Legal

Subprocessors

These are the third parties that process data on behalf of Pressbotics. Nothing else is in use. Each row states what the service is for and which categories of personal information it actually receives.

Last updated 13 September 2026. Questions: info@pressbotics.com. This page describes how the Pressbotics service actually behaves; it is not legal advice and has not yet been reviewed by a lawyer.

Current subprocessors

This list is current as of 13 September 2026. We will update this page when a subprocessor is added, removed or replaced, and business customers under our Data Processing Addendum receive notice of changes.

Pressbotics subprocessors, purpose, data received and processing location
SubprocessorPurposeCategories of data receivedWhere processed
SupabaseDatabase, authentication and file storage — the primary system of record.Account identifiers (email, user id), workspace and site records, action history, encrypted WordPress credentials, agent key hashes, encrypted MFA secrets, support threads, security events including IP addresses.United States (AWS regions used by the Supabase project).
StytchThe OAuth authorization server behind Connected Apps, used when an AI agent asks for access to a workspace.Organization and member identity tied to a workspace: workspace reference, member identifier and email. No site content and no credentials.United States.
StripePayments, subscriptions and invoicing.Billing identity (name, email, billing address as you enter it) and payment metadata such as subscription and invoice state. Card numbers go directly to Stripe; Pressbotics never receives or stores them.United States and Ireland (Stripe's global processing).
LinearSupport ticket tracking. Every report filed from the app becomes a Linear issue so the team can answer it.The full text of your report, the diagnostic context attached to it (current route, plan tier, recent action identifiers, browser user agent) and the reporting user's email address.United States.
SignupGateSignup abuse and fraud prevention, evaluated once at registration.Email address (including its domain) and originating IP address at the moment of signup. Nothing else, and nothing after signup.United States.
DeepSeekThe large language model behind the in-app assistant.The conversation content you type into the assistant plus the workspace context supplied with it (site names, plan, recent action summaries). Assistant conversation content is sent to a third-party model provider.Outside the EEA; see the AI disclosure on the privacy page.
RailwayHosting for the publishing rail — the component that talks to your WordPress sites.Action payloads in transit (the post content being published), site URLs, and the decrypted WordPress credential only in memory for the duration of a request.United States.
CloudflareDNS, TLS termination, edge delivery and hosting for the web application.Request metadata: IP address, user agent, requested URL, and the request and response bodies in transit.Global edge network; nearest point of presence.

Why the data column is specific

California's CCPA regulations require a business to identify the categories of personal information disclosed to each service provider, not merely to name the vendor. The middle column above is written to that standard: it describes the actual fields each service receives from Pressbotics, as implemented in the code.

What no subprocessor receives

Plaintext WordPress credentials are never stored by any of the services above. They are encrypted with a key held only by the publishing rail and decrypted in memory only for the duration of a publish request. Raw agent keys exist only in your hands — we hold one-way hashes. No subprocessor receives your content for model training, and we do not sell or share personal information for cross-context behavioural advertising.

Questions

Subprocessor questions, or a request to be notified of changes: info@pressbotics.com. This page describes system behaviour as implemented; it is not legal advice.