SUBPROCESSORS

Who else processes your data

Running CodeRook means other companies hold parts of it. Here is each one, what it handles, and where.

The list

ProviderWhat it handlesWhere
CloudflareThe website and API, project file storage, delivery, bot verification, and outbound service email. Most requests reach Cloudflare before they reach anything else.Global network, with our workers placed in Asia-Pacific
PlanetScaleThe PostgreSQL database: accounts, permissions, project and version metadata, quotas, and audit records. Not project file contents, which live in object storage.Managed cloud infrastructure
StripeSubscriptions and payments. Card details go to Stripe directly and are never held by us.Global, under Stripe's own processing terms
Google and GitHubSign-in, and only for accounts that chose one of those providers. Nothing is shared with them unless you use them to sign in.Global

What this means in practice

Your project contents sit in Cloudflare object storage, addressed by a digest of the content rather than by a name that describes them. The database holds the record of what those objects are and who may reach them, and those two live with different providers.

Processing happens outside Australia. That is unavoidable for a service delivered on a global network, and it is the kind of overseas disclosure a privacy policy is expected to disclose rather than bury.

Changes to this list

If we add a provider that handles personal information or project content, it will appear here, and the changelog will say so. We would rather you learn about a new provider from us than notice it in a network trace.

Not on this list

We do not use advertising networks, and we do not share project content with anyone for training machine learning models — see AI on CodeRook and our terms, where that is a binding commitment rather than a statement of intent.