Who handles what

Subprocessors and Third Parties

Last updated September 2, 2026

01Core service providers

Provider/categoryPurposeData involved
AnthropicCommercial AI API and Agent SDKPrompts, conversation context, attachments, tool definitions, output and usage
OpenAICommercial AI API and Codex App Server for selected agent modelsPrompts, conversation context, attachments, tool definitions, output and usage
FastlyContent delivery, TLS edge and traffic deliveryIP address, request metadata and delivered content
OxaPayCurrent cryptocurrency checkout and confirmationOrder/payment reference, plan price, selected asset/network and transaction status
Hosting infrastructure (legal name pending)Application, private storage and backupsAccount, content, workspace, logs and billing records
Configured mail transport (legal name pending)Verification, reset, security, usage and plan emailEmail address and message content
Browser push servicesOptional web notificationsPush endpoint, device/browser routing data and notification content

Infrastructure and mail vendor legal names depend on the production deployment. They must be confirmed in the merchant-readiness review before card processing is activated.

02Optional services you connect

ServiceWhen usedTypical data
Google identityIf you choose Google sign-inName, email, profile image and OAuth account identifier
Google WorkspaceIf you connect Gmail, Calendar or DriveOAuth tokens and the data/actions requested within granted scopes
Apple MusicIf configured and connectedMusic authorization, catalog/library requests and playback state
Remote MCP/API servicesIf you add or invoke themInstructions, headers, credentials and task data needed for the call

03User-directed websites

A website or API visited through Agent mode is usually an independent third party, not an Orrerie subprocessor. It receives the requests, cookies, account information, files and form values required by your authorized instruction. Its terms and privacy policy apply.

04Changes and card processing

Providers can change as infrastructure evolves. Material additions will be reflected by the date above and, where appropriate, an in-service notice. Stripe is not currently an Orrerie processor and must not be listed as active until the account, legal entity and integration exist.

Questions about a provider or international transfer can be sent to hello@orrerie.com.