Subprocessors
Last updated: August 9, 2026
Pocular LLC (“Pocular”) uses the following third-party service providers (“subprocessors”) to operate pocular.com and the Pocular platform. Each processes personal information or customer content only as needed to provide the services described below. We do not sell personal information.
We may update this list when we add, replace, or remove subprocessors. Material changes will be reflected on this page by revising the “Last updated” date. Enterprise customers with a data processing agreement (DPA) that requires advance notice of subprocessor changes should follow the notice process in that agreement; otherwise, continued use of the Service after an update constitutes acknowledgment of the revised list to the extent permitted by law.
This page supplements our Privacy Policy.
Current subprocessors
| Subprocessor | Purpose | Data processed | Location / notes |
|---|---|---|---|
| Supabase | Database, authentication, file storage, Realtime | Account email, workspace/project content, import files (temporary), entitlements | Hosted Postgres; region per project settings |
| Vercel | Application hosting, CDN, Web Analytics, Speed Insights | HTTP logs, request metadata, anonymized performance analytics | Edge / serverless |
| Stripe | Payment processing (Project Credits) | Billing email, payment method (by Stripe), checkout metadata | PCI handled by Stripe |
| Resend | Transactional email | Recipient email, invite/handoff copy, project names; in-app feedback notifications (message and optional screenshot) | Email delivery only |
| Inngest | Background jobs (import extraction, import purge, feedback delivery) | Job IDs and project IDs for imports; feedback delivery events carry a feedback submission ID only (content is loaded from our database) | Durable workflow orchestration |
| AWS Bedrock (and/or Anthropic) | Smart Import LLM extraction, AI report generation | Document text and prompts sent for inference | Provider depends on deployment configuration; Excel imports may use a deterministic parser without an LLM |
| Upstash | Rate limiting | Hashed rate-limit keys (user/IP identifiers) | Required in Vercel production |
| Slack (optional) | Optional in-app feedback notifications via incoming webhook | Feedback message summary, submitter email, workspace name, page URL (only when a webhook is configured) | Used only if configured for the deployment |
Customer content in AI features
Smart Import: Uploaded files are stored temporarily for processing. For Word/PDF extraction or field inference, document text may be sent to the configured LLM provider. Excel imports typically use a deterministic parser unless LLM enhancement is enabled for your deployment.
AI reports: Aggregated project statistics and prompts—and, depending on report type, requirement bodies—may be sent to the LLM provider.
Usage ledger: We store event types, counts, and metadata such as hashed file names and token estimates—not raw file contents.
Retention (summary)
Import jobs: Uploaded files and extraction artifacts are purged according to configured purge windows; committed and cancelled imports remove associated storage objects. A scheduled job clears expired terminal import artifacts.
Completed projects: Retained indefinitely under the current product policy (no automatic free-tier project purge).
For broader retention practices, see our Privacy Policy.
Contact
Data processing questions: support@pocular.com. For legal inquiries: legal@pocular.com.