Subprocessors

Last updated: May 3, 2026

Phoenix Horizon, Inc. ("Phoenix") uses the third-party subprocessors listed below to deliver Rush and related services. Each subprocessor is bound by a written agreement that requires equivalent security and confidentiality protections to those that Phoenix provides under its own Privacy Policy and Terms of Service.

Change notice. We will give existing customers at least 30 days' notice before adding or replacing a Critical or High tier subprocessor that processes customer personal data. Notices are posted on this page and emailed to account owners. Customers may object by contacting privacy@getrush.ai within the notice period.

Cross-border transfers. Where a subprocessor is established outside the EEA or the UK, transfers are governed by the European Commission's 2021 Standard Contractual Clauses and the UK International Data Transfer Addendum, supplemented by encryption in transit and at rest.

Tiers. Critical = handles customer data on the production path; SOC 2 Type 2 + DPA required. High = handles operational data on Phoenix's behalf; SOC 2 Type 2 or ISO 27001 + DPA required. Low = invoked only when a specific agent the user installs requires the API; the user is notified in the agent's description.

SubprocessorPurposeRegionAttestationTier
SupabaseManaged Postgres (sessions metadata, usage metrics, audit logs, accounts)EU (or US — see notice below)SOC 2 Type 2Critical
HetznerCompute infrastructure for api.prix.devGermany (EU)ISO 27001Critical
CloudflareCDN, DNS, R2 object storage, Origin CA, WorkersGlobal anycastSOC 2 Type 2; ISO 27001/27018; PCICritical
StripePayments and subscription billingUnited States (global)SOC 2 Type 2; PCI DSS Level 1Critical
AnthropicLLM inference (Claude family) routed through our proxyUnited StatesSOC 2 Type 2Critical
OpenAILLM inference routed through our proxyUnited StatesSOC 2 Type 2Critical
OpenRouterLLM routing fallbackUnited StatesSelf-attestedCritical
GoogleOAuth and Gmail / Calendar / Sheets API access (when user authorizes)United States / globalSOC 2 Type 2; ISO 27001/27018Critical
MicrosoftOAuth and Microsoft 365 API access (when user authorizes)United States / EUSOC 2 Type 2; ISO 27001Critical
SlackOAuth (workspace integration) when user authorizesUnited StatesSOC 2 Type 2; ISO 27001High
Twitter (X)OAuth when user authorizesUnited StatesSOC 2 Type 2High
NotionOAuth when user authorizesUnited StatesSOC 2 Type 2High
WorkOSSingle sign-on for organisationsUnited StatesSOC 2 Type 2Critical
1Password BusinessEncrypted secrets vault for production secretsPer tenantSOC 2 Type 2Critical
TailscaleZero-trust overlay network for administrative accessGlobalSOC 2 Type 2Critical
GitHubSource code and CIUnited StatesSOC 2 Type 2High
Better StackCentralized log storageEUSOC 2 Type 2High
ResendTransactional and operational emailUnited StatesSOC 2 Type 2High
Grafana CloudMetrics dashboards and alertingUnited States / EUSOC 2 Type 2; ISO 27001High
PostHogProduct analytics (subject to your consent)United States / EUSOC 2 Type 2High
SentryCrash and error reportsUnited StatesSOC 2 Type 2High
TelegramOperational alerts only — no customer content; migration to PagerDuty in progressGlobalSelf-attestedHigh
SendblueiMessage gateway for outbound notificationsUnited StatesSelf-attestedHigh
HiggsfieldImage / video generation (only when invoked by an agent the user has installed)United StatesVariableLow
ReplicateModel inference (only when invoked by an agent)United StatesVariableLow
PerplexityWeb research API (only when invoked by an agent)United StatesVariableLow
DeepgramSpeech-to-text (only when invoked by an agent)United StatesSOC 2 Type 2Low
ElevenLabsText-to-speech (only when invoked by an agent)United StatesSOC 2 Type 2Low
HumeAffective voice (only when invoked by an agent)United StatesVariableLow
ExaSearch API (only when invoked by an agent)United StatesVariableLow
ApifyWeb scraping (only when invoked by an agent)EUVariableLow
DataForSEOSEO data (only when invoked by an agent)United StatesVariableLow
WolframComputation API (only when invoked by an agent)United StatesVariableLow
ApolloSales prospecting (Phoenix internal only — no customer data)United StatesSOC 2 Type 2Low
Late.devSocial scheduling (only when invoked by an agent)United StatesVariableLow
Alpha VantageFinancial data (only when invoked by an agent)United StatesVariableLow
Financial Modeling PrepFinancial data (only when invoked by an agent)United StatesVariableLow

Questions or objections

Contact privacy@getrush.ai with any question about a subprocessor. We respond within 30 days.