Subprocessors
Last updated: August 10, 2026
Orchestra AI ("Orchestra") uses the third-party service providers listed below ("subprocessors") to deliver the Spyglasses platform. A subprocessor is a vendor that may process data on our behalf in the course of providing our Services. We maintain data processing agreements with our subprocessors and require safeguards consistent with our Privacy Policy and Terms of Use — including our commitment that customer data is never used to train AI or machine-learning models beyond serving your own requests.
We review this list as our vendors change and update this page when subprocessors are added or replaced. Questions about this list can be sent to legal@orchestra-ai.com.
Data category key
- Account data — names, email addresses, organization details of Spyglasses users.
- Customer Content — data you submit or that the platform generates for you: prompts and tracked queries, brand and competitor information, monitored site content, reports, and exports.
- Usage Data — technical telemetry about how the Spyglasses application is used.
- Site traffic telemetry — visitor events from your own website collected by the Spyglasses tracker (page paths, user agents, referrers).
- Payment data — billing details, handled only by our payment processor.
Core infrastructure
| Subprocessor | Purpose | Data processed | Primary region |
|---|---|---|---|
| Vercel | Application hosting, serverless compute, and content delivery | All categories in transit | United States |
| Cloudflare | Web application firewall and network security in front of the platform | All categories in transit | Global (edge network) |
| Supabase | Primary database and file storage (logos, generated reports, exports) | Account data, Customer Content | United States (AWS us-east-2) |
| ClickHouse Cloud | Analytics event store for AI-visitor traffic | Site traffic telemetry | United States (GCP us-east1) |
| Inngest | Background job orchestration (report generation, monitoring runs, exports) | Account data, Customer Content in job payloads | United States |
Payments, communications, and monitoring
| Subprocessor | Purpose | Data processed | Primary region |
|---|---|---|---|
| Stripe | Payment processing, subscriptions, and invoicing | Payment data, Account data | United States |
| Postmark (ActiveCampaign) | Transactional email delivery | Account data, email content | United States |
| Sentry | Error monitoring and diagnostics | Usage Data, error context | United States |
| PostHog | Product analytics | Account data, Usage Data | United States |
| Google Analytics | Marketing site and application traffic analytics | Usage Data | United States |
| Slack | Internal operational notifications (e.g. new sign-ups, subscription events) | Account data | United States |
AI platforms and search data
Monitoring how AI assistants describe your brand requires running your tracked prompts through those platforms. Customer prompts and brand terms are sent to the following providers to produce your visibility results; responses are analyzed and stored in your account.
| Subprocessor | Purpose | Data processed | Primary region |
|---|---|---|---|
| DataForSEO | Prompt runs on ChatGPT, Gemini, and Google AI Overviews; search rankings and keyword data | Customer Content (prompts, brand and competitor terms, domains) | United States |
| OpenAI | Direct prompt runs, analysis, and text embeddings | Customer Content | United States |
| Anthropic | Direct prompt runs (Claude) and content analysis | Customer Content | United States |
| Google (Gemini API) | Direct prompt runs with grounding | Customer Content | United States |
| Perplexity | Direct prompt runs | Customer Content | United States |
| Microsoft Azure | Prompt runs through Microsoft Copilot with Bing grounding — used only for organizations that enable the Copilot add-on | Customer Content | United States |
| Langfuse | AI request observability and cost tracking | Customer Content in AI request traces | United States |
Content retrieval, enrichment, and document generation
| Subprocessor | Purpose | Data processed | Primary region |
|---|---|---|---|
| Firecrawl | Fetching and extracting content from monitored and cited web pages | URLs of customer and cited pages | United States |
| Browserbase | Cloud browser rendering for site audits and screenshots | Customer site URLs and rendered page content | United States |
| Brave Search | Search result lookups supporting visibility analysis | Search queries derived from brand and competitor terms | United States |
| Replicate | Relevance scoring for citation analysis | Query text and page content excerpts | United States |
| Carbone | PDF and presentation rendering of reports | Customer Content (report contents) | France (EU) |
| Abstract API | Company name resolution from domains | Domain names | United States |
| Brandfetch | Brand logo lookup by domain (loaded in your browser) | Domain names | United States |
| Geoapify | Location search and geocoding for geo-targeted prompts | Location text entered by users | Germany (EU) |
Customer-controlled connections
Some connections are made at your direction to systems you control and are not subprocessors: your own identity provider when you configure single sign-on, and your own Google Analytics property when you enable the analytics integration. Data sent to these destinations is governed by your agreements with those providers.