Legal

Subprocessors

Register version 2026-07-14 - effective July 14, 2026

This register lists the principal providers that may process personal data for Trumpets and company-operated Apps. A provider is used only when the relevant feature is enabled. Customer-selected connectors are not listed because the Customer chooses and contracts for them separately.

We review this register and the applicable processing and transfer terms before enabling a provider in production. Business Customers may object to a new subprocessor as described in the Data Processing Addendum.

ProviderPurposeData categoriesProcessing locationSafeguard
Supabase, Inc.Authentication, PostgreSQL database, object storage, and backend infrastructure.Account identifiers, Customer Content, configuration, files, and operational metadata.Customer-selected project region plus provider support and subprocessor locations.DPA; European Commission SCCs or another lawful mechanism where required.
Google LLC and relevant Google affiliatesGoogle Cloud and Firebase hosting, Gemini processing, embeddings, file processing, Google Search grounding, Workspace integrations, and consented Analytics.Feature-dependent Customer Content, search queries, integration content, technical data, or consented website usage data.Configured cloud region where available; model, search, support, and Analytics processing can occur outside the EEA.Google data processing terms; SCCs, adequacy, or another lawful mechanism where required.
OpenRouter, Inc.API routing to a specifically selected non-Gemini model endpoint.Prompts, necessary context, outputs, and request metadata.United States and the location of the selected downstream endpoint.DPA and SCCs where required; Trumpets enforces per-request zero data retention and disables provider fallback.
Anthropic, PBC (through OpenRouter)Claude model inference when the Customer selects an Anthropic model.Prompts, necessary context, outputs, and request metadata.The location published for the selected zero-data-retention endpoint.OpenRouter zero-data-retention route; DPA and SCCs where required.
OpenAI, L.L.C. (through OpenRouter)Model inference when the Customer selects an OpenAI model.Prompts, necessary context, outputs, and request metadata.The location published for the selected zero-data-retention endpoint.OpenRouter zero-data-retention route; DPA and SCCs where required.
Stripe Payments Europe, Limited and relevant Stripe affiliatesCheckout, subscriptions, invoices, payment fraud prevention, and payment-related tax processing.Customer and billing identifiers, billing address, order, payment, tax, and transaction data.EEA and other Stripe group or service locations.Stripe data processing terms; SCCs, adequacy, or another lawful mechanism where required.
Brevo SASTransactional email, support notifications, newsletter double opt-in, and campaign delivery.Email address, name where supplied, message content, delivery metadata, and newsletter status.European Union and documented provider subprocessor locations.DPA; SCCs or another lawful mechanism where required.

Questions about a particular transfer or provider can be sent to hello@trumpets.ai.

Stay in tune.

Product notes, orchestration patterns, and the occasional field report - sent only when there’s something worth playing.

One email a month at most. Unsubscribe anytime.