Subprocessors
These are the third-party services that process customer data on behalf of JCIL.AI. Every item lists what it does, what data it sees, and where the processing happens. When this list changes, we update this page and the date at the bottom.
| Service | Purpose | Data received | Region | Policy |
|---|---|---|---|---|
| Anthropic | AI model inference (Claude models: Haiku 4.5 for every answer and background helper, larger Claude models for specialized work like document generation), native web search when a turn needs live results, and sandboxed document generation on Anthropic-hosted containers | User messages, system prompts, attached images and documents passed to the model; the search queries the model composes on search turns. Not used for training; retained briefly by Anthropic for abuse monitoring under its commercial terms | US; compute may route | View |
| OpenAI | Text embeddings (memory constellation and document library search) and voice dictation transcription (Whisper). No conversation is answered by OpenAI; it never sees a chat turn | Memory text and document passages sent for embedding; recorded audio clips sent for transcription when you use hold-to-speak. Not used for training under OpenAI's API terms | US; compute may route | View |
| Supabase | Authentication, PostgreSQL database | Profiles, conversations, messages, memories, billing transactions | US | View |
| Vercel | Application hosting, edge middleware, DNS, Blob storage for uploads | Request metadata, uploaded files | US | View |
| Stripe | Payment processing (subscription and credits) | Name, email, payment method (card numbers never touch JCIL.AI servers) | US | View |
| Resend | Transactional email (welcome, receipts, alerts) | Email address, message content | US | View |
| Upstash | Redis-backed rate limiting | Rate-limit counters keyed by user ID or IP; no message content | US | View |
| Composio | Third-party app connectors (Gmail, Calendar, and others) only when a user connects them | Only what the requested action requires | US | View |
| Cloudflare | Turnstile bot protection on the sign-in and sign-up forms. It runs only on those two forms and never on a conversation | IP address, user agent, and browser signals collected by the Turnstile challenge | US | View |
| Brave Search | Search results for the scheduled routines that gather headlines and reference material. Chat web search runs through Anthropic, not Brave | The routine's search query text only. No account identifier, no conversation content | US | View |
| Open-Meteo | Weather forecasts when you ask about the weather | A city name or a pair of coordinates. Nothing that identifies you | EU-operated public API | View |
| bible-api.com | Verbatim Scripture lookup (World English Bible) | The passage reference you asked for, such as John 3:16. Nothing else | US | View |
| Sentry | Application error monitoring | Error traces and request metadata, and on an error a session replay with text and inputs masked | US | View |
Where your data lives
Everything we store about you is held in the United States -- your account, your conversations, your memory, your documents -- and every company that stores your data is American. Two lookup services above (Open-Meteo for weather, bible-api.com for Scripture) receive no personal data at all: a city name or a passage reference, nothing tied to you.
Your prompts and answers are never used to train any model, by us or by any company above. Anthropic, which serves the model and the built-in web search, retains API inputs and outputs for a limited period for abuse monitoring under its commercial terms and does not train on them; its privacy documentation linked above has the specifics.