Effective 2026-07-24
Subprocessors
Brogan LLC engages the vendors below to provide Cluestick. Each is bound by written processing terms that are no less protective than the commitments in our own Data Processing Agreement, to the extent those commitments apply to the service it provides. For most of these vendors that instrument is the vendor’s own data processing agreement, linked from its name; push delivery is provided under the Apple Developer Program License Agreement instead, and the link on Apple’s name is its privacy documentation rather than a DPA.
| Subprocessor | Purpose | Data | Location |
|---|---|---|---|
| Neon | Managed Postgres — the primary application database | Account data; Conversation and message content; End-user identifiers and device context | United States |
| Cloudflare | R2 object storage — attachment bytes | Attachment files uploaded by end users and agents | United States |
| Vercel | Application hosting, compute and logging, and Vercel Web Analytics — the aggregate page-view counter that runs on every page of our website and dashboard | All data in transit through the service; Request logs; Website page-view events from visitors to our own site | United States |
| Upstash | Redis — rate limiting and short-lived operational counters | IP addresses and API key identifiers | United States |
| Resend | Transactional email — sign-in codes and notifications | Account email addresses; Email message content | United States |
| Apple | APNs — push notification delivery to end-user devices. Apple provides APNs under the Apple Developer Program License Agreement rather than a separate negotiated data processing agreement, so the link on its name is Apple's published privacy documentation rather than a DPA. | Device push tokens; Notification content | United States |
| Stripe | Subscription billing and payment processing | Customer billing contact and payment details | United States |
| Sentry | Application error monitoring for Cluestick's own systems. Sentry acts as a subprocessor only in this capacity — not when a customer connects their own Sentry account, which Cluestick accesses solely as a read-only integration under that customer's agreement with Sentry. | Error traces, which may incidentally include identifiers | United States |
Integrations are not subprocessors
Cluestick can display context from a customer’s own RevenueCat, PostHog, Mixpanel or Sentry account. Those lookups run on credentials the customer supplies, are performed on demand while an agent views a conversation, and their results are not stored by Cluestick. Those vendors are the customer’s processors under the customer’s own agreements, not ours.
Changes
We give at least thirty (30) days notice, by email to the address registered on the account, before we add or replace a subprocessor. Where a subprocessor has to be replaced sooner in order to protect the security or the continuity of the Service, we give notice as soon as we reasonably can. Customers may object to a new subprocessor within the notice period on reasonable data-protection grounds, as set out in the Data Processing Agreement.