Sub-processors

Third parties Onnie uses to deliver the service, and the categories of data they may handle.

Last updated: August 6, 2026. This page is Onnie's public sub-processor list — not a countersigned Data Processing Agreement. If you need a formal DPA, or have questions about how your data is processed, contact us at legal@onnie.ai.

Sub-processors

ProcessorPurposeData categoriesRegionPrivacy policy
SupabasePostgres database, authentication, real-time subscriptions, and file storage where used; Vault for connector OAuth tokens; Edge Functions including the host code-execution sandbox, routine scheduling, and platform SDKUser accounts, workspace data, messages, files, session tokens; encrypted connector OAuth secrets in Vault; code payloads and execution I/O for the sandboxUS (AWS us-east-1)View →
VercelWeb application hosting, edge network, and deployment infrastructureIP addresses, request logs, deployed application trafficGlobal (edge)View →
CloudflareOnnie AI engine (Workers and Durable Objects), R2 object storage for files and images, and edge protection as usedRequest metadata, engine payloads, stored object and file dataGlobal (edge)View →
AnthropicAI model inference (Claude) when workloads are routed to Anthropic-backed modelsChat and agent messages, and workspace context sent as model inputUSView →
OpenAIAI model inference (including Quick / speed-tier agent workloads) when routed to OpenAI-backed modelsChat and agent messages, and workspace context sent as model inputUSView →
xAIAI model inference (Grok) when workloads are routed to xAI-backed modelsChat and agent messages, and workspace context sent as model inputUSView →
GoogleGemini model inference (agent runs, compaction and fast slots, image generation, and embeddings as used by the engine); first-party Workspace connectors (Gmail, Calendar, Drive) via Google APIs — Onnie performs OAuth and stores tokens in Supabase VaultModel inputs and outputs for Gemini; connector content and metadata under user-granted scopes; OAuth tokens held in Supabase VaultGlobalView →
NotionFirst-party Notion connector — Onnie handles OAuth and stores tokens in Supabase VaultWorkspace and page content accessed under user-granted scopes; OAuth tokens held in Supabase VaultUS / GlobalView →
FirecrawlPlatform web search and web scrape tools used by the Onnie AI engineSearch queries, target URLs, and retrieved page content returned for agent useUSView →
ResendTransactional email delivery (notifications, invites, magic links)Email addresses, email contentUSView →
Dodo PaymentsSubscription billing and payment processing (merchant of record)Billing email, subscription status, payment method metadata (no raw card data)USView →

Customer-configured third parties (for example custom MCP servers you connect) are not Onnie sub-processors. Their processing is governed by those providers and your configuration.

Changes to this list

We may update this list as we add or remove sub-processors. Material changes will be announced via email to workspace owners at least 14 days in advance.