subprocessors

draft. not yet in force. see the checklist at the end.

everyone who processes data on crosscode's behalf, what they get, and where it sits. this page is the authoritative list referenced by the privacy policy and the data processing agreement.

six vendors. there is no seventh: the docs site loads no fonts, no cdn scripts and no third-party tags, and the only external hostname anywhere in its html is github.com.

effective from {{EFFECTIVE_DATE}}.

the list

subprocessor what it does for crosscode data it can access where it runs transfer mechanism
vercel inc. hosts the website and the serverless api. everything passes through it in transit all request and response data in transit, including file contents; server logs including ip addresses united states (iad1, plus edge) vercel dpa, eu sccs; vercel is eu–us data privacy framework certified
supabase inc. postgres database and authentication everything stored: file contents and paths, account records, project and invite records, device-code rows, email addresses, password hashes, github identities, sessions; automated backups canada, aws ca-central-1, montréal supabase dpa, eu sccs, plus the eu adequacy decision for canadian commercial organisations
github, inc. (microsoft) oauth identity provider; hosts the public repository and the uptime workflow your github account identity; the repository-access check at invite redemption is made against github with your own oauth token united states github dpa, eu sccs; microsoft is data privacy framework certified
posthog, inc. product analytics server-side: seven named events keyed on your supabase user id, with at most a file-version count and a new-user flag. website: four page events with no account id and no persistent identifier. no file contents, no paths, no branch or repository names, no email, no github login united states (us.i.posthog.com) posthog dpa, eu sccs
functional software, inc. (sentry) error monitoring route template, http method, status, platform request id, a redacted error message, and stack frames from crosscode's own code by basename. request bodies, headers, cookies and environment are never sent united states (ingest.us.sentry.io) sentry dpa, eu sccs
npm, inc. (github / microsoft) distributes the crosscode-cli package nothing about you. download requests carry an ip address and a user agent to npm, as any package install does united states covered by the github/microsoft terms above

sub-subprocessors. vercel and supabase each run on aws and front their endpoints with cloudflare, and both use their own further subprocessors. their dpas and subprocessor lists govern those; crosscode does not contract with them directly.

notable, because people ask

changes

adding or replacing a subprocessor is a change to what happens to your data, so:

how to object

reply to the notice, or write to privacy@getcrosscode.dev, before the 30 days are up. say which subprocessor and why.

we will explain the choice and look for an alternative. if there isn't one you can live with, you can stop syncing and ask for deletion under §9 of the privacy policy. the service is free, so there is nothing to refund and nothing holding you to it. objecting does not entitle you to have the vendor removed; it entitles you to a straight answer and a clean exit.

change log

date change
{{EFFECTIVE_DATE}} initial list published.

before this takes effect

view raw markdown · generated from docs/subprocessors.md at build time, do not hand-edit this page.