LEGAL

Sub-processors

LAST UPDATED · September 2026

This is the register referenced by our Data Processing Agreement. It lists every third party that may process customer data on Knull's behalf, together with what it is used for. It is maintained in the product rather than supplied on request.

Core sub-processors

These are engaged for every Knull account. The service cannot be delivered without them.

Sub-processorPurposeData involvedProcessing region
Supabase (managed Postgres, Auth, Storage)Primary database, authentication, file storageAccount details, workspace content, generated artefacts, audit and receipt recordsEU / US (project region)
Cloudflare WorkersApplication hosting and server executionRequest metadata in transit; no durable storageGlobal edge
AnthropicPrimary model provider for generation and reasoningPrompt content you or your agents submit; no training on API dataUS
OpenAIReasoning and computer-use tierPrompt content for those specific tasksUS
StripePayments, subscriptions, payoutsBilling name, email, card token, transaction recordsUS / EU
ResendTransactional email (invoices, briefs, approvals, receipts)Recipient address and message contentUS / EU

Capability sub-processors

These are engaged only for the capabilities you use or connect. If you never run a video generation, no video provider processes your data.

Sub-processorPurposeData involvedProcessing region
SentryError monitoringError messages, stack traces, route and organisation identifiers. Secrets and personal data are stripped before sendEU / US
PostHogProduct analyticsPseudonymous usage events; no third-party advertising cookiesEU
VercelPublishing customer-generated websites and custom domainsSite content you publish, DNS recordsGlobal edge
BrowserlessHeadless browser sessions for computer-use tasksPages your agent visits during a scoped session; screenshots are held in memory onlyEU / US
Firecrawl / Tavily / SerpApiWeb crawl, research and search-result dataSearch and URL queries you requestUS
fal.ai / Nano Banana / HiggsfieldImage and video generationGeneration prompts and reference imagesUS
ElevenLabsAgora voice synthesis and realtime voice sessionsVoice session audio and transcriptsUS / EU
TwilioSMS delivery when enabledRecipient number and message contentUS
Nango / ComposioOAuth brokerage for connectors you choose to connectOAuth tokens, encrypted at rest before storageEU / US

Connectors you add

When you connect an external account — an ad platform, an inbox, a store, an analytics property — that provider becomes a processor of the data you direct Knull to read or write there, under your own agreement with them. Connected accounts are listed in your workspace settings and can be disconnected at any time, which revokes Knull's stored token.

Cookie posture

Knull sets first-party cookies for authentication and session continuity only. We set no third-party advertising or cross-site tracking cookies, and we do not sell or share personal information for cross-context behavioural advertising. Product analytics are pseudonymous and can be disabled per organisation in privacy settings.

Your data rights

Export and deletion are self-service: workspace data export is available from the Ops screen, and account deletion is requested from privacy settings, which records the request and removes personal data on the documented schedule. Contact-level GDPR actions (export, erase) are available on each contact record. For anything the tooling does not cover, email privacy@knullos.lovable.app.

Changes to this register

We update this page when a sub-processor is added or removed. Customers on a signed DPA are notified of material additions before the new processor begins handling their data, and may object under the terms of the DPA.