Subprocessors.

The third parties that process data on our behalf, what each is used for, and what it receives. Services marked optional are engaged only if you turn that feature on.

SubprocessorPurposeData received
AnthropicAI model inference — the generation that builds your projectYour prompts and your project source code
E2BIsolated sandboxes where code runs during generationProject source code during a build
Advin Services LLCCompute and storage for the platform and your deployed sites (United States)All data hosted on CoDuck
StripePayments and subscription billingBilling contact details and payment metadata. Card numbers are entered directly with Stripe and never reach our servers.
Amazon Web Services (SES, SNS)Transactional and lifecycle email deliveryYour email address and the content of messages we send you
CloudflareBot protection on sign-up, and DNSIP address and request metadata
GitHubOptionalRepository sync, if you connect a repositoryProject source code and the access token you grant
GoogleOptionalSign-in with Google, and Search Console integration if connectedYour email address, and search analytics for sites you connect
BraveOptionalWeb search, when the assistant needs current informationSearch queries derived from your prompt

Changes to this list

We update this page before a new subprocessor begins handling customer data, not after. If you have a data processing agreement with us and would like advance notice of changes, email security@coduck.ai and we will add you to the notification list.