The services that help us run Writ.
We rely on a small, deliberate set of sub-processors. Here is each one, the role it plays, and the data it touches.
Sub-processors
Each provider is engaged under a data processing agreement and processes data only as needed to deliver Writ.
Stripe
- Purpose
- Payment processing for subscriptions and prepaid-wallet top-ups.
- Data categories
- Billing contact (email, billing address), payment metadata, tax ID where required. Full card numbers are not stored by Writ.
- Region
- United States / EU
- Conditional?
- No - part of the standard Service.
DigitalOcean
- Purpose
- Cloud hosting, compute, and the managed run fleet; object storage where DigitalOcean Spaces is used.
- Data categories
- Application data, run artifacts, and encrypted secrets at rest.
- Region
- United States / EU
- Conditional?
- No - part of the standard Service.
Anthropic
- Purpose
- Managed AI model inference for AI sessions, navigation, and assistive features.
- Data categories
- Prompt content for AI navigation. Never your encrypted secrets or personas.
- Region
- United States
- Conditional?
- Managed AI only - not used when you supply your own (BYO) AI key or run locally.
OpenAI
- Purpose
- Managed AI model inference for AI sessions, streaming, and assistive features.
- Data categories
- Prompt content for AI navigation. Never your encrypted secrets or personas.
- Region
- United States
- Conditional?
- Managed AI only - not used when you supply your own (BYO) AI key or run locally.
Google (Gemini)
- Purpose
- Managed AI model inference and grounded web-search for AI features.
- Data categories
- Prompt content for AI navigation and search grounding. Never your encrypted secrets or personas.
- Region
- United States
- Conditional?
- Managed AI only, and only when a Gemini key is configured - not used on BYO or local runs.
Email delivery (SMTP)
- Purpose
- Transactional email and email notifications - verification, alerts, and billing.
- Data categories
- Recipient email address and message content.
- Region
- United States / EU
- Conditional?
- No - part of the standard Service.
Sentry
- Purpose
- Backend error and diagnostic reporting.
- Data categories
- Error and diagnostic events with stack context; not intended to carry personal data.
- Region
- EU / United States
- Conditional?
- Only when an error-reporting DSN is configured; otherwise disabled.
Cloudflare
- Purpose
- Edge / CDN in front of the API, Turnstile bot-defense captcha, and the edge-resolved country header for the sanctions/embargo gate.
- Data categories
- Request metadata, IP, and user agent; captcha challenge token; ISO-3166 country from the edge header.
- Region
- Global edge
- Conditional?
- Turnstile runs only when configured as the captcha provider; the country header is trusted only when Cloudflare fronts the API.
hCaptcha
- Purpose
- Alternative bot-defense captcha (a drop-in replacement for Turnstile).
- Data categories
- Captcha challenge token and IP for verification.
- Region
- United States / EU
- Conditional?
- Only when hCaptcha is configured as the captcha provider.
Twilio
- Purpose
- SMS notification delivery (and WhatsApp where configured) for alerts you set up.
- Data categories
- Destination phone number (E.164) and message body.
- Region
- United States / EU
- Conditional?
- Only for the SMS/WhatsApp notification channel, and only when Twilio credentials are configured and enabled.
S3-compatible object store
- Purpose
- Storage of tenant file assets, run artifacts, and backups.
- Data categories
- File-asset bytes, run outputs, and encrypted data at rest.
- Region
- Provider / region-dependent
- Conditional?
- Default is Writ-hosted storage; an external S3-compatible provider (AWS S3, DigitalOcean Spaces, Cloudflare R2) is used only when configured per-tenant or by env.
PostHog
- Purpose
- Privacy-first product analytics for the marketing site and app, consent-gated.
- Data categories
- Usage events and page views after consent. No run content, credentials, or extracted data.
- Region
- EU (self-hostable)
- Conditional?
- Only after the visitor accepts analytics in the consent banner.
Notice of changes
We update this list when we add or remove a sub-processor. Enterprise customers can request advance notice of material changes as part of a Data Processing Addendum. To be notified, or to ask about a specific provider, contact our team.
Questions about how we process data?
Request our DPA or ask about a specific sub-processor.