Subprocessors and service providers
Last updated: August 9, 2026
This page identifies material providers and provider categories used to deliver broomva.tech. The currently configured model catalog may include OpenAI, Anthropic, xAI, Google, Meta, Mistral, Alibaba, Amazon, Cohere, DeepSeek, Perplexity, Vercel, Inception, Moonshot, Morph, ZAI. The selected model determines which model provider receives a request. Not every provider receives data from every user: processing depends on the feature, selected model, account method, and analytics choice. A public list is a transparency aid and is not yet a contract-grade production data-flow inventory; it does not replace a signed data-processing or international-transfer agreement where one is legally required.
| Provider | Purpose | Data | Processing location |
|---|---|---|---|
| Vercel | Hosting, deployment, storage, analytics, and AI Gateway | Account, content, request, technical, and optional analytics data | United States and provider-controlled regions |
| Neon | Database and authentication | Account, organization, authentication, chat, and application data | Configured database region and provider support locations |
| Stripe | Checkout, subscriptions, invoices, and payment fraud controls | Identity, billing, transaction, and payment data | United States and provider-controlled regions |
| Sentry | Essential error and performance monitoring | Error, request, device, and diagnostic data; session replay disabled | United States and provider-controlled regions |
| PostHog | Product reliability events and consented browser analytics | Account identifiers, feature events, pages, referrals, and device data | United States cloud endpoint |
| Langfuse | AI and agent observability and model-call tracing | User, chat, model, trace, and technical identifiers; telemetry may include prompts and outputs depending on active settings | Configured or provider-controlled cloud region |
| Google and GitHub | Optional account authentication | Account identifier, name, email, avatar, and authentication records | Provider-controlled regions |
| AI model providers via Vercel AI Gateway | Generate text, code, images, and other requested outputs | Prompts, relevant context, attachments, tool inputs, and generated output | Depends on the selected model provider |
| Tavily and Firecrawl | Web search and URL retrieval when invoked | Search queries, URLs, and tool parameters | Provider-controlled regions |
| Deployment-configured Redis provider | Resumable chat streams and short-lived relay state | Session and stream identifiers and transient message state | Depends on the production REDIS_URL provider and region |
| Broomva-operated Arcan and Lago services | Agent execution, memory, knowledge, sessions, and public assets | Account identifiers, agent/session content, files, and technical data | Deployment region, including Railway-hosted services where configured |
| OpenRouter | Alternative AI model gateway when that route is configured | Prompts, relevant context, attachments, and generated output | United States and downstream provider regions |
| Base Account, configured Base RPC, and the public Base blockchain | Optional wallet authentication and onchain identity features | Wallet address, signed message, chain identifiers, and public immutable blockchain records | Public distributed blockchain and provider-controlled RPC regions |
Changes and questions
We update this page when material providers change. Contract customers should use the notice and objection process in their signed agreement. Questions may be sent to contact@broomva.tech. See the Privacy Policy for purposes, legal grounds, transfers, retention, and rights.