Subprocessors and service providers

Last updated: September 16, 2026

Mythos Software, LLC uses the providers below to operate Mythos. Their role depends on the service and data involved. The Privacy Policy covers our controller activities; the Data Processing Agreement covers customer personal data processed on documented instructions.

Providers are identified by service name; their applicable contracting entities are defined in Mythos’s provider agreements. An infrastructure region describes the deployment, not a promise that all support, control-plane processing or downstream subprocessors stay in that country.

Core platform and customer-content processing

ProviderPurpose and dataProcessing locationProvider terms
Supabase (Supabase Pte. Ltd.)Authentication, Postgres and private storage: account information, project and collaboration content, credits, connection metadata and consented analytics records.Mythos’s platform project is in Frankfurt, Germany (eu-central-1). Provider operations and subprocessors can involve other countries.Privacy, DPA
Google CloudApp, isolated build and connector runtime; the dedicated connector-gateway Cloud SQL database; managed secrets, operational logs and scheduling. Receives content needed for requests/builds, encrypted connection credentials, provider-response payloads and execution receipts, plus infrastructure metadata.Main Cloud Run runtime and connector database: Frankfurt, Germany (europe-west3). Certain control-plane and operational processing can occur outside that region, including the United States.Cloud privacy and data processing
GitHubPrivate source repositories, commit history and authorized GitHub connections.United States and other locations under GitHub’s service terms; no EU-only residency promise.Privacy, DPA
OpenAICode-generation inference and optional planning, transcription, document extraction and requested image generation. Receives only the context needed for the selected feature. Mythos does not persist dictation audio or use customer project content to train its own models.Processing under the applicable API account terms; Mythos does not promise EU-only inference or zero provider retention.Business data controls, DPA
CloudflareDNS/security proxy, private preview artifacts and source bundles, immutable published-build storage in R2, edge hosting and consent-controlled analytics transport. Receives private project/build content for storage, public published content and network request metadata; the bounded analytics event excludes raw IP and full user-agent values. Private preview/source objects are not exposed by the public-site Worker.Global edge network and service infrastructure. No blanket EU-only storage or routing commitment.Privacy, DPA
Resend (Plus Five Five, Inc.)Authentication and transactional email, including recipient, bounded collaboration context, action links and delivery events. No project source or provider credentials are intentionally included.Sending region and storage residency differ. The provider documents US storage for account, email metadata, logs and API records even when sending through an EU region.Terms, DPA
SentryScrubbed technical error reports and diagnostic metadata. Session replay is disabled.Mythos uses Sentry’s EU service. Provider support and subprocessors remain subject to its terms.Privacy, DPA

Other service providers and role boundaries

ProviderPurpose and role
StripeHosted Checkout, Billing, customer portal, fraud prevention and financial compliance. Full card details are handled in Stripe’s hosted flow. Stripe can act as processor for certain merchant services and as an independent controller for its own payment and compliance activities. Privacy, DPA.
Fern (Birch Solutions, Inc. dba Fern)Public documentation hosting at docs.mythos.new. Receives public documentation and ordinary visitor requests. Mythos does not send account sessions, private project content or connector credentials through documentation links. Privacy.
Services you connectYour selected GitHub, Supabase and other connected-service accounts remain governed by your provider agreements. They are not all Mythos subprocessors merely because an integration exists. Authorizing an action can transmit the data required by that action to the selected provider.

Changes

For customer processing under our DPA, we give at least thirty days’ advance email or in-product notice of a new or replacement subprocessor, with the objection process described in that agreement. Publication here alone is not proof that individual notice was delivered. Urgent security or continuity changes follow the DPA’s specific exception.

Questions or a supported objection: privacy@mythos.new.