SUBPROCESSORS
Last updated August 22, 2026
This page lists every third-party data processor ("Subprocessor") that Roverly Inc. ("we," "us," or "our") engages to help deliver our services (the "Services"). It is referenced by our Privacy Notice: https://roverly.ai/legal/privacy.
Each Subprocessor below is engaged under a written data processing agreement carrying obligations at least as protective as those we commit to. Our own Data Processing Addendum is available on request from legal@roverly.ai.
CURRENT SUBPROCESSORS
| Provider | Purpose | Data processed | Location |
|---|---|---|---|
| Google Cloud Platform (Google LLC) | Compute, database, blob storage, networking, logging, and monitoring | All customer crawl data (screens, logs, anomalies, settings) — redacted at source — plus account metadata | us-east1 (South Carolina, United States) |
| Google Gemini API (Google LLC) | AI inference — screen understanding, navigation decisions, difference classification, and screen-identity judging | Screenshots and accessibility trees from the active crawl — redacted on your device before they are sent | United States regional endpoint |
| Stripe, Inc. | Subscription billing and payment processing | Billing contact name and email, subscription metadata, and payment tokens. Stripe holds card data; we never store full card numbers | United States |
| Resend | Transactional email — sign-in links, invitations, verification, billing notices, and contact-form delivery | Recipient name, email address, and message content, including single-use link tokens | United States |
| WorkOS, Inc. | Enterprise single sign-on, directory sync (SCIM), and audit-log streaming. Enterprise plans only; opt-in | Work email, single sign-on and directory identifiers, attributes and group membership, and forwarded authentication-audit events | United States (EU region available) |
| Cloudflare, Inc. (Turnstile) | Bot and abuse protection on sign-in, sign-up, and single sign-on authorization | Client IP address, browser and interaction signals, and the challenge token at authentication time. No cross-site tracking | Global (edge network) |
| Nango | OAuth connection brokerage for Jira and GitHub integrations. Only if you connect Jira or GitHub | OAuth tokens (held by Nango, not by us) and connector metadata, plus the issue payload we file on your behalf | United States (EU region available) |
| Google Analytics (Google LLC) | Website analytics for our public site — traffic sources, page views, and aggregate usage. Not used in the signed-in dashboard | Cookie identifiers, IP address, page paths, and browser and device characteristics — collected only after you consent to analytics cookies | United States |
Redacted at source
Our Desktop Agent redacts detected personal and payment-card data on your device before any capture is uploaded or sent for AI inference. The Subprocessors above therefore receive redacted content, not the raw values. Redaction is best-effort detection and is on by default; a workspace administrator may opt a tenant into unredacted capture, and each run permanently records the mode it ran under.
Data boundaries
- Card data never reaches us. Stripe collects and holds it; we store only a billing contact and subscription state.
- OAuth tokens never reach us. Nango holds the token you authorize and injects it at request time; we persist only a non-secret connection handle. Jira and GitHub are your own systems that we file into on your behalf, not our Subprocessors.
- WorkOS, Cloudflare Turnstile, and Nango are opt-in or configuration-gated. A tenant that has not enabled the corresponding feature shares no data with that vendor.
Configured but not active
Stytch (a device-fraud signal on the authentication surface) is present in our codebase but is not currently enabled — no credentials are configured, so it processes no data today. If we turn it on, it will be added to the table above, with notice, before it goes live.
WHAT WE DO NOT USE
We keep this list short and add a vendor only when a feature requires one. As of the date above we do not use:
- Third-party analytics in the dashboard. No analytics tag is deployed in the signed-in dashboard; we rely on our own first-party request logging there. Google Analytics runs on our public website only, and only if you consent to analytics cookies.
- A content delivery network for static assets. Our sites are served directly from our own cloud project. Cloudflare appears above only for Turnstile bot protection, not as a CDN.
- A customer support platform. Support runs through email to legal@roverly.ai, not a hosted helpdesk.
CHANGES TO THIS LIST
If we add or replace a Subprocessor, we update this page and notify every active customer contact at least thirty (30) days in advance, so that you have an opportunity to object before the change takes effect. To raise an objection, contact us using the details below.
| Date | Change |
|---|---|
| April 23, 2026 | Initial publication |
| July 9, 2026 | Documented on-device redaction at source. No Subprocessor added or removed |
| July 10, 2026 | Documented the full active Subprocessor set already in service (Stripe, Resend, WorkOS, Cloudflare Turnstile, Nango); noted Stytch as configured but inactive |
| August 22, 2026 | Reissued in final form. No Subprocessor added or removed |
| August 22, 2026 | Added Google Analytics for the public website, gated on your consent |
HOW CAN YOU CONTACT US ABOUT THIS LIST?
If you have questions about a specific Subprocessor, our vendor-diligence process, or wish to object to a change, you may email us at legal@roverly.ai, call us at (+1)9049300419, or contact us by post at:
Roverly Inc.
5412 Olimpico Wy
Leander, TX 78641
United States