Subprocessors
Last updated 2026-09-25
These are the third parties that process data on TraceLog's behalf. Notice is given before one is added, so a customer can object.
The list
EU hosting describes where TraceLog stores data, and that storage does not move: every event, daily aggregate and account record stays in eu-central-1. Three optional operations send information outside the region: answering a question, signing in with Google, and paying for a subscription through Stripe. If a customer does not ask a question, sign in with Google, or choose a paid plan, none of those providers receives their information. Creating an account with email and password is the one that is not optional: Cloudflare checks the person signing up from its global network, and receives no account data. Signing up with Google skips that check. One other request leaves the region but carries no data: once an hour a background process sends a signal to the uptime monitor described below.
One resource sits outside the EU and holds no data: the TLS certificate this site is served with, which the content delivery network reads only from its own North Virginia region. A certificate is a public key and a domain name. Every origin it points at is in Frankfurt.
| Subprocessor | What it does | Data it sees | Region |
|---|---|---|---|
| Resend | Delivers transactional email: the alert, the diagnostic, and account mail such as address verification and password reset | The recipient's email address and the content of the message | EU |
| Authenticates an account when the person chooses Google Sign-In | The Google account identifier, verified email address, name, profile image, and OAuth security metadata — never measurement data | Global | |
| Anthropic | Reads questions asked in the product's conversation and chooses which governed read answers them; TraceLog states the answer, and no text the model writes reaches the reader | The question as typed, the project's declared conversion path, and what TraceLog's governed reads return — aggregate numbers, recorded findings and, when the question needs them, the customer's own notes on actions and changes — never raw events, sessions, identifiers or payloads | United States |
| Stripe | Takes the subscription payment, hosts the checkout and the invoice portal, and is where card details are entered and held | The account owner's email address, the plan chosen, and the payment details entered on Stripe's own pages — never any conversion-record data | United States |
| Cloudflare | Checks that whoever creates an account with email and password is a person (Turnstile) | The IP address and browser signals of the person signing up, during that check — never the email address, the password or any measurement data | Global |
| Amazon Web Services | Runs the application, the API, the background processes and the database, and serves this site and the capture runtime from immutable per-version paths | Everything the product stores, and the network requests that reach it | EU (eu-central-1, Frankfurt) |
Not subprocessors
Geolocation is a local lookup. TraceLog reads a MaxMind GeoLite2 Country database file on its own machines to turn an IP address into a two-letter country code; no address leaves the service, and none is stored.
An external uptime monitor receives only a signal that TraceLog is running. Once an hour a background process sends one request to a fixed address, with no content and no parameters — no personal data, no customer information, and no list of customers. This lets an external service detect if that process stops.
A customer's own platform — their store, CMS, or server — belongs to the customer and is not TraceLog's subprocessor. Integrations run inside that platform under the customer's control.
Changes
Additions are announced to account owners by email before they take effect, and this page carries the date of its last change. Objections go to info@tracelog.io.
If you have questions about this page, email info@tracelog.io. A person from TraceLog will reply.