Subprocessors
Every third party that processes data on Conifer's behalf, what they receive, and why.
This page lists every third party that processes personal data on Conifer's behalf. It is published separately from the privacy policy so it can be kept current without amending the policy itself.
We will update this page before adding a new subprocessor. If you rely on this list, check it when your agreement renews.
Infrastructure and service providers
| Subprocessor | What it does for us | What it receives | Location |
|---|---|---|---|
| Cloudflare, Inc. | Hosts conifer.build, serves every page and API function, provides the coarse country signal | Request metadata: IP address (in transit, not stored by us), user agent, country | United States / global edge |
| Supabase, Inc. | Database and account authentication | Account email, magic-link tokens, form submissions, analytics events, usage telemetry | United States |
| Railway Corp. | Runs the inference gateway and billing service | Account id, request metadata, token counts, encrypted provider keys | United States |
| Stripe, Inc. | Payment processing | Name, email, payment card details — collected by Stripe directly; card data never reaches Conifer | United States |
| Resend (Plus Five Five, Inc.) | Transactional email and newsletter delivery | Email address, name, message content you send us, email open and click events | United States |
| GitHub, Inc. (Microsoft) | Hosts release binaries and the desktop update feed | IP address and user agent when your app checks for updates or downloads a release | United States |
Feature-specific processors
These receive data only when you use the specific feature.
| Subprocessor | Triggered by | What it receives |
|---|---|---|
| Brave Software, Inc. | Using the web-search tool in a conversation | Your search query |
| Model providers — Anthropic, OpenAI, and the other providers in the served catalogue | Routing a turn to a cloud model | The prompt and conversation context required to answer that turn |
About model providers
When a turn runs on a cloud model, the prompt goes to the exact serving endpoint selected for that turn — and to no other. Which provider that is depends on the model you or the router selected; the served catalogue is shown at conifer.build/models.
That provider's own terms and privacy policy govern what it does with the request, including when you bring your own API key. Conifer does not control a provider's retention. If this matters to you, run local models — the whole product is built so you can.
Not on this list
We do not use advertising networks, data brokers, session-replay tools, or third-party analytics services. Analytics is first-party and cookieless.