Subprocessors

Last Updated: 2026-08-05

GenieForge Technologies Inc. uses the following categories of subprocessors to help deliver the GenieForge platform. Personal data is shared only as needed for the stated purpose, under contracts that restrict use of the data to providing services to GenieForge.

For the full privacy narrative, see the Privacy Policy and End-User Privacy Policy.


Core Platform

SubprocessorPurposeTypical location
Amazon Web Services (AWS)Hosting, compute, databases, object storage, email delivery (SES), and AI inference via AWS BedrockUnited States
CloudflareCDN, DDoS protection, TLS termination, and custom hostname / vanity domain routingGlobal edge
StripeSubscription billing and invoicing for BuildersUnited States

AI Inference (non-HIPAA Apps)

Non-HIPAA Apps may use additional model providers to generate assistant and agent responses. Prompts, conversation context, and necessary attachments may be sent to these providers.

SubprocessorPurposeTypical location
AnthropicLarge language model inferenceUnited States
OpenAILarge language model inference and related AI features (for example image generation when enabled)United States
xAILarge language model inferenceUnited States

HIPAA-mode Apps are restricted to AWS Bedrock (and other vendors only if covered under GenieForge's Business Associate arrangements). See the HIPAA note below.


Analytics

SubprocessorPurposeTypical location
PostHogProduct analytics (page views, feature usage), subject to cookie preferences (opt-out; consent where required); disabled for HIPAA-touching builder contexts and certain End-User surfacesUnited States

Optional Tools (used only when enabled)

These providers receive data only when a Builder or App uses the related feature.

SubprocessorPurposeTypical location
TavilyWeb searchUnited States
SonioxAudio transcriptionUnited States
ApifyWeb data retrieval / scraping featuresUnited States
Firebase Cloud Messaging / web push providersPush notification deliveryUnited States

Optional tools that send data outside the AWS HIPAA boundary are blocked for HIPAA-mode Apps.


Customer-Directed Integrations

Builders may connect third-party services (for example Google, Slack, Notion, HubSpot, Stripe customer integrations, or custom webhooks). Those destinations are chosen and controlled by the Builder (App Owner). They are not GenieForge subprocessors for GenieForge's own purposes; they process data under the App Owner's instructions and the third party's terms.


HIPAA Note

For Apps with HIPAA mode enabled under a signed Business Associate Agreement, Protected Health Information is processed primarily within the AWS environment covered by GenieForge's Business Associate arrangements. External analytics, non-Bedrock AI providers, and optional tools listed above that are outside that boundary are disabled or blocked for those Apps.

Custom domains may route browser and API traffic through Cloudflare. App Owners processing PHI should use GenieForge-provided hostnames unless GenieForge has confirmed in writing that the custom-domain path is covered under applicable Business Associate arrangements. App Owners remain responsible for Customer-Directed Transfers they configure.


Updates

We may update this list as our providers change. Material changes will be handled consistently with our Privacy Policy. For diligence questions, email privacy@genieforge.ai or support@genieforge.ai.


Contact