Bespoke AI
Subprocessor List
The service providers and conditional processing boundaries represented in Bespoke AI.
- Version
- 2026.09.5
- Effective
- 28 September 2026
How to read this list
A subprocessor processes personal information for Bespoke Technologies to help provide Bespoke AI. “Core” means the product architecture expects the service for ordinary operation. “Conditional” means the service is used only when its feature and deployment configuration are enabled.
Locations identify the provider's principal or expected processing footprint at the level currently supported by source and public provider information. Providers may use their own subprocessors and global infrastructure. Follow each provider link for its current details.
Core infrastructure
Vercel
Purpose: application hosting, serverless execution, content delivery, and AI Gateway transport. Data can include requests, technical metadata, account-linked product traffic, and the prompt context sent for AI processing. Principal location: United States; infrastructure and subprocessors may operate globally. Vercel privacy and subprocessor information.
Neon, a Databricks product
Purpose: managed PostgreSQL database hosting for accounts, projects, conversations, entitlements, support records, and related product metadata. Databricks, Inc. is the current parent of Neon, LLC. Principal location: United States; processing region depends on the selected database deployment. Neon product terms and Databricks subprocessor information provide current details.
Cloudflare
Purpose: R2 object storage and delivery for user-uploaded files and artifacts. Data can include object contents, storage identifiers, integrity metadata, and access requests. Principal location: United States; Cloudflare operates global infrastructure. Cloudflare subprocessor information.
Conditional service providers
AI model providers
Purpose: generate requested text, reasoning, image, audio, or other AI output. Bespoke AI can route eligible work through Vercel AI Gateway to configured providers including Google, OpenAI, DeepSeek, Moonshot AI, and Alibaba model services. Data can include prompts, selected conversation or Project context, and attachments needed for the request. Processing location and retention vary by eligible route and provider.
xAI
Purpose: voice transcription when the person records a message. Data sent through Vercel AI Gateway can include the audio clip, the person’s Project names, and file names in the current Project to improve spelling. Bespoke does not store the audio clip. Until zero data retention is enabled on our AI Gateway plan, xAI processes the clip under its standard API terms, which say it keeps requests for up to 30 days for abuse review and does not train on them without permission.
Purpose: speech synthesis when the person asks Bespoke to read an answer aloud in one of its voices. Data sent through Vercel AI Gateway is the text of that answer, one sentence at a time, as it would be read, with code and tables described rather than read out. Bespoke does not store the audio; the person’s device keeps a copy so a replay is not sent again. The request runs on Bespoke’s own xAI account, where xAI’s zero data retention is on; if that account cannot serve it, the Gateway may retry on Vercel’s xAI account, where xAI’s standard API terms apply until zero data retention is enabled on our AI Gateway plan.
OpenAI voice
Purpose: fallback transcription of the same audio clip if the primary route fails. Project and file names may accompany the request where supported. Bespoke does not store the audio clip. Until zero data retention is enabled on our AI Gateway plan, OpenAI processes the clip under its standard API terms, which describe keeping API data for up to 30 days for abuse monitoring and not using it to train models by default.
Purpose: fallback speech synthesis of the same sentence if the primary route fails. Bespoke does not store the audio. Until zero data retention is enabled on our AI Gateway plan, OpenAI processes the text under its standard API terms.
Resend
Purpose: transactional account, verification, password-reset, and support email. Data can include recipient name, email address, message purpose, delivery metadata, and the support information submitted for email delivery. Principal location: United States. Resend privacy information.
9bits and Twilio
Purpose: phone verification by SMS or WhatsApp when the selected provider is configured. Data can include phone number, one-time code, delivery channel, and delivery status. 9bits is the primary configured SMS adapter; Twilio Verify is retained as a provider-neutral alternate. Processing location depends on the selected provider and communications network.
PostHog
Purpose: privacy-restricted product analytics when configured. Data is limited to approved product event names, bounded properties, and identified account state; automatic page capture, session replay, heatmaps, private URL properties, and IP enrichment are disabled in the current product configuration. Expected region: European Union cloud endpoint. PostHog privacy information.
Sentry
Purpose: optional error reporting and performance diagnostics. Bespoke-owned redaction excludes secrets and long private content before telemetry leaves the application boundary. Principal location: United States; processing may be global. Sentry privacy information.
Serper
Purpose: web search used to ground answers on current information. This happens both when you ask for it and automatically, when an answer depends on information that may have changed since the assistant was trained. Data shared: a generated search query and standard request metadata. Not shared: your conversation, uploaded files, saved memory, project instructions, or account identifiers. Processing location varies by provider.
Retention: Serper keeps a record of the queries sent from our account. Its privacy policy says it keeps most personal data for as long as that account exists, and it sets no shorter deletion period for search queries.
Onward disclosure: to return results, Serper passes the query to Google Search. Serper also shares information with service providers it relies on for billing, security monitoring, and customer support, and requires them to keep it confidential.
Use and role: Serper’s privacy policy describes processing to operate its service, for billing, and for compliance. It does not describe using search queries to train AI models or selling them. Where a query contains personal data, Serper acts as processor for Bespoke Technologies.
WeatherAPI
Purpose: optional coarse weather context for the suggested starter questions on the home screen. Requests are designed to use coarse location context only, and are not used to produce chat responses. Processing location varies by provider.
Connected services acting independently
Some connected services may determine parts of their processing independently rather than acting only as Bespoke subprocessors. This can include Google for optional social sign-in and Paystack or Flutterwave for payment initiation, fraud prevention, and settlement. Their own privacy notices apply when you use those services.
Changes and notice
We will update this register before or when a material new processor or processing purpose is introduced. A material legal change receives a new calendar version and preserves the prior register. Where required, we will provide additional notice before the change takes effect.
Questions or objections
Ask a question about a provider, transfer, or safeguard through the Bespoke Technologies contact page. See the Privacy Policy for your wider privacy rights.