What this page is
A subprocessor is a company we use to run the service that may process personal data on our behalf. This list lives on its own page, separate from the Privacy Policy, because it changes more often than the policy does — and because a list you can link to directly is more useful than a paragraph buried in a longer document.
The Privacy Policy explains what we process and why. This page answers the question 'who else'.
Always involved
These are part of running the service — you cannot use PS UI TOOLKIT without them.
- Hetzner Online GmbH — hosting
- Runs the servers that hold the application, the database, your uploaded logos and your generated packages. Location: Falkenstein, Germany (EU). Receives: everything described in section 3 of the Privacy Policy, because it is the infrastructure that data sits on.
- Resend — transactional email
- Delivers account email: address confirmation, password reset, trial reminders and support notifications. Receives: the recipient address, the subject and the message body. Confirmation email is mandatory to sign up, so this one is unavoidable.
- Let's Encrypt — TLS certificates
- Issues and renews the HTTPS certificate for the site automatically. Receives: the domain name and the operator's own certificate account address. No customer data.
- GitHub Container Registry — software distribution
- Where the production container images are pulled from during deployment. Data flows towards us rather than away from us: no customer data is sent.
Only if you turn it on
Nothing reaches these unless the corresponding feature is active.
- The AI provider you choose — AI assistant
- Off by default and only available on Pro and Max. Selectable from a fixed list: OpenAI, Anthropic, Google Gemini, xAI, DeepSeek, Moonshot and NVIDIA. Receives: the full manifest of the project you are working on, your message and any pasted text, recent conversation history, and your custom templates if you ask for a template. Section 5 of the Privacy Policy has the detail. Your key, your account with them, their terms.
- Payment provider — not chosen yet (merchant of record)
- There is no entry to make here yet, and we would rather show the empty slot than quietly leave it out. No payment company has been selected, the production configuration names none, and the product has no checkout — so nothing has ever been sent to anyone for billing. Once payments go live, the chosen merchant of record will appear here by name and will receive your email address, your workspace identifier and the plan you chose, and it will hold the billing and tax records as seller of record. Card data will go to it directly and will never pass through us. We will name it on this page before the first charge, not after.
Not used at all
For the avoidance of doubt, none of the following appears anywhere in the product:
- Analytics, product telemetry, session recording and heatmaps. The website loads no third-party script of any kind.
- Advertising networks, remarketing pixels and data brokers.
- Content delivery networks and external font services. Fonts are bundled and served from our own domain, and the content security policy blocks connections to other origins outright.
Changes to this list
When we add or replace a subprocessor we update this page and the date at the top. If the change affects what leaves the platform, we will also announce it in the app before it takes effect.
If your organisation needs advance notice of subprocessor changes under a contract, or needs a data processing agreement, write to us and we will arrange it.
Contact
Questions about this list: info@psuitoolkit.com.