Sub-processors
Version 1.7 · 3 October 2026
Every service that receives data Borehole holds. Not a category list — the actual vendors, what each one gets, whether the service needs it to run, and where you can opt out.
Anything that receives data belonging to the people who use Borehole is here, however small the amount. Services that receive only our data — billing for our own cloud spend, for instance — are not, because they hold nothing of yours.
Google Cloud
- For
- Hosting, database, scanning
- Where
- europe-west1 (Belgium)
- Transfer
- Kept in an EU region by a US-headquartered company, whose terms allow access from the United States. Mechanism: Google LLC: the EU-U.S. Data Privacy Framework and its UK Extension, under which it is certified, with the 2021 standard contractual clauses in its data processing terms as the fallback
- Receives
- Everything Borehole stores: accounts, reports, orders, sessions. Also the servers' request logs, with each request's IP address, which Google keeps for 30 days in the same region.
Stripe
- For
- Payments
- Where
- United States and globally
- Transfer
- Outside the EU. Mechanism: Stripe, Inc.: the EU-U.S. Data Privacy Framework and its UK Extension, under which it is certified, with the 2021 standard contractual clauses in its data processing terms as the fallback
- Receives
- Your email address and what you bought. Card details go to Stripe directly and never reach us.
- Also a controller
- Stripe decides for itself how it handles your card and the payment, for fraud prevention and its own legal duties, under its own privacy notice.
Google Workspace
- For
- The mailboxes at borehole.dev: support@, billing@, takedown@ and security@
- Where
- United States and other Google locations
- Transfer
- Outside the EU. Mechanism: Google LLC: the EU-U.S. Data Privacy Framework and its UK Extension, under which it is certified, with the 2021 standard contractual clauses in its data processing terms as the fallback
- Receives
- Mail you send to an address at borehole.dev, including a reply to one of our emails: your address, what you write, and anything you attach. Refund, access and deletion requests, objections from contributors and takedown requests arrive this way.
GitHub
- For
- Sign-in, metadata for public repositories, and who controls a repository
- Where
- United States
- Transfer
- Outside the EU. Mechanism: GitHub, Inc.: the EU-U.S. Data Privacy Framework and its UK Extension, under which it is certified, with the 2021 standard contractual clauses in its data processing terms as the fallback
- Receives
- Your GitHub identity, when you sign in with it. For a private report from a github.com remote, the repository's owner and name, to ask whether a signed-in person controls it. Never its contents: the collector reads a private repository on your own machine.
- Also a controller
- Your GitHub account, and what GitHub records when you sign in with it, are GitHub's, under its own privacy statement.
OSV (Google Open Source Security) not needed to run the service
- For
- Known-vulnerability lookups
- Where
- United States
- Transfer
- Receives nothing about a person
- Receives
- The ecosystem, name and version of each locked dependency whose lockfile shows a public registry served it, sent by our server; from collector 0.7.10 every other package stays on your machine. For a public repository we survey ourselves, also the surveyed commit and the name of a package the repository publishes. Your project's own package name crosses to our server as its manifest declares it, and when you run the collector our server sends that name to no one: it looks up a project's own package, in OSV or anywhere else, only for a public repository we survey ourselves. Never a private repository's name, a path, code, or anything about you.
NVD (US National Vulnerability Database) not needed to run the service
- For
- Known-vulnerability lookups for a public repository
- Where
- United States
- Transfer
- Receives nothing about a person
- Receives
- The name of a public repository we survey ourselves, to find the product it is and that product's published vulnerabilities. Nothing about a private repository, and nothing about you.
Anthropic not needed to run the service
- For
- Review of paid reports on public repositories
- Where
- United States and other Anthropic locations
- Transfer
- Outside the EU. Mechanism: Anthropic, PBC: the 2021 standard contractual clauses in its data processing terms. It is not certified under the EU-U.S. Data Privacy Framework
- Receives
- Only for a paid survey of a public repository: the report's findings, and what the review reads of that repository at the surveyed commit (files, search results, paths, and commit subjects with email addresses and @handles removed). A file goes as written, so one that names people, such as an AUTHORS file or a copyright line, goes with the names. Never a commit author from the history, never who bought the survey or anything else about you, and never anything from a private repository or the collector.
Resend
- For
- Transactional email
- Where
- eu-west-1 (Ireland)
- Transfer
- Kept in an EU region by a US-headquartered company, whose terms allow access from the United States. Mechanism: Resend, Inc.: the EU-U.S. Data Privacy Framework and its UK Extension, under which it is certified, with the 2021 standard contractual clauses in its data processing terms as the fallback
- Receives
- The address a receipt or a reply is sent to, and the message.
Sentry not needed to run the service
- For
- Error reports
- Where
- Germany
- Transfer
- Kept in an EU region by a US-headquartered company, whose terms allow access from the United States. Mechanism: Functional Software, Inc.: the EU-U.S. Data Privacy Framework and its UK Extension, under which it is certified, with the 2021 standard contractual clauses in its data processing terms as the fallback
- Receives
- Diagnostic context when something breaks. Scrubbed before it leaves the process, by key name and by value shape.
PostHog not needed to run the service
- For
- Product analytics
- Where
- EU cloud
- Transfer
- Kept in an EU region by a US-headquartered company, whose terms allow access from the United States. Mechanism: PostHog, Inc.: the EU-U.S. Data Privacy Framework and its UK Extension, under which it is certified, with the 2021 standard contractual clauses in its data processing terms as the fallback
- Receives
- From the server only: a pseudonymous identifier (a hash, under a secret salt, of your address and browser, or of your account's number when signed in; never the address or your GitHub identity), the pages reached with no query string, the referring site's name, and which steps were reached. Private reports are never counted. Nothing runs in your browser. Session replay is off.
- Opt out
- Turn on Do Not Track or Global Privacy Control in your browser, and nothing is counted.
Transfers outside the EU
Our servers, database and request logs are in the EU. Mail you send us is not. Stripe, Google Workspace, GitHub and Anthropic keep data outside the EU. Google Cloud, Resend, Sentry and PostHog keep data in the EU regions listed above, but they are US-headquartered and their terms allow access from the United States. Each entry above names its transfer mechanism. For a copy of the clauses that apply, write to support@borehole.dev. You cannot buy without Stripe or sign in without GitHub, which is stated here rather than in a footnote because it is not a choice we can offer you.
For a private survey
When you run the collector, we process the bundle and the private report as your processor, under the data processing agreement. Of the services above, only Google Cloud stores bundle data. The agreement's annex lists the rest and what each one receives.
Changes
Adding a sub-processor changes who can see your data, so it is a change to this page with a new version and date. If you have accepted the data processing agreement, its section 4.4 also applies: notice by email before the change, and a right to object. If you have an arrangement with us that requires more notice, it takes precedence over this paragraph.
See also the Privacy Policy, the Terms and the data processing agreement.