OS×
All policies
Legal

Subprocessors

Effective June 3, 2026

Draft template. This document is a starting point pending review by the operator’s legal counsel. It is provided for convenience and is not legal advice.

The third-party services OS x relies on to operate.

About this list

We engage the vendors below to help operate OS x. Each is bound by contract to confidentiality and security obligations appropriate to the data it processes. We update this list as our vendors change. A subprocessor only receives the data needed for its function.

Current subprocessors

SubprocessorPurposeData categoriesRegion
AnthropicAI model inference for assistant featuresAI prompts and the workspace context needed to answer themUnited States
SupabaseDatabase, file storage, and authenticationAccount data and workspace contentUnited States
ResendTransactional email deliveryRecipient email, message contentUnited States
StripeSubscription billing and paymentsBilling contact and payment metadataUnited States
TwilioSMS one-time codes for document signingRecipient phone number, verification codeUnited States
LiveKitReal-time video for meeting roomsSession connection data, audio/video streamsUnited States
VercelApplication hosting and deliveryRequest metadata and logsUnited States / global edge
ClamAV (self-hosted)Malware scanning of uploaded filesUploaded file contents (transient)Operator-controlled

Vendor policies

For the AI subprocessor, see Anthropic’s Usage Policy (https://www.anthropic.com/legal/aup) and Privacy Policy (https://www.anthropic.com/legal/privacy). Links to other vendors’ terms are available on request.

Changes

We will update this page when we add or remove a subprocessor. Where your agreement requires advance notice of subprocessor changes, we will provide it as agreed.