Trust

Sub-processors

Last updated: September 29, 2026

Back

These services process personal data on Loomrail's behalf to run the product. Each receives only what its job needs and may not use it for its own purposes. Model providers are used through their business APIs, which by their terms do not use API data to train their models. Company customers are told about a new sub-processor at least 30 days before it starts (see the DPA). Questions: grievance@loomrail.com.

Infrastructure

ServiceWhat it doesWhere
Google CloudApplication servers, file storage, task queues, secret storage, logsSingapore; logs also in Mumbai, India
NeonDatabase (accounts, agents, chats, settings)Singapore
UpstashShort-lived cache and rate-limit countersTokyo, Japan
VercelHosting the web app; routing AI requests to model providers (AI Gateway)Global edge network
Google Workspace (Gmail)Sending account and notification emailsGlobal
Dodo PaymentsPayments and tax, as merchant of record (card and bank details stay with them)United States and India

AI and media

ServiceWhat it doesWhere
OpenAIAnswering messages, speech-to-text and text-to-speechUnited States
Anthropic, Google (Gemini) and other model providers via Vercel AI GatewayAnswering messages, and making images and video, when you or your company choose that model or Auto picks itMostly United States
fal.aiMusic generationUnited States
DuckDuckGo, Wikipedia, Google News, OpenverseWeb search when you ask an agent to search (receive the search words only)Global
PexelsStock photo search (receives the search words only)Global

Company admins can limit which models their members use. Free or unnamed ("stealth") preview models are not offered. Apps and AI keys you connect yourself (Google, Microsoft, Slack, Notion, your own fal.ai or OpenAI key, and others) are not our sub-processors: data goes to them only when you ask, under your own account with that service.