The third parties we use to run Athmane, and what each one receives. Each processes personal data only as needed for the function described here. Where a location is still marked below, we have not finished confirming that vendor's processing region and transfer safeguard.
| Sub-processor | Purpose | Data processed | Location / transfer |
|---|---|---|---|
| MiniMax | AI model provider (code generation, chat) | Your prompts + relevant project files | being confirmed |
| E2B | Executes your generated code in a Firecracker microVM to produce the live preview | Your project's source files, and anything your code writes or fetches while running | being confirmed |
| Stripe | Payments, subscriptions, top-ups, invoices | Billing contact + card data (held by Stripe) | being confirmed |
| Resend | Our own transactional email (magic-link sign-in, receipts) | Your email address + message content | being confirmed |
| Hetzner | Cloud hosting / infrastructure (all app data + wallet) | All Service data at rest | EU (Germany / Finland) |
| Cloudflare | DNS + DDoS / WAF in front of the Service, and the CDN that caches your published app | IP addresses, request metadata, and cached copies of your published app's files | being confirmed |
| GitHub | Opt-in integration (push generated code to a repo) | Your GitHub token + the code you push | being confirmed |
| Figma | Opt-in integration (import a design) | Your Figma token + the design you import | being confirmed |
| Name.com | Domain registrar of record when you buy a domain through Athmane | Registrant name, email, phone and postal address (ICANN requires them) | being confirmed |
| Web fonts served from Google’s CDN on every console page, the add-card panel and invoices | Your IP address and User-Agent, on every page load | being confirmed | |
| esm.sh / unpkg / Tailwind CDN | JavaScript and CSS your PUBLISHED app loads directly from these CDNs, in each visitor’s browser | Your visitors’ IP addresses and User-Agents — the request is made by their browser, not by us | being confirmed |
A published app loads some JavaScript and CSS from public CDNs in the browser of whoever visits it. That request carries their IP address, not yours, and it is made by their browser rather than by our servers — so it is a disclosure you may need in your own privacy notice, and we list it here so you can write one that is true. Nothing about your visitors reaches us through it.
That marker means we have not finished verifying where that vendor processes your data, or which transfer safeguard applies to it — so we are not going to state one here. We publish the value once it is settled rather than a value we have not checked. Until then, if a specific vendor's transfer basis matters for your own compliance, ask us at [email protected] and we will tell you exactly where that row stands.
Our application backend (Appwrite) is self-hosted by us on Hetzner, not a separate SaaS vendor — so app data stays within our EU Hetzner infrastructure rather than going to an Appwrite-operated cloud. GitHub and Figma only receive data if you connect them; disconnecting stops further processing.
We are not an email provider. We operate no email infrastructure and do not send mail on behalf of the apps you build. If your app sends email, you connect your own provider account — Resend, Mailjet, SendGrid, Postmark, Mailgun, Brevo, or a compatible endpoint. That provider is your processor under your contract with them: we hold no account there and never move your recipients' data to a vendor of our choosing. We store the credential you give us encrypted, and relay only what your app asks us to relay. List your chosen provider in your own privacy notice. The Resend row above covers only our emails to you.
We update this list before adding or replacing a sub-processor that handles personal data, and — where required — give you a way to object. Questions: [email protected].