Home  /  Legal  /  Subprocessors

Legal

Subprocessors

Every third party that processes Lossless customer data — what they do, where they sit, what categories of data they receive, and the 30-day notice we give before adding a new one.

Last updated May 23, 2026. To get notified by email whenever this page changes, email privacy@lossless-ai.com from the address on your account.

Cloud infrastructure

VendorPurposeData categoriesRegionContract
Google Cloud (GCP)Compute (Cloud Run), database (Cloud SQL), object storage (GCS), key management (KMS), logging, Cloud Tasks.All categories of Customer Data and Lossless service data.US-WEST1 (default)
EU-WEST3 (EU opt-in)
DPA in place; SCCs available

Authentication

VendorPurposeData categoriesRegionContract
WorkOSSingle sign-on (SSO), passkeys, directory sync for enterprise tenants.Email, name, SSO identifier, IP at login.USDPA in place
StytchBackup auth provider (passwordless, magic links) — used for users not on SSO.Email, IP, device user-agent.USDPA in place

Payments

VendorPurposeData categoriesRegionContract
StripeCredit-card billing, invoice issuance, tax compliance.Name, billing address, last-four card digits, transaction history. We do not store full card numbers; Stripe holds them.USDPA in place; PCI DSS compliant vendor

AI inference

VendorPurposeData categoriesRegionContract
AnthropicLarge language model inference (Claude). Summaries, classification, Q&A on your records.The minimum content needed to answer your specific request. Never OAuth tokens or payment instruments.USNo training Enterprise agreement; configured per call.
OpenAILLM inference for select features (mostly embeddings and lighter tasks).Same as above.USZero-retention Zero-data-retention org tier; no logging.
Google Vertex AI / GeminiLLM inference for select features.Same as above.USNo training Vertex enterprise; data-not-used-for-improvement configured.

Vector store

VendorPurposeData categoriesRegionContract
PineconeVector embeddings of your records, used for fast semantic search.Embeddings (not raw text); workspace-scoped namespaces.USDPA in place

Connector providers (data inflow)

VendorPurposeData categoriesRegionContract
PlaidBank, credit-card, mortgage, and investment account connectivity.Account metadata, balances, transactions, account numbers, owner identifiers (last-four SSN where the institution provides it).USGLBA-regulated; DPA in place
Google (Gmail, Calendar, Drive)OAuth read access to user-authorized Google Workspace surfaces.Email content, calendar events, files (only what the user grants).USStandard OAuth scopes; we hold tokens, not credentials.
Microsoft 365Outlook / OneDrive equivalents.Same as above for Microsoft accounts.USStandard OAuth scopes.
Rental platforms (Airbnb, VRBO, Hostaway, Guesty)Listing, reservation, guest, message, and payout data for STR hosts who connect.Guest profiles, reservation history, messages, payouts.VariesPer-platform OAuth + DPA where offered.

Operational

VendorPurposeData categoriesRegionContract
ResendTransactional email delivery (signup, security alerts, deletion confirmations).Email address; email body for the transactional message itself.USDPA in place
Sentry (or equivalent APM)Application error monitoring.Stack traces with PII scrubbed; user_id only, no content.USDPA in place; PII-scrub filter enabled.
GitHubSource-code hosting. Does not process Customer Data.n/a (not a customer-data subprocessor).USn/a
Subscribe to updates. If you'd like to be notified of any change to this list — additions, removals, or scope changes — email privacy@lossless-ai.com from your account email. We notify all active customers automatically and post the update with at least 30 days' lead time.

Process for new subprocessors

  1. We complete a vendor diligence review: security posture, data minimization, DPA terms, sub-processing chain, breach history.
  2. We notify all active customers by email and post the addition on this page at least 30 days before the vendor receives any customer data.
  3. Customers who object may terminate without penalty during the notice window.
  4. After the notice window, the vendor goes live; the audit trail records the live date.

Subprocessors we have considered and declined

We do not use any third-party advertising network, analytics SDK with cross-site identifiers, attribution platform, or marketing-automation vendor that would receive product data. We have evaluated and declined the major players in each of those categories.