Skip to content

Legal

Subprocessors

Last updated 26 August 2026

A subprocessor is a third party Vorx Ltd ("Vorx") engages to process personal information on our behalf in order to deliver the Platform described in our Privacy Policy. This page lists our current subprocessors, drawn directly from the vendors actually wired into our infrastructure rather than a generic list, and what each one is used for.

We review this list against our own configuration when we publish it, but vendors and their roles can change between reviews. Legal entity names below are the vendors' commonly known trading names; contact legal@vorx.com for the precise contracting entity behind any of them, to be notified of changes, or with any other questions.

1. How to read this list

Each entry names the vendor, what we use it for, and roughly what kind of data passes through it. A vendor appears here because Vorx's own infrastructure calls it directly — we did not include tools that only support our internal operations (accounting, recruiting, and the like) and never touch Platform data.

Some vendors act as an intermediary in front of other providers. Where that's true, we say so explicitly rather than listing only the name closest to us.

2. AI model inference — OpenRouter (and, potentially, Anthropic)

Vorx does not currently hold direct accounts with individual AI model providers. Model calls made while generating or editing your app — including the text of your prompts and the code/content generated in response — are routed through OpenRouter, which in turn calls the specific model provider configured for that step (at the time of writing, primarily Anthropic and Google). OpenRouter's own downstream model providers should be understood as further subprocessors of OpenRouter for this purpose, not of Vorx directly, but we name this chain here because it is where your prompt content actually goes.

We are evaluating a direct integration with Anthropic for some model calls. Anthropic is not in use as a direct subprocessor today; we name it now so that, if that evaluation ships, the same processing described above may also flow to Anthropic directly without changing what this page has already told you.

3. Hosting, CDN and deployment — Cloudflare, Fly.io, Google Cloud

  • Cloudflare — DNS, CDN, and edge delivery for vorx.com and published customer sites/apps; sees request traffic to those domains.
  • Fly.io — hosts live preview instances of in-progress builds while you're working on them.
  • Google Cloud Platform — build infrastructure (Cloud Run, Cloud Build) and file storage for uploaded assets (Google Cloud Storage).

4. Customer app backends — Supabase

If you opt an app into a cloud backend, its database and related backend services are provisioned on Supabase infrastructure, under a project Vorx manages on your behalf. Data your app's own users create through it — the app's own end-user data, not just your Vorx account data — is stored there.

5. Billing and payments — Stripe

Stripe processes subscription billing and payment card details. Vorx does not store full card numbers; Stripe handles that as an independent PCI-DSS compliant processor.

6. Authentication and SSO — WorkOS

WorkOS brokers enterprise single sign-on (SSO/SAML) and directory sync for organizations that use it, and handles the identity data that flow requires (email, name, and whatever attributes your identity provider sends).

7. Transactional email — Postmark

Postmark delivers account, billing, and notification emails on our behalf, which necessarily includes your email address and the content of those messages.

8. Product and website analytics — PostHog, Google Analytics

  • PostHog — product analytics and session replay inside the Vorx app itself, so we can see where builders get stuck. Runs only in production, on PostHog's EU Cloud (data is processed in the EU). It can capture in-app interactions and screen recordings of your Vorx sessions — of the Vorx interface, not of your published app's end users.
  • Google Analytics — page analytics on the vorx.com marketing site only. Analytics storage is off by default and only enabled if a visitor grants consent; ad storage and ad personalization stay denied either way. It does not run inside the app.

9. Changes to this list

We'll update the date at the top of this page when we add, remove, or change the role of a subprocessor. For material additions, contact legal@vorx.com to ask about advance-notice arrangements for your account.