Subprocessors
Last updated: July 24, 2026
Pocular LLC (“Pocular”) uses the following third-party service providers (“subprocessors”) to operate pocular.com and the Pocular platform. Each processes personal information or customer content only as needed to provide the services described below. We do not sell personal information.
We may update this list when we add, replace, or remove subprocessors. Material changes will be reflected on this page by revising the “Last updated” date. Enterprise customers with a data processing agreement (DPA) that requires advance notice of subprocessor changes should follow the notice process in that agreement; otherwise, continued use of the Service after an update constitutes acknowledgment of the revised list to the extent permitted by law.
This page supplements our Privacy Policy.
Current subprocessors
| Subprocessor | Purpose | Data processed | Location / notes |
|---|---|---|---|
| Supabase | Database, authentication, file storage, Realtime | Account email, workspace/project content, import files (temporary), entitlements | Hosted Postgres; region per project settings |
| Vercel | Application hosting, CDN | HTTP logs, request metadata | Edge / serverless |
| Stripe | Payment processing (Project Credits) | Billing email, payment method (by Stripe), checkout metadata | PCI handled by Stripe |
| Resend | Transactional email | Recipient email, invite/handoff copy, project names | Email delivery only |
| Inngest | Background jobs (import extraction, retention purge, feedback delivery) | Job IDs, project IDs, non-content job payloads | Durable workflow orchestration |
| AWS Bedrock (and/or Anthropic) | Smart Import LLM extraction, AI report generation | Document text and prompts sent for inference | Provider depends on deployment configuration; Excel imports may use a deterministic parser without an LLM |
| Upstash | Rate limiting | Hashed rate-limit keys (user/IP identifiers) | May be used when enabled in production |
Customer content in AI features
Smart Import: Uploaded files are stored temporarily for processing. For Word/PDF extraction or field inference, document text may be sent to the configured LLM provider. Excel imports typically use a deterministic parser unless LLM enhancement is enabled for your deployment.
AI reports: Aggregated project statistics and prompts—and, depending on report type, requirement bodies—may be sent to the LLM provider.
Usage ledger: We store event types, counts, and metadata such as hashed file names and token estimates—not raw file contents.
Retention (summary)
Import jobs: Uploaded files and extraction artifacts are purged according to configured purge windows; committed imports remove associated storage objects on commit.
Completed free-tier projects: May be purged after a retention window via scheduled cleanup jobs.
For broader retention practices, see our Privacy Policy.
Contact
Data processing questions: support@pocular.com. For legal inquiries: legal@pocular.com.