Copilotly

Legal

Subprocessors

Every third party that touches your data, what each one sees, and where it sits. Including the part people least expect - that model providers see your messages.

Effective · Last updated

Current subprocessors

ProviderWhat it doesWhat it seesLocation
OpenAIModel inference for some copilotsMessage content sent to that copilotUnited States
AnthropicModel inference for some copilotsMessage content sent to that copilotUnited States
Google CloudModel inference for some copilotsMessage content sent to that copilotUnited States
Amazon Web ServicesHosting, storage and backupsAll stored data, encrypted at restUnited States
StripePayment processing on webCard details, billing address, emailUnited States
RevenueCatSubscription management for the iOS and Android appsPurchase and entitlement state, app user IDUnited States
Google AnalyticsAggregate site analyticsPage views, referrer, approximate locationUnited States
NetragaOur own visitor analyticsPage views, referrerUnited States
ConferbotWebsite chat widgetWhat you type into the widgetIndia

No model provider is permitted to train on data submitted through our accounts. That is a contractual term, not an assumption.

Why model providers see your messages

Worth being direct about, because it is the part people least expect. A copilot response is generated by a large language model, and generating it requires sending your message to whoever runs that model.

Copilotly does not train or host the underlying models. What it builds is the configuration layer - which model, what it is told, what it asks first, and where it stops. That means your message travels to OpenAI, Anthropic or Google depending on which copilot you used.

Our agreements with each of them prohibit training on that data and require deletion within their stated retention windows. Those windows exist for abuse monitoring and are typically 30 days.

If that is not acceptable for a particular category of information, do not put it in. That is a genuine limitation of any AI product, ours included, and a vendor telling you otherwise is either self-hosting or misleading you.

Changes to this list

We will update this page before a new subprocessor begins processing personal data, not after. Enterprise customers with a signed data processing agreement receive notice by email and have the contractual right to object.

To be notified of changes, email [email protected] and ask to be added to the list.

Data processing agreements

Each subprocessor is engaged under a written agreement that limits processing to the purposes we specify, requires appropriate security measures, and includes Standard Contractual Clauses where data leaves the UK or EEA.

If you need a DPA with us - which is usually a procurement requirement rather than a personal one - email [email protected].