Subprocessors
MIOSA uses a small set of third-party subprocessors to run the platform. This page lists each one, the purpose it serves, the category of data it handles, and where it is located.
1. About subprocessors
A subprocessor is a third party that processes personal data on our behalf so that we can deliver a service to you. We engage only a small number, each for a specific and necessary function, and we require every one of them to protect personal data under written terms at least as protective as the commitments we make to you. Engaging a subprocessor does not reduce our responsibility: MIOSA remains accountable to you for the performance of our subprocessors, and we choose them with care.
2. How we notify you of changes
You give us general authorisation to engage subprocessors, and this page is the current, authoritative list. Before we engage a new subprocessor or change how an existing one is used, we update this page so it always reflects current practice.
Where a change materially affects the processing of personal data, we notify Enterprise customers in advance under their agreement and give them an opportunity to object. If you would like to be notified directly, contact enterprise@miosa.ai or support@miosa.ai and ask to be added to subprocessor notifications.
3. Current subprocessors
| Subprocessor | Purpose | Data category | Location | Privacy |
|---|---|---|---|---|
| Resend | Transactional and account email delivery | Account email address, message content | United States | Privacy policy |
| Sentry | Error tracking and crash reporting | Application error data and request/device metadata (sensitive fields redacted) | United States | Privacy policy |
| Commas (FanBasis, Inc. d/b/a Commas) | Payment processing and merchant of record | Name, email, billing address, payment method details | United States | Privacy policy |
| Cloudflare | DNS, TLS certificate issuance and edge delivery | Domain names, request metadata | Global edge network | Privacy policy |
| OpenAI | Documentation assistant and agent model inference (BYOK) | Question text and retrieved documentation excerpts; agent prompts when the customer selects the provider | United States | Privacy policy |
| Groq | Documentation assistant and agent model inference (BYOK) | Question text and retrieved documentation excerpts; agent prompts when the customer selects the provider | United States | Privacy policy |
| Google (OAuth) | “Sign in with Google” authentication | Name, email address, profile picture | United States | Privacy policy |
| GitHub (OAuth) | “Sign in with GitHub” authentication and repository import | Username, email address, public profile data | United States | Privacy policy |
4. Model providers you choose
AI agents and the documentation assistant can call a range of model providers, including Anthropic, OpenAI, Google Gemini, Groq, Mistral, DeepSeek, OpenRouter and a local Ollama runtime. When you select a provider, your prompts and context are sent to that provider for inference under your own API keys (bring your own key). MIOSA does not read or store the content of those prompts and responses, and the provider you choose acts under its own terms and privacy policy. Providers you enable are your choice and your responsibility to review.
5. Analytics
MIOSA does not use third-party advertising or behavioural-analytics subprocessors. Usage data stays within the platform we operate.