Policy
Subprocessors
The third parties ZeroWidth uses to deliver the service.
We publish this list so customers always know who has potential access to data passing through the service.
ZeroWidth uses a small set of third-party services to operate the product. Each is bound by a data-processing agreement that imposes obligations no less protective than our own Data Processing Addendum.
Current set
| Subprocessor | Purpose | Region |
|---|---|---|
| Google Cloud Platform | Application hosting, primary database, object storage, image registry | United States |
| WorkOS | Authentication, SSO, identity provider integrations (Google, Microsoft, SAML, magic link) | United States |
| Loops | Transactional email — invites, email-change confirmations, security notifications, contact-form delivery, newsletter signup confirmation. Holds opt-in mailing-list state for newsletter subscriptions. | United States |
| SendGrid (Twilio) | Newsletter and broadcast email delivery (Distributed Cognition and similar opt-in mailing-list sends) | United States |
| Cloudflare | Bot protection (Turnstile) on public forms such as newsletter signup — processes the visitor's IP address and browser signals to distinguish humans from bots | United States |
| Twilio | Text-message (SMS) transport for the shared messaging number — carries the phone numbers and message content of people who text an assistant | United States |
| OpenRouter | AI model routing — provides a single API surface in front of the model providers configured for a workspace | United States |
| Stripe | Billing, payment processing, invoicing | United States |
Direct AI provider configuration
When a workspace configures an AI provider directly (instead of routing through OpenRouter), the content sent through that flow is forwarded to the provider under the API key the workspace supplies. ZeroWidth acts as a conduit only; the provider's own terms govern that data. The workspace owner is in control of which providers are configured — removing a key from a workspace immediately stops new requests while in-flight ones complete.
Notice of changes
When we add, replace, or remove a subprocessor we'll notify workspace administrators by email with reasonable advance notice before the change takes effect. You can object to the change on reasonable grounds; if we can't resolve the objection together, you may terminate the affected services per the Terms.
To subscribe to subprocessor change notifications independently of your workspace role, email contact@zerowidth.ai with "Subprocessor notifications" in the subject.
Change log
- 2026-07: Added Cloudflare (Turnstile bot protection on public forms).
- 2026-06: Added Loops; clarified SendGrid scope (newsletter and broadcast delivery only — transactional email moved to Loops).
- 2026-06: First publication.
Contact
For subprocessor questions: contact@zerowidth.ai.
ZeroWidth, LLC
Other policies and agreements