Subprocessors and service providers
Last updated: August 14, 2026
Reference translationThis English translation is provided for convenience only. TheJapanese version is the authoritative version. If there is any inconsistency or discrepancy between the Japanese version and this translation, the Japanese version will prevail.
This page lists two separate categories. They are not the same set.
- Subprocessors: providers we engage when processing, as a processor on your documented instructions, the response data you collect through surveys. These are covered by ourData Processing Agreement.
- Providers we use as a controller: payments, our own product analytics, email for our own accounts, and similar — services whose purposes we determine ourselves. They are not entrusted with response data and are therefore not subprocessors under the DPA. Our handling is described in thePrivacy Policy.
1. Subprocessors (response data)
| Provider | Purpose | Data processed | Processing location | How respondent data reaches it |
|---|---|---|---|---|
| Cloudflare, Inc. | Application hosting, database, file storage, cache, and queues | Account data, workspace data, survey definitions, response data, access logs | United States and global edge locations | Response data itself is stored in D1, R2, and similar |
| OpenRouter, Inc. | Routing of AI inference for AI features | The instruction text needed to run the AI feature, and the survey definition or response excerpts it targets | United States | When you run analysis over responses, response content is sent as inference context |
| Functional Software, Inc. (Sentry) | Error tracking and diagnostics | Error details, stack traces, request metadata, and session replays of the response screen (text and inputs are masked) | United States | Error capture and session replay also run on the public response screen, so information about a respondent session can reach it |
AI model providers: our direct subprocessor is OpenRouter, Inc.. Individual model providers sit downstream of OpenRouter, Inc. and are not covered by the advance notice in section 3. Where you select a model or provider at run time, that selection is itself your instruction to use that provider.
2. Providers we use as a controller
The providers below are not entrusted with response data. They are listed for transparency.
| Provider | Purpose | Data processed | Processing location | Why no response data is sent |
|---|---|---|---|---|
| Stripe, Inc. | Subscriptions, payments, and usage-based billing | Billing details, payment methods (collected directly by Stripe), subscription and usage identifiers | United States | Used only for our own billing; no response data is sent |
| Resend, Inc. | Sending magic links, workspace invitations, and our own notification email | Account email addresses and the contents of those messages | United States | Only account-related email is sent; we do not email respondents (you distribute response links yourself) |
| PostHog, Inc. | Our own product analytics and acquisition measurement (only where consent is given) | Pseudonymous identifiers, user identifiers, workspace identifiers, page paths, campaign and referrer data, product events | United States | Analytics we carry out for our own purposes; survey questions and response content are deliberately not sent |
| Hound Technology, Inc. (Honeycomb) | Performance monitoring and distributed tracing | Request route, duration and status, workspace identifiers, and account user identifiers | United States | Spans carry only route, status, and identifiers — never response content |
In addition, if you choose to sign in with Google or Microsoft OAuth, information is sent to that provider for authentication. That is an authentication method you choose yourself, and is not a subprocessing of response data.
3. Notice of changes
Before adding or changing a subprocessor listed in section 1, we will normally notify you at least30 days in advance by updating this page and sending a notice to your registered email address. Changes to the providers in section 2 are reflected by updating this page.
You may object to a change on reasonable grounds after such notice. If we cannot offer an alternative within a reasonable period, you may terminate the affected part of the Service.
Where there is a security emergency, we may change a subprocessor without prior notice and inform you promptly afterwards.
4. Obligations imposed on subprocessors
Our contracts with each subprocessor impose obligations that are substantially equivalent to those we owe under the DPA, including processing only as necessary to deliver the Service, confidentiality, and appropriate technical and organizational security measures. We remain responsible to you for the acts of our subprocessors.
5. International processing
As shown above, processing takes place outside Japan, including in the United States. There are two legs. Transfers from EEA and UK customers to us rely on the adequacy decisions Japan holds; as a personal information handling business operator under the Japanese Act on the Protection of Personal Information, we comply with the Supplementary Rules for that data. For onward transfers from us to the subprocessors in section 1, we engage them as a processor, so where a mechanism is required we put in place Module Three of the standard contractual clauses or another lawful mechanism. See section 11 of theDPA for details.
6. Contact
Questions about this page: contact form.
7. Authoritative version
The authoritative version of this page is the Japanese version. Translations into other languages are provided for convenience; if there is any discrepancy with the Japanese version, the Japanese version prevails.