Current August 21, 2026
Sub-processors
The infrastructure, AI, communications, and retrieval providers that help Juno AI Labs deliver Avalon.
1. How to read this list
A Sub-processor processes Customer Personal Data for Juno to provide Avalon. A provider receives only the data needed for its function, subject to configuration and the work a customer requests. Locations describe typical corporate or processing footprints and do not override a workspace’s selected Global or EU storage architecture.
Some model providers are reached through a routing provider. Some capabilities are optional and receive data only when enabled. Customer-directed integrations are listed separately because the customer—not Juno—chooses the destination and instructs the disclosure.
2. Service Sub-processors
| Provider | Service and data | Processing location |
|---|---|---|
| Cloudflare, Inc. | Hosting, regional compute, databases, object storage, durable coordination, queues, content delivery, network security, and operational logs. | Selected Global or EU architecture; global network and support. |
| OpenRouter, Inc. | Routes bounded prompts, task context, and model responses to configured inference providers. | United States; downstream model location varies. |
| xAI LLC | Primary model inference for bounded prompts, task context, and generated responses, routed through OpenRouter. | United States / provider infrastructure. |
| Google LLC | Structured and classification model inference; identity and Google-service access when a customer authorizes those capabilities. | Global provider infrastructure. |
| Anthropic, PBC | Fallback model inference for bounded prompts, task context, and generated responses, when used. | United States / provider infrastructure. |
| Microsoft Corporation | Optional Azure OpenAI real-time dictation and transcription when the feature is enabled. | Configured Azure deployment region. |
| PostHog, Inc. | Product analytics for the Global region, and Global Worker operational logs and traces; product events keyed on a random per-person identifier, account name and email, and — in traces — Durable Object query parameters that can include work stream titles, descriptions, previews, and message previews. European Union workspaces are not exported. | United States. |
| Plus Five Five, Inc. (Resend) | Transactional email, workspace invitations, and inbound-email routing; recipient, sender, message, and delivery metadata. | United States / provider infrastructure. |
| SideGuide Technologies, Inc. (Firecrawl) | Public web search and page retrieval requested by a user or task; search query, target URL, and retrieved public content. | United States / provider infrastructure. |
3. Customer-directed integrations
When a customer connects or instructs Avalon to communicate with one of these services, Avalon sends data to and receives data from that provider at the customer’s direction. The provider is generally the customer’s own vendor or independent controller, not a general Avalon Sub-processor for every customer.
| Service | Customer-directed purpose |
|---|---|
| Google Workspace | Gmail, Calendar, Drive, Docs, and Sheets context and actions authorized by the connected user. |
| GitHub | Repository, issue, pull-request, and related development context and actions. |
| Linear | Issue, project, team, and workflow context and actions. |
| Notion | Page, database, and workspace context and actions. |
| Slack | Workspace bot interactions and optional user-authorized Slack tools. |
| Customer webhooks and email recipients | Data delivered to endpoints or recipients configured by the customer. |
4. Changes and objections
We will update this page at least 15 days before a new Sub-processor begins processing Customer Personal Data, except where an urgent change is necessary for security or availability. The “Current” date identifies the latest revision.
A customer with a Data Processing Addendum may object during the notice period on reasonable data-protection grounds by emailing privacy@with-avalon.com. Include the workspace, provider, and specific concern without sending Customer Content or credentials. The resolution process in the DPA applies.
5. Provider documentation
Provider names and functions are published for transparency. Their own trust centers and privacy documentation may change independently. Contact privacy@with-avalon.com for deployment-specific diligence materials or a signature-ready transfer addendum.