Trust
Subprocessors
These are the third parties that can process customer content today. The list reflects the deployment as it is actually configured, not a template.
| Party | Purpose | Content received |
|---|---|---|
| Supabase | Application database, authentication and private file storage | Accounts, workspace records, uploaded documents, extracted text, vectors, questionnaires, answers, audit history |
| Cloudflare (via the application host) | Serving the application and running server-side request handling | Requests in transit, including uploaded file bytes while they are being processed |
| Lovable AI Gateway | Routing drafting and search requests to the underlying model provider | The question text and the retrieved passages sent for drafting or indexing |
| OpenAI (reached through the gateway above) | Drafting model and text-embedding model | The question text and the retrieved passages included in a single request |
Currently configured models
Loading current configuration…
AI processing can be switched off per workspace in Settings. With it off, no customer text leaves the application for drafting or indexing, and drafting is unavailable.