This page is under legal review. It describes how Omniscio works today and we intend to stand behind it, but the wording is not final and may change. If anything here matters to a decision you are making, please email legal@omniscio.com and we will confirm it in writing.
Omniscio — Subprocessors
Effective date: 2026-08-20 Last updated: 2026-08-25
Key terms at a glance
Plain-English summary — not a substitute for the full Subprocessors list. This box is a quick, friendly overview of the points people ask about most. It is not legal language and does not replace the sections below, which are what actually applies. If anything here seems to differ from those sections, the full sections control.
- What a "subprocessor" is. A third party that handles some of your data on our behalf, under our own accounts, to help run the Services. This page names each one and the data it touches. (See "What this page is.")
- The core ones run the product. Anthropic (the AI), Google/Firebase (accounts, database, our AI gateway, push), Stripe (payments), plus error-reporting, email, and low-cost "helper" AI providers. (See "Core subprocessors.")
- Optional ones only see data if you turn a feature on. Things like GIF search, web-scraping tools, bundled AI keys, and default read-aloud receive data only when you use that specific feature — several are off by default. (See "Optional subprocessors.")
- Your own connections aren't our subprocessors. When you connect a service on your own key or account (an AI provider, Slack, Notion, a bank sync, and so on), data flows straight to that provider under its terms — we're not in the middle. (See "Services you connect on your own account.")
- We store your data in the US — but a few AI vendors are not US-based. The Services are offered only in the United States, and everything we store lives here. A small number of the vendors below process content outside the US. We name each one below, under "Where processing happens," so you can see exactly which.
- We tell you when the list changes. When we add or replace a subprocessor, we update this page and its effective date. (See "How we notify you of changes.")
- DPA on request. Business and team customers can request a data-processing agreement at legal@omniscio.com.
What this page is
A subprocessor is a third party that processes personal data on Omniscio's behalf, under Omniscio LLC's own accounts, to help us provide the Services. This page lists those subprocessors, what each does, and the data involved.
It does not list the many services you can connect on your own account or API key (for example, an AI provider you bring your own key for, or a Slack or Notion workspace you link). For those, you deal with that provider directly under its own terms and we are not acting as your processor — see "Services you connect on your own account" below.
The Services are currently offered only in the United States, and the data we store is stored in the United States (see Privacy Policy §4). Some of the vendors below are not US-based — see "Where processing happens" for the specific list. We are putting data-processing agreements (DPAs) in place with the subprocessors below; a DPA is available for business/team customers on request at legal@omniscio.com.
Where processing happens
Our own storage and backend are in the United States — accounts, database, files, team and Shares content, and error reports all live in a US region.
Being offered only in the US bounds where our customers are. It does not bound where a vendor is. These vendors process content outside the United States:
| Vendor | Where | What it processes | When |
|---|---|---|---|
| CrofAI | China | The prompt/message content of a "DeepSeek" helper request, when our gateway's primary upstream errors and the request fails over (see the Core table) | Automatic failover — you cannot see it happen |
| DeepSeek | China | The prompt/message content of the helper features routed to it on a Company key | When our gateway routes a helper request there |
| Fish Audio | China-founded, no region stated | The response text read aloud, forwarded verbatim through our relay | Only if you turn on voice (off by default) |
| OpenRouter → Alibaba | China (onward leg) | Some OpenRouter helper requests are served by an Alibaba-operated model upstream | When our gateway routes a helper request there |
| Fontshare (Indian Type Foundry) | India | Your IP address, browser user-agent and the page you were on — your browser fetches our brand typeface directly from them. No cookie, no tracking. | Every visit to a page on this website, including this one |
| Google Fonts | Global (Google) | Your IP address, browser user-agent and the page you were on — your browser fetches the body typeface directly from them. No cookie, no tracking. | Every visit to a page on this website, including this one |
| Google Analytics / Google Tag Manager | Global (Google) | Your IP address, browser user-agent, the pages you view, and a randomly-generated analytics identifier — loaded on every page of our public websites, these legal pages included. Google sets its own _ga cookies, and its advertising features ("Google signals") are on, which our Privacy Policy treats as a "share" and, in some states, a "sale". Consent-gated: analytics and ad storage stay denied until you accept the banner, and you can opt out at any time from the "Do Not Sell or Share My Personal Information" link in our footer or with Global Privacy Control. |
Every visit to a page on this website, including this one, once you accept |
Some of the services you connect on your own account are also non-US — Moonshot/Kimi, Zhipu/GLM and MiniMax are China-hosted, and the OpenStreetMap Nominatim geocoder is EU-hosted. Those run under your account with that provider, so the relationship (and the transfer) is directly between you and them.
Core subprocessors (used to run the Services)
| Subprocessor | What it does for us | Data it may process |
|---|---|---|
| Anthropic (Claude) | Default AI provider for agent sessions. The optional personal-development features (AI-coaching, journal reflection) also call Anthropic to generate insights, on your own Anthropic API key (only if you have one set) | Your prompts, code, file contents, conversation context, and attachments; and, for the personal-development features, the coaching/journal text those insight calls process (on your own key) |
| Google — Firebase / Google Cloud | Authentication, database (Firestore), cloud functions, hosting, our AI gateway (Cloud Run), secret storage, and mobile push (FCM) | Account/identity, billing and metering, usage/spend aggregates, support content, diagnostics, and team/Shares data |
| Stripe, Inc. | Payment processing and US sales-tax calculation | Payment method and billing details (held by Stripe); we receive a customer identifier and subscription status |
| Sentry | Application crash/error reporting | Crash/error reports with scrubbed messages |
| Resend | Transactional email (bug reports, digests, notifications) and product-activation / onboarding email | Email content the App sends; for activation/marketing messages, your email address and the message content |
| Cloudflare | Agent-email relay (inbound and outbound) | Email routed through the agent-email feature, including sender/recipient, subject, and body |
| AgentMail | Feedback / bug-report intake | Bug-report and feedback content, and the reporter's email address |
| Groq | Cost-efficient "helper" AI model via our gateway (e.g., inbound-email pre-screening/classification and short spoken summaries) | The content those helper features process (e.g., inbound email text) |
| OpenRouter, OpenAI, DeepSeek (via our AI gateway, on Company-held keys) | Cost-efficient "helper" AI models for built-in features — session titles, summaries and digests, Plain Speak rewrites, contact-name inference, email filtering/thread summaries, and Inbox Pilot (classifying the recent turns of an agent session, and drafting a reply when you enable that) | The prompt/message content those helper features process |
| RunInfra (serves our DeepSeek lane) | The "DeepSeek" models above are actually served through RunInfra on a Company-held key — it is the upstream our gateway's DeepSeek lane forwards to | The same prompt/message content the DeepSeek helper lane processes |
| CrofAI (backup for our DeepSeek lane) | Automatic backup upstream: if RunInfra errors, our gateway retries the same request against CrofAI on a Company-held key, so a DeepSeek-lane request can be served by CrofAI instead | The same prompt/message content the DeepSeek helper lane processes |
| FlowVoice (Company-hosted dictation server) | OS-wide voice dictation (speech-to-text) — engaged only if you turn on dictation | Live microphone audio you dictate, plus the foreground app name and window title |
Supermail backend (mailback.jls.dev, Company self-hosted) |
Backend for the Supermail inbound-email feature and its server-side contact enrichment — engaged only if you use Supermail | Inbound email sender, subject, and body, plus contact-enrichment lookups |
Optional subprocessors (only when you enable a specific feature)
These run on Company-held keys, but only process data when you use the corresponding feature. Several are off by default.
| Subprocessor | Feature | Data it may process |
|---|---|---|
| Klipy | SMS GIF search in the SMS composer (uses a Company default key unless you set your own) | Your typed GIF search terms |
| Firecrawl, Apify, X/Twitter | Built-in web-scraping / data-extraction / read-only tweet-search tools | The URLs, queries, or page content you request |
| OpenAI, Google Gemini, Perplexity ("bundled API keys," off by default) | Lets your agent call these providers through our gateway on Company keys | Your prompts and context for those calls (Gemini and Perplexity are pre-integrated but not yet active) |
| CrofAI, DeepInfra (pooled-key coding lanes) — not yet active | Paid pooled-key lanes that would run a whole coding session on a Company key. Staged, not funded — no data reaches either lane today; they will be moved to the Core table before being switched on | Once enabled: the whole session — every prompt, file the agent reads, and tool result. CrofAI is China-hosted. |
| Fish Audio | Default text-to-speech (read-aloud) on a Company-funded relay — engaged only if you turn on voice (off by default) | The response text read aloud (may contain names or message content) |
| Soniox | Text-to-speech (read-aloud / narration) on a Company-funded relay, alongside Fish Audio — engaged only if you turn on voice (off by default) | The response or narration text read aloud, forwarded verbatim (may contain names or message content) |
Services you connect on your own account (not our subprocessors)
When you connect these on your own API key or account, data flows directly from your device to that provider under its terms — we are not the processor, so they are not our subprocessors. They are listed here for transparency:
- AI / coding providers on your own key — OpenAI/Codex, Google Gemini, DeepSeek, Moonshot/Kimi, Zhipu/GLM, MiniMax, xAI, OpenRouter, Together, and the model resellers you can point a session at (CrofAI, DeepInfra, InferX). Picking one of these repoints the whole coding session — every prompt, every file the agent reads, and every tool result — to that provider. DeepSeek, Moonshot/Kimi, Zhipu/GLM and CrofAI are China-hosted.
- Cloud coding agents on your own key — Devin (Cognition), which runs the session on Devin's own US cloud and receives your prompts, agent context, and code.
- Voice providers on your own key — Deepgram, ElevenLabs, Groq, Meta (Muse Voice Transcribe, also reachable through OpenRouter), Speechify, xAI, Pika, Soniox (speech-to-text / text-to-speech).
- GitHub — sign-in, and the repository work you ask the App to do on your own GitHub account: pushing a branch, opening a pull request, or reading PR / issue activity. Pushing or opening a PR transmits every commit's author and committer name and email address together with the code changes.
- Channels and messaging you connect — Pushbullet (SMS), Slack, Telegram, Discord, and the email/calendar accounts you link.
- Board / project-management tools you connect — Trello, Jira, Notion, Linear, ClickUp, Airtable, Asana, Monday.
- Meeting, content & automation tools you connect — Granola, Fathom, Zoom, Loom, Canva, Vimeo, Zapier.
- Cloud backup you connect — Dropbox and Microsoft OneDrive. The backup archive itself is encrypted before it leaves your device (the provider sees ciphertext only), but signing in transmits your account email and display name to that provider in the clear.
- Design and image search you connect — Mobbin (design-inspiration search on your own Mobbin session) and Unsplash (cover-image search; not active — no key is wired, so nothing is sent today). Each receives the search terms you type.
- Bank sync (the Coffer feature) — a SimpleFIN bridge you configure.
- Investment prices (Yahoo Finance) — the Investments view looks up a price and history for each ticker you hold, from a keyless public endpoint (
query1.finance.yahoo.com). No API key or account identifier is sent, but the symbols themselves are. - Weather lookup (Open-Meteo) — if you use a weather automation, the place name you type and the coordinates it resolves to are sent to the keyless public Open-Meteo endpoints (EU-hosted). No API key or account identifier is sent.
- Contact/company enrichment — Gravatar (profile image) and Clearbit (company logo), when a card is enriched.
- Location search (OpenStreetMap / Nominatim) — the card-location picker sends your typed place-search queries to the OpenStreetMap Nominatim geocoder (
nominatim.openstreetmap.org), a keyless public endpoint (EU-hosted). No API key or account identifier is sent.
How we notify you of changes
We maintain the current list on this page. When we add or replace a subprocessor, we will update this page and the effective date above, and — where required by an applicable data-processing agreement — give business/team customers advance notice and the opportunity to object as that agreement provides. Material changes are also reflected in the Privacy Policy's "Last updated" date.
Contact
Questions or a DPA request: legal@omniscio.com, Omniscio LLC, 5301 Terminal St, Charlotte, NC 28208.