Subprocessors
Last updated: July 4, 2026
A subprocessor is a third-party company that processes personal data on our behalf while we run AllMCP for you. Because AllMCP acts as a data processor for our customers, we tell you exactly which vendors we rely on, what data they touch, and where they run.
How we notify you of changes
We will give you 30 days' notice before adding a new subprocessor, by updating this page and emailing registered accounts. If you object to a new subprocessor, email privacy@allmcp.co within the notice period and we will work with you on a resolution.
Current subprocessors
| Subprocessor | Purpose | Data touched | Location |
|---|
| Amazon Web Services (AWS) | Cloud hosting for all AllMCP infrastructure | All service data at rest and in transit: account data, encrypted provider credentials (AES-256-GCM), usage metadata logs. Tool-call content passes through in memory and is never stored. | United States |
| Google | OAuth sign-in (relay only) | Your account email and Google account identifier, during sign-in | United States / global |
| GitHub | OAuth sign-in | Your account email and GitHub account identifier, during sign-in | United States / global |
| Sentry | Error monitoring | Error events only, scrubbed of tokens, API keys, and personal data by a denylist-based scrubber before they leave our servers | United States |
| Resend | Transactional email (when enabled) | Your account email address and the content of emails we send you (e.g., account deletion notices) | United States |
| Vercel | Web frontend and API proxy | Request metadata (e.g., IP address, headers) transiting the dashboard and its API proxy | United States / global edge |
What is not on this list
- Our databases and cache are not subprocessors. PostgreSQL and DragonflyDB are self-hosted inside our own AWS VPC — they are infrastructure we operate, not third parties.
- GitBook hosts our public documentation only. It never receives customer or end-user data, so it is not a subprocessor.
- AllMCP is a non-profit with no paid billing, so no payment processor is used. If that ever changes, we will announce it through the notice process above before it goes live.
A note on tool-call content
AllMCP does not store the content of your tool calls — no CRM records, spreadsheets, or messages are persisted. Content flows through our AWS-hosted relay to your connected provider and back to your agent. Usage logs contain metadata only (IDs, provider, tool name, duration, status), plus upstream error strings truncated to 1,000 characters, which may quote fragments of a provider's error text.
Questions? Email privacy@allmcp.co.