Sub-processor List
Last updated: 2026-08-08
Overview
This page is the canonical list of Maestrio’s data sub-processors — third-party entities that Maestrio engages to process personal data on behalf of Customers as part of the Maestrio feedback collection and agent automation service. It is maintained in accordance with Section 5 of the Maestrio Data Processing Agreement (“DPA”).
By accepting the DPA, Customers grant Maestrio general written authorization to engage the sub-processors listed below. Maestrio will provide at least 30 days’ prior written notice by email before adding or replacing any sub-processor, in accordance with Section 5 of the DPA.
Default Sub-processors
The following sub-processors are engaged by default as part of the standard Maestrio service and apply to all Customers.
| Sub-processor | Purpose | Data Transferred | Region | DPA / Transfer Basis |
|---|---|---|---|---|
| Anthropic | AI triage and coding agent inference | Customer code, feedback content | US | Anthropic API ToS (no-training commitment); Brazil LGPD safeguards as applicable |
| OpenRouter | AI model routing | Customer code, feedback content | US | OpenRouter API ToS; Brazil LGPD safeguards as applicable. Note: OpenRouter routes requests to multiple underlying model providers. Maestrio selects configurations whose data-use terms are consistent with the no-training commitment; actual data handling may vary by provider endpoint. See Privacy Policy for details. |
| Cloudflare | Workers compute, R2 object storage | Customer code, feedback content, agent logs | Global edge; R2: US | Cloudflare DPA; Brazil LGPD safeguards as applicable |
| Railway | Infrastructure hosting (Next.js dashboard, PostgreSQL, Redis) | All account-holder and end-user data | US | Railway DPA |
| GitHub | GitHub App, OAuth, webhooks | Repository contents, account identity | US | GitHub DPA; Brazil LGPD safeguards as applicable |
| OAuth authentication; consent-gated website analytics | OAuth: name, email, profile picture. Analytics: page URL, session statistics, approximate location, and browser/device information | US | Google Cloud DPA and Google Ads Data Processing Terms; Brazil LGPD safeguards as applicable | |
| Resend | Transactional email | Name, email address | US | Resend DPA; Brazil LGPD safeguards as applicable |
| PostHog | Product analytics | Account-holder identity, usage events, session metadata | US | PostHog DPA; Brazil LGPD safeguards as applicable |
| Grafana Cloud(Loki) | Log aggregation | Service logs (may include user/org IDs) | US | Grafana DPA; Brazil LGPD safeguards as applicable |
| Grafana Cloud(Tempo) | Distributed tracing | HTTP traces, DB spans (may include metadata) | US | Grafana DPA; Brazil LGPD safeguards as applicable |
| Stripe | Subscription billing, payment processing | Billing name, email, subscription state | US | Stripe DPA; Brazil LGPD safeguards as applicable |
Optional / Customer-Activated Integrations
There are no optional customer-activated sub-processors available as of the last-updated date above. If Maestrio introduces one, this section will identify the provider, purpose, data transferred, processing region, and applicable transfer safeguards before the integration is made available.
Changes to This List
Maestrio will provide Customers with at least 30 days’ prior written notice (by email to the address registered on the Customer’s account) before adding or replacing any default sub-processor listed above.
Customers may object to a new or replacement sub-processor within 30 days of receiving such notice, as described in Section 5 of the DPA.
The date at the top of this page reflects when the list was last updated. We recommend that Customers bookmark this URL and review it periodically.