SUBPROCESSORS
Who else processes your data
Running CodeRook means other companies hold parts of it. Here is each one, what it handles, and where.
The list
| Provider | What it handles | Where |
|---|---|---|
| Cloudflare | The website and API, project file storage, delivery, bot verification, and outbound service email. Most requests reach Cloudflare before they reach anything else. | Global network, with our workers placed in Asia-Pacific |
| PlanetScale | The PostgreSQL database: accounts, permissions, project and version metadata, quotas, and audit records. Not project file contents, which live in object storage. | Managed cloud infrastructure |
| Stripe | Subscriptions and payments. Card details go to Stripe directly and are never held by us. | Global, under Stripe's own processing terms |
| Google and GitHub | Sign-in, and only for accounts that chose one of those providers. Nothing is shared with them unless you use them to sign in. | Global |
What this means in practice
Your project contents sit in Cloudflare object storage, addressed by a digest of the content rather than by a name that describes them. The database holds the record of what those objects are and who may reach them, and those two live with different providers.
Processing happens outside Australia. That is unavoidable for a service delivered on a global network, and it is the kind of overseas disclosure a privacy policy is expected to disclose rather than bury.
Changes to this list
If we add a provider that handles personal information or project content, it will appear here, and the changelog will say so. We would rather you learn about a new provider from us than notice it in a network trace.
Not on this list
We do not use advertising networks, and we do not share project content with anyone for training machine learning models — see AI on CodeRook and our terms, where that is a binding commitment rather than a statement of intent.