$ cat SUBPROCESSORS.md

Subprocessors

Third-party service providers that process personal data on behalf of Kommit AI. We select providers with strong data protection practices and maintain Data Processing Agreements with each.

SubprocessorPurposeData ProcessedLocation
AnthropicAI conversations & PRD generationConversation messages, project contextUnited States
OpenAIText embeddings for semantic search (RAG)Node content, messagesUnited States
VercelApplication hosting, file storage, web analyticsAll application data, uploaded filesUnited States
NeonManaged PostgreSQL databaseAll persisted dataUnited States
PostHogProduct analytics & error trackingUsage events, user identityEuropean Union (Frankfurt)
GitHubOAuth authentication, repository integrationAuth tokens, repository codeUnited States
StripePayment processingBilling information, emailUnited States
LangfuseAI observability & tracingAI request traces, token usageEuropean Union (Germany)
BotcruncherBot detection & ad fraud preventionTraffic patterns, IP metadata, behavioral signalsEuropean Union

Last updated: April 4, 2026

We will update this page when subprocessors change and notify affected customers by email at least 30 days in advance of any new subprocessor being engaged.

Questions? Contact us at privacy@getkommit.ai