Legal
Subprocessors
The third parties that process data on our behalf to operate the service. We do not sell data, and we do not share your email content with anyone except the vendors listed below.
Our approach
We aim to keep this list short and each relationship load-bearing. Where a function can be performed in-house (for example, message sanitization or delivery logic), we keep it in-house rather than add a vendor. We do not use third parties for advertising, analytics, or training machine-learning models on your data.
| Vendor | Purpose | Data processed | Region |
|---|---|---|---|
| Cloudflare | Compute, network edge, and object storage | API request metadata, message bodies, attachments and raw MIME archives stored as objects | Global edge (data stored in the bucket's configured jurisdiction) |
| Neon | Managed PostgreSQL — the primary datastore | Organization and user records, inboxes, message metadata and bodies, drafts, API key hashes, webhook configuration and delivery logs | Configured compute region |
| Amazon SES | The sole email transport, inbound and outbound | Recipient addresses, message content, and bounce/complaint events for sending reputation | AWS regions selected for the account |
| Single sign-on for the developer console | Email address, name, and Google account identifier. Retained only if you sign in with Google. | Google's global infrastructure | |
| Stripe | Subscription billing for paid plans | Billing contact, plan, and payment status. Card numbers are handled by Stripe and never reach our systems. | Stripe's global infrastructure |
Email content. Messages you send or receive transit Amazon SES and are archived in Cloudflare R2. We are the only party with logical access to your message bodies.
Changes to this list. If we add a subprocessor we will update this page and notify customers by email before it takes effect. See the changelog for material changes.
Questions about this list or our data handling can go to privacy@gork.email. See also our Privacy Policy and Security.