Subprocessors

Last updated July 31, 2026

Third parties that process data on our behalf. Core subprocessors apply to every workspace. Optional ones only receive data if a workspace explicitly connects them.

Draft — not yet in effect

This document is a prepared baseline awaiting legal review and the registered entity details. It does not yet form a binding agreement. Self-serve signup remains closed until it does.

Core subprocessors

Used by every workspace. Operating the product is not possible without these.

Supabase
Primary database, authentication, and file storage
Data handled: Account details, workspace records, CRM data, uploaded media
Vercel
Application hosting, edge routing, and product analytics
Data handled: Request metadata, IP addresses in transit, aggregate page analytics
Anthropic
The Claude models behind Arc's reasoning and drafting
Data handled: Prompt content: the records and instructions Arc reasons over
Google Cloud (including Gemini)
Agent runner execution, object storage, and generative models
Data handled: Prompt content, generated assets, run logs
Stripe
Subscription billing and payment processing
Data handled: Billing contact and payment details — handled by Stripe, never stored by us
Resend
Transactional email and approved campaign delivery
Data handled: Recipient addresses and message content for approved sends
Sentry
Error monitoring and diagnostics
Data handled: Error traces and limited request context

Optional subprocessors

Only involved when a workspace enables the corresponding connector. If you never turn one on, it never receives your data.

Higgsfield
Generative media, when a workspace enables the connector
Data handled: Generation prompts and resulting assets
HubSpot
CRM import, when a workspace connects it
Data handled: Contact and company records the workspace chooses to import
Mailchimp
Audience import, when a workspace connects it
Data handled: List and contact records the workspace chooses to import
Slack
Operational alerts to a workspace's own channel
Data handled: Alert content only
Meta (Ad Library)
Competitor ad intelligence, when enabled
Data handled: Public ad-library queries — no customer data sent
Google Business Profile
Review monitoring, when a workspace connects it
Data handled: Public review content for the workspace's own listings
NOAA / National Weather Service
Severe-weather signals for a workspace's service area
Data handled: Geographic queries only — no customer data sent

Changes

This list is maintained alongside the code rather than as a separate document, so a new dependency or connector is added here before it ships. We will give notice of material additions to core subprocessors.