---
title: "Sub-processors"
description: "The third parties that process personal data on our behalf, what each one receives, and where it runs."
canonical: https://keepitlocal.app/subprocessors
last-updated: 2026-09-13
---

# Sub-processors

The third parties that process personal data on our behalf, what each one receives, and where it runs.


Version 0.1 (draft). Last updated 7 September 2026.

These are the third parties that process personal data on our behalf when you use KeepItLocal
Redact for the web. This page is Annex III to our [data processing agreement](/dpa), and we
will publish a change here and give at least 30 days' notice before a new sub-processor starts
processing.

The list is short by design. Because documents are redacted inside your browser, no
sub-processor ever receives document content: not the file, not the pages, not the text the
detectors matched, not the exported result.

| Sub-processor | What it is used for | What it receives | Region | Transfer mechanism | Status |
| --- | --- | --- | --- | --- | --- |
| Resend | Transactional email only: address verification, password reset, workspace invitations. No marketing email is sent | The recipient address, the subject and the rendered message body | United States | Standard contractual clauses and the UK addendum | In use when email is enabled |
| Paddle | Merchant of record for paid plans: checkout, payment processing, invoicing, tax and refunds | Your name, billing address, tax status and payment instrument, which Paddle holds as a controller for those purposes, plus the plan you bought | United Kingdom and European Union | Standard contractual clauses and the UK addendum where applicable | Planned, not live: paid plans have not launched |
| Google | Optional "sign in with Google". Only used if you choose it, and it can be switched off for the whole platform | Your Google account email address, whether it is verified, your name and your profile photo URL. Your profile photo is then loaded by your browser directly from Google | United States | Standard contractual clauses and the UK addendum | Optional, off unless configured and enabled |
| [Hosting provider to be confirmed] | Running the application and the Postgres database that holds account data, and storing encrypted backups of it | Everything the service stores: account records, session metadata, audit rows, certificates, shared report metadata and early access requests | European Union | No transfer outside the EEA | To be selected, see the open item below |

## What each one means in practice

**Resend.** Email is the one place where an address leaves our own database. We keep a
delivery record for 30 days holding the recipient's domain, the subject, the provider and
whether it succeeded. No message body is stored: a stored body would decrypt to a live
sign-in or password-reset link, so re-sending is replaced by re-triggering the original flow.
Email can be switched off platform-wide, in which case no message is sent and Resend receives
nothing.

**Paddle.** When paid plans launch, Paddle is the seller of record: you buy from Paddle, and
Paddle handles the payment, the tax and the invoice. Card details never reach us. We keep the
subscription reference and the plan tier so that we know what your account is entitled to.

**Google.** Sign in with Google is a convenience, not a requirement, and there is always a
password alternative. If you never use it, Google receives nothing about you from us. Where
your account has a Google profile photo, your browser fetches that image from Google directly,
which means Google can see that the image was requested; our content security policy allows no
other third-party origin.

**Hosting provider.** The provider that runs the application and the database is the one
sub-processor with access to everything we store, which is why the region and the contract
matter more here than anywhere else. The decision is an open item and this row will be
completed with the provider's name, its sub-processor terms and its region before this page is
published.

## Not sub-processors

- **Your browser and your device.** Where the document actually gets redacted. Not ours.
- **Third-party analytics, advertising, error tracking, session replay, chat widgets, content
  delivery networks for third-party scripts.** None of these are used. There is no third-party
  script on any page of the service. Visits are counted by our own server, with a daily-rotating
  hash that identifies nobody and no cookie; see the privacy notice.

## Open items before this page is published

- Hosting is Hetzner in the EU. Nightly backups remain an open item.
- Paddle is not live. Its row becomes operative when paid plans launch.
- Signed data processing agreements with each sub-processor need to be obtained and filed. This
  takes calendar time nobody controls, so it is started early.
