Sub-processors
Last updated: 11 September 2026
To run sundae_bar we use a number of third-party companies. Where any of them handle personal data on our behalf, they act as our sub-processors and are bound by contract to process that data only on our instructions.
This page is the current list. We keep it here, rather than inside our privacy policy, so that it stays accurate: when we add or change a provider we update this page, and you can see what changed without us having to rewrite our policy.
Before we add a new sub-processor we will update this page. If you have an account with us and would like to be told when that happens, email legal@sundaebar.ai and we will add you to the notification list.
Some of these providers operate outside the United Kingdom. Section 9 of our privacy policy explains how we protect your data when it is transferred internationally.
Hosting and infrastructure
| Provider | What we use it for | What it receives |
|---|---|---|
| Vercel | Hosts our website and web application | All web traffic, including IP addresses, pages visited, and anything you submit through the site |
| Railway | Hosts our agent service and API | Data processed while an agent runs, and application logs |
| Upstash | Rate limiting, to keep the service available and prevent abuse | IP addresses, used only as short-lived counters |
Database, accounts and file storage
| Provider | What we use it for | What it receives |
|---|---|---|
| Supabase | Our primary database, sign-in system and file storage | Account details, email address, profile information, agent configurations, conversations, and any files you upload |
AI models and agent features
Scout and the agents you run are powered by AI models we access through a gateway rather than contracting with each model provider directly. Which model answers a given message can vary, including automatic failover between providers, so more than one of the providers below may handle your conversations over time.
| Provider | What we use it for | What it receives |
|---|---|---|
| Vercel AI Gateway | Routes all of Scout's model requests, and executes web search | Your messages, the conversation history replayed with each message, what Scout remembers about you, and the results of any tool an agent uses |
| OpenAI | Answering messages, and separately for search indexing, listing summaries, categorisation and safety checks on submitted files | Conversation content via the gateway. Separately and directly: search terms you type, search terms Scout composes from your conversation, and the text of publicly listed agents and skills |
| Anthropic | Answering messages, and checking messages for prompt-injection attempts | Conversation content, via the gateway |
| Perplexity | Web search, when an agent searches the web | The search query, which is written by the agent and may reflect what you asked it |
| Exa | Web search | As above |
| Tako | Web search | As above |
| Mastra Platform | Monitoring how agents run, so we can find and fix faults | Technical traces of agent activity. We filter recognised sensitive fields before these are sent, though that filtering works on field names and is not a guarantee that no personal content is included |
We do not permit these providers to use your conversations to train their models.
Payments
| Provider | What we use it for | What it receives |
|---|---|---|
| Stripe | Taking payments, managing subscriptions and credit top-ups, and paying marketplace sellers | Your name, email address, billing address, country, VAT or tax number where you provide one, and your payment details. Card numbers go to Stripe directly and are never held by us |
| Taxually | Working out and filing VAT, through Stripe's integration | Transaction records needed for tax returns |
| Provider | What we use it for | What it receives |
|---|---|---|
| Resend | Sign-in, sign-up and password reset emails, and replies to contact form enquiries | Your email address, and the content of any message you send us through the contact form |
| Beehiiv | Our newsletter, if you subscribe | Your email address and your subscription preferences |
Analytics
These providers only receive data if you accept analytics cookies. You can change that at any time through Cookie settings in our footer.
| Provider | What we use it for | What it receives |
|---|---|---|
| Google (Tag Manager and Analytics) | Understanding how people use the site so we can improve it | Pages visited, IP address, general device information, and an account identifier if you are signed in |
| Mixpanel | Understanding how people move through the product | As above |
Advertising
We do not run advertising campaigns continuously. These providers receive nothing about you unless you have accepted marketing cookies, and nothing at all during periods when we are not advertising.
| Provider | What we use it for | What it receives |
|---|---|---|
| Meta | Advertising sundae_bar, and measuring whether an advert led to a visit | That you visited a page, and general device information |
| Advertising sundae_bar, and measuring whether an advert led to a visit | As above | |
| X | Advertising sundae_bar, and measuring whether an advert led to a visit | As above |
Error monitoring
| Provider | What we use it for | What it receives |
|---|---|---|
| Sentry | Recording errors so we can fix them | Technical details of the error, which can include the account identifier and surrounding request information. Sentry processes this in the European Union |
Content and media
| Provider | What we use it for | What it receives |
|---|---|---|
| Sanity | Managing the content on our marketing pages, news and legal documents | Your IP address when your browser loads content or images from it |
| Mux | Hosting and playing the videos on our website, and measuring whether they play smoothly | Your IP address and device details when a video plays, and a viewer identifier cookie only if you have accepted analytics cookies |
Security and abuse prevention
| Provider | What we use it for | What it receives |
|---|---|---|
| Cloudflare | Checking that sign-up, sign-in, contact and submission forms are used by people rather than bots | Your IP address and basic browser signals, when you use one of those forms |
Signing in and importing code
| Provider | What we use it for | What it receives |
|---|---|---|
| GitHub | Signing in with GitHub, and importing skills from repositories you point us at | Your GitHub identity and profile if you sign in that way, and the repository addresses you ask us to read |
| Signing in with Google | Your Google identity and profile if you sign in that way |
sundae_bar Lab and Subnet 121
The Lab works differently from the rest of the platform, and we would rather say so plainly than bury it.
When you submit an agent or skill to a Lab challenge, that submission is evaluated automatically. Part of that evaluation runs on validator software that is open source and operated by independent participants in the Bittensor network on their own hardware, which we do not own or control. Submissions are also sent to several AI providers to be run and scored.
| Provider | What we use it for | What it receives |
|---|---|---|
| Independent validator operators | Running the evaluation that scores submissions | The content of your submission |
| OpenRouter, Together AI, Chutes, Google, OpenAI, Anthropic | Running and scoring submitted agents and skills | The content of your submission |
| TaoStats | Network and pricing data | Publicly visible network identifiers |
| The Bittensor network | Recording rewards and scores on-chain | Wallet addresses, scores and rewards. Anything written to a public blockchain is permanent and cannot be deleted or corrected by us or by anyone else |
If you take part in the Lab, please treat your submissions as material you are comfortable sharing outside our systems.
Questions
Email legal@sundaebar.ai.