Data protection

Subprocessors & GDPR

Last updated: July 2026

We're an EU company and process personal data under the GDPR. Koove's twist: the server stores only ciphertext and sealed keys, so no subprocessor ever has access to the plaintext value of your secrets.

Current subprocessors

ProviderPurposeData processedLocation
Vercel Inc.Hosting and CDN for koove.io and the API.Request data, IP (access logs).US / edge global
Prisma Data PlatformManaged database (Postgres).Account data, usage metadata, encrypted envelopes (never plaintext), access logs.UE / US
Stripe Payments EuropePayment and subscription processing.Billing email. Card data is handled by Stripe (PCI-DSS L1); Koove never sees it.IE / US
Google (Workspace)Support, security and legal email.Any personal data you send us by email.UE / US
Google Analytics 4Web analytics — ONLY after your cookie consent.Pseudonymous site usage. Not loaded without consent.US

Anthropic is used only to generate blog content (topics and prompts) and does NOT process users' personal data, so it is not listed as a customer-data subprocessor.

Data Processing Agreement (DPA)

We offer a DPA to companies that need one. Request it at [email protected] and we'll include this subprocessor list as an annex. We'll notify you of changes with reasonable notice.

Your rights

You can access, correct or delete your data and close your account anytime ([email protected]). More detail on the Legal page.