Total Vault
Effective June 10, 2026

Subprocessors

These are the third-party services that handle some part of Total Vault's operations. Each one only receives the minimum data needed to do its job.

In plain English
Your files live on Backblaze. Everything else (database, jobs, email) is a focused dependency we’d move off if it failed us. AI providers see thumbnails and metadata, never originals.

1. Current list

VendorPurposeDataLocationPolicy
BackblazeEncrypted object storage for your files and thumbnailsFile contents, derived thumbnails, file metadataUnited StatesView ↗
NeonManaged Postgres database (files, folders, activity, audit log)Account info, file metadata, hashes, activity recordsUnited States (US-East)View ↗
VercelWeb hosting and edge servingRequest logs, IP addresses, application trafficUnited StatesView ↗
Cloudflare (realtime)Realtime sync and presence (live multi-user updates)Organization and user IDs, presence signals, file and project event IDsUnited States / global edgeView ↗
Cloudflare R2Storage for derived video assets (poster, preview clip, 1080p proxy)Derived video assets only (never originals)United States / global edgeView ↗
InngestBackground-job runner for verification and AI tasksJob payloads (file IDs, organization IDs)United StatesView ↗
ResendTransactional email (sign-in codes, receipts)Recipient email address, email subject and bodyUnited StatesView ↗
StripePayment processing and subscription billingBilling contact, subscription status, payment-method details (held by Stripe)United StatesView ↗
AnthropicAI rename, event grouping, and natural-language searchThumbnails, filenames, EXIF metadata, queriesUnited StatesView ↗
CohereImage embeddings for visual similarity searchThumbnails (no originals)Canada / United StatesView ↗
SentryError and performance monitoringError events, request metadata, IP addressUnited StatesView ↗
GoogleCloud import source (read-only Google Drive)Encrypted OAuth token, file metadata, and the files you choose to importUnited StatesView ↗
DropboxCloud import source (read-only)Encrypted OAuth token, file metadata, and the files you choose to importUnited StatesView ↗

2. When this list changes

We will update this page before adding a new subprocessor or removing an existing one. Account owners can subscribe to change notifications by emailing support@totalvault.ai — we’ll send a brief notice at least 14 days in advance for any change that materially affects how customer data is processed.

3. Contractual safeguards

Each of the vendors above is bound by a written data-processing agreement (or equivalent) that requires them to handle customer data only on our instructions, maintain industry-standard security controls, and notify us of any incident. We have configured AI vendors to disable training on customer inputs and to retain request payloads only as long as needed to deliver the response.

Cloud import sources (Google Drive, Dropbox) are connected only when you choose to import from them, using read-only access. We never modify or delete anything in your connected accounts, and you can disconnect them at any time.