Legal
Subprocessors
Last updated: 27 July 2026
Convira OÜ uses a small number of third-party providers to run the product. This page names each of them, says what it does for us, what personal data it can process as a result, and where it operates. It is the companion to the Privacy Policy, which explains what we collect and why, and the Security page, which explains how it is protected.
1. What this page covers
Convira OÜ is the controller for the personal data described in the Privacy Policy. The providers below are the service providers we rely on to run Convira, and they receive personal data only as needed to do the job named against them. We do not sell personal data, and we do not run advertising or cross-site tracking.
This page is kept in step with the Privacy Policy, which lists the same providers alongside the data they handle, and with the Security page. If the three ever disagree, the Privacy Policy is the one to trust and the others are out of date.
2. Current subprocessors
In the same order as the Privacy Policy's sharing table, so the two can be read side by side.
| Provider | What it does for us | Personal data it can process | Where |
|---|---|---|---|
| Stripe | Payments, subscriptions, invoicing | Your card details, which go directly to Stripe - we never see or store them - and your subscription itself: the customer and subscription records, plan, billing currency and amount, seat count for teams, and billing period dates. The matching identifiers and metadata Convira keeps on its own side are listed in the Privacy Policy; the card is not among them. | EU / US |
| Resend | Delivering transactional and contact-form email | The address we send to and the contents of the message. That includes what you enter in the help page contact form or the enterprise inquiry form on the pricing page: your name, email address, and message, plus company and optional team size for enterprise inquiries. | US |
| Cloudflare | Bot protection (Turnstile) on web forms | The Turnstile bot check that runs when you submit a public form on convira.ai. | Global |
| Vercel | Hosting the website and cookieless analytics | Requests to convira.ai, and our aggregate analytics: page views and selected marketing interactions recorded with static labels, the page path, and aggregate context such as referrer, country, and device type. Form values, email addresses, search parameters, and auth-page activity are not sent to analytics, and it sets no cookies. | Global / US |
| Sentry | Error and performance monitoring (personal data scrubbed) | Technical request and error data from the Convira API and web dashboard, configured to exclude authentication headers, cookies, and values that look like passwords, tokens, or secrets. | US |
| Anthropic, OpenAI, Google, xAI | AI model inference for cloud runs | The content of a cloud run - the prompt, files, and context the task needs - forwarded so the provider can generate the response. Anthropic also receives the messages you type into the support chat on this website. See below. | US |
| Supabase | Database and backend hosting for the Convira API | What Convira stores on its own side: account data, billing identifiers and metadata, authentication and security records, and operational metadata about runs. The contents of cloud runs are not stored by us at all, so they are not written here either. | EU |
3. AI model providers
Cloud runs are fulfilled by third-party AI model providers - currently Anthropic, OpenAI, Google, and xAI. To generate a response, the provider receives the content of your request. Each provider processes that data under its own privacy policy and data-retention practices, which we do not control. We pass the request through to the routed provider; we do not retain the request or response content ourselves.
Two things follow from that, and both matter to a review. A single cloud run is routed to one provider, so the four names above are the set that can be involved rather than four companies that each see everything. And a run on the local runtime or a self-hosted Private Box reaches none of them: the agent runs on your own machine or your own server against models you host, and the run record stays on that hardware. The exception is a billed tool you deliberately invoke, described below.
Anthropic appears in one more place. The support chat widget on this website sends the messages you type to Anthropic to generate a reply, so please do not enter sensitive personal data there; for account-specific help, email support@convira.ai.
4. What subprocessors do not receive
A list of who receives data is only half of an answer. The other half is what does not leave, which on Convira is most of it:
- Local and Private Box run content. On the local runtime or a self-hosted Private Box, the agent runs on hardware you control against models you host. Prompts, files, memory, and inference stay there and are not transmitted to Convira as a run. The one exception is a billed tool you choose to invoke - web and X research, image and video generation, connector actions - which needs managed provider keys we hold, so that single call's input plus the identifiers used to route and bill it are sent to Convira to execute and returned to your device.
- The contents of your cloud runs, on our side. We retain only operational metadata about a cloud run - status, timestamps, the runtime, model and provider used, durations, and token and credit usage. The text you entered, the files involved, the tool inputs and outputs, and the model's responses are not stored on our systems; that record lives on your device. The content does pass through our infrastructure in transit on its way to the AI model provider.
- Card details. Payments are processed by Stripe and card details go directly to it. We do not see or store them.
- Anything identifying in analytics. Our analytics is cookieless and receives no form values, email addresses, search parameters, or auth-page activity.
- Credentials. Error monitoring is configured to exclude authentication headers, cookies, and values that look like passwords, tokens, or secrets. Passwords are stored only as Argon2id hashes, never in a form that can be reversed, and third-party model-provider API keys are held in our server environment rather than in the database.
5. Where processing happens
Convira OÜ is based in Estonia, in the EU. Some of the providers above are located in, or process data in, countries outside the European Economic Area, in particular the United States. Where that happens, the transfer is covered by an adequacy decision of the European Commission, by the EU Standard Contractual Clauses, or by another lawful transfer mechanism. Ask us at support@convira.ai for more detail on a specific provider.
The Where column describes where each provider operates, at the level of detail the Privacy Policy states it. Read it as a description, not as a data-residency guarantee - nothing on this page is one. If your requirement is that run content never leaves hardware you control, the answer is the local runtime or a Private Box with managed online tools left off, not a region setting.
6. Changes to this list
When we add, replace, or remove a provider, we update this page and change the date at the top. Contractual arrangements around subprocessor changes - notice periods, and any right to object - belong in a data processing agreement rather than on a public page. If you use Convira to process personal data of others and you are subject to the GDPR as a controller, request the current Data Processing Addendum from support@convira.ai.
7. Contact
Convira OÜ
Järvevana tee 9, Kesklinn, 11314 Tallinn, Harju County, Estonia
Registry code 17268095
support@convira.ai