The third parties that process data on our behalf, what each is used for, and what it receives. Services marked optional are engaged only if you turn that feature on.
| Subprocessor | Purpose | Data received |
|---|---|---|
| Anthropic | AI model inference — the generation that builds your project | Your prompts and your project source code |
| E2B | Isolated sandboxes where code runs during generation | Project source code during a build |
| Advin Services LLC | Compute and storage for the platform and your deployed sites (United States) | All data hosted on CoDuck |
| Stripe | Payments and subscription billing | Billing contact details and payment metadata. Card numbers are entered directly with Stripe and never reach our servers. |
| Amazon Web Services (SES, SNS) | Transactional and lifecycle email delivery | Your email address and the content of messages we send you |
| Cloudflare | Bot protection on sign-up, and DNS | IP address and request metadata |
| GitHubOptional | Repository sync, if you connect a repository | Project source code and the access token you grant |
| GoogleOptional | Sign-in with Google, and Search Console integration if connected | Your email address, and search analytics for sites you connect |
| BraveOptional | Web search, when the assistant needs current information | Search queries derived from your prompt |
We update this page before a new subprocessor begins handling customer data, not after. If you have a data processing agreement with us and would like advance notice of changes, email security@coduck.ai and we will add you to the notification list.