Subprocessors
Effective 2026-09-20 · version 1
The vendors that process customer data on our behalf to run ResidualsOS, what each one receives, and where it runs. This list is part of the Privacy Policy. We do not use analytics, advertising or error-reporting services that would put customer identifiers with a third party.
| Provider | Purpose | Location and notes |
|---|---|---|
| Cloudflare, Inc. | Hosting and storage: the application and the Owner Console (Workers), every database (D1), uploaded files, statements and backups (R2), configuration (KV), ingest queues, inbound email routing for the ticket intake, Access in front of the Owner Console, and request logs. | United States company; global edge network. All customer data is stored and processed here. Encrypted in transit and at rest by Cloudflare. |
| Resend | Transactional email sent from the platform's own domain: email verification, workspace invitations, statement-ready notices to partners, the weekly owner digest, and the platform's operational alerts to us. | United States. Receives the recipient address, the recipient's name where the message carries one, the workspace name, and the message body (a link, a period, a partner name, summary figures). Keeps sent mail under its own retention. |
| Microsoft Corporation (Microsoft 365 / Outlook) | Only when a person connects their own Outlook mailbox. Mail is read and sent through Microsoft Graph with that person's delegated consent, from their own mailbox in their own or their employer's Microsoft tenant. | The customer's provider, not ours. Nothing reaches Microsoft that the mailbox did not already hold, except the emails the person chooses to send. Disconnecting deletes the tokens we stored. |
| GitHub, Inc. | Source code, continuous integration, a daily availability probe, and the nightly offsite-backup job. | United States. The probe sees status codes only. Workspace slugs (short names) are recorded in the repository for provisioning. Once the offsite copy is armed, the backup job moves each night's database dumps through an ephemeral runner and retains nothing after the job ends; it is not armed today. |
| UptimeRobot | External availability monitoring of the application's public health endpoint, so an outage is noticed from outside Cloudflare. | Sees only the response to its own request (a status code and the deployed version). No customer data. |
| Offsite backup storage — not yet selectedPlanned — not yet in use | A second copy of the nightly database dumps in an account and vendor separate from Cloudflare. | Will be named here, with its location, before it receives any data. |
| Payment processor — not yet selectedPlanned — not yet in use | Collecting our own subscription invoices from customers. | Will be named here before any card is collected. Card numbers will be entered on the processor's hosted page, never stored by us. |
1. How this list changes
This list is dated by the version at the top of the page. When we add or replace a vendor that will handle customer data, we post the change here and email workspace owners when we publish it, and where that is practical we set its effective date at least 30 days out. If you object to a new vendor on reasonable data-protection grounds, tell us at privacy@residualsos.com before the effective date and we will work with you on it; if we cannot, you may end the agreement under the Terms of Service.
2. What is not on the list
Microsoft appears above only because a user may connect their own mailbox; in that case Microsoft is your provider under your own agreement with it, and nothing we do puts data there that your mailbox did not already hold, apart from the emails your users send. Cloudflare’s request logs are covered by the Cloudflare row. Our source code is on GitHub; customer data is kept out of it by policy and by a check that refuses database dumps in a commit.