Subprocessors

Last updated October 8, 2026

Operator note: this list describes the default Citeroot stack (Vercel, Neon, Stripe, Resend and four AI providers). If you deploy with different providers, edit this file so it matches what you actually use, and fill in the regions you chose.

Citeroot uses the following subprocessors to deliver the Service. We require each to meet security and confidentiality obligations consistent with our DPA.

ProviderPurposeWhat it receivesLocation
Vercel Inc.Application hosting and serverless functionsAll traffic to the app; function logsUnited States, with edge locations worldwide
Neon (or the Postgres provider you choose)DatabaseEverything stored in your accountRegion selected at deployment
Stripe, Inc.Payments and invoicingName, email, billing details and payment method, entered on Stripe's own pagesUnited States and other Stripe regions
ResendTransactional emailYour email address and the content of emails we send youUnited States
OpenAICollecting answers from ChatGPTPrompt text and brand and competitor namesUnited States
AnthropicCollecting answers from Claude; writing briefs and insightsPrompt text, brand and competitor names; the facts used in a draftUnited States
Google (Gemini API)Collecting answers from GeminiPrompt text and brand and competitor namesUnited States and other Google regions
Perplexity AICollecting answers from PerplexityPrompt text and brand and competitor namesUnited States

The AI providers receive prompts and brand names, not your account details. Each provider's API terms govern its handling of that content; we do not use Customer Data to train models.

#Notice of changes

We'll notify customers at least 30 days before adding or replacing a subprocessor that processes personal data, and customers may object on reasonable grounds.