Legal

Subprocessors

Last updated 11 September 2026

These are the third parties that may process data on our behalf when you use MastroSDR. This page is referenced by our Data Processing Addendum.

Used by every workspace
ProviderPurposeData involved
VercelHosts and serves the MastroSDR applicationEvery request to the site or the app, and the IP address it came from. Application data passes through it in transit.
NeonRuns the Postgres database everything is kept inAll application data at rest: accounts, workspaces, prospects, drafts, messages and delivery events.
Trigger.devRuns the scheduled and background work: queued sends, reply and bounce checks, and list refillsWhatever the job it is running reads or writes, which includes prospects, drafts and message records.
CloudflareTurnstile, the challenge on the sign-up, sign-in and password reset formsYour IP address and a browser signal, at the moment you submit one of those three forms.
StripePayments and subscription managementBilling contact and payment metadata. Card numbers go directly to Stripe and never reach us.
ResendDelivers MastroSDR's own account email: password resets, address confirmation and team invitations. Your outreach never goes through it. That leaves your own mailbox.Your account email address and the contents of those messages
GooglePlaces, the business directory a search on the Find screen runs againstThe words you search for, such as a trade and a town. None of your own prospects are sent to it.
Brave Search or SerperFinds companies that are not on a map, and looks for the right person when a site names nobodyThe search terms, and a company name or domain when the search is about a specific company.
tregContact discovery and enrichment: finds a published business email address for a companyCompany name, company domain, contact name. treg routes each lookup on to whichever data provider answers it, so those companies receive the same three fields.

Providers you choose

For sending, and for AI once you connect a key, you decide which of these companies processes your data and you contract with them directly.

Only the providers you connect
ProviderPurposeData involved
Your AI providerGenerates email drafts on requestYour pitch text and the prospect details for the email being written
Your email providerDelivers the emails you sendRecipient address, subject and body
An assistant you connectReads and writes on your behalf when you connect it, such as Claude or ChatGPTWhatever the permissions you approved allow, which may include prospects and drafts
Your CRMRecords replies, bounces and unsubscribes against the contact, on a workspace where a HubSpot connection is switched on. Nothing is sent to a CRM otherwise, and the signed webhook carries the same events to any endpoint you add.The prospect's email address, contact name and company name, and a note on the contact's timeline describing what happened

If you connect no email provider, MastroSDR cannot send on your behalf at all, though you can still export drafts and send them yourself.

A sending domain we manage

You can send from your own mailbox, which is the default and involves none of the companies below. You can also have MastroSDR set up a sending domain for you. Mail from that domain leaves through our relay rather than your mailbox, so these three become subprocessors for as long as you use it.

Only if you use a sending domain we set up
ProviderPurposeData involved
Amazon Web ServicesRelays mail from a sending domain MastroSDR manages, and holds that domain's sending identityRecipient address, subject and body of every email sent that way. This relay is ours, not yours.
CloudflareHolds the DNS for a managed sending domain, and routes replies to it back to youThe domain's records, and the sender and contents of any reply that comes back through it.
Name.comRegisters a domain bought through the done-for-you setupThe registrant name, address, email and phone that ICANN requires for a registration.

The domain and its signing key are yours. We publish the records and relay the mail; you can point the domain elsewhere at any time and keep sending from it.

The AI drafts included with a paid plan

Paid plans include a monthly allowance of AI drafts that run without you connecting anything. Those drafts are generated through our provider account, which makes that provider a subprocessor for your prospect data whenever the allowance is used.

Used only when you have not connected your own AI key
ProviderPurposeData involved
GroqWrites the AI drafts included with a paid plan, on MastroSDR's own accountThe prospect details and pitch used to generate an email. Only while the included allowance is in use.

This applies only while you are drawing on the included allowance. Connect your own AI key and every generation goes through your account instead, from that moment on, and this provider stops processing anything of yours. Point MastroSDR at a self-hosted or local model and nothing leaves the machine you name.

Our website, not your workspace

Two analytics providers see visitors to our marketing pages. Neither has access to workspace data of any kind: not prospects, not drafts, not replies, not your pitch. Meta's advertising script is not loaded on any signed-in screen at all.

Visitors to our marketing site
ProviderPurposeData involved
Meta (Facebook)Measures our advertising: which ad a visitor arrived from, and whether they went on to create an accountMarketing pages only, never a signed-in screen. Page views, IP address, browser user agent, and on sign-up a one-way hash of the email address. Automatic form scraping is switched off.
PostHogProduct analytics: which screens are used and where people get stuckPage views and feature usage, served through our own domain. Session recording is switched off in our code, so no screen contents, prospect names or draft text are ever captured.

Changes

We will update this page and notify account owners by email before adding a subprocessor that processes customer personal data.