Sundae Bar Logo

Sub-processors

Last updated: 11 September 2026

To run sundae_bar we use a number of third-party companies. Where any of them handle personal data on our behalf, they act as our sub-processors and are bound by contract to process that data only on our instructions.

This page is the current list. We keep it here, rather than inside our privacy policy, so that it stays accurate: when we add or change a provider we update this page, and you can see what changed without us having to rewrite our policy.

Before we add a new sub-processor we will update this page. If you have an account with us and would like to be told when that happens, email legal@sundaebar.ai and we will add you to the notification list.

Some of these providers operate outside the United Kingdom. Section 9 of our privacy policy explains how we protect your data when it is transferred internationally.

Hosting and infrastructure

ProviderWhat we use it forWhat it receives
VercelHosts our website and web applicationAll web traffic, including IP addresses, pages visited, and anything you submit through the site
RailwayHosts our agent service and APIData processed while an agent runs, and application logs
UpstashRate limiting, to keep the service available and prevent abuseIP addresses, used only as short-lived counters

Database, accounts and file storage

ProviderWhat we use it forWhat it receives
SupabaseOur primary database, sign-in system and file storageAccount details, email address, profile information, agent configurations, conversations, and any files you upload

AI models and agent features

Scout and the agents you run are powered by AI models we access through a gateway rather than contracting with each model provider directly. Which model answers a given message can vary, including automatic failover between providers, so more than one of the providers below may handle your conversations over time.

ProviderWhat we use it forWhat it receives
Vercel AI GatewayRoutes all of Scout's model requests, and executes web searchYour messages, the conversation history replayed with each message, what Scout remembers about you, and the results of any tool an agent uses
OpenAIAnswering messages, and separately for search indexing, listing summaries, categorisation and safety checks on submitted filesConversation content via the gateway. Separately and directly: search terms you type, search terms Scout composes from your conversation, and the text of publicly listed agents and skills
AnthropicAnswering messages, and checking messages for prompt-injection attemptsConversation content, via the gateway
PerplexityWeb search, when an agent searches the webThe search query, which is written by the agent and may reflect what you asked it
ExaWeb searchAs above
TakoWeb searchAs above
Mastra PlatformMonitoring how agents run, so we can find and fix faultsTechnical traces of agent activity. We filter recognised sensitive fields before these are sent, though that filtering works on field names and is not a guarantee that no personal content is included

We do not permit these providers to use your conversations to train their models.

Payments

ProviderWhat we use it forWhat it receives
StripeTaking payments, managing subscriptions and credit top-ups, and paying marketplace sellersYour name, email address, billing address, country, VAT or tax number where you provide one, and your payment details. Card numbers go to Stripe directly and are never held by us
TaxuallyWorking out and filing VAT, through Stripe's integrationTransaction records needed for tax returns

Email

ProviderWhat we use it forWhat it receives
ResendSign-in, sign-up and password reset emails, and replies to contact form enquiriesYour email address, and the content of any message you send us through the contact form
BeehiivOur newsletter, if you subscribeYour email address and your subscription preferences

Analytics

These providers only receive data if you accept analytics cookies. You can change that at any time through Cookie settings in our footer.

ProviderWhat we use it forWhat it receives
Google (Tag Manager and Analytics)Understanding how people use the site so we can improve itPages visited, IP address, general device information, and an account identifier if you are signed in
MixpanelUnderstanding how people move through the productAs above

Advertising

We do not run advertising campaigns continuously. These providers receive nothing about you unless you have accepted marketing cookies, and nothing at all during periods when we are not advertising.

ProviderWhat we use it forWhat it receives
MetaAdvertising sundae_bar, and measuring whether an advert led to a visitThat you visited a page, and general device information
GoogleAdvertising sundae_bar, and measuring whether an advert led to a visitAs above
XAdvertising sundae_bar, and measuring whether an advert led to a visitAs above

Error monitoring

ProviderWhat we use it forWhat it receives
SentryRecording errors so we can fix themTechnical details of the error, which can include the account identifier and surrounding request information. Sentry processes this in the European Union

Content and media

ProviderWhat we use it forWhat it receives
SanityManaging the content on our marketing pages, news and legal documentsYour IP address when your browser loads content or images from it
MuxHosting and playing the videos on our website, and measuring whether they play smoothlyYour IP address and device details when a video plays, and a viewer identifier cookie only if you have accepted analytics cookies

Security and abuse prevention

ProviderWhat we use it forWhat it receives
CloudflareChecking that sign-up, sign-in, contact and submission forms are used by people rather than botsYour IP address and basic browser signals, when you use one of those forms

Signing in and importing code

ProviderWhat we use it forWhat it receives
GitHubSigning in with GitHub, and importing skills from repositories you point us atYour GitHub identity and profile if you sign in that way, and the repository addresses you ask us to read
GoogleSigning in with GoogleYour Google identity and profile if you sign in that way

sundae_bar Lab and Subnet 121

The Lab works differently from the rest of the platform, and we would rather say so plainly than bury it.

When you submit an agent or skill to a Lab challenge, that submission is evaluated automatically. Part of that evaluation runs on validator software that is open source and operated by independent participants in the Bittensor network on their own hardware, which we do not own or control. Submissions are also sent to several AI providers to be run and scored.

ProviderWhat we use it forWhat it receives
Independent validator operatorsRunning the evaluation that scores submissionsThe content of your submission
OpenRouter, Together AI, Chutes, Google, OpenAI, AnthropicRunning and scoring submitted agents and skillsThe content of your submission
TaoStatsNetwork and pricing dataPublicly visible network identifiers
The Bittensor networkRecording rewards and scores on-chainWallet addresses, scores and rewards. Anything written to a public blockchain is permanent and cannot be deleted or corrected by us or by anyone else

If you take part in the Lab, please treat your submissions as material you are comfortable sharing outside our systems.

Questions

Email legal@sundaebar.ai.