Subprocessors

Last updated September 1, 2026. Back to Vorklee

This list describes third-party vendors that process personal data on behalf of Vorklee when you use our platform. We update this page when we add or replace a subprocessor.

VendorRoleDataRegionNotes
ClerkAuthentication, MFAEmail, name, sessionUnited StatesSOC 2; GDPR tooling
NeonPostgreSQL databaseAll org-scoped application dataUnited States (project region)DPA via Neon
VercelHosting, edge networkRequest logs, build artifactsGlobalDPA via Vercel
UpstashRedis (cache, analytics, SSE)Scrubbed analytics, cache keysUS/EU per projectDPA via Upstash
SentryError monitoringScrubbed crash eventsUnited StatesDPA via Sentry; sendDefaultPii disabled
Google (Gemini)AI inferenceScrubbed prompts via platform AI gateUnited StatesAPI terms; secrets redacted before send
StripeBilling (when enabled)Billing contact, payment tokensUnited StatesPCI; Stripe DPA
Cloudflare R2File attachments (where used)Uploaded file blobsPer bucketDPA via Cloudflare
Firebase / FCMPush notifications (where enabled)Device tokensGoogleFirebase terms

Enterprise customers may request a DPA or formal Transfer Impact Assessment before signature.

Subprocessors | Vorklee