Subprocessors
Every third party that processes customer data to run Creobot, what it does and where.
Subprocessors
These are the third parties that process customer data on our behalf to run Creobot. Customer data means your account and billing details, the content you train agents on, and the conversations and leads your agents collect from your visitors.
| Provider | What it does for Creobot | Data it processes | Location |
|---|---|---|---|
| Render | Application hosting for the Creobot API and background jobs, and Redis (Render Key Value) for job queues and rate limits | All data the service processes while it is handled by the API | Singapore |
| MongoDB Atlas (MongoDB, Inc., on AWS) | Primary database | Account and workspace details, agent settings, conversations, leads and site form submissions | Mumbai, India (AWS ap-south-1) |
| Qdrant Cloud (Qdrant Solutions GmbH) | Vector database for retrieval | Embedded passages of the website pages and files you train an agent on | Region being confirmed |
| Amazon Web Services (S3) | File storage | Files you upload to train an agent | Region being confirmed |
| Vercel | Hosting for the dashboard at app.creobot.ai and the widget script | Dashboard requests and the page requests that load the widget | Global edge network |
| Cloudflare | DNS, CDN, the creobot.ai website and email routing | Website visits and email sent to creobot.ai addresses | Global edge network |
| OpenAI | AI replies on OpenAI models, embeddings and chat summaries | Visitor messages, the passages retrieved to answer them, and your content when it is embedded | United States |
| Anthropic | AI replies when an agent uses a Claude model | Visitor messages and the passages retrieved to answer them | United States |
| Google (Gemini API) | AI replies when an agent uses a Gemini model | Visitor messages and the passages retrieved to answer them | United States |
| Cohere | Reranking retrieved passages before an answer is written | The visitor question and the candidate passages | United States |
| Stripe | Payments, subscriptions and invoices | Billing contact and payment details; card numbers are held by Stripe, never by Creobot | United States |
| Resend | Transactional email: sign-up, password reset, sign-in alerts, lead and handoff notifications | Recipient address and the content of the email | United States |
| Sentry (Functional Software, Inc.) | Error monitoring | Error reports, which can include request details such as a URL or account id | United States |
AI model providers
Each agent has a primary model and a fallback, chosen by you. A reply goes to the provider of whichever model answers it, so an agent that only uses OpenAI models sends nothing to Anthropic or Google. Embeddings and chat summaries use OpenAI, and reranking uses Cohere, whichever reply model is chosen.
What each provider retains, and for how long, is set by its own API terms. We do not claim zero retention and we do not summarise those terms into a promise of our own.
Integrations you turn on
These only receive data when you connect them. They work under your own account with that service, so they are listed here to show where data goes rather than as our subprocessors.
| Service | Used for | Data sent |
|---|---|---|
| Google Sign-In | Signing in with a Google account | Your name and email address from Google |
| Slack | Lead, handoff and summary notifications, and replying from Slack | Conversation excerpts and lead details you choose to send |
| Cal.com and Calendly | Booking meetings from a conversation | The booking details the visitor enters |
| Make | Sending leads and events to your own automations | The events and lead details you configure |
| Webflow | The Creobot Webflow app, if you install it | Site and CMS content you connect |
Trust
Every party in the chain
Naming the chain is the question worth asking every vendor, including us. This is ours.