Ask The Captain Subprocessor Register
DRAFT FOR HUMAN AND LEGAL REVIEW — NOT APPROVED FOR PUBLICATION OR RELIANCE.
This register reflects the August 2026 plan and current infrastructure configuration, not signed vendor commitments or a completed data-flow audit. “Subprocessor” is used provisionally. Legal roles, locations, contracts, transfer mechanisms, and notification commitments must be confirmed before external tenant data is processed.
Draft date: 31 August 2026
Proposed operator: Someday Somehow Brewing (full legal entity details to be inserted)
Contact for changes or objections: [privacy/legal email to be inserted]
Reviewer note — register commitment: Confirm whether this is a public register, contractual subprocessor list, or internal processing map; define update notice, objection, replacement, and termination rights; and align it with the Terms, privacy notice, DPA, and each vendor agreement.
Proposed providers
| Provider | Proposed role and purpose | Region / processing location | Data categories that may be processed | When used |
|---|---|---|---|---|
| Fly.io | Hosts the Captain API/web workloads in Fly Machines and the per-user hosted CLI environments (Sprites); routes requests; stores Sprite overlays/checkpoints; holds runtime secrets | Primary application region syd (Sydney, Australia). Control-plane, support, network, backup, and Sprite storage locations are not yet contractually verified |
Account and tenant content in requests; prompts/outputs; workflow data; files in transit; logs and network metadata; encrypted runtime secrets; hosted user CLI state | Core service; Sprites only for users who enable hosted AI clients |
| Neon | Managed PostgreSQL database for application records, tenant content, encrypted credentials, audit, queues, and run/cost records | AWS ap-southeast-2 (Sydney, Australia) is configured. Backup, support, telemetry, and control-plane locations are not yet contractually verified |
Identity/account data; tenant business content; integration metadata and encrypted secrets; assistant/workflow records; audit/security events; usage and billing-related records | Core service |
| Amazon Web Services — AWS KMS | Holds the platform master key and performs GenerateDataKey, Encrypt, Decrypt, and DescribeKey for per-tenant envelope encryption |
ap-southeast-2 (Sydney, Australia) |
Tenant and key identifiers in encryption context; wrapped data keys; transient plaintext tenant data keys during KMS operations; KMS audit/usage metadata. Customer secret plaintext is encrypted locally and is not intended to be sent to KMS | Core credential/key protection |
| Cloudflare | Authoritative DNS for askthecaptain.app; current records are DNS-only (proxied = false) |
Global DNS network; account/control-plane locations are not region-pinned | Domain and DNS configuration; administrator/account metadata; DNS query metadata handled by Cloudflare’s authoritative service. Application payloads are not intended to transit Cloudflare while records remain DNS-only | Core DNS |
| GitHub | Hosts source code, issues, CI/CD workflows, deployment configuration, and repository/environment settings; may later provide a tenant-connected task integration | Global service; storage/support locations are not region-pinned in this draft | Developer/admin identifiers; source and infrastructure configuration; CI metadata and deployment events; repository secrets held by GitHub; if a tenant enables the integration, selected issue/task, repository, installation, and user-attribution data | Core engineering/operations; tenant content only when a GitHub connection is enabled |
| Tigris Data | S3-compatible object storage for OpenTofu state; the plan also proposes tenant exports, printable sheets, and uploads | Backend is configured as region auto; physical location and any Australia pinning are not yet verified |
Infrastructure state and resource identifiers, which may contain sensitive configuration metadata; if planned product storage is enabled, tenant files, exports, printable records, and object metadata | Core infrastructure state; product object storage is planned but must be confirmed before use |
| Anthropic | User-connected LLM vendor for Claude/Claude Code assistant processing; the user authenticates directly or supplies a tenant API key under the selected mode | Determined by the user’s Anthropic plan, Anthropic contract, and service configuration; not pinned or verified in this draft and may involve overseas processing | User-selected prompts, retrieved tenant context, conversation content, tool results, outputs, account/workspace identifiers, and usage metadata. Captain must not receive or intermediate Claude subscription session credentials | Conditional and user-directed |
| OpenAI | User-connected LLM vendor for ChatGPT/Codex or API assistant processing; the user authenticates directly or supplies a tenant API key under the selected mode | Determined by the user’s OpenAI plan, contract, and service configuration; not pinned or verified in this draft and may involve overseas processing | User-selected prompts, retrieved tenant context, conversation content, tool results, outputs, account/workspace identifiers, and usage metadata. Captain must not receive or intermediate ChatGPT subscription session credentials | Conditional and user-directed; hosted subscription mode remains subject to policy confirmation |
Reviewer note — provider table: Verify every row against signed terms, DPAs, architecture, production telemetry, vendor subprocessor lists, retention/training settings, government-access terms, security measures, and international-transfer mechanisms. Determine whether Cloudflare, GitHub, Anthropic, or OpenAI is legally a processor, subprocessor, independent controller, or direct provider to the Customer in each mode. Do not promise a region from a configured deployment value alone.
Providers not yet selected or approved
The plan anticipates capabilities that may require additional providers, including transactional email, native push delivery (Apple Push Notification service, Firebase Cloud Messaging, and/or Expo), error tracking, log shipping, payments, analytics, malware scanning, customer support, legal/accounting services, and off-site logical backups. They are not approved by this draft and must be added before personal information is sent to them.
Reviewer note — launch gate: Complete vendor selection and data-flow review before the relevant feature ships. Decide whether Apple, Google/Firebase, Expo, app stores, and professional advisers belong in the public register, privacy notice only, or a separate recipient list.
Proposed review and change process
The owner of this register should review it before each production vendor or data-flow change and at least quarterly. A proposed provider should not receive tenant personal information until security, privacy, contract, location, retention, and deletion reviews are complete. Material changes should be communicated to Customers using the notice and objection process approved for the final DPA or Terms.
Reviewer note — governance: Assign an owner and approver; define the review evidence, risk threshold, emergency replacement process, notice period, objection remedy, version history, and public change channel. “Quarterly” and “material” are proposals, not approved commitments.