Subprocessors
Last updated: 06/12/2026
PlotCipher uses the third-party service providers below to deliver the Service. Each is bound by a written contract requiring confidentiality, security, and use of personal information only for the disclosed purpose. None of these vendors is authorized to use PlotCipher customer data for their own marketing or to train general-purpose AI models.
We will provide at least thirty (30) days' advance notice of any material change to this list (new subprocessor or significant change in data processed), via in-product banner and email to billing contacts on file. Paying customers may object by emailing mark@tryplotcipher.com within the notice period.
| Vendor | Purpose | Data processed | Region |
|---|---|---|---|
Stripe, Inc. Privacy notice ↗ | Payment processing, subscription billing, customer portal | Billing email, customer ID, subscription metadata, charge events | United States Direct disclosure (CCPA service-provider contract) |
Amazon Web Services, Inc. Privacy notice ↗ | Application hosting, RDS Postgres database, S3 object storage, SES transactional email | All account and content data at rest | US East (N. Virginia) / US West (Oregon) Direct disclosure (CCPA service-provider contract) |
Mapbox, Inc. Privacy notice ↗ | Map tiles, geocoding, vector overlays | IP address, viewport coordinates (no account data) | United States Direct disclosure (CCPA service-provider contract) |
OpenAI, L.L.C. Privacy notice ↗ | Natural-language generation for memos, summaries, outreach drafts (paid tier; data is NOT used to train OpenAI models per their commercial terms) | Prompt text, parcel context, generated outputs | United States Direct disclosure (CCPA service-provider contract) |
PostHog, Inc. Privacy notice ↗ | Aggregated usage analytics (opt-in via cookie consent) | IP address (anonymized), page paths, event names | United States Direct disclosure (CCPA service-provider contract) |
Sentry, Inc. Privacy notice ↗ | Runtime error and crash reporting | Stack traces, request URL, IP address (scrubbed of PII) | United States Direct disclosure (CCPA service-provider contract) |
Vendor classification
For CCPA / CPRA purposes, all vendors listed are categorized as service providers(formerly “service providers” pre-CPRA, now “contractors” in some cases). We do not classify any of these vendors as “third parties” receiving personal information for their own purposes.
Enterprise data processing addendum (DPA)
Enterprise customers may execute a Data Processing Addendum that incorporates this subprocessor list by reference and provides for advance notice and right-to-object on material changes. Email mark@tryplotcipher.com to request a DPA.
Reporting
Questions about a specific vendor or its security posture: mark@tryplotcipher.com.
General privacy questions: mark@tryplotcipher.com.