Back to Home

Legal

Subprocessors

The third parties that process data on our behalf to operate the service. We do not sell data, and we do not share your email content with anyone except the vendors listed below.

Our approach

We aim to keep this list short and each relationship load-bearing. Where a function can be performed in-house (for example, message sanitization or delivery logic), we keep it in-house rather than add a vendor. We do not use third parties for advertising, analytics, or training machine-learning models on your data.

VendorPurposeData processedRegion
CloudflareCompute, network edge, and object storageAPI request metadata, message bodies, attachments and raw MIME archives stored as objectsGlobal edge (data stored in the bucket's configured jurisdiction)
NeonManaged PostgreSQL — the primary datastoreOrganization and user records, inboxes, message metadata and bodies, drafts, API key hashes, webhook configuration and delivery logsConfigured compute region
Amazon SESThe sole email transport, inbound and outboundRecipient addresses, message content, and bounce/complaint events for sending reputationAWS regions selected for the account
GoogleSingle sign-on for the developer consoleEmail address, name, and Google account identifier. Retained only if you sign in with Google.Google's global infrastructure
StripeSubscription billing for paid plansBilling contact, plan, and payment status. Card numbers are handled by Stripe and never reach our systems.Stripe's global infrastructure

Email content. Messages you send or receive transit Amazon SES and are archived in Cloudflare R2. We are the only party with logical access to your message bodies.

Changes to this list. If we add a subprocessor we will update this page and notify customers by email before it takes effect. See the changelog for material changes.

Questions about this list or our data handling can go to privacy@gork.email. See also our Privacy Policy and Security.