Subprocessors
Last updated: 2026-05-28.
A subprocessor is any third party that processes customer data on our behalf in order to deliver the service. We keep this list current so B2B customers can do their own vendor review without asking us, and so EU and UK customers can satisfy GDPR/UK-GDPR Article 28(2) obligations.
When we add, change, or remove a subprocessor we send notice at least 30 days before the change takes effect, to the email address on file for each tenant admin. You can object during that window by writing to legal@talkingunicorn.email — if we can't accommodate, you may terminate per the Terms of Service and we will refund any prepaid unused service.
Infrastructure subprocessors
| Vendor | Role | Region | Data category |
|---|---|---|---|
| Hetzner Online GmbH | Bare-metal + cloud hosting (mail server, MariaDB, Redis, Qdrant) | Finland (Helsinki) | Email content at rest; account metadata; logs |
| Cloudflare, Inc. | Reverse proxy / DDoS / Turnstile bot check on signup | Global anycast | TLS termination of traffic to inbox.talkingunicorn.email; signup form metadata |
Service subprocessors
| Vendor | Role | Region | Data category |
|---|---|---|---|
| Stripe, Inc. | Subscription billing + Stripe Identity (account verification only) | United States, EU | Billing email, payment-method tokens, invoice records |
| Apple Inc. | Apple Push Notification service (APNs) for iOS push notifications | United States | Device push token, message subject snippet |
| Google LLC | Firebase Cloud Messaging (FCM) for Android push notifications | United States | Device push token, message subject snippet |
| Let's Encrypt / ISRG | Domain-validated TLS certificate issuance | United States | Public domain names only |
Optional AI subprocessors
These are only engaged when the tenant has opted in to a non-default provider chain. Operators can swap any of these out from the /operator/llm-providers panel; see also our Privacy Policy §"AI processing & retention".
| Vendor | Role | Region | Data category |
|---|---|---|---|
| Anthropic, PBC | Hosted Claude inference for UNI drafting and Q&A (optional) | United States | Message bodies, tenant prompts |
| OpenAI, LLC | Hosted GPT inference (optional) | United States | Message bodies, tenant prompts |
| Groq, Inc. | Hosted open-weights inference (optional) | United States | Message bodies, tenant prompts |
| RunPod, Inc. | GPU compute for tenant-isolated fine-tunes (optional, Alicorn White Label) | United States | Tenant fine-tune datasets only — not raw mail |
Default behavior is that AI processing runs on our own infrastructure (vLLM on Hetzner). Tenants on Alicorn White Label may opt their workspace into hosted providers via /admin/llm-providers; the choice is per-tenant and recorded in the audit log.
How to be notified of changes
Tenant admins are emailed automatically. Anyone else can subscribe by emailing legal@talkingunicorn.email with subject "Subprocessor updates" — we'll add the address to the notification list and confirm with a one-time opt-in email.
This page is the authoritative version; the dated timestamp above is the last edit. Material changes are also entered in the operator audit log.