Sub-processors
Last updated August 5, 2026
Alloy Systems, Inc. ("Alloy," "we," "us") engages the third parties listed below to help deliver the Alloy service. Each of these sub-processors may process Customer Data on our behalf, in each case limited to what is necessary for the purpose described.
This page describes Alloy's hosted (cloud) service. Customers who run Alloy in a dedicated VPC, in their own cloud account, or on their own infrastructure control their own environment, and the infrastructure sub-processor below does not apply to those deployments. Customers who configure their own model provider or a self-hosted model replace the model sub-processors below with the provider of their choice.
Infrastructure
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| Hetzner Online GmbH | Cloud infrastructure hosting: application servers, database, and S3-compatible object storage | All Customer Data stored by the Alloy hosted service, including messages, files, and workspace content | Germany (EU) |
Model providers
Alloy's AI teammates send prompt content to a large language model provider in order to generate a response. Which provider handles a given request depends on the model selected for that AI teammate.
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| Large language model providers | Generating AI teammate responses, including model routing to the selected provider | Prompt content submitted to an AI teammate: message text, conversation context, and attached file content | Primarily United States |
As of the date above, the providers used for Alloy-managed models are Anthropic, OpenAI, Google, and OpenRouter (which routes requests to further inference providers on our behalf). We may add, remove, or substitute providers within this category as model availability changes; customers can request the current list, or notice of changes to it, using the contact details in our Privacy Notice.
Customers who need a fixed provider can configure their own model provider — such as AWS Bedrock, Google Vertex, or Azure OpenAI — or run a self-hosted model. In that case prompt content is sent to the provider the customer has contracted with directly, and none of the model providers described above process it. On Alloy's hosted service, prompt content still passes through Alloy's infrastructure as described under Infrastructure above.
Operational services
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| FoundryLabs, Inc. (E2B) | Sandboxed code execution for AI teammate tool use | Code and data supplied to a code-execution step by a workflow or AI teammate | United States |
| Functional Software, Inc. d/b/a Sentry | Application error monitoring and diagnostics | Error reports and diagnostic metadata, which may incidentally include user identifiers | United States |
| MailerSend, Inc. | Transactional email delivery | Recipient email address and the contents of transactional messages such as sign-in and notification emails | United States |
Integrations you choose to connect
Alloy connects to third-party systems — such as Slack, Google Workspace (Gmail, Drive, Calendar), Microsoft Teams, and Telegram — only when a customer explicitly enables that integration. When you connect one, data flows between Alloy and that system as needed to operate the integration, and the third party's own terms and privacy policy govern its handling of your data. Disconnecting an integration stops that data flow. These providers are not engaged by Alloy as sub-processors; they act on your instruction as a system you already use.
Changes to this list
We update this page when we add or replace a sub-processor. Customers with an active subscription may request advance notice of changes by contacting us, and may raise a reasonable objection to a new sub-processor as set out in their agreement with Alloy.
Contact
Questions about this list, or about how we process personal information, can be sent to us using the details in our Privacy Notice.