Last updated: August 27, 2026
VXBE uses the providers below to operate Buddy and vxbe.space. A provider receives only the categories needed for its role, but content-bearing providers may process conversation text, files, media, browser content, or action data when a requested feature requires it.
| Provider | Purpose | Information it may process |
|---|---|---|
| Cloudflare | Website and API delivery, security, Workers, Containers, Agent sessions, storage, databases, queues, email routing, browser features, AI Gateway, and AI processing | Account and session references, network and request metadata, conversation and work data handled by the service, stored files, operational events, exact-host HTTP(S) relay traffic for an isolated no-auth package, and AI requests routed through the gateway. When a person enables optional AI-content review, the standard vxbe Gateway retains their new AI request and response payloads for VXBE's restricted debugging and product-improvement review; the separate no-content-export route does not retain those payloads. |
| Neon | Hosted PostgreSQL for account, entitlement, usage, billing, schedules, feedback, security-review, and other purpose-specific records | Account-linked records, usage and billing data, user-shared feedback, and restricted incident records |
| Clerk | Authentication, account security, and private-preview waitlist | Email, authentication identifiers, session and security state, and waitlist or invitation state |
| Stripe | Checkout, subscriptions, credits, invoicing, tax-related payment data, refunds, and disputes | Billing identity, payment method and transaction data, purchase status, and fraud signals |
| Photon (Spectrum) | iMessage transport for Buddy text conversations, including message and requested file delivery | Sender and recipient text addresses, assigned Buddy number, iMessage conversation and provider message identifiers, inbound and outbound message content, requested file bytes, filenames, MIME type and size, delivery state, and operational metadata |
| OpenRouter | Routing VXBE-funded AI inference to eligible model providers; ordinary prompt logging and use-of-inputs controls are not enabled by VXBE | AI requests and responses in transit, including conversation content or derived context needed for the request, plus usage metadata |
| Underlying AI model providers | Generate responses, form or rank context, create embeddings, and understand text or media | The request content sent through the eligible route and provider-generated response or representation |
| Morph | Automated turn-quality and possible prompt-bypass classification | The message or Buddy response being classified, plus provider usage metadata |
| PostHog | Public-website and content-free product analytics, optional AI-content review, and Support tickets for feedback a person deliberately shares | Pseudonymous public-site identifiers, masked interactions and heatmaps, performance and bounded browser-error data, and closed product events; AI request and response content only when optional review is enabled for that account, for restricted VXBE debugging and improvement of Vxbe and Buddy; consented conversation or Buddy-report content when a person deliberately shares feedback through Support |
| Composio | Connected-app authorization, credential custody, tool discovery, and requested actions | Account reference, connection state, provider credentials in Composio custody, requested action data, and results |
| E2B | Isolated computer-like workspaces for requested file, command, and browser work | Workspace files, typed operations, command output, artifacts, network activity, and workspace metadata |
Specific outside services a person chooses to connect, such as an email, calendar, storage, or productivity provider, are not VXBE subprocessors for all users. They receive information only when the person connects or directs Buddy to use that service, and their own terms and privacy policies apply.
VXBE may change infrastructure or model providers as reliability, capability, privacy, or cost needs change. We update this page before or when a new provider begins processing a materially new category of personal information. Material changes also receive notice under the Privacy Policy when required.
Questions can be sent to privacy@vxbe.space.