Sub-processors

Draft — not yet reviewed by counsel

This is a beta draft, written to be complete enough for legal review, not yet reviewed by counsel. Do not treat it as final or binding until that review is complete and this frontmatter's status changes.

suo uses the following sub-processors to operate the service. This list will be kept current as the platform's infrastructure evolves, and this page's lastReviewed date will be updated whenever it changes.

| Sub-processor | Purpose | Data involved | | --- | --- | --- | | Cloudflare | Edge compute (Workers), per-index storage (Durable Objects, SQLite), the control plane database (D1), object storage for crawled pages (R2), and approximate, sampled query analytics (Analytics Engine) | Account data, indexed content, query logs (no IP, no raw user identifier), crawled page snapshots |

This list has no email-delivery sub-processor today: the dashboard's sign-in code is only ever printed to the local dev console (apps/dashboard/server/auth.ts, sendVerificationOTP) and throws outside local development, so no account email is sent yet. The PR that wires up production email delivery for sign-in must update this table with the email provider and bump lastReviewed — this list is only accurate by omission until then.

Notification of changes

Beta accounts will be notified of a new sub-processor, or a change in an existing one's role, before it takes effect where reasonably possible. As the beta moves toward general availability, this page will also carry a subscribe mechanism for change notifications.


Placeholder for legal review: a formal sub-processor change-notification and objection process (timeline, contact method) is intentionally not drafted above pending counsel's input, along with confirmation of Cloudflare's data-processing terms as they apply to this list.