Cogbird is now in private beta.

Subprocessors

Every third party we share data with, and exactly what each one receives.

Last updated

Everace AB uses the third parties below to operate Cogbird. Each receives only what is listed, and each is bound by a data processing agreement. Transfers outside the EU rely on Standard Contractual Clauses.

We will update this page before adding a new subprocessor. To be told when that happens, write to [email protected].

Subprocessors

WhoWhat forWhat they receiveWhere
Hetzner Online GmbHServers and the database. Everything is stored here.All of it — account data, search data, crawled page content.Falkenstein, Germany (EU)
Cloudflare, Inc.DNS and proxy in front of the application.Request metadata in transit. No stored data.Global edge; EU entity Cloudflare Germany GmbH
Anthropic PBCWrites the one explanatory paragraph on a surfaced suggestion, and classifies pages by type. This is the subprocessor most worth reading twice.Page titles, URLs, extracted headings, short extracts of the page text — a few hundred characters at a time — and the numeric evidence behind a finding. Where a change is drafted against a connected repository, the paragraph being edited. Never whole page bodies, and never Search Console credentials.United States
OpenAI, L.L.C.Embeddings only — turning text into vectors so four comparisons can see past paraphrase. No prose is generated here and no judgement is made here.Short text fragments: titles, headings, query strings.United States
DataForSEO LLCCompetitor discovery and result-page measurement.Query strings and domain names. No account data and no page content.United States
Resend, Inc.Transactional email — verification, password resets, verdict notifications. Resend hands delivery to Amazon SES, so that is where the message physically leaves from.Name, email address, and the contents of those messages.United States
GitHub, Inc.Only for a site you have switched on. Reads the repository you install the app on, and opens pull requests against it — including through a coding agent, for the findings no function covers. A site in manual mode — the default — never reaches this.The contents of the repository you grant access to, and the branches and pull requests we open on it. No search data and no account data.United States
Stripe, Inc.Payments and subscription billing.Billing name, email, address and payment details. We never see card numbers.United States / Ireland
PostHog, Inc.Crash reports and which screens get used, so a broken page is found before somebody writes in about it.The path of the page visited, browser and device type, and the message and stack of any error. Not the query string — it carries invite and password-reset tokens — and not the contents of any screen: autocapture and session recording are both switched off, so no domain, query or suggestion of yours is sent.EU region (Frankfurt). Data does not leave the EU.
Google LLCDraws the small icon beside a site name in the app, by resolving that site’s own favicon. Nothing else — this is unrelated to the Search Console grant you issue, which is listed further down as a source you connect.The domain of a site you have added, requested by your browser rather than by us, with the referrer stripped. Google therefore sees a public domain name and the IP that asked for it, and is not told which account it belongs to. No account data and no page content.United States

Sources you connect, which are not subprocessors

These are the other direction. You authorise us to read from them, using a grant you issue and can revoke without involving us — so with one exception they receive nothing from us that was not already theirs. The exception is GitHub, which appears in both lists because a site you have switched on writes to it, and it is called out below.

  • Google Search ConsoleRead-only, on a grant you issue and can revoke in your Google account at any time.
  • Bing Webmaster ToolsRead-only, on an API key you paste and can rotate at any time.
  • PostHogOptional and read-only, on a grant you issue against your own project — in whichever region you already keep it. It answers which pages are worth anything, and nothing is written back.
  • GitHubOptional, and the one connection that is not read-only. Installing the app lets a site you have switched on open pull requests against that repository; nothing merges without you unless you separately turn on auto-merge, and even then only for the changes a fixed rule wrote rather than a coding agent, and only once your own checks report green on the pull request. It is also listed above, because we write to it rather than only read from it.
  • WebflowOptional, and not read-only. A Site API token you generate in that site’s own settings and revoke there, scoped by Webflow to that one site. It lets a site you have switched on propose changes to a page’s SEO title and description — nothing is written until you approve each one — and, where you have also turned on writing new pages, add an item to a collection as an unpublished draft.
  • WordPressOptional, and not read-only. An application password you issue from your own profile and revoke there, which cannot be used to sign in to wp-admin. It is only ever sent over HTTPS. It lets a site you have switched on propose changes to a page’s SEO title and meta description — nothing is written until you approve each one — and, where you have also turned on writing new pages, write a post as an unpublished draft.
  • IndexNowOptional. Submits the URLs you have changed to the search engines that accept being told — Bing and Yandex among them, not Google. They receive a URL on your own domain and the key that proves you own it, and nothing else.

Where the rest of it lives

Everything not listed above — the database, the pages we crawled, the ledger of what was shipped — is stored on servers in the EU and is not shared with anyone. See the privacy policy for how long, and for the two model providers that are worth reading about in full.