Last updated: August 28, 2026
VXBE uses the providers below to operate Buddy and vxbe.space. A provider receives only the categories needed for its role, but content-bearing providers may process conversation text, files, media, browser content, or action data when a requested feature requires it.
| Provider | Purpose | Information it may process |
|---|---|---|
| Cloudflare | Website and API delivery, security, Workers, Containers, Agent sessions, storage, databases, queues, email routing, browser features, AI Gateway, and AI processing | Account and session references, network and request metadata, conversation and work data handled by the service, stored files, operational events, exact-host HTTP(S) relay traffic for an isolated no-auth package, and AI requests routed through the gateway. Private R2 storage keeps exact account-owned Buddy Log event bodies for up to 90 days unless cleared sooner. When a person enables optional AI-content review, the standard vxbe Gateway retains their new AI request and response payloads for VXBE's restricted debugging and product-improvement review; the separate no-content-export route does not retain those payloads. |
| Neon | Hosted PostgreSQL for account, entitlement, usage, billing, schedules, feedback, security-review, and other purpose-specific records | Account-linked records, usage and billing data, user-shared feedback, restricted incident records, and Buddy Log object manifests and deletion metadata. Buddy Log manifests include account, session, turn, event, time, object locator, checksum, size, retention, and deletion state, but not the exact event body. |
| Clerk | Authentication, account security, and private-preview waitlist | Email, authentication identifiers, session and security state, and waitlist or invitation state |
| Stripe | Checkout, subscriptions, credits, invoicing, tax-related payment data, refunds, and disputes | Billing identity, payment method and transaction data, purchase status, and fraud signals |
| Photon (Spectrum) | iMessage transport for Buddy text conversations, including message and requested file delivery | Sender and recipient text addresses, assigned Buddy number, iMessage conversation and provider message identifiers, inbound and outbound message content, requested file bytes, filenames, MIME type and size, delivery state, and operational metadata |
| OpenRouter | Routing VXBE-funded AI inference to eligible model providers and executing the public-web search server tool; ordinary prompt logging and use-of-inputs controls are not enabled by VXBE | AI requests and responses in transit, including conversation content or derived context needed for ordinary inference; for public-web research, one focused public-web question, the helper-generated search query, Buddy's selected Parallel mode, returned public URLs, titles, excerpts, and usage metadata |
| Parallel | Public-web search engine used server-side by OpenRouter. Parallel's standard Customer Terms permit it to use search inputs and outputs to develop, improve, and train its services and models. | The helper-generated public-web search query; a necessary public subject identifier only when the person explicitly asks to research that subject; basic mode by default or Buddy's selected turbo, fast, or advanced override; returned public URLs, titles, and excerpts; and provider usage metadata. VXBE does not add the surrounding conversation, memory, files, connected-app or browser content, credentials, user location, or VXBE account/session/turn/tool identifiers to the search parameters. |
| Underlying AI model providers | Generate responses, form or rank context, create embeddings, and understand text or media | The request content sent through the eligible route and provider-generated response or representation |
| Morph | Automated turn-quality and possible prompt-bypass classification | The message or Buddy response being classified, plus provider usage metadata |
| PostHog | Public-website and content-free product analytics, optional AI-content review, and Support tickets for feedback a person deliberately shares | Pseudonymous public-site identifiers, masked interactions and heatmaps, performance and bounded browser-error data, and closed product events; AI request and response content only when optional review is enabled for that account, for restricted VXBE debugging and improvement of Vxbe and Buddy; consented conversation or Buddy-report content when a person deliberately shares feedback through Support |
| Composio | Connected-app authorization, credential custody, tool discovery, and requested actions | Account reference, connection state, provider credentials in Composio custody, requested action data, and results |
| E2B | Isolated computer-like workspaces for requested file, command, and browser work | Workspace files, typed operations, command output, artifacts, network activity, and workspace metadata |
Specific outside services a person chooses to connect, such as an email, calendar, storage, or productivity provider, are not VXBE subprocessors for all users. They receive information only when the person connects or directs Buddy to use that service, and their own terms and privacy policies apply.
VXBE may change infrastructure or model providers as reliability, capability, privacy, or cost needs change. We update this page before or when a new provider begins processing a materially new category of personal information. Material changes also receive notice under the Privacy Policy when required.
Questions can be sent to privacy@vxbe.space.