Sub-processors

Sub-processors

Pure Grace AI, LLC — AI Privacy Center

Version: 1.0 · Effective Date: July 1, 2026

This page lists the third-party sub-processors Pure Grace AI, LLC (“Company”) engages to process Customer Personal Data in providing the AI Privacy Center services. It is published for transparency and is kept synchronized with Annex III of our Data Processing Addendum (DPA). Where this page and the DPA differ, the DPA — including its full legal-entity, data-region, and transfer-mechanism detail — governs.

Company self-hosts its site-scanning (headless-browser) infrastructure on Company-controlled compute; public browser services are blocked in production by the scan engine.

Third-party platforms a customer selects and connects on its own behalf (for example WordPress, Webflow, Shopify, or the customer’s own hosting) are customer-selected destinations and integrations, governed by the customer’s instructions and those third parties’ own terms. They are not Company sub-processors unless Company separately engages the provider to process Customer Personal Data on Company’s behalf.

Current sub-processors

Sub-processor Purpose Primary region Vendor sub-processor / trust page
Anthropic AI drafting of privacy policies and data-subject-request response text United States https://trust.anthropic.com/subprocessors
Neon PostgreSQL database hosting United States https://neon.com/subprocessors
Twilio SendGrid Transactional email United States https://twilio.com/legal/sub-processors
Upstash Rate limiting United States https://trust.upstash.com/subprocessors
Stripe Billing and payment processing United States https://stripe.com/legal/service-providers
Fly.io, Inc. Application and site-scanning compute hosting (self-hosted browser and API runtime) United States (Ashburn, Virginia / iad) https://fly.io/legal/sub-processors

International transfers

Where Company processes personal data of individuals in the European Economic Area, the United Kingdom, or Switzerland, transfers of that data to the United States are covered by the applicable transfer mechanism — the EU Standard Contractual Clauses (Module 2) and the UK International Data Transfer Addendum (with Swiss adaptations where relevant), as applicable. These mechanisms apply where and when such personal data is in scope.

Changes to this list

Company will provide at least thirty (30) days’ advance notice before authorizing a new or replacement sub-processor to process Customer Personal Data, unless a shorter period is required to address an emergency, security risk, legal requirement, or service-continuity issue, in which case Company will provide notice as soon as reasonably practicable. Customer’s right to object is governed by the DPA.

Contact

Questions about this list or our data-processing practices: privacy@puregraceai.com

Scroll to Top