Subprocessors

Last updated: July 24, 2026

Pocular LLC (“Pocular”) uses the following third-party service providers (“subprocessors”) to operate pocular.com and the Pocular platform. Each processes personal information or customer content only as needed to provide the services described below. We do not sell personal information.

We may update this list when we add, replace, or remove subprocessors. Material changes will be reflected on this page by revising the “Last updated” date. Enterprise customers with a data processing agreement (DPA) that requires advance notice of subprocessor changes should follow the notice process in that agreement; otherwise, continued use of the Service after an update constitutes acknowledgment of the revised list to the extent permitted by law.

This page supplements our Privacy Policy.

Current subprocessors

SubprocessorPurposeData processedLocation / notes
SupabaseDatabase, authentication, file storage, RealtimeAccount email, workspace/project content, import files (temporary), entitlementsHosted Postgres; region per project settings
VercelApplication hosting, CDNHTTP logs, request metadataEdge / serverless
StripePayment processing (Project Credits)Billing email, payment method (by Stripe), checkout metadataPCI handled by Stripe
ResendTransactional emailRecipient email, invite/handoff copy, project namesEmail delivery only
InngestBackground jobs (import extraction, retention purge, feedback delivery)Job IDs, project IDs, non-content job payloadsDurable workflow orchestration
AWS Bedrock (and/or Anthropic)Smart Import LLM extraction, AI report generationDocument text and prompts sent for inferenceProvider depends on deployment configuration; Excel imports may use a deterministic parser without an LLM
UpstashRate limitingHashed rate-limit keys (user/IP identifiers)May be used when enabled in production

Customer content in AI features

Smart Import: Uploaded files are stored temporarily for processing. For Word/PDF extraction or field inference, document text may be sent to the configured LLM provider. Excel imports typically use a deterministic parser unless LLM enhancement is enabled for your deployment.

AI reports: Aggregated project statistics and prompts—and, depending on report type, requirement bodies—may be sent to the LLM provider.

Usage ledger: We store event types, counts, and metadata such as hashed file names and token estimates—not raw file contents.

Retention (summary)

Import jobs: Uploaded files and extraction artifacts are purged according to configured purge windows; committed imports remove associated storage objects on commit.

Completed free-tier projects: May be purged after a retention window via scheduled cleanup jobs.

For broader retention practices, see our Privacy Policy.

Contact

Data processing questions: support@pocular.com. For legal inquiries: legal@pocular.com.