Skip to content
Ente
PricingSign in

Provider transparency

Subprocessors.

Infrastructure and AI providers engaged by Ente, separated from systems a customer chooses to connect.

How to read this list

A subprocessor handles customer personal data on Ente's behalf to provide the service. A connected service is selected by the customer or user and already has its own relationship with them. Optional means the data flow starts only after that feature is enabled.

Subprocessor register

Convex, Inc.

Purpose
Application backend, authentication, database, file storage, and server-side processing
Data
Account data, workspace content, files, integration credentials, recordings, transcripts, and operational metadata
Status
Always on
Location
Production region not yet confirmed. Convex offers EU West (Ireland) and US East (N. Virginia).
Safeguards
Ente's executed vendor terms, DPA, and any transfer mechanism must be confirmed before publication.
Evidence state
Found throughout the application backend; deployment-region evidence is pending from Agent 1.
Convex regionsConvex DPAConvex subprocessors

Netlify, Inc.

Purpose
Hosting and delivery of the public website and web application frontend
Data
IP address, request metadata, browser/device information, and requested content
Status
Always on for hosted web surfaces
Location
Global delivery network; Ente's site configuration and relevant processing locations are not yet confirmed.
Safeguards
Netlify DPA and applicable SCCs/DPF reliance require account-level confirmation.
Evidence state
The repositories contain Netlify deployment configuration; production account evidence is pending.
Netlify privacy statementNetlify DPA

OpenAI, L.L.C.

Purpose
Audio transcription, transcript compaction, realtime voice, titles, and optional structured analysis
Data
Audio, transcript text, prompts, selected workspace context, and generated output
Status
Feature-dependent
Location
The application currently calls the global API endpoint. Account data-residency and retention controls are not yet confirmed.
Safeguards
OpenAI DPA and transfer safeguards require account-level confirmation.
Evidence state
Direct API calls are verified in code; production project settings are pending from Agent 1.
OpenAI API data controlsOpenAI enterprise privacy

Anthropic, PBC

Purpose
Summaries, agents, recording structuring/reflection, and optional model-provided web search
Data
Prompts, transcript or activity content, selected workspace context, tool results, and generated output
Status
Feature-dependent
Location
Code requests global inference. Anthropic states commercial API storage is US-only by default and processing may occur in the US, Europe, Asia, and Australia.
Safeguards
Anthropic DPA incorporates SCCs; Ente's accepted terms and account settings still require confirmation.
Evidence state
Direct API use and global inference configuration are verified in code; contractual settings are pending.
Anthropic data locationsAnthropic retentionAnthropic DPA information

Amazon Web Services EMEA SARL (Amazon Bedrock)

Purpose
AI search and long-recording structuring using a Moonshot AI model hosted through Amazon Bedrock
Data
Questions, selected workspace evidence, transcript text, prompts, and generated output
Status
Feature-dependent
Location
The default endpoint in code is EU North (Stockholm). Production endpoint and cross-region controls require confirmation.
Safeguards
AWS DPA applies through AWS service terms; the contracting account and model-specific terms must be verified.
Evidence state
The region-specific Bedrock Mantle endpoint is verified in code; production overrides are pending.
Bedrock Mantle endpointsBedrock privacy FAQAWS subprocessors

Plus Five Five, Inc. (Resend)

Purpose
Transactional and notification email delivery
Data
Recipient email address, sender, subject, message content, and delivery metadata
Status
Service-wide, event-triggered
Location
Resend states account data, email metadata, logs, and API records are stored in the United States; sending region is configurable.
Safeguards
Resend DPA includes SCCs and states EU-US DPF participation; Ente's account acceptance requires confirmation.
Evidence state
Direct Resend API delivery is verified in code; Ente's sending-region setting is pending.
Resend DPAResend regionsResend subprocessors

AgentMail, Inc.

Purpose
Public support, privacy, security, and commercial correspondence
Data
Sender and recipient addresses, subject lines, message and attachment content, threading information, and delivery metadata
Status
Always on for messages sent to ente@agentmail.to
Location
United States. AgentMail states that data from users outside the United States is transferred to and processed in the United States.
Safeguards
AgentMail refers to a DPA in its terms, but Ente's accepted DPA and Chapter V transfer mechanism have not been verified.
Evidence state
The Ente contact inbox is active. AgentMail states that messages, drafts, attachments, and inbox records remain until deleted; some raw objects and receipt logs have no configured automatic expiry.
AgentMail privacy policyAgentMail termsAgentMail subprocessors

PostHog, Inc.

Purpose
Coarse product-surface analytics
Data
A product_surface_viewed event, an allowlisted coarse surface name, an ephemeral in-memory identifier, SDK event UUID, and unavoidable network metadata such as IP address
Status
Deployed integration; production project and provider-side settings remain unverified
Location
PostHog offers EU Cloud in Frankfurt and US Cloud in Virginia; Ente's configured host is pending.
Safeguards
DPA, host, provider-side IP handling, retention, and consent/legal-basis decision require confirmation.
Evidence state
Agent 1 verified and deployed a minimal event allowlist that excludes stable Ente identity, URLs, user-authored text, autocapture, persistence, and session replay; account settings remain pending.
PostHog trust centerPostHog privacy documentation

Google Cloud EMEA Limited (Pub/Sub)

Purpose
Delivery of Gmail mailbox change notifications
Data
Connected mailbox address, Gmail history identifier, and delivery metadata
Status
Feature-dependent (Gmail connection)
Location
Message location is controlled by the Pub/Sub topic policy; Ente's production policy is pending.
Safeguards
Google Cloud DPA applies to contracted Cloud services; Ente's account and location policy require confirmation.
Evidence state
The Gmail push endpoint is verified in code; cloud project settings are pending.
Pub/Sub message storage policyGoogle Cloud DPA

Customer-authorized connected services

These services and import utilities are not presented as Ente subprocessors merely because Ente can connect to or import from them. Their own terms and privacy notices apply to the customer's account.

ServiceRoleData flowActivation
Google Workspace (Gmail and Calendar)Customer-authorized connected service; Google also acts under the customer's Google relationship.OAuth identity, mailbox and calendar data, send-as aliases, tokens, and customer-requested changes.Optional. Ente requests Gmail modify and Calendar read/write scopes only when the user connects the feature. Google API Limited Use rules apply.
Microsoft / OutlookCustomer-authorized connected service; Microsoft acts under the customer's Microsoft relationship.OAuth identity, an application-encrypted refresh token when the deployment key is configured, mailbox data, and messages sent at the user's request.Optional. Ente requests offline access plus Outlook IMAP and SMTP permissions when connected.
User-selected IMAP/SMTP and CalDAV providersCustomer-authorized connected systems selected and controlled by the customer.Server address, username, encrypted credential/token, mail or calendar content, and requested changes.Optional. The actual provider and country depend on the server entered by the user.
PlaudCustomer-authorized connected recording source operating under the customer's Plaud relationship.Encrypted Plaud token, device and recording metadata, and imported audio.Optional. Code supports EU, global, and Asia-Pacific Plaud endpoints; the user selects the server.
LaMetricCustomer-authorized display integration.A configured device requests limited daily workspace statistics from Ente.Optional and inactive until configured.
Browser push servicesDevice/browser delivery service selected by the user and browser vendor.Push endpoint and encrypted notification payload routed through the browser's push service.Optional and inactive until the user enables notifications.
Notion and ClickUp import utilitiesCustomer-authorized one-time import sources, not persistent Ente connections.Environment-supplied import credential and the content selected for import; imported records become ordinary Ente content.Optional operator utility. Imported content remains until explicitly deleted even though no connection is retained.

Subprocessor changes

The final DPA will state the notice channel, advance-notice period, objection process, and effective date. Those are contractual promises and remain blocked on founder/counsel approval.

Ente

Ente, from entity. One identity across every system.

PrivacyGoogle dataSubprocessorsTermsImpressumContact
© 2026Deutsch