Trust — Subprocessors

Everyone who touches
your data, on the record.

Fyltre relies on a small set of third parties to deliver the Service. Each is contractually bound to protect your data and process it only as instructed. Here is the complete list.

Last updated — February 2026

AI processing

Email/message content for summarization, classification, and draft reply generation

Never used for model training. Retained only within OpenAI's limited abuse-monitoring window, then deleted.

United States

Database & authentication

User accounts, encrypted OAuth tokens, AI-generated summaries, conversation metadata, audit logs

Retained until removed by our automated retention jobs or account deletion

EU (eu-west) or US region

Application hosting

HTTP requests, serverless function execution. No persistent storage of user content.

Function logs retained for 30 days. No user content stored.

Global edge, primary US/EU

Rate limiting

Request counters and rate-limit keys (user IDs or IP addresses). No message content.

Counters expire automatically with the rate-limit window (1–60 minutes)

Global

Payment processing

Customer email, subscription status, payment method tokens. Fyltre never sees or stores full card details.

Per Stripe's retention policy; payment records kept for legal/financial compliance

United States / Ireland (EU)

Email provider integration

OAuth tokens (encrypted at rest); Gmail API calls to fetch and send email on your behalf

Fyltre stores encrypted OAuth tokens only. Email content fetched on demand.

Global (Google Cloud)

Messaging provider integration

OAuth tokens (encrypted at rest); Slack API calls to read messages and channels on your behalf

Fyltre stores encrypted OAuth tokens only. Message content fetched on demand.

Global (AWS)

Email & messaging integration

OAuth tokens (encrypted at rest); Microsoft Graph API calls to fetch emails and messages

Fyltre stores encrypted OAuth tokens only. Email content fetched on demand.

Global (Azure)

Change notification

No surprises. Ever.

We provide at least 30 days’ notice before engaging a new subprocessor or materially changing how an existing one processes personal data. Team and Enterprise customers can subscribe to change notifications by contacting security@fyltre.com.

Questions about our subprocessors? security@fyltre.com