Skip to main content

Subprocessors

Last updated: May 8, 2026

Asios Standup uses the following third-party service providers (subprocessors) to operate the Service. Each is bound by their published Terms of Service and our agreements with them. We re-evaluate this list quarterly and will update it before adding any new subprocessor that processes user data.

ProviderRegionPurposeData ProcessedSafeguards
RenderUSABackend hosting (Node.js API) and managed Postgres databaseAll persistent data: accounts, groups, members, check-ins, summaries, AI usage logSOC 2; daily encrypted backups, 30-day retention
VercelUSAFrontend hosting (Next.js) and edge functionsStatic assets, server-rendered pages; no PII at restSOC 2; HTTPS terminated at edge
StripeUSAPayment processing for per-group subscriptionsBilling email, payment method, Stripe Customer ID, Subscription ID, group IDPCI DSS Level 1; we never see raw card numbers
ResendUSATransactional email: group invites, weekly recap delivery, quiet-member nudgesRecipient email address, sender display name, message bodyDMARC/DKIM/SPF aligned; ToS covers data processing
GroqUSAAI inference for Free-tier groups (Llama 3.3 70B)PII-redacted check-in text, persona system prompt; no audioProduction API tier — no training on customer data; ≤30-day safety retention
AnthropicUSAAI inference for Pro and Team tier groups (Claude)PII-redacted check-in text, persona system prompt; no audioCommercial Terms — no training on customer data; ≤30-day safety retention
OpenAIUSAAI inference fallback (chat completions) and Whisper voice transcription (Pro+)PII-redacted check-in text for chat; raw audio (≤60s) for Whisper transcription onlyAPI tier — no training on customer data; ≤30-day safety retention; transcribed audio is discarded immediately after Whisper returns
Google Analytics 4USAAggregate marketing-site traffic and signup-funnel analyticsAnonymised page views, referrer, country, device type. Configured with Consent Mode v2 — no PII, no group IDs, no check-in text is ever sentIP anonymisation enabled; data retention set to 14 months

PII Redaction Before AI Calls

Before any check-in text is sent to Groq, Anthropic, or OpenAI for chat completion, we apply a defence-in-depth scrubber that replaces:

  • Email addresses → [email]
  • Phone numbers (loose international match, ≥10 digits) → [phone]
  • Long digit runs (12–19 digits, e.g. card / account numbers) → [number]

Voice audio sent to Whisper cannot be redacted before transcription; the transcribed text returned by Whisper is then handled like any other check-in.

Notification of Changes

We publish updates to this list here. Material additions (a new provider that processes check-in content) will also be communicated via in-app notice or email at least 14 days before they take effect, where feasible.

Contact

Questions or concerns about a specific subprocessor? Email asios_app@proton.me.

Asios LLC · Austin, TX · USA