Grace← Home

DRAFT — NOT LEGAL ADVICE. Prepared as a starting draft. Verify each provider's current entity, purpose and data-processing region before publishing — regions in particular are configuration- and plan-dependent and change over time. [TO CONFIRM: …] items need your input.

Sub-processors — Grace

To provide Grace we use a small number of trusted service providers ("sub-processors") that may process personal information contained in Customer Data on our behalf. We impose data-protection obligations on each of them consistent with our Data Processing Addendum (data-processing-addendum.md).

Last updated: [TO CONFIRM]

Sub-processor Service provided Data processed Primary location [TO CONFIRM each]
Clerk, Inc. User authentication and identity management Account identity, credentials, sign-in metadata United States
Neon, Inc. Application database (PostgreSQL) All application data, including Customer Data Australia — Sydney (ap-southeast-2)
Vercel Inc. Application hosting, edge/serverless compute, and file storage (Blob) Application traffic, logs, uploaded files/attachments Australia — Sydney (syd1) for compute; [TO CONFIRM: Blob region]
Upstash, Inc. Rate limiting (managed Redis) Request metadata (e.g. identifiers used for rate limiting) [TO CONFIRM: the region configured for Grace]
Anthropic, PBC Optional — the "Ask Grace" AI assistant (only when a workspace enables it) Prompts + the records a user asks about (may contain personal information) United States [TO CONFIRM: region; ZDR?]

Notes:

  • Data residency. The primary application database and file storage are hosted in Australia. Authentication (Clerk) is processed in the United States. When a workspace enables the optional AI assistant, the prompts and records it processes are sent to Anthropic in the United States — see the overseas-disclosure sections of the Privacy Policy and DPA.
  • Optional AI features (Anthropic). The AI assistant is off by default and is used only if a workspace enables it. When enabled, the prompts submitted to the assistant and the records it is asked about are processed by Anthropic under its Commercial Terms and Data Processing Addendum; Anthropic does not use the data to train its models and (under its API terms) deletes it within approximately 30 days. [TO CONFIRM: whether Grace has enabled a Zero-Data-Retention agreement with Anthropic, which removes that 30-day storage.]
  • [TO CONFIRM] Confirm whether any analytics, email/notification, error-monitoring, or payment provider is added before launch (e.g. a transactional email service, or Stripe/Clerk Billing once charging begins) and add it here.
  • Changes. We keep this list current. Material changes to sub-processors are notified as set out in the DPA. The live version will be published at grace.eganservices.com/sub-processors.
© 2026 Egan Services · Grace
Privacy PolicyTerms of ServiceData Processing AddendumAcceptable Use PolicySub-processorsSecurity