Deadline Pilot uses the subprocessors below to deliver our service. Each handles a specific function — authentication, hosting, document storage, AI extraction, email delivery, or operational support. Customer data shared with each subprocessor is limited to what that function requires.
We notify customers at least 30 days before adding a new subprocessor or materially changing how an existing one is used. Notifications go to your account email and are also posted to this page.
What the status column means. DPA signed means a data processing agreement is executed with that vendor. DPA pending means we rely on the vendor’s standard terms while the agreement is being put in place. Standard ToS means the vendor receives no customer data, so no processing agreement is required.
Rows marked Not in use are providers our software can be configured to use but which receive nothing today. They are listed in advance so that enabling one is never a surprise.
Updated 2026-09-11: the statuses for Anthropic, OpenAI and Google Cloud were corrected from “signed” to “pending”, and Migadu, Namecheap, DeepSeek, xAI and Portkey were added. If you need a signed agreement with any specific vendor before you use the service, write to privacy@deadlinepilot.com and we will tell you where that stands.
Current subprocessors
| Subprocessor | Purpose | Data accessed | Location | DPA |
|---|---|---|---|---|
| Render | Hosting (frontend, backend, worker), managed Postgres, managed Redis | All application data — Render hosts the app | United States (Oregon) | DPA signed |
| Clerk | User authentication, session management, MFA, OAuth providers | Email, name, IP addresses, session metadata | United States | DPA signed |
| Stripe | Payment processing, subscription management, invoicing | Email, billing address, payment method tokens (no card numbers) | United States | DPA signed |
| Cloudflare | Object storage (R2) for uploaded documents and generated calendar files; CDN in front of the site | Uploaded documents (PDF, DOCX), generated .ics files | Global edge (your data resides in your selected R2 jurisdiction) | DPA signed |
| Postmark | Transactional email delivery; inbound email parsing for the E-Service forwarding flow | Outbound email contents; inbound email contents (when you forward to your unique address) | United States | DPA signed |
| SendGrid | Email delivery fallback when Postmark is unavailable | Outbound email contents | United States | DPA signed |
| Anthropic | AI extraction of deadlines from court orders (Claude API) | OCR text from your uploaded documents (up to 50,000 characters per call); page images when direct-vision mode is enabled | United States | DPA pending |
| OpenAI | Alternative AI extraction provider | OCR text from your uploaded documents (when configured as the active provider) | United States | DPA pending |
| Google Cloud (Vision API) | OCR for scanned PDFs | PNG renders of your document pages (typically 200–300 DPI) | United States | DPA pending |
| Sentry | Error tracking and performance monitoring (when enabled) | Exception messages, request metadata (sanitized to remove credentials and PII) | United States | DPA signed |
| Migadu | Inbound email for our @deadlinepilot.com addresses | Any message you send to privacy@, legal@, security@, support@ or accessibility@ — including the content of a data-subject access, correction or erasure request | Switzerland / European Union | DPA pending |
| Namecheap | Authoritative DNS for deadlinepilot.com | No customer data — DNS records only | United States | Standard ToS |
| DeepSeekNot in use | Selectable alternative AI extraction provider | None today. Would receive OCR text from your documents if enabled. | China | DPA pending |
| xAI (Grok)Not in use | Selectable alternative AI extraction provider | None today. Would receive OCR text from your documents if enabled. | United States | DPA pending |
| PortkeyNot in use | Optional AI gateway that proxies requests to the provider above | None today. Would receive whatever the AI provider receives if enabled. | United States | DPA pending |
| GitHub | Source code, CI/CD pipelines, dependency vulnerability scanning | Source code only — no customer data | United States | Standard ToS |
Questions or objections
If you have questions about how these subprocessors handle your data, or if you'd like to object to the addition of a new subprocessor, contact privacy@deadlinepilot.com. For security reports, see our security page.