Subprocessors
Last updated: May 8, 2026
Asios Standup uses the following third-party service providers (subprocessors) to operate the Service. Each is bound by their published Terms of Service and our agreements with them. We re-evaluate this list quarterly and will update it before adding any new subprocessor that processes user data.
| Provider | Region | Purpose | Data Processed | Safeguards |
|---|---|---|---|---|
| Render | USA | Backend hosting (Node.js API) and managed Postgres database | All persistent data: accounts, groups, members, check-ins, summaries, AI usage log | SOC 2; daily encrypted backups, 30-day retention |
| Vercel | USA | Frontend hosting (Next.js) and edge functions | Static assets, server-rendered pages; no PII at rest | SOC 2; HTTPS terminated at edge |
| Stripe | USA | Payment processing for per-group subscriptions | Billing email, payment method, Stripe Customer ID, Subscription ID, group ID | PCI DSS Level 1; we never see raw card numbers |
| Resend | USA | Transactional email: group invites, weekly recap delivery, quiet-member nudges | Recipient email address, sender display name, message body | DMARC/DKIM/SPF aligned; ToS covers data processing |
| Groq | USA | AI inference for Free-tier groups (Llama 3.3 70B) | PII-redacted check-in text, persona system prompt; no audio | Production API tier — no training on customer data; ≤30-day safety retention |
| Anthropic | USA | AI inference for Pro and Team tier groups (Claude) | PII-redacted check-in text, persona system prompt; no audio | Commercial Terms — no training on customer data; ≤30-day safety retention |
| OpenAI | USA | AI inference fallback (chat completions) and Whisper voice transcription (Pro+) | PII-redacted check-in text for chat; raw audio (≤60s) for Whisper transcription only | API tier — no training on customer data; ≤30-day safety retention; transcribed audio is discarded immediately after Whisper returns |
| Google Analytics 4 | USA | Aggregate marketing-site traffic and signup-funnel analytics | Anonymised page views, referrer, country, device type. Configured with Consent Mode v2 — no PII, no group IDs, no check-in text is ever sent | IP anonymisation enabled; data retention set to 14 months |
PII Redaction Before AI Calls
Before any check-in text is sent to Groq, Anthropic, or OpenAI for chat completion, we apply a defence-in-depth scrubber that replaces:
- Email addresses →
[email] - Phone numbers (loose international match, ≥10 digits) →
[phone] - Long digit runs (12–19 digits, e.g. card / account numbers) →
[number]
Voice audio sent to Whisper cannot be redacted before transcription; the transcribed text returned by Whisper is then handled like any other check-in.
Notification of Changes
We publish updates to this list here. Material additions (a new provider that processes check-in content) will also be communicated via in-app notice or email at least 14 days before they take effect, where feasible.
Contact
Questions or concerns about a specific subprocessor? Email asios_app@proton.me.
Asios LLC · Austin, TX · USA