Sub-processors
Version 1.0 · 23 September 2026
Every service that receives data Borehole holds. Not a category list — the actual vendors, what each one gets, and whether you can use the product without it.
Anything that receives data belonging to the people who use Borehole is here, however small the amount. Services that receive only our data — billing for our own cloud spend, for instance — are not, because they hold nothing of yours.
Google Cloud
- For
- Hosting, database, scanning
- Where
- europe-west1 (Belgium)
- Receives
- Everything Borehole stores: accounts, reports, orders, sessions.
Stripe
- For
- Payments
- Where
- United States and globally
- Receives
- Your email address and what you bought. Card details go to Stripe directly and never reach us.
GitHub
- For
- Sign-in and repository access
- Where
- United States
- Receives
- Your GitHub identity, and — for a private scan — read access to the repository you chose, for the length of that scan.
Resend
- For
- Transactional email
- Where
- eu-west-1 (Ireland)
- Receives
- The address a receipt or a reply is sent to, and the message.
Sentry optional
- For
- Error reports
- Where
- Germany
- Receives
- Diagnostic context when something breaks. Scrubbed before it leaves the process, by key name and by value shape.
PostHog optional
- For
- Product analytics
- Where
- EU cloud
- Receives
- A pseudonymous identifier — a salted hash, never your address — and which pages were reached. Session replay is off.
Transfers outside the EU
Our own infrastructure is in the EU. Stripe and GitHub are US companies, so using them involves a transfer outside the EU under their standard contractual clauses. You cannot buy without Stripe or sign in without GitHub, which is stated here rather than in a footnote because it is not a choice we can offer you.
Changes
Adding a sub-processor changes who can see your data, so it is a change to this page with a new version and date. If you have an arrangement with us that requires advance notice, it takes precedence over this paragraph.
See also the Privacy Policy and the Terms. For a data processing agreement, write to support@borehole.dev.