Full Architectural Transparency

Authorized Subprocessors & Vendor Register

In accordance with our commitment to absolute architectural transparency and global regulatory compliance (GDPR Article 28(2) and SOC 2 CC6.6), this register maintains an exhaustive, continuously verified list of third-party infrastructure and service providers.

0
Core Data Subprocessors
Zero third-party vendors ever receive, process, or store your text, prompts, or sensitive PII.
100% Local Execution

Administrative & Infrastructure Providers

These vendors support static asset delivery, billing, and transactional support inquiries. None of these vendors have access to the PII scrubbing engine.

Vendor EntityService PurposeData HandledSecurity / Location
Paddle.com Market Ltd Merchant of Record & Subscription Billing Customer billing email, name, VAT/tax IDs, payment token. 0 prompt text / 0 PII from sessions. PCI-DSS Level 1 · UK & Global
PayPal, Inc. Direct Payment Processor (Zero-Server Capture) PayPal payer account ID, transaction status. 0 prompt text / 0 PII from sessions. PCI-DSS Level 1 · USA & Global
Vercel Inc. Static Hosting, Edge CDN & Anonymous Analytics Static file requests, anonymized aggregate pageviews. 0 customer data stored. SOC 2 Type II, ISO 27001 · Global
Cloudflare, Inc. DNS Routing & DDoS Edge Protection Transient IP routing for static assets. 0 application backend data. SOC 2 Type II, ISO 27001 · Global
Web3Forms / Resend Administrative Form Delivery User-submitted contact inquiries / CISO Whitepaper requests. Strictly air-gapped from scrubber. SOC 2 · USA / Global

Subprocessor Exposure Across All 4 Environments

Web Workspace

Runs in browser tab. Third-party subprocessors for session data = 0.

Chrome Extension (MV3)

Runs in target tab renderer. Third-party subprocessors for prompts = 0.

PII MCP Server

Runs over local stdio / IPC. Zero outbound network sockets. Subprocessors = 0.

Developer SDK

Isomorphic npm library. Pure deterministic functions. Subprocessors = 0.

Notification Policy for Subprocessor Updates

In the event that PrivacyScrubber engages new administrative or hosting vendors, we will update this register at least 30 days prior to authorizing any new subprocessor. Because our core architecture is strictly Zero-Server, PrivacyScrubber will never engage cloud subprocessors to ingest or process your unencrypted data.