Legal

Subprocessors

Every vendor that touches data on our behalf, what it does, and which categories of data it sees — with the confirmation status of each.

What this list is

A subprocessor is a vendor that processes personal data on behalf of Knomatic so that the CodeMonster platform can run. This page lists each one, what it does for you, and what categories of data it touches. It is referenced by the Data Processing Agreement and matches the compliance status page.

Every entry below is marked “confirmation pending” until the founder confirms the vendor, the contract, and the processing region. Nothing on this page should be read as final.

This page becomes the confirmed, versioned list referenced by the compliance status page once counsel and the founder sign it off. Until then it is the working list — ask for the signed version with the DPA.

Current subprocessors

SubprocessorPurposeData categoriesRegionStatus
Amazon Web Services (AWS)Hosting, compute, object storage, CDN, DNS, TLS certificatesApplication data, build artifacts, uploaded files, logs[PLACEHOLDER: region]Confirmation pending
SupabaseApp records, versions, deployments, edit sessions, and tool telemetry for custom frontends and the agent control surfaceApp metadata, deployment records, builder identifiers[PLACEHOLDER: region]Confirmation pending
SparkPostDelivery of the emails your workflows sendRecipient addresses and templated message content from workflows[PLACEHOLDER: region]Confirmation pending
Firebase (Google)Push notifications sent by workflows; optional single sign-on providerDevice tokens and notification payloads; identity claims when used for SSO[PLACEHOLDER: region]Confirmation pending
CarbonePDF generation for workflow reportsReport data passed to templates[PLACEHOLDER: region]Confirmation pending

Who is not on this list

Your AI provider. CodeMonster connects the AI subscription you already pay for to the platform from your desktop. Your prompts and keys travel between you and that provider under your own agreement, so the provider is not our subprocessor and is not listed here. If that ever changes for a hosted option, the provider appears on this page before that option ships.

Endpoints your own workflows call — Zapier, Make, n8n, or any HTTP service you configure — are your choice and your vendors, not ours.

Changes to this list

We will update this page and give notice [PLACEHOLDER: notice period] days before adding or replacing a subprocessor, so you can object under the DPA. [PLACEHOLDER: notice mechanism — email to account owner, page update, or both.] Last reviewed: 2026-08-15.

Contact

Questions about a subprocessor go to privacy@codemonster.ai. Security questions go to security@codemonster.ai.