What this list is
A subprocessor is a vendor that processes personal data on behalf of Knomatic so that the CodeMonster platform can run. This page lists each one, what it does for you, and what categories of data it touches. It is referenced by the Data Processing Agreement and matches the compliance status page.
Every entry below is marked “confirmation pending” until the founder confirms the vendor, the contract, and the processing region. Nothing on this page should be read as final.
This page becomes the confirmed, versioned list referenced by the compliance status page once counsel and the founder sign it off. Until then it is the working list — ask for the signed version with the DPA.
Current subprocessors
| Subprocessor | Purpose | Data categories | Region | Status |
|---|---|---|---|---|
| Amazon Web Services (AWS) | Hosting, compute, object storage, CDN, DNS, TLS certificates | Application data, build artifacts, uploaded files, logs | [PLACEHOLDER: region] | Confirmation pending |
| Supabase | App records, versions, deployments, edit sessions, and tool telemetry for custom frontends and the agent control surface | App metadata, deployment records, builder identifiers | [PLACEHOLDER: region] | Confirmation pending |
| SparkPost | Delivery of the emails your workflows send | Recipient addresses and templated message content from workflows | [PLACEHOLDER: region] | Confirmation pending |
| Firebase (Google) | Push notifications sent by workflows; optional single sign-on provider | Device tokens and notification payloads; identity claims when used for SSO | [PLACEHOLDER: region] | Confirmation pending |
| Carbone | PDF generation for workflow reports | Report data passed to templates | [PLACEHOLDER: region] | Confirmation pending |
Who is not on this list
Your AI provider. CodeMonster connects the AI subscription you already pay for to the platform from your desktop. Your prompts and keys travel between you and that provider under your own agreement, so the provider is not our subprocessor and is not listed here. If that ever changes for a hosted option, the provider appears on this page before that option ships.
Endpoints your own workflows call — Zapier, Make, n8n, or any HTTP service you configure — are your choice and your vendors, not ours.
Changes to this list
We will update this page and give notice [PLACEHOLDER: notice period] days before adding or replacing a subprocessor, so you can object under the DPA. [PLACEHOLDER: notice mechanism — email to account owner, page update, or both.] Last reviewed: 2026-08-15.
Contact
Questions about a subprocessor go to privacy@codemonster.ai. Security questions go to security@codemonster.ai.