Subprocessors
Register version 2026-07-14 - effective July 14, 2026
This register lists the principal providers that may process personal data for Trumpets and company-operated Apps. A provider is used only when the relevant feature is enabled. Customer-selected connectors are not listed because the Customer chooses and contracts for them separately.
We review this register and the applicable processing and transfer terms before enabling a provider in production. Business Customers may object to a new subprocessor as described in the Data Processing Addendum.
| Provider | Purpose | Data categories | Processing location | Safeguard |
|---|---|---|---|---|
| Supabase, Inc. | Authentication, PostgreSQL database, object storage, and backend infrastructure. | Account identifiers, Customer Content, configuration, files, and operational metadata. | Customer-selected project region plus provider support and subprocessor locations. | DPA; European Commission SCCs or another lawful mechanism where required. |
| Google LLC and relevant Google affiliates | Google Cloud and Firebase hosting, Gemini processing, embeddings, file processing, Google Search grounding, Workspace integrations, and consented Analytics. | Feature-dependent Customer Content, search queries, integration content, technical data, or consented website usage data. | Configured cloud region where available; model, search, support, and Analytics processing can occur outside the EEA. | Google data processing terms; SCCs, adequacy, or another lawful mechanism where required. |
| OpenRouter, Inc. | API routing to a specifically selected non-Gemini model endpoint. | Prompts, necessary context, outputs, and request metadata. | United States and the location of the selected downstream endpoint. | DPA and SCCs where required; Trumpets enforces per-request zero data retention and disables provider fallback. |
| Anthropic, PBC (through OpenRouter) | Claude model inference when the Customer selects an Anthropic model. | Prompts, necessary context, outputs, and request metadata. | The location published for the selected zero-data-retention endpoint. | OpenRouter zero-data-retention route; DPA and SCCs where required. |
| OpenAI, L.L.C. (through OpenRouter) | Model inference when the Customer selects an OpenAI model. | Prompts, necessary context, outputs, and request metadata. | The location published for the selected zero-data-retention endpoint. | OpenRouter zero-data-retention route; DPA and SCCs where required. |
| Stripe Payments Europe, Limited and relevant Stripe affiliates | Checkout, subscriptions, invoices, payment fraud prevention, and payment-related tax processing. | Customer and billing identifiers, billing address, order, payment, tax, and transaction data. | EEA and other Stripe group or service locations. | Stripe data processing terms; SCCs, adequacy, or another lawful mechanism where required. |
| Brevo SAS | Transactional email, support notifications, newsletter double opt-in, and campaign delivery. | Email address, name where supplied, message content, delivery metadata, and newsletter status. | European Union and documented provider subprocessor locations. | DPA; SCCs or another lawful mechanism where required. |
Questions about a particular transfer or provider can be sent to hello@trumpets.ai.
Stay in tune.
Product notes, orchestration patterns, and the occasional field report - sent only when there’s something worth playing.