Subprocessors
Draft pending legal review.
These are the third parties that process data on Orren's behalf, what each holds, and where. This page is referenced by the Privacy Policy and the Data Processing Addendum. We update the date at the top when the list changes.
Infrastructure
- Google Cloud Run (Google LLC, us-central1, United States). Runs Orren's API, worker and brain services. Holds requests in transit and short-lived logs.
- Google Cloud SQL for PostgreSQL (Google LLC, us-central1). Holds synchronised customer records, relationships, connector state and tokens, licence and account records, and diagnostics.
- Google Cloud Storage (Google LLC, United States). Holds app update packages and files a customer uploads for a job, for the life of the job.
- Google Vertex AI (Google LLC, United States). Receives the content of a question and the context assembled to answer it, and media a customer asks to be transcribed or analysed. Models from Google, and Anthropic models served through Vertex AI, may be used. Google's Vertex AI terms prohibit using customer content to train models.
- Google Cloud Logging (Google LLC). Holds service logs: request paths, status codes, timings and error messages. Not customer content.
Communications and payments
- Resend (Resend, Inc., United States). Delivers the six-digit sign-in code to a customer's email address. Holds the address and the delivery record.
- Stripe (Stripe, Inc., United States). Processes licence purchases and renewals. Holds the customer's email, card details and payment history. Orren never sees the card number.
Platforms a customer connects
These are not subprocessors in the usual sense: the customer connects them, and each one acts under its own terms. They are listed so that the flow of data is complete.
- Meta / Instagram. Sends Orren the messages, comments and reactions on the customer's connected professional account; receives the messages and comment replies the customer or their automations send. Orren's servers hold the access token.
- Google (YouTube and Calendar). Provides channel, video and calendar data at the customer's request, with tokens held in the customer's Mac Keychain. Receives calendar bookings the customer asks Orren to write.
- Notion. Provides the pages the customer shared with Orren. Orren's servers hold the token so the sync can run.
- Calendly. Provides bookings and invitees, with a token held in the customer's Mac Keychain.
- Stripe (as the customer's own account). Provides payment events from the customer's own Stripe account so payments can be matched to leads. Orren's servers hold the account reference.
- Other AI assistants the customer connects through Orren's MCP endpoint read the customer's records under the customer's licence and are governed by their own providers.
Apple
- Apple Inc. signs and notarises the application and delivers crash and hang diagnostics to the app on the customer's Mac. Apple does not receive customer records from Orren.
Questions: josh@conquermental.com.