Subprocessors
Last updated: July 30, 2026
Pullify, LLC d/b/a Easel Software Solutions (“Easel”) uses carefully selected subprocessors to operate the platform. This page lists providers that may process personal data or Customer Content on our behalf. We will update this list as our infrastructure changes. Enterprise customers with a DPA may receive additional notice and objection rights as specified in that agreement.
Current subprocessors
The table below reflects known production dependencies as of the last updated date. Privacy policy URLs may change; verify on the provider’s site.
| Provider | Purpose | Typical data | Privacy / trust |
|---|---|---|---|
| Fly.io | Edge compute and hosting for easel-edge and related apps | Deployment traffic, logs, infrastructure metadata | fly.io/legal/privacy-policy |
| Amazon Web Services (AWS) | Serverless function compute (Lambda) and artifact object storage (S3) used to build and run deployments | Deployment artifacts, function packages, request/response traffic handled by your functions, operational logs | aws.amazon.com/privacy |
| Neon | Managed Postgres for control-plane data | Account, project, and operational database records | neon.tech/privacy-policy |
| Autumn | Billing entitlements and usage metering | Customer and usage identifiers, plan metadata | useautumn.com/privacy |
| Stripe | Payment processing (via billing partners) | Billing contact and payment metadata | stripe.com/privacy |
| Resend | Transactional email delivery | Email address and message content | resend.com/legal/privacy-policy |
| GitHub | OAuth authentication and repository integration | Account identifiers, repo metadata you authorize | GitHub privacy statement |
| Trigger.dev | Background job execution | Job payloads and operational logs related to automations | trigger.dev/legal/privacy |
| Daytona | Build and development sandbox infrastructure | Build context and related operational data | daytona.io/privacy-policy |
| CrowdSec | Abuse detection / security intelligence (edge) | Security signals derived from request traffic | crowdsec.net/privacy-policy |
| Bunny.net | Object storage and CDN-related infrastructure (static assets, ISR cache, pull zones) | Deployment artifacts, cache objects, and related operational metadata | bunny.net/privacy |
| Cloudflare | S3-compatible object storage (R2) for operational assets such as deployment screenshots | Screenshot images and related object metadata | cloudflare.com/privacypolicy |
| OpenRouter | AI model routing for Easel Agent Mode (alpha) and related in-product AI features | Prompts, code context, and completions you submit when using those features | openrouter.ai/privacy |
When you use Agent Mode or other in-product AI features, OpenRouter may route requests to underlying model providers (for example Anthropic, OpenAI, or Meta). Those providers process the request content under their own terms and privacy policies, as selected for each model, and are not Easel subprocessors for other platform features.
Updates
We may add or replace subprocessors as we evolve the platform. Material changes will be reflected on this page. Enterprise customers with a signed DPA may have contractual notice and objection rights as stated in that DPA. For questions or to request notice for Enterprise accounts, contact legal@easel.sh.
See also our Privacy Policy and Data Processing Agreement.