Collivo Sub-processors
Last updated: 10 August 2026
To provide the Collivo platform ("the Services"), we use a small number of trusted third-party companies ("sub-processors") that process data on our behalf. Before a sub-processor handles personal information, we put appropriate data-protection terms in place. For most sub-processors this is a Data Processing Agreement requiring them to process data only on our instructions, keep it secure and confidential, and not use it for their own purposes. A small number of AI providers offer their services only on standard terms and do not sign a separate agreement; for these we rely on their published data-processing and privacy terms together with the technical safeguards we configure — such as no-training and zero-data-retention settings — to achieve comparable protection. In all cases we remain responsible to you for how these providers handle your data.
This page lists our current sub-processors. We keep it up to date and will post changes here before a new sub-processor starts handling your data. To be notified of changes, contact us at privacy@collivo.com.
Current sub-processors
| Sub-processor | Service / purpose | Data processed | Primary location |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, file storage, operational logging, and secrets management | Application data and content stored and processed to run the Services | United States |
| MongoDB Atlas | Primary application database | Account data, workspace content, and related metadata | United States |
| Vercel | Hosting and delivery of our marketing website | Website visitor data and basic site analytics; waitlist page delivery | United States / global edge network |
| WorkOS | Authentication, accounts, and single sign-on (SSO) | Name, email address, profile photo, organisation membership, and authentication/audit events | United States |
| Anthropic | Language-model provider for the AI assistant (used directly) | Your prompts, document context, and AI responses; no model training, retained only briefly for safety/abuse monitoring (up to 30 days) then deleted | United States |
| OpenAI | Language-model provider for the AI assistant (used directly) | Your prompts, document context, and AI responses; no model training, retained only briefly for safety/abuse monitoring (up to 30 days) then deleted | United States |
| Groq | Language-model provider for the AI assistant (used directly) | Your prompts, document context, and AI responses; no model training, retained only briefly for safety/abuse monitoring (up to 30 days) then deleted | United States |
| OpenRouter | AI gateway that routes the AI assistant to additional vetted language-model providers | Your prompts, document context, and AI responses, routed under a zero-data-retention configuration | United States (gateway); model providers in the US, EU, or Israel — see note below |
| Together AI | AI image generation | Image-generation prompts and generated images, processed with zero data retention and no model training | United States |
| Brave Search | Web search within the assistant | Search queries you trigger | United States |
| Unsplash | Stock images (e.g., cover images) | Image search terms; serves licensed stock photographs | United States |
| Stripe | Payment processing (applies when paid plans are enabled) | Billing and payment details | United States / global |
| Waitlister | Waitlist sign-up on our marketing website | Email address | United States / global (hosted on Google Firebase) |
AI model providers (behind our AI gateway)
When you use the AI assistant, your prompts are processed by large-language-model providers that generate the responses. By default, we use Anthropic, OpenAI, and Groq directly and also route to additional vetted providers through OpenRouter (our AI gateway). None of these providers train on your content; the direct providers may retain it only briefly for safety and abuse monitoring (up to 30 days) before deletion, while the OpenRouter-routed providers are configured for zero data retention (no storage). An organisation admin can enable Zero Data Retention for their organisation (off by default), which disables the direct providers so that requests run only through the zero-data-retention providers. These providers are located in the United States and, for some OpenRouter-routed models, in the European Union (France, Finland, Spain, the Netherlands, or Sweden) or Israel.
What is not a sub-processor
When you choose to connect a third-party account — for example Google (Drive, Gmail, Calendar), Microsoft (Outlook mail, calendar, SharePoint/OneDrive), Box, or GitHub — Collivo accesses your own data held by that service, at your direction and with your authorisation. Those companies are the providers of services you have chosen to connect, not sub-processors acting on Collivo's behalf, and your use of them remains subject to their own terms and privacy policies. You can disconnect a connected account at any time.
Contact
Questions about our sub-processors or data handling? Contact us at privacy@collivo.com.
Related: Terms of Service · Privacy Policy · Acceptable Use Policy