The list below is complete as at 2026-08-19. Under section 4 of the data processing addendum we give at least 30 days’ notice by email before adding or replacing any of them.
Worth stating explicitly, because it is unusual: there is no email provider on this list. We are not reselling Amazon SES or anyone else, so your recipients’ addresses are not handed to a third-party sender in order to deliver your mail. That is the whole point of running our own infrastructure.
| Sub-processor | What it does | What it processes | Where |
|---|---|---|---|
| Hostinger International | Hosting for the service — the servers your mail and your records live on. | All service data, including message content while it is queued and delivery records. | European Union (Lithuania) |
| Cloudflare | DNS, TLS termination and protection against denial-of-service and abuse at the edge. Also the Turnstile check on the contact form, which is how we tell a person from a script without a CAPTCHA. | Request metadata — IP address, user agent, requested URL. For a contact form submission, the IP address is sent to Cloudflare to verify the Turnstile token. Because Cloudflare terminates TLS in front of the API and re-encrypts to our origin, the body of every API request passes through its edge in the clear — which includes the content of a message you send us. Cloudflare R2 also stores our encrypted off-site database backups. | Global edge network. Transfers under standard contractual clauses. |
| PayU Payments Private Limited | Payment processing for paid plans — taking the card or UPI mandate, authorising each charge, and issuing refunds. It is the only payment processor: card, UPI, Google Pay and netbanking all go through it, whether the card was issued in India or not. | Billing name, email, card or UPI details and payment history. Card numbers are held by PayU and never reach us. No message content. | India. Payment data is stored in India under the Reserve Bank of India’s localisation rules. Transfers from the EEA and the UK are made under standard contractual clauses. |
| Two things. Sign in with Google, for people who choose it instead of a password. And Firebase Cloud Messaging, which is how a notification reaches the mobile app — plus Crashlytics, which reports a crash in that app. No analytics, no fonts, no advertising. | For accounts that use Google sign-in: the email address, name and profile picture Google returns, and the fact that a sign-in happened. For push notifications: the sender and the subject line of a received message, because those are what the notification shows on your lock screen — so some message content does reach Google, and disabling new-mail notifications stops it. For crash reports: the device model, OS version and a stack trace. No message content, address or account identifier is attached to a crash report. | United States. Transfers under standard contractual clauses. |
What is not on the list, and why that is the interesting part
There is no analytics vendor. And there is no AI or model provider of any kind — nothing in the system sends your mail, or anything derived from it, to one.
Two things that used to be on this list no longer belong there, and saying so is the point of keeping it. The nightly database backups are handed to a third party: they go to Cloudflare R2, encrypted to a public key before they leave the machine, so what Cloudflare holds is ciphertext rather than a readable database. And there is a crash-reporting service for the mobile app — Firebase Crashlytics — which receives a stack trace, the device model and the OS version. It is deliberately given no message content, no address and no account identifier, so a crash report cannot be tied back to you or to your mail.
Payments
Card details are entered directly with our payment processor and never pass through our servers. We store the subscription and payment records needed to bill you, invoice you and answer a question about a charge — not your card number.
We are changing processor, which is why the row above names none. The replacement is identified here before it handles a payment, on the same notice period as any other addition to this list, and the same right to object applies.
Objecting to one
If you reasonably object to a sub-processor on data protection grounds, email [email protected] within the notice period. We will work to find an alternative, and if we cannot you may terminate the affected service and get a refund of prepaid fees for the unused period.