Sub-processors
Effective: April 27, 2026 · Last updated: October 8, 2026
This document lists the third-party sub-processors that may process Customer Data on behalf of Tangle Technologies, Inc. ("Tangle") in connection with Tangle-operated websites, applications, and services at tangle.tools and any of its subdomains (*.tangle.tools), together with our APIs and related services. We update this list when sub-processors are added, removed, or change their role. See the Privacy Policy for how Tangle handles personal information and the Security Information Page for current security practices.
Notification
Customers can subscribe to sub-processor change notifications by emailing [email protected] with subject line "Sub-processor notifications". We give at least 30 days' notice before adding a new sub-processor that processes Customer Data, except where the change is required by law or to address a security incident.
Active sub-processors
| Sub-processor | Service | Customer Data processed | Region | Legal basis |
|---|---|---|---|---|
| Hetzner Online GmbH | Cloud infrastructure hosting (compute, storage, networking) | All Customer Data within sandboxes | Germany / Finland | Standard Contractual Clauses (SCCs) for EU transfers |
| Cloudflare, Inc. | Edge processing and security, DNS, DDoS protection, D1 databases, KV and R2 storage | Request metadata, IP addresses, application and account records, conversation and knowledge content, files, and audit artifacts | US, EU edge POPs | SCCs |
| Stripe, Inc. | Payment processing | Billing email, name, payment-method tokens (no full PAN) | US | DPA on file |
| Google LLC (Google Workspace) | Email, calendaring, document collaboration for Tangle staff | Customer support communications | US | DPA on file |
| Sentry (Functional Software, Inc.) | Error reporting, performance telemetry | Error events with credentials, PCI cardholder data, and government IDs scrubbed by the runtime redactor before send | US | DPA on file |
| OpenAI, L.L.C. | LLM inference when Customer selects an OpenAI model in the sandbox | Prompt and completion text the Customer's agent sends; the egress filter scrubs authentication credentials, PCI cardholder data, and government IDs before transmission | US | API DPA; per-request store: false enforced when the Customer hasn't set it |
| Anthropic, PBC | LLM inference when Customer selects an Anthropic model | Same as OpenAI; account-level Zero Data Retention (ZDR) governs vendor retention | US | Commercial Terms + ZDR addendum |
| Resend | Transactional email (account, billing, security notifications) | Email addresses of account holders | US | DPA on file |
Model providers
These providers may receive request content through the Tangle Router, sandboxes, or agent applications according to the configured model and route. An application or agent can configure a default model. A model developer can differ from the inference provider that receives the request; for example, GLM models can be hosted by Together AI. Review the model and provider configuration before submitting data that requires a particular provider. Providers marked "No" in the last column must not receive EEA, UK, or Swiss personal data.
| Model Provider | Service | Country of establishment | EEA/UK/Swiss personal data |
|---|---|---|---|
| OpenAI | Text, image, audio models | United States | Yes (SCCs) |
| Anthropic | Text models | United States | Yes (SCCs) |
| Google (Gemini API) | Text, image, video models | United States | Yes (SCCs) |
| xAI | Text models | United States | Yes (SCCs) |
| Mistral AI | Text models | France | Yes |
| Cohere | Text and embedding models | Canada | Yes (adequacy) |
| AI21 Labs | Text models | Israel | Yes (adequacy) |
| Groq | Open-model inference | United States | Yes (SCCs) |
| Together AI | Open-model inference | United States | Yes (SCCs) |
| Fireworks AI | Open-model inference | United States | Yes (SCCs) |
| Cerebras | Open-model inference | United States | Yes (SCCs) |
| SambaNova | Open-model inference | United States | Yes (SCCs) |
| NVIDIA | Open-model inference | United States | Yes (SCCs) |
| Hugging Face | Open-model inference | United States | Yes (SCCs) |
| Replicate | Open-model and media inference | United States | Yes (SCCs) |
| fal | Image and video models | United States | Yes (SCCs) |
| Black Forest Labs | Image models | Germany | Yes |
| Runway | Video models | United States | Yes (SCCs) |
| HeyGen | Video avatar models | United States | Yes (SCCs) |
| Sync Labs | Lip-sync video models | United States | Yes (SCCs) |
| D-ID | Video avatar models | Israel | Yes (adequacy) |
| Twelve Labs | Video understanding models | United States | Yes (SCCs) |
| You.com | Web search | United States | Yes (SCCs) |
| OpenRouter | Model aggregation; routes requests to configured inference providers | United States | Yes (SCCs) |
| ph0ny | Voice models; operated by an affiliate under common control, hosted on Hetzner | Germany | Yes |
| DeepSeek | Text models | China | No |
| Moonshot AI | Text models | China | No |
| Zhipu AI (Z.ai) | Text models | China | No |
| Kling (Kuaishou) | Video models | China | No |
| MoonMath | Open-model inference | Not yet confirmed | No |
Retention by each Model Provider follows its own terms. On the sandbox egress path, OpenAI Chat Completions receive store: false when the caller has not set that field. This setting controls response storage; it is not a general zero-retention guarantee. Anthropic processing under the applicable account is covered by a Zero Data Retention addendum. The applicable customer agreement governs provider selection and notice requirements. This inventory does not by itself establish that any required customer notice or vendor assessment has been completed.
Provider that does not process Customer Data
GitHub, Inc. provides source code hosting, CI execution, and a container registry for Tangle internal source. It does not process Customer Data. Its region is the US, under an Enterprise agreement.
Sub-processor categories Customers may opt out of
- Model providers. Customers can select a model where the product exposes that choice; otherwise the app or agent configuration selects it. The routing configuration determines which provider receives request content. Customers requiring a specific vendor under their own DPA or BAA should contact [email protected].
Outbound data minimization
Tangle sandbox runtime controls include the following layers where that runtime and egress path are used:
- Internal observability redaction. Credentials, PCI cardholder data, and government identifiers are stripped from logs, error events, audit trails, and billing events before they leave the runtime.
- External egress redaction and request-storage settings. Outbound JSON bodies to model vendors run through the same redactor; OpenAI Chat Completions are augmented with
store: falsewhen the Customer hasn't set it.
The sandbox runtime exposes its configured posture at GET /privacy (authenticated). These sandbox controls are not a claim that every direct API request, agent application, or third-party tool passes through that egress path. Provider retention depends on the request settings and the applicable provider agreement.