Legal
Subprocessors
Last updated Oct 7, 2026
Draft for legal review
This list awaits legal review. It is accurate today and is part of our draft data processing agreement.
These providers process data on our behalf so that we can run DeployYourCode. Each one's certifications and attestations are its own: they cover that provider's systems, not ours. Where a provider is used only when you choose a feature, that is said beside it.
We update this page when we add or remove a provider, and the date above moves with it. The terms we intend to offer on notice of a new provider are in our draft data processing agreement. Questions: legal@deployyourcode.com.
Fly.io
Fly.io, Inc.- What it does
- Runs every app you deploy, its databases and the private network they share.
- Runs our own web app, build service, image registry and background-job server.
- Data it receives
- Your built images, your environment variables while your apps run, the contents of your databases, and what your apps print to their logs.
- Where
- United States
- Fly.io holds
- SOC 2 Type 2 — as stated on its site, read Oct 5, 2026
- Its documents
- Security and compliance
Supabase
Supabase, Inc.- What it does
- Hosts our own database.
- Data it receives
- Accounts, organizations and their members, projects and settings, your encrypted secrets, usage records and audit records.
- Where
- United States
- Supabase holds
- SOC 2 Type 2 — as stated on its site, read Oct 5, 2026
- ISO 27001 — as stated on its site, read Oct 5, 2026
- Its documents
- Security and complianceData processing agreement
Cloudflare
Cloudflare, Inc.- What it does
- Registers the domain names you buy through us, and serves DNS for them and for our own domains.
- Runs the human check on sign-up, sign-in and the abuse report form.
- Forwards email sent to our addresses.
- PlannedCarries the traffic of apps behind our edge: it terminates their TLS, so it sees that traffic unencrypted. No app is behind the edge yet.
- Data it receives
- Registrant details for domains you buy through us, DNS records, the browser signals its human check reads, email sent to our addresses, and — once our edge is live — the requests and responses of the apps behind it.
- Cloudflare holds
- SOC 2 Type II — as stated on its site, read Oct 5, 2026
- ISO 27001 — as stated on its site, read Oct 5, 2026
- ISO 27701 — as stated on its site, read Oct 5, 2026
- ISO 27018 — as stated on its site, read Oct 5, 2026
- PCI DSS Level 1, as a service provider — as stated on its site, read Oct 5, 2026
- Its documents
- Security and complianceData processing agreement
Tigris Data
Tigris Data, Inc.- What it does
- Stores the images you upload and the archive of our background-job history.
- Data it receives
- Organization logos and avatars you upload, and the archived history of the background jobs run for you.
- Tigris Data holds
- SOC 2 Type II — as stated on its site, read Oct 5, 2026
- Its documents
- Security and complianceData processing agreement
Stripe
Stripe, Inc.- What it does
- Takes payments for plans, usage and domain names.
- Data it receives
- Billing contact details, invoices, usage totals for metered billing, and your payment methods — card numbers are entered on Stripe's own pages and never reach our servers.
- Stripe holds
- PCI DSS Level 1, as a service provider — as stated on its site, read Oct 5, 2026
- SOC 1 and SOC 2 Type II reports — as stated on its site, read Oct 5, 2026
- EU–US Data Privacy Framework — as stated on its site, read Oct 5, 2026
- Its documents
- Security and complianceData processing agreement
Resend
Resend, Inc.- What it does
- Sends our transactional email.
- Data it receives
- The recipient's address and the message: invitations, sign-in and password-reset links, receipts and billing alerts.
- Where
- United States
- Resend holds
- SOC 2 Type II — as stated on its site, read Oct 5, 2026
- Its documents
- Security and complianceData processing agreement
- What it does
- Hosts the mailboxes that receive email sent to our support and abuse addresses, which Cloudflare's email routing forwards there.
- PlannedAnswers, through Google Web Risk, whether a public app address we host is listed as phishing or malware (our daily abuse check).
- Data it receives
- Whatever you send to those addresses: your email address, your message and anything attached to it. For Web Risk, once on: the public address of an app we host, nothing else.
- When
- Only when you email us; the Web Risk check, once on, covers every public app.
- Google holds
- Nothing listed here.
- Its documents
- Security and complianceData processing agreement
Anthropic
Anthropic, PBC- What it does
- Answers the in-app assistant and writes AI fixes.
- Gives a second opinion in our automatic abuse check of a public app's front page when it goes live — from features extracted from the page, never the page itself.
- Data it receives
- What you ask the assistant, and the details of your projects, deployments and usage it reads to answer; for an AI fix, the repository files and build log being diagnosed; for the abuse check, a public app's title, headings, form targets and visible text.
- When
- When you use the assistant or AI fixes, and when a public app of yours goes live.
- Anthropic holds
- SOC 2 Type I and Type II — as stated on its site, read Oct 5, 2026
- ISO 27001:2022 — as stated on its site, read Oct 5, 2026
- ISO/IEC 42001:2023 — as stated on its site, read Oct 5, 2026
- Its documents
- Security and compliance
GitHub
GitHub, Inc.- What it does
- Holds the repositories you connect: we read them to build your apps, and open fix pull requests you ask for.
- Data it receives
- The contents and commit history of the repositories you connect.
- When
- Only for the repositories you connect.
- GitHub holds
- SOC 1 Type 2 and SOC 2 Type 2 — as stated on its site, read Oct 5, 2026
- ISO/IEC 27001:2022 — as stated on its site, read Oct 5, 2026
- Its documents
- Security and compliance
Sentry
Functional Software, Inc.- What it does
- Collects error reports from our own servers.
- Data it receives
- The error, where in our code it happened, and the page or API address it happened on.
- When
- Only while error reporting is switched on for our servers.
- Sentry holds
- SOC 2 Type I and Type II — as stated on its site, read Oct 5, 2026
- ISO 27001 — as stated on its site, read Oct 5, 2026
- Its documents
- Security and complianceData processing agreement
Former subprocessors
- Inngest, used until Sep 24, 2026. Ran our background jobs — deploys, database provisioning, usage metering. Data it received: What each background job was given and what it produced, kept under Inngest's own retention policy.