Subprocessors

Last updated: August 9, 2026

Pocular LLC (“Pocular”) uses the following third-party service providers (“subprocessors”) to operate pocular.com and the Pocular platform. Each processes personal information or customer content only as needed to provide the services described below. We do not sell personal information.

We may update this list when we add, replace, or remove subprocessors. Material changes will be reflected on this page by revising the “Last updated” date. Enterprise customers with a data processing agreement (DPA) that requires advance notice of subprocessor changes should follow the notice process in that agreement; otherwise, continued use of the Service after an update constitutes acknowledgment of the revised list to the extent permitted by law.

This page supplements our Privacy Policy.

Current subprocessors

SubprocessorPurposeData processedLocation / notes
SupabaseDatabase, authentication, file storage, RealtimeAccount email, workspace/project content, import files (temporary), entitlementsHosted Postgres; region per project settings
VercelApplication hosting, CDN, Web Analytics, Speed InsightsHTTP logs, request metadata, anonymized performance analyticsEdge / serverless
StripePayment processing (Project Credits)Billing email, payment method (by Stripe), checkout metadataPCI handled by Stripe
ResendTransactional emailRecipient email, invite/handoff copy, project names; in-app feedback notifications (message and optional screenshot)Email delivery only
InngestBackground jobs (import extraction, import purge, feedback delivery)Job IDs and project IDs for imports; feedback delivery events carry a feedback submission ID only (content is loaded from our database)Durable workflow orchestration
AWS Bedrock (and/or Anthropic)Smart Import LLM extraction, AI report generationDocument text and prompts sent for inferenceProvider depends on deployment configuration; Excel imports may use a deterministic parser without an LLM
UpstashRate limitingHashed rate-limit keys (user/IP identifiers)Required in Vercel production
Slack (optional)Optional in-app feedback notifications via incoming webhookFeedback message summary, submitter email, workspace name, page URL (only when a webhook is configured)Used only if configured for the deployment

Customer content in AI features

Smart Import: Uploaded files are stored temporarily for processing. For Word/PDF extraction or field inference, document text may be sent to the configured LLM provider. Excel imports typically use a deterministic parser unless LLM enhancement is enabled for your deployment.

AI reports: Aggregated project statistics and prompts—and, depending on report type, requirement bodies—may be sent to the LLM provider.

Usage ledger: We store event types, counts, and metadata such as hashed file names and token estimates—not raw file contents.

Retention (summary)

Import jobs: Uploaded files and extraction artifacts are purged according to configured purge windows; committed and cancelled imports remove associated storage objects. A scheduled job clears expired terminal import artifacts.

Completed projects: Retained indefinitely under the current product policy (no automatic free-tier project purge).

For broader retention practices, see our Privacy Policy.

Contact

Data processing questions: support@pocular.com. For legal inquiries: legal@pocular.com.