Every vendor that touches customer data to run inrelay — what each one does, and where it runs.
inrelay uses a small number of third-party vendors to run the service. Each processes customer data only for the purpose listed, under a data-processing agreement, as described in our DPA and privacy policy. We notify customers before adding a subprocessor.
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | database, authentication, and storage for workspace content | United States |
| AI model API (Gemini) for triage, reply drafting, and help-article generation; no training on customer data per API terms | United States | |
| OpenAI | AI model API for triage, reply drafting and help-article generation; no training on customer data per API terms, inputs and outputs retained up to 30 days for abuse monitoring | United States |
| Groq | AI model API for triage, reply drafting and help-article generation; no training on customer data per API terms, no retention by default | United States |
| Anthropic | AI model API (Claude), used only when a customer connects their own Anthropic account in settings. Those calls run under that customer’s own contract with Anthropic, and inrelay sends Anthropic no data for customers who have not connected a key | United States |
| SendGrid (Twilio Inc.) | Email sent and received under the CUSTOMER’s own identity — their support address, their replies to end users, and inbound mail forwarded to us. This carries conversation content and end-user email addresses, so it sees more customer data than any other mail vendor here | United States |
| Resend | Transactional email sent under inrelay’s own identity — account-deletion and data-export notices. Recipient address and message content only; no unsubscribe, because a notice that someone is about to lose their data is not marketing | United States |
| Stripe | Payments and subscription billing. Card details are entered on Stripe’s own hosted Checkout and never reach inrelay — we store no card data. We hold only Stripe’s customer and subscription identifiers, plus the plan and period they imply | United States |
| Vercel | Hosting and CDN for the marketing site, the web app and the chat widget. Serves pages and application code; sees request metadata (IP address, user agent) in its edge logs. Workspace content lives in the database, not here | United States |
| Railway | Runs the inrelay application server — the process that handles inbound mail, live chat, AI calls and the hosted help centres. Conversation content passes through it in transit for every one of those, so it is on the path of essentially all customer data | United States |
| Cloudflare | Authoritative DNS for inrelay domains, and — once customer help-centre domains ship — the TLS termination and proxy in front of them. DNS alone carries no customer content; where the proxy is enabled, requests and their metadata pass through it in transit | United States (global edge) |
| Mailgun (Sinch) | Second email provider, from launch: the fallback for sending under the customer’s own identity, and the secondary route for inbound mail if the primary refuses it. Carries the same conversation content and end-user addresses as the primary when it is in use | United States |
| Cloudflare R2 | From launch: hosting for the desktop application downloads and its update feed. Serves released binaries and sees download request metadata; no workspace content is stored here | United States (global edge) |
Vendor list current as of August 2026. AI vendor terms checked 20 August 2026. Entries marked “from launch” describe vendors in place for the public launch of the service.
Questions about a vendor on this list belong with the data processing agreement; the rights you hold over the data itself are summarised at /gdpr, and the commercial relationship lives in the terms of service.
Give your customers faster answers and your team their evenings back.
Desktop and mobile. Free for solo.