Sub-processors

Last updated August 5, 2026

Alloy Systems, Inc. ("Alloy," "we," "us") engages the third parties listed below to help deliver the Alloy service. Each of these sub-processors may process Customer Data on our behalf, in each case limited to what is necessary for the purpose described.

This page describes Alloy's hosted (cloud) service. Customers who run Alloy in a dedicated VPC, in their own cloud account, or on their own infrastructure control their own environment, and the infrastructure sub-processor below does not apply to those deployments. Customers who configure their own model provider or a self-hosted model replace the model sub-processors below with the provider of their choice.

Infrastructure

Sub-processorPurposeData processedLocation
Hetzner Online GmbHCloud infrastructure hosting: application servers, database, and S3-compatible object storageAll Customer Data stored by the Alloy hosted service, including messages, files, and workspace contentGermany (EU)

Model providers

Alloy's AI teammates send prompt content to a large language model provider in order to generate a response. Which provider handles a given request depends on the model selected for that AI teammate.

Sub-processorPurposeData processedLocation
Large language model providersGenerating AI teammate responses, including model routing to the selected providerPrompt content submitted to an AI teammate: message text, conversation context, and attached file contentPrimarily United States

As of the date above, the providers used for Alloy-managed models are Anthropic, OpenAI, Google, and OpenRouter (which routes requests to further inference providers on our behalf). We may add, remove, or substitute providers within this category as model availability changes; customers can request the current list, or notice of changes to it, using the contact details in our Privacy Notice.

Customers who need a fixed provider can configure their own model provider — such as AWS Bedrock, Google Vertex, or Azure OpenAI — or run a self-hosted model. In that case prompt content is sent to the provider the customer has contracted with directly, and none of the model providers described above process it. On Alloy's hosted service, prompt content still passes through Alloy's infrastructure as described under Infrastructure above.

Operational services

Sub-processorPurposeData processedLocation
FoundryLabs, Inc. (E2B)Sandboxed code execution for AI teammate tool useCode and data supplied to a code-execution step by a workflow or AI teammateUnited States
Functional Software, Inc. d/b/a SentryApplication error monitoring and diagnosticsError reports and diagnostic metadata, which may incidentally include user identifiersUnited States
MailerSend, Inc.Transactional email deliveryRecipient email address and the contents of transactional messages such as sign-in and notification emailsUnited States

Integrations you choose to connect

Alloy connects to third-party systems — such as Slack, Google Workspace (Gmail, Drive, Calendar), Microsoft Teams, and Telegram — only when a customer explicitly enables that integration. When you connect one, data flows between Alloy and that system as needed to operate the integration, and the third party's own terms and privacy policy govern its handling of your data. Disconnecting an integration stops that data flow. These providers are not engaged by Alloy as sub-processors; they act on your instruction as a system you already use.

Changes to this list

We update this page when we add or replace a sub-processor. Customers with an active subscription may request advance notice of changes by contacting us, and may raise a reasonable objection to a new sub-processor as set out in their agreement with Alloy.

Contact

Questions about this list, or about how we process personal information, can be sent to us using the details in our Privacy Notice.