Data protection
Subprocessors & GDPR
Last updated: July 2026
We're an EU company and process personal data under the GDPR. Koove's twist: the server stores only ciphertext and sealed keys, so no subprocessor ever has access to the plaintext value of your secrets.
Current subprocessors
| Provider | Purpose | Data processed | Location |
|---|---|---|---|
| Vercel Inc. | Hosting and CDN for koove.io and the API. | Request data, IP (access logs). | US / edge global |
| Prisma Data Platform | Managed database (Postgres). | Account data, usage metadata, encrypted envelopes (never plaintext), access logs. | UE / US |
| Stripe Payments Europe | Payment and subscription processing. | Billing email. Card data is handled by Stripe (PCI-DSS L1); Koove never sees it. | IE / US |
| Google (Workspace) | Support, security and legal email. | Any personal data you send us by email. | UE / US |
| Google Analytics 4 | Web analytics — ONLY after your cookie consent. | Pseudonymous site usage. Not loaded without consent. | US |
Anthropic is used only to generate blog content (topics and prompts) and does NOT process users' personal data, so it is not listed as a customer-data subprocessor.
Data Processing Agreement (DPA)
We offer a DPA to companies that need one. Request it at [email protected] and we'll include this subprocessor list as an annex. We'll notify you of changes with reasonable notice.
Your rights
You can access, correct or delete your data and close your account anytime ([email protected]). More detail on the Legal page.