Subprocessors

Every vendor that touches personal data on Oat's behalf, what it does, and what it receives. Providers you connect yourself are listed separately.

Last updated 23 September 2026

The operating company name, its registered address and the governing law for these terms are to be confirmed by counsel before public launch. Everything else on this page describes what the service does today.

Always in use

Subprocessors used to run Oat for every workspace
VendorWhat it does for OatWhat it receives
VercelHosts the web app and serves every requestRequests and responses, technical logs, server-side environment
Vercel AI GatewayRoutes calls to the configured writer model and to Dollop, Oat's checker, which runs on Jev by TypeSafe AI; the model providers sit behind itThe draft, its brief, voice rules and evidence for the call in hand. Never credentials or tokens
NeonPostgres database and the private object storage bucketAll workspace records and files, and access and contact requests
ClerkSign-in, sessions and user recordsName, email address, sign-in method, session data
TavilyWeb research for draftsSearch queries derived from the topic. Not your archive
RailwayRuns the worker that prepares, assesses, renders and publishesThe job in hand: the draft, its context, and the encrypted connection it needs for a delivery
ResendSends a notification email when a request arrives through this site, only where configuredThe contents of that request

Model providers behind the gateway are configurable per deployment; the desk shows the model identifier in use on every draft. The location of each vendor and the transfer mechanism for data leaving the UK and the EEA will be added here once confirmed by counsel.

Only when you connect them

These receive data only after a member of your workspace connects the account, and only what that connection needs. Disconnecting stops the flow and deletes the stored token.

Providers that receive data when a workspace connects them
ProviderConnectionWhat it receives
GoogleGoogle Analytics, Search Console, YouTubeYour sign-in for the OAuth grant; for uploads, the approved video and its title and description
MetaInstagramYour sign-in for the OAuth grant; approved captions and images for publishing
LinkedInLinkedInYour sign-in for the OAuth grant; approved posts for sharing
HeyGenVideo rendersThe approved script and the avatar and voice you chose in your own HeyGen account
KapsoWhatsApp, on Oat's shared numberMessages between you and Oat, and your linked phone number
AppleMessages for BusinessMessages between you and Oat in that conversation
GitHubRepository publishingApproved pieces as files committed to the repository, branch and folder you chose
Your site hostWordPress or Vercel deploy hookApproved pieces as posts, or a build trigger

Changes

When a vendor is added or removed, this page changes and the date at the top changes with it. Workspace Owners are told by email before a new always-in-use vendor receives their data. Questions go through the contact page.