Operator note: this list describes the default Citeroot stack (Vercel, Neon, Stripe, Resend and four AI providers). If you deploy with different providers, edit this file so it matches what you actually use, and fill in the regions you chose.
Citeroot uses the following subprocessors to deliver the Service. We require each to meet security and confidentiality obligations consistent with our DPA.
| Provider | Purpose | What it receives | Location |
|---|---|---|---|
| Vercel Inc. | Application hosting and serverless functions | All traffic to the app; function logs | United States, with edge locations worldwide |
| Neon (or the Postgres provider you choose) | Database | Everything stored in your account | Region selected at deployment |
| Stripe, Inc. | Payments and invoicing | Name, email, billing details and payment method, entered on Stripe's own pages | United States and other Stripe regions |
| Resend | Transactional email | Your email address and the content of emails we send you | United States |
| OpenAI | Collecting answers from ChatGPT | Prompt text and brand and competitor names | United States |
| Anthropic | Collecting answers from Claude; writing briefs and insights | Prompt text, brand and competitor names; the facts used in a draft | United States |
| Google (Gemini API) | Collecting answers from Gemini | Prompt text and brand and competitor names | United States and other Google regions |
| Perplexity AI | Collecting answers from Perplexity | Prompt text and brand and competitor names | United States |
The AI providers receive prompts and brand names, not your account details. Each provider's API terms govern its handling of that content; we do not use Customer Data to train models.
#Notice of changes
We'll notify customers at least 30 days before adding or replacing a subprocessor that processes personal data, and customers may object on reasonable grounds.