Adalyst engages the sub-processors below to host, secure, deliver, and operate the Service. Each provider processes customer data only as needed to support Adalyst or where required by law. The list is maintained on change; workspaces with notifications enabled are emailed when an entry is added, removed, or materially changed.
A machine-readable version is served at GET /api/public/sub-processors for customers who track sub-processors inside their own vendor-management system.
| Provider | Purpose | Data categories | Region | DPA |
|---|---|---|---|---|
| Amazon Web Services | Object storage (S3) for uploaded spreadsheets, campaign images, and document assets. |
| US | On request |
| Anthropic | Large language model processing for Adalyst Intelligence analysis, findings generation, and copy rewrites. All prompts are PII-redacted before transmission (see LLM gateway). |
| US | On request |
| Google LLC | Google sign-in (identity), Google Ads and GA4 API connectivity for customers who enable those integrations, and first-party Google Analytics (GA4) measurement on the public Adalyst website. Website analytics (GA4) load only after a visitor accepts analytics cookies. The identity and API uses apply only when a user signs in with Google or connects Google Ads / GA4. |
| US | On request |
| Microsoft | Microsoft sign-in (identity) for customers who choose Microsoft single sign-on. Applies only when a user signs in with Microsoft. |
| US | On request |
| OpenAI | Large language model processing for Adalyst Intelligence chains where Anthropic is not the selected provider. All prompts are PII-redacted before transmission (see LLM gateway). |
| US | On request |
| Railway | Cloud infrastructure hosting for the Adalyst API, worker, and web applications, including the managed PostgreSQL database and the Redis cache and background job queue. Hosted region: us-east4. Includes the primary database and the Redis instance used for background jobs. |
| US | On request |
| Resend | Transactional email delivery (account verification, password reset, invitations, service notices). |
| US | On request |
| Sentry | Application error tracking and performance monitoring. PII scrubbing is applied before events leave the application. |
| US | On request |
| Stripe | Subscription billing, checkout, and payment processing. Card data is handled entirely by Stripe — Adalyst never stores card numbers or CVVs. |
| US, IE | On request |
For questions about this list or DPA documentation, email privacy@adalyst.app. The full Privacy Policy is at /privacy.