Subprocessors

Last updated: 2026-07-19.

A subprocessor is any third party that processes customer data on our behalf in order to deliver the service. We keep this list current so B2B customers can do their own vendor review without asking us, and so EU and UK customers can satisfy GDPR/UK-GDPR Article 28(2) obligations.

When we add, change, or remove a subprocessor we send notice at least 30 days before the change takes effect, to the email address on file for each tenant admin. You can object during that window by writing to legal@talkingunicorn.email — if we can't accommodate, you may terminate per the Terms of Service and we will refund any prepaid unused service.


Infrastructure subprocessors

Vendor Role Region Data category
Hetzner Online GmbH Bare-metal + cloud hosting (mail server, MariaDB, Redis, Qdrant) Finland (Helsinki) Email content at rest; account metadata; logs
Lambda, Inc. Dedicated GPU compute we operate for UNI inference (we deploy our own model; Lambda provides hardware only, does not operate an AI over your mail) United States (operator: confirm region) Message content transiently, only during a requested AI task; not retained
Cloudflare, Inc. Reverse proxy / DDoS / Turnstile bot check on signup Global anycast TLS termination of traffic to inbox.talkingunicorn.email; signup form metadata

Note: some UNI inference also runs on hardware we physically own. Owned hardware is not a subprocessor and is not listed here.

Service subprocessors

Vendor Role Region Data category
Stripe, Inc. Subscription billing + Stripe Identity (account verification only) United States, EU Billing email, payment-method tokens, invoice records
Apple Inc. Apple Push Notification service (APNs) for iOS push notifications United States Device push token, message subject snippet
Google LLC Firebase Cloud Messaging (FCM) for Android push notifications United States Device push token, message subject snippet
Let's Encrypt / ISRG Domain-validated TLS certificate issuance United States Public domain names only

AI processing

No third-party AI service processes your mail content. UNI is our own model, run on infrastructure we operate (see Lambda + owned hardware above). We do not send your email content to Anthropic, OpenAI, Groq, or any other hosted AI provider.

If our own inference capacity is unavailable, requests fail over to other inference nodes we operate — never to a third-party AI service.

Vendor Role Region Data category
RunPod, Inc. GPU compute for training tenant-isolated model adapters (optional; not in the live request path) United States Tenant fine-tune datasets only — never raw mail served to end users

Retention: UNI processes the content a request needs and retains nothing beyond your own account memory. See the Privacy Policy → "How UNI handles your mail".


How to be notified of changes

Tenant admins are emailed automatically. Anyone else can subscribe by emailing legal@talkingunicorn.email with subject "Subprocessor updates" — we'll add the address to the notification list and confirm with a one-time opt-in email.

This page is the authoritative version; the dated timestamp above is the last edit. Material changes are also entered in the operator audit log.