Trust & Safety
Subprocessors
Everyone outside DiemDesk who can handle personal data on our behalf, what each one does, and exactly what it can see. Published rather than sent on request, because a reviewer should not have to email us to find out who else is involved.
Last updated August 2026
The complete list — 4
Stripe
Their privacy policyPayments and subscription billing
- What it sees
- Name, email and billing details of paying customers. Card numbers go to Stripe directly and are never seen by DiemDesk.
- Location
- United States, with global processing
Anthropic
Their privacy policyThe AI tools — chat, summarise, translate, question generator, AI find-and-redact
- What it sees
- Only the text a request needs, and only when you invoke an AI tool. Never the file itself, and nothing at all if you do not use those tools.
- Location
- United States
Hostinger
Their privacy policyServer hosting for the site, the API and the server-side conversions
- What it sees
- Account records, and any file passing through a server-side tool for the seconds the conversion takes.
- Location
- European Union
Cloudflare
Their privacy policyDNS, TLS termination and protection against attack traffic
- What it sees
- Connection metadata such as IP address, as any network provider sees. No file contents.
- Location
- Global edge network
Why the list is this short
It is structural, not modest. Most of the catalogue runs inside your browser, so there is no processing to delegate to anyone. A service whose every tool uploads needs a subprocessor for storage, another for the conversion pipeline, a CDN in front of both, and usually an analytics vendor watching all of it. We do not run analytics that identify you, and the tools that never receive a file cannot hand it on.
Who is deliberately NOT on this list
- No analytics or advertising vendor. No Google Analytics, no pixels, no session recording. See Privacy.
- No email marketing platform holding your contacts.
- No customer-support tool with a copy of your documents in a ticket.
- No cloud storage provider for your files. File Vault contents are encrypted on your device before they are stored, so what sits at rest is ciphertext we cannot read.
Changes
We will tell customers before adding a subprocessor, so there is time to object. If you want to be told directly rather than by watching this page, email [email protected] and ask to be on the notification list. This page carries the date it was last reviewed at the top.
Processor terms are on the DPA page.