vega

Subprocessors

Every company that stores Vega customer data, processes it, or runs a model over it, what each one receives, and where it is.

version 7.1effective 2026-09-21

1The list

Six companies. One of them, Amazon Web Services, has four jobs: it is the infrastructure underneath the database; since 9 September 2026 its Amazon Bedrock service runs EVERY model step Vega has, over customer content; since 10 September 2026 its S3 service stores the files a person chooses to keep, as received; and since 20 September 2026 its SES service sends transactional email — sign-in codes, invitations and connector alerts — the role Resend held until that date. Resend remains listed: the code still carries it as a rollback path, off in production. The sixth, Stripe, is the payment processor; its code has been in the product since 24 August 2026 and this page did not say so until today. This is the complete list as of the effective date, and it is part of the Privacy Policy.

CompanyWhat it does for VegaWhat it receivesWhere
Supabase Inc.Database, authentication and file storage, the primary storeEverything Vega holds: account records, session content, work moments, the graph, embeddings, and encrypted verbatim prompts and repliesAWS ap-northeast-1, Tokyo, Japan
Amazon Web ServicesFour jobs. File storage: since 10 September 2026 its S3 service holds the files you choose to keep, exactly as received, encrypted at rest, readable by you only through fifteen-minute links; nothing is extracted from them and no model reads them. Under the database: the infrastructure Supabase runs on. Model inference: since 5 September 2026 its Amazon Bedrock service runs the personal-life filter and the context memory writer, on Anthropic's Claude models as served by Amazon, under an AWS account held personally by a founder and used as Vega's. The remaining model steps each have their own switch and none has moved; the Anthropic row says which are on its API. Transactional email, since 20 September 2026: its SES service sends sign-in codes, invitations, context-share invites and connector alerts through the one shared transport, lib/mailTransport.ts, configured by `MAIL_SMTP_HOST` — the role Resend held until this date, and Resend's own row below says what remains of that pathFiles you upload (since 10 September 2026): the file as received, and nothing derived from it. Under the database: the same data, at rest, as Supabase's infrastructure provider. On Bedrock: up to 1,800 characters of every capture, after credential shapes are removed and a pattern screen has run on Vega's side, and before anything is stored; and, for the memory writer, the new turns of a context after the same redaction, up to 40 turns of up to 4,000 characters each, together with the entries that context already holds. On SES (since 20 September 2026): the recipient's email address, and the full text of sign-in codes, invitations, context-share invites and connector alertsDatabase infrastructure: ap-northeast-1, Tokyo, Japan. Bedrock: requests go to us-west-2, Oregon, United States, and the cross-region profile Vega uses serves them in Oregon, Virginia or Ohio. The hourly memory job itself also runs in us-west-2. The Bedrock region is set per deployment: a deployment set to eu-west-1 sends requests to Ireland and its profile serves them only in Frankfurt, Stockholm, Milan, Spain, Ireland or Paris — this row is updated when the production region changes. Transactional email (SES, since 20 September 2026): eu-west-1, Dublin, Ireland
Vercel Inc.Application hosting and serverless functionsEvery request in transit, and server logs. Vega does not write content to its logs, but error strings can carry fragmentsFunctions pinned to Tokyo (hnd1); platform and logging in the United States
Anthropic PBCModel author, and nothing else as of 9 September 2026. The Claude models Vega uses are Anthropic's. Every one of them now runs inside Amazon's Bedrock service, under an AWS account held personally by a founder and used as Vega's. Amazon's published position, which Vega cannot verify, is that the model provider has no access to prompts or completions there. Vega's code no longer calls Anthropic's own API on any path. A fallback to that API remains wired at two call sites, capsule writing and anonymisation, and is off by default; it fires only when Amazon cannot answer at all, never for a rate limit or a timeoutNothing, by Vega's code. Every model request now goes to Amazon. That Anthropic receives nothing inside Amazon's service is Amazon's published position, which Vega cannot verify. The one exception is the fallback described above, which is off by default; if it were turned on and Amazon could not answer, the same request would reach Anthropic's APIUnited States
ResendRollback path only, since 20 September 2026 — not the primary transport. Transactional email ran through Resend until this date; the same code (lib/mailTransport.ts) still builds a Resend transport when `RESEND_API_KEY` is set and `MAIL_SMTP_HOST` is not, so the path is disclosed for as long as it exists in the code, not only while a deployment happens to use it. Production sets `MAIL_SMTP_HOST` and does not reach this branchNothing today. If the rollback path is ever used: your email address, and the contents of sign-in codes, invitations, context-share invites and connector alerts — the same categories Amazon Web Services receives on SES aboveUnited States
Stripe, Inc.Payment processing for a personal or Team subscription. Checkout is hosted by Stripe: no card field renders anywhere inside Vega and no card number reaches Vega's serversYour email address, the amount, and the card details you type on Stripe's own page. Vega stores Stripe's identifiers for the customer and the subscription and nothing else, never a card number. No capture, work moment, session content or any other work data is sent to Stripe at any pointUnited States

2What is not on the list

  • No analytics, advertising or session-recording provider. There is no such dependency in the application at all.
  • No error-reporting service. Errors go to the hosting provider's logs and nowhere else.
  • No font or asset CDN. Web fonts are downloaded at build time and served from Vega's own origin, so loading a Vega page sends no request to a font host.
  • No card number ever reaches Vega. Payment runs on Stripe's own hosted page and Vega stores Stripe's identifiers and nothing else. Until 9 September 2026 this line read "No payment processor. Vega takes no payments and holds no card data", which stopped being true on 24 August 2026 when the payment code landed. Stripe is now listed in section 1.
  • No CRM, support desk or marketing tool holding customer content.
  • No embedding provider. Search vectors are computed by a model that runs inside Vega's own servers and sends no customer text anywhere. Its weights (about 23 MB) are downloaded once from a public model host; that download carries no customer data and happens whether or not anyone has ever used Vega. Until 19 August 2026 embeddings were computed by OpenAI; that was a third AI company on this list and it is gone.
  • Vega's separate training database has never been configured in production and, since 16 September 2026, cannot be opened by the code at all: the switch is a constant in the source set to off. It holds nothing and is not a subprocessor. If it is ever enabled it will appear here first, with a new version of the Privacy Policy.

3Changes to this list

We will publish a new subprocessor on this page at least 30 days before it starts processing customer data, and email account holders when we do. If you have a reasonable data-protection objection, tell us within those 30 days at help@tryvega.tech; if we cannot resolve it, you can export what we can produce and close your account.

Every change is recorded in section 5 with a date, so this page's history is readable rather than implied.

4The AI providers, in detail

This is the section a security reviewer asks about, so it carries more than a table row. Two companies are in it: Amazon Web Services, which now runs every model step, and Anthropic, which makes the models Amazon serves. The statements attributed to each provider are that provider's own published claims, with the date Vega read them; they are not Vega's measurements, and Vega has no way to verify them.

Vega has no zero-retention arrangement with Anthropic, and none with Amazon Web Services. Zero retention at Anthropic is not self-serve: it requires a sales conversation and approval, and Vega has not obtained it. Amazon publishes a no-storage default for the models Vega uses on Bedrock; that is Amazon's published position, quoted below with the date it was read, not an agreement Vega has signed. Content is sent under each company's standard terms.

Amazon Web Services, what Vega sends, since when, and which models
Since 9 September 2026, EVERY model step Vega runs. Amazon first ran two of them on 5 September 2026 (15:51 UTC, the time of the first rows in Vega's model ledger with provider bedrock); the rest followed on 8 and 9 September. The category that is new to Amazon on 9 September is decrypted verbatim transcript: the daily job that derives a session's context sends one, up to 28,000 characters, and until this date that job called Anthropic instead. The full set follows. The personal-life filter: up to 1,800 characters of every capture, after credential shapes are removed and a pattern screen has run on Vega's side, before anything is stored; that model call is the filter, so what it reads is not yet filtered. The context memory writer: the new turns of a context after the same redaction, up to 40 turns of up to 4,000 characters each, with the entries that context already holds, so it can update rather than duplicate them. Model: Anthropic's claude-sonnet-4-6 as served by Amazon Bedrock since 21 September 2026 (claude-haiku-4-5 from 5 September to 21 September 2026), under an AWS account held personally by a founder and used as Vega's. On the web tier the call is authenticated by a one-hour credential minted from the hosting provider's signed identity token against a role whose permissions are bedrock:InvokeModel and bedrock:InvokeModelWithResponseStream on named model and inference-profile ARNs; the hourly memory job runs as an Amazon function in us-west-2 under its own execution role. No static key is stored in Vercel; one legacy IAM access key remains in the account, unused by the application, pending deletion. Every other step is listed under Anthropic below; each has its own switch and none has moved.
Anthropic, what Vega sends at capture today, and which models
Nothing, as of 9 September 2026. Until 8 September the classifier, thread clustering, the capsule writer, the anonymiser and interest tagging called this API, and until 9 September so did the daily context-derivation job; all of them now run on Amazon Bedrock. Models used, wherever they run: since 21 September 2026, claude-sonnet-4-6 on every path (claude-haiku-4-5 on eight of them before that date). A move to claude-sonnet-5 was configured the same night and did not take effect: the model is not yet invokable on the account Vega uses, so every path fell back to claude-sonnet-4-6. Read from /api/health on 21 September 2026, which reports the model each of the fifteen paths actually calls. Six of the fourteen model paths have no live caller in the product today: rollup summarising, semantic leak detection, re-tagging, a leak-fix draft, the ask path (its screen was deleted) and the coaching path (its route has no screen calling it); they would call Anthropic's API if reached and are listed so that this list is complete rather than convenient. The personal-life filter and the context memory writer are no longer on this route; see the Amazon entry.
Anthropic, what Vega sends at query time
An answer about your own work is phrased by claude-sonnet-4-6 on Amazon Bedrock since 9 September 2026; no screen in the product calls this path today (the ask screen was deleted), so what follows describes the code rather than a running feature. The request carries your retrieved work moments (title, context, work type, signals), the titles of your open threads, and, where you have opted into keeping verbatim text, decrypted excerpts of your own prompts and the model's replies, capped at 600 characters per transcript turn and shorter for a cited moment. The request is scoped to your own seat, so no other person's content can enter it, and the answer returns only to you. The coaching path works the same way and likewise has no screen calling it today.
The direct fallback, what it would do, and that it is off
A direct fallback exists in the code at two call sites, capsule writing and anonymisation. If either step were on Amazon Bedrock and its switch turned on, the same request would be re-issued to Anthropic's API when Amazon cannot answer at all: no credential, a failed credential exchange, a role that does not admit the model, or a model the region does not serve. It never fires for a rate limit or a timeout. The switch is off by default and turns on only when it holds exactly one value. Both of those steps are now on Bedrock, so the fallback can fire for them; it is off by default and Vega has not turned it on. It is not wired on the personal-life filter, the context memory writer or the classifier, so Vega's code sends the Bedrock steps' requests to Amazon only. Turning it on for a step that carries it puts Anthropic on that step's route and is a change to this list.
Amazon Web Services, their published position
Amazon's Bedrock documentation states that the service "uses a zero data retention (ZDR) data security model. This means that by default, Amazon Bedrock does not store model inputs or outputs", that it "uses a zero operator access (ZOA) data security model. This means no operators of the service can access model input or output", and that because model providers have no access to the accounts the models are deployed in, "they don't have access to Amazon Bedrock logs or to customer prompts and completions" (docs.aws.amazon.com/bedrock/latest/userguide/data-protection.html and abuse-detection.html, read 2026-09-07). The same pages name specific models whose traffic is retained for up to 30 days for abuse detection; on the date read, Vega's two models, Claude Haiku 4.5 and Claude Sonnet 4.6, were not among them. RE-READ 21 September 2026, because the models changed and a list read a fortnight ago is not evidence about today. The page names the models whose traffic is retained, and they are Anthropic's Claude Fable 5 and Claude Fable 5.1, whose traffic is retained in full for up to 30 days and whose classifier-flagged traffic may be read by a person at Amazon, and a set of OpenAI GPT models whose classifier-flagged traffic is retained. claude-sonnet-4-6, the model every Vega path now runs, is not named; neither is claude-sonnet-5, so the answer does not change if the account's access to it opens. Amazon's data-retention page puts it in one sentence: "There is no data retention change to Claude models released before Claude Fable 5." Vega uses neither Fable model and has no configuration that would permit one. Amazon's data-retention page, re-read 21 September 2026, now describes retention as an account-level and project-level MODE rather than a single default, and the change matters to what Vega can promise. Under "default" it still states that "AWS may retain the data for safety and abuse-prevention purposes. The model provider does not receive it" — but a mode of "none" is now documented as "Zero data retention. No request or response data is written to durable storage by AWS or shared with the model provider", and the page says plainly that if you require guaranteed zero retention you set that mode. Vega has not set it. Until it does, this entry describes Amazon's default and not a guarantee Vega holds, which is the same caveat as before with one difference: the guarantee is now available and unclaimed rather than unavailable. The page also records that the legacy "provider_data_share" mode no longer shares anything — "Amazon Bedrock does not share your content with model providers today", and that retained data from cross-region inference is stored in the region where the request is processed (docs.aws.amazon.com/bedrock/latest/userguide/data-retention.html, read 2026-09-07). Read back on 15 September 2026 on the AWS account Vega uses, one held personally by a founder: no model-invocation logging is configured in us-west-2, eu-west-1 or ap-northeast-1, and no model customisation job exists in any of them, so Amazon's no-storage default is the configured state and not only the published one. That reading is a point in time and is repeated before each version of this page. Amazon's third-party model terms state that "Anthropic Services on Amazon Bedrock are sold by Anthropic" and that using them means agreeing to Anthropic's commercial terms (aws.amazon.com/legal/bedrock/third-party-models, read 2026-09-07), so Anthropic's no-training term below applies on this route as well.
Anthropic, their published position
Anthropic's commercial terms state that "Anthropic may not train models on Customer Content from Services" (anthropic.com/legal/commercial-terms, effective 2025-06-17, read 2026-09-07). Anthropic's privacy centre states that it deletes inputs and outputs "within 30 days of receipt or generation" (privacy.claude.com, read 2026-09-07), and its platform documentation states that retained data "is never used for model training without your express permission" and that zero data retention is requested through their sales team and enabled per organisation (platform.claude.com, read 2026-08-12). Anthropic's own DPA states that in that relationship "Customer is the controller and Anthropic is Customer's processor" (read 2026-08-12); in Vega's case, Vega is that customer, not you.
OpenAI, removed, and what that means for text already sent
Until 19 August 2026 one text per session (the sanitised capsule) went to OpenAI's embeddings endpoint, and until 12 August 2026 the verbatim prompt and reply, up to 8,000 characters, went there too. Both paths are deleted from the code and Vega holds no OpenAI credential. Removing a subprocessor does not un-send what was already sent: text that reached OpenAI before those dates is subject to whatever its standard terms allowed, and Vega cannot recall it. Of the vectors OpenAI computed, the per-session ones (a session's capsule vector and its private vector) have been nulled; the tag vectors, 1,536-dimension vectors on canonical tags, are still stored in a rollback column and have not been deleted.

What Vega is doing about it. Three things. The OpenAI leg is deleted and embeddings run on a model inside Vega's own servers, which took one company off this list on 19 August 2026. Two model steps, the personal-life filter and the context memory writer, run on Amazon Bedrock since 5 September 2026 under an AWS account held personally by a founder and used as Vega's, where Amazon's published position, which Vega cannot verify, is no storage by default and no provider access. The remaining steps each have their own switch and none has moved; whether any does, one at a time or at once, is a decision the founders have not taken. A moved step changes who holds content and under whose terms, and it is not a zero-retention agreement: Vega has signed none with either company, and obtaining one is a contract rather than a code change. This page will say so until one is signed.

5Change log

DateChange
2026-09-21Version 7.1. No company added or removed. The eight paths that ran claude-haiku-4-5 (topic gate, memory writer, capsule, anonymiser, interests, semantic leaks, retag, leak fix) now run claude-sonnet-4-6, so every one of the fifteen paths runs that model. A second step to claude-sonnet-5 for the heavier paths was configured the same night and did NOT take effect, because claude-sonnet-5 is not yet invokable on the account Vega uses; this page states what /api/health reports rather than what was configured. Region, provider and retention are unchanged: still Amazon Bedrock, us-west-2 inference profiles, zero data retention. A MINOR bump because who receives content, what is collected and how long it is kept are all unchanged — only the model version each already-disclosed path calls.
2026-09-20Version 7.0. No company added or removed. Transactional email moves from Resend to Amazon SES (Ireland) with the hosting move to AWS. Amazon Web Services gains a fourth job — sign-in codes, invitations, context-share invites and connector alerts now send through its SES service via the shared transport, lib/mailTransport.ts, configured by `MAIL_SMTP_HOST` — and the Amazon row and its Where cell are restated to say so. Resend is restated as a rollback path: the code still builds a Resend transport when `RESEND_API_KEY` is set and `MAIL_SMTP_HOST` is not, so it stays disclosed for as long as that path exists, the same stance section 4 already takes with the Anthropic direct-API fallback. A MAJOR bump because who receives transactional email content changed.
2026-09-19Version 6.0. No company added or removed. Section 1 now says Stripe processes Team subscriptions as well as personal ones, so a listed company receives the payment details of a second kind of buyer. A MAJOR bump for that reason; it ships in the same release as terms 3.0 and privacy 6.0 so you are asked once. Section 3's 30-day notice and section 4's reading of the Stripe dates are unchanged by this version.
2026-09-16Version 5.1 (folded into 6.0 before publication). No company added or removed. Two corrections of state. Vega's training database, already listed as not configured, is now also disabled in the source code (a constant set to off, lib/trainingStore.ts), because the founders decided on 12 September 2026 that Vega does not train on content; the Privacy Policy and the Terms took MAJOR bumps the same day to say so. And the Amazon entry's retention line, which said Vega had not read back its own account's configuration, now records the reading of 15 September 2026: no model-invocation logging and no customisation job in any region Vega uses.
2026-08-12First published. Supabase, AWS, Vercel, Anthropic, OpenAI and Resend listed. No prior list existed, so no additions or removals are recorded; this is the starting state, not a claim that nothing changed before it.
2026-08-19OpenAI OpCo, LLC removed. It received one text per session (the sanitised capsule) to compute a search vector. That code path is deleted and the work now runs on a model inside Vega's own servers, so no text leaves Vega for an embedding at all. Nothing was added in its place. Text sent before this date cannot be recalled; the per-session vectors it produced have been nulled, and its tag vectors are still stored in a rollback column (section 4). A subprocessor REMOVAL needs no advance notice under section 3, which governs additions, but it is recorded here because a customer who read this page last week was told something that is no longer true.
2026-08-19No company added or removed. The Anthropic entry was corrected: it disclosed only what Vega sends at capture, and omitted that Anthropic is also the engine behind every answer Vega gives you about your own work, receiving your retrieved moments and decrypted excerpts of your own turns at the moment you ask. That was true before this date and was not disclosed; it is disclosed now. Section 4 also states plainly what the absence of a zero-retention agreement means for query-time content.
2026-09-05Amazon Web Services' role widened. Already listed as the infrastructure under the database, it began running two of Vega's model steps on its Amazon Bedrock service in us-west-2, United States: the personal-life filter and the context memory writer, both on Anthropic's Claude Haiku 4.5 as served by Amazon, under an AWS account held personally by a founder and used as Vega's; no static key is stored in Vercel, and one legacy IAM access key remains in the account pending deletion. The first requests on Bedrock are in Vega's model ledger at 15:51 UTC. No company was added or removed. This page was not updated on that date; it was updated on 7 September 2026, and no notice was given. Whether one was owed for a listed company changing role is counsel question 44, recorded in section 3 rather than answered here. Content those two steps sent to Anthropic before this date is subject to Anthropic's retention, not Amazon's.
2026-09-10Version 5.0. Amazon Web Services gains a third job: file storage. From this date a file a person attaches to an AI conversation can be kept, on their request, in Amazon's S3 service in us-west-2 — the file only, as received, with nothing read out of it; encrypted at rest; readable by the owner only through fifteen-minute links; deleted with the file or the account. This is a new CATEGORY of content going to an already-listed company, the same shape as 9 September's move of decrypted transcripts: no company added, no 30-day clock on its face, and the notice question is the one section 3 already records. Same day, MINOR corrections to the privacy and security pages brought five leftover sentences into line with 4.0 ('two steps on Bedrock' became every step).
2026-09-09Version 4.0. Every model step now runs on Amazon Bedrock, and Anthropic's API receives nothing from Vega's code. The last six paths moved on this date: the daily context-derivation job, the ask and coaching paths, semantic leak detection, re-tagging and the leak-fix draft. Only the first of those has a live caller in the product. The materially new fact is the category: derivation sends a DECRYPTED VERBATIM TRANSCRIPT of a session, up to 28,000 characters, and Amazon had never received decrypted transcript before this date — Anthropic had, and no longer does. The reason for the move was operational rather than commercial: the Anthropic account had no credit from 4 September, so those steps were failing rather than running. No company was added or removed; both were already listed. Section 3 records the notice question rather than answering it.
2026-09-09Stripe, Inc. added. Payment code landed in Vega on 24 August 2026 and this page was not changed then; until today section 2 said in terms that there was no payment processor, which was false from that date. Nothing about it was hidden deliberately: the check that is supposed to catch an undisclosed processor reads host names out of the source, and Stripe's library builds its own, so the check reported this page correct on every run. That check now derives its candidates from the dependency list instead, and a new one cannot pass unnoticed the same way. Whether any customer data has actually reached Stripe depends on whether a payment has been taken; section 3 records the notice question rather than answering it. No other company was added or removed.
2026-09-07Version 3.0. The Anthropic entry was restated as two roles: the author of the models, which on the Bedrock steps run inside Amazon's service where Amazon says the provider has no access, and the direct API that the remaining steps still call. Section 4 now says which step is on which route, describes the direct fallback that two call sites carry, states that it is off by default and that neither of those call sites is on Bedrock, and adds Amazon's published position on Bedrock data handling with the date it was read. Anthropic's terms and privacy centre were re-read on this date. The list did not gain or lose a company on this date.