Subprocessors & Data Flows
DRAFT · Version subprocessors-2026-08-29-v2 · Last updated August 29, 2026
This page lists the third parties (“subprocessors”) that may process data on TapQuality's behalf, the purpose of each engagement, the categories of data involved, and the effective date of this disclosure.
Verbatim client text (chat, intake answers, briefs) is processed by our self-hosted local model only and is never sent to a third-party LLM provider. Only non-verbatim, derived material (structured plans, research summaries) may reach Anthropic's Claude API, and only for the research and planning lanes. This routing is enforced in code, not by policy alone.
The table below is the primary disclosure. Detail notes follow for self-hosted processing and processors that are evaluated but not currently armed.
| Vendor | Purpose | Data categories | Status | Effective date |
|---|---|---|---|---|
| Neon (PostgreSQL) | Primary application database | Account; Organization & project content; Operational records | Active | August 29, 2026 |
| Vercel | Application hosting, build pipeline, and file (Blob) storage | Account; Uploaded assets & reports; Request metadata | Active | August 29, 2026 |
| Anthropic (Claude API) | Non-verbatim research and planning generation only | Derived, non-verbatim planning & research material | Active | August 29, 2026 |
| Microsoft 365 (Graph, app-only) | Outbound transactional email (account & lifecycle notices) | Recipient email address; Notification content | Active | August 29, 2026 |
| Stripe | Billing and invoicing (invoice-then-pay; no stored-card auto-charge) | Billing contact; Invoice line items; Payment status | Active | August 29, 2026 |
| Dropbox Sign (HelloSign) | E-signature for NDAs and engagement contracts | Signer name & email; Signed document | Active | August 29, 2026 |
| Sentry | Error monitoring (error events only; PII collection disabled) | Error/exception metadata | Evaluated, not armed | August 29, 2026 |
Self-hosted processing (not a third-party subprocessor)
Verbatim client chat and intake text is processed by TapQuality's self-hosted local model (Ollama) on our own hardware. That path is disclosed here for honesty about where client text goes; it is not a third-party subprocessor.
Not used
TapQuality installs no analytics, advertising, or third-party tracking technology, and uses no SMS/telephony provider. Optional research-upgrade providers (e.g. Gemini, Perplexity) are referenced in configuration but are not wired and receive no data.
Changes to this list
This page revs independently of Terms and Privacy. Material additions or removals of active subprocessors will update the version stamp and effective date on this page. Questions: privacy@tapquality.ai.