Sub-processors
Third parties Onnie uses to deliver the service, and the categories of data they may handle.
Last updated: August 6, 2026. This page is Onnie's public sub-processor list — not a countersigned Data Processing Agreement. If you need a formal DPA, or have questions about how your data is processed, contact us at legal@onnie.ai.
Sub-processors
| Processor | Purpose | Data categories | Region | Privacy policy |
|---|---|---|---|---|
| Supabase | Postgres database, authentication, real-time subscriptions, and file storage where used; Vault for connector OAuth tokens; Edge Functions including the host code-execution sandbox, routine scheduling, and platform SDK | User accounts, workspace data, messages, files, session tokens; encrypted connector OAuth secrets in Vault; code payloads and execution I/O for the sandbox | US (AWS us-east-1) | View → |
| Vercel | Web application hosting, edge network, and deployment infrastructure | IP addresses, request logs, deployed application traffic | Global (edge) | View → |
| Cloudflare | Onnie AI engine (Workers and Durable Objects), R2 object storage for files and images, and edge protection as used | Request metadata, engine payloads, stored object and file data | Global (edge) | View → |
| Anthropic | AI model inference (Claude) when workloads are routed to Anthropic-backed models | Chat and agent messages, and workspace context sent as model input | US | View → |
| OpenAI | AI model inference (including Quick / speed-tier agent workloads) when routed to OpenAI-backed models | Chat and agent messages, and workspace context sent as model input | US | View → |
| xAI | AI model inference (Grok) when workloads are routed to xAI-backed models | Chat and agent messages, and workspace context sent as model input | US | View → |
| Gemini model inference (agent runs, compaction and fast slots, image generation, and embeddings as used by the engine); first-party Workspace connectors (Gmail, Calendar, Drive) via Google APIs — Onnie performs OAuth and stores tokens in Supabase Vault | Model inputs and outputs for Gemini; connector content and metadata under user-granted scopes; OAuth tokens held in Supabase Vault | Global | View → | |
| Notion | First-party Notion connector — Onnie handles OAuth and stores tokens in Supabase Vault | Workspace and page content accessed under user-granted scopes; OAuth tokens held in Supabase Vault | US / Global | View → |
| Firecrawl | Platform web search and web scrape tools used by the Onnie AI engine | Search queries, target URLs, and retrieved page content returned for agent use | US | View → |
| Resend | Transactional email delivery (notifications, invites, magic links) | Email addresses, email content | US | View → |
| Dodo Payments | Subscription billing and payment processing (merchant of record) | Billing email, subscription status, payment method metadata (no raw card data) | US | View → |
Customer-configured third parties (for example custom MCP servers you connect) are not Onnie sub-processors. Their processing is governed by those providers and your configuration.
Changes to this list
We may update this list as we add or remove sub-processors. Material changes will be announced via email to workspace owners at least 14 days in advance.