Subprocessors
Records Labs runs on a small set of infrastructure and AI providers. This list names each one and what it does with your data. Each processes data to provide its function. Model providers reached through OpenRouter may also train on it only if your organization picks Allow training as its Data retention policy.
Last reviewed 2026-10-01. A current list is available on request at privacy@recordslabs.ai.
Used for every organization
Hosting and storage
Supabase — database (Postgres), sign-in, and file storage, including uploaded originals, chat attachments, and Creations. Hosted on AWS in the US West region.
TurboPuffer — the search index that holds embeddings of your content (search vectors, not the text itself), one namespace per organization. AWS US West.
Railway — the application servers and ingestion workers, plus the cache they share. US West.
Vercel — hosting for the web application. US West.
Cloudflare — network edge for the web application and for published pages on
recordslabs.site.GitHub — source control and the automated jobs that take encrypted database backups.
AI
OpenRouter — routes answer generation and other in-app AI work to model providers (for example Anthropic, OpenAI, Google, xAI). Your Data retention policy controls which providers are eligible.
Voyage AI — embeddings (turning text and images into search vectors) and reranking of search results.
Mistral, Google Gemini, and Reducto — document extraction and OCR for PDFs that contain tables, figures, drawings, or scanned pages, and for images. Mistral and Reducto can receive the whole PDF file even when only some pages need reading; Gemini receives page images and figure crops. These vendors are called directly, so the Data retention policy does not apply to them, and they may process data outside US West.
OpenAI — transcription of uploaded audio and video, and of YouTube videos whose captions cannot be fetched.
Operations
Stripe — payments, invoices, and billing management.
Resend — sends sign-in, notification, and Help Desk emails, and receives forwarded email for inbox connections.
Sentry — error monitoring. Events carry diagnostics only; request bodies and conversation content are never sent.
Upstash — rate limiting for the public chat widget.
Used only when you enable a feature
Google APIs — only when a member connects Google Drive, Gmail, Google Calendar, Google Contacts, Google Chat, or Google Analytics.
Microsoft — only when a member connects Microsoft 365 or Outlook.
Slack, HubSpot, Salesforce, Zendesk, Intercom, Dynamics 365, Jira, Dropbox, ClickUp, and other business-system connectors — only when your organization connects that system. Records Labs reads from the system. It writes back only when you use that channel (for example, answers posted in Slack) or when a person approves a Skill action, such as updating a CRM record.
Recall.ai — only when the meeting notetaker is used.
FetchTranscript — only when you add YouTube videos as knowledge and YouTube's captions cannot be read directly. It receives the video's ID, not your content.
Exa (reached through OpenRouter) and Tavily — web search for agents that have Public web search turned on, used when the answer model's own search is not available.
Twilio and ElevenLabs — only for organizations that have phone channels turned on. Speech-to-text in those calls runs through Twilio; ElevenLabs supplies the voices.
Alpha Vantage, FRED, Alpaca, and SEC EDGAR — public market data, only for agents using the market data skill.
What this list does not include
Providers used only for Records Labs' internal development, evaluation, and testing do not handle customer data and are not listed. Vendors that a published page or app embeds at your own choice, such as a tag manager you configure under Analytics & tracking, are your own subprocessors, not ours.
Reporting a security concern
Email security@recordslabs.ai. Reports are acknowledged within two business days and triaged within five. Please do not open public issues for security reports.
If you are a customer, you can also open Help and support in the app's sidebar footer, choose Submit a request, and pick the Security or privacy category. Security reports are treated as top priority (P1) on every plan.