Skip to content
OpenE2EE
Legal

Subprocessor List

Providers that process customer information for OpenE2EE services.

ProviderPurposeData boundary
CloudflareRelay compute, encrypted storage, delivery state, security, DNS, and public websiteEncrypted payloads, public key material, opaque routing and usage state, and request metadata
VercelConsole and documentation hostingConsole requests, authentication session data, and project administration
WorkOSConsole authentication and organization identityAccount, organization, and authentication data
StripePayments, subscriptions, tax, invoices, and billing portalBilling identity, payment status, subscription data, and Relay aggregate usage mapped inside Console
Expo, Apple, Google, and browser push servicesData-only device wake deliveryProvider token, project routing, and opaque wake payload; no message plaintext
Better StackAvailability monitoring and public statusProbe results, endpoint status, and sanitized operational metadata
Google WorkspaceBusiness email and support communicationsContact details and communication content

OpenE2EE does not give these providers message plaintext, device private keys, ratchet state, or attachment keys. Some providers can process network metadata that their role inherently requires. The Privacy Notice describes the complete boundary.

We will update this list before adding a subprocessor that handles a new material category of customer data. Send questions to privacy@open-e2ee.dev.