

What reaches it: Prompt context for your missions: names, email content, conversation content, and vault excerpts.

In what form: Plain content selected for the mission at hand.

When it runs: Whenever a mission or conversation uses your connected model.

Assessment status: An internal privacy impact assessment is on file for this flow; counsel review of the internal assessments is pending.

Anthropic (under Invice's key, not yours) Assessment open

Model calls Invice makes on its own behalf, separate from the provider you connect: reading and classifying uploaded documents, parsing inbound replies, summarising conversations, drafting entity notes, and the mission-learning step.

Region: United States.

What reaches it: The content of the documents, emails, and conversations those steps process. The mission-learning step replaces the contact names, addresses and phone numbers it matches from your records with neutral placeholders before content reaches this flow, and prefers your own connected model where one exists; details it does not match, including any typed inside a message, can still be included.

In what form: Plain content for the document, reply and conversation steps; learning excerpts leave only after deterministic replacement of matched identifiers.

When it runs: During internal processing steps; each call claims against a per-workspace daily ceiling before the provider is contacted.

Assessment status: Open. Listed unassessed on 2026-08-20; the learning step was minimized on 2026-08-21. Counsel review is the assessment gate and has not happened. The learning note in our privacy policy is dated August 21, 2026 and will be removed when learning inference runs in a Canadian region.

OpenAI (vault embeddings, under Invice's key) Assessment open

Embeddings for vault indexing and retrieval, under our own key.

Region: United States today; we are moving embeddings to a Canadian region.

What reaches it: Vault document chunks at indexing time, and retrieval query text at search time.

In what form: Plain text chunks and queries.

When it runs: When documents are indexed and when vault search runs.

Assessment status: Open. This flow is disclosed here and on the security brief; its privacy assessment row is open rather than on file, and we say so instead of leaving it between categories.

Resend

Transactional and notification email: owner notifications (which may contain end-client summaries), teammate invites, playbook comment notifications, and gateway one-time passcodes.

Region: Provider-operated infrastructure; not pinned by Invice.

What reaches it: Recipient addresses and notification bodies; owner notifications can carry summary-level references to end clients.

In what form: Plain email content at summary level.

When it runs: On account and mission notifications.

Assessment status: An internal privacy impact assessment is on file for this flow; counsel review of the internal assessments is pending.

Stripe

Subscription billing for your Invice plan; card details are entered with and held by Stripe, never by Invice.

Region: Provider-operated infrastructure; not pinned by Invice.

What reaches it: Subscriber email, a workspace identifier, and Stripe's own billing identifiers. No card data touches Invice.

In what form: Billing metadata.

When it runs: On subscription events.

Assessment status: An internal privacy impact assessment is on file for this flow; counsel review of the internal assessments is pending.

Slack (optional)

Posts mission messages to a channel you connect, only when a mission uses it.

Region: Provider-operated infrastructure; not pinned by Invice.

What reaches it: Mission message content and the channel you connect.

In what form: Plain message content.

When it runs: Only when you connect Slack and a mission posts to it.

Assessment status: An internal privacy impact assessment is on file for this flow; counsel review of the internal assessments is pending.

Browserbase (optional)

Headless web browsing, only when a mission needs it.

Region: Provider-operated infrastructure; not pinned by Invice.

What reaches it: The target URL being browsed.

In what form: Target URLs.

When it runs: Only when a mission browses the web.

Assessment status: An internal privacy impact assessment is on file for this flow; counsel review of the internal assessments is pending.

SerpAPI / Google Custom Search / Serper.dev (optional)

Web search for contact discovery and public research, only when enabled.

Region: Provider-operated infrastructure; not pinned by Invice.

What reaches it: Search query terms composed by the AI agent.

In what form: Query text. Queries carrying an email address or a credential are structurally rejected before they leave.

When it runs: Only when web research is enabled.

Assessment status: An internal privacy impact assessment is on file for this flow; counsel review of the internal assessments is pending.

Inngest (optional, currently off)

Background job scheduling, when configured.

Region: Provider-operated infrastructure; not pinned by Invice.

What reaches it: Opaque identifiers, timestamps, and enums only; no client content.

In what form: Metadata only.

When it runs: Only when configured; it is off by default.

Assessment status: An internal privacy impact assessment is on file for this flow; counsel review of the internal assessments is pending.

Questions about any row: hello@invice.ai. The date at the top of this page moves when the register changes.