Subprocessors

Last updated: September 2, 2026

A subprocessor is a third party that Henry AI Technologies LLC ("Henry", "we") engages to process Customer Content on our behalf in order to provide the Service. This page lists our current subprocessors, what each one does for us, the kinds of data it handles, and where it processes that data. It is the list referenced in our Data Processing Addendum and Privacy Policy.

How we notify you of changes. Before a new subprocessor processes Customer Content, we update this page and email the owners of every Workspace at least 30 days in advance. To have notices sent to an additional address (for example a privacy or procurement mailbox), email privacy@usehenry.aiwith the subject line "Subprocessor updates". Customers subject to data protection laws may object to a new subprocessor as described in the DPA.

Infrastructure and core subprocessors

These providers are involved in running the Service for every Customer.

SubprocessorPurposeData processedLocation
Vercel (including Vercel AI Gateway and Vercel Sandbox)Application hosting and serverless compute; routing of model requests to AI providers; isolated per-Workspace microVMs for code execution.Customer Content in transit through the application; model prompts and responses; files and artifacts produced in the sandbox.United States (Oregon)
Supabase (hosted on Amazon Web Services)Primary database, authentication, and file storage.All stored Customer Content, account data, and authentication identifiers; uploaded files and attachments; Agent Browser screenshots; originals of documents texted to a personal Workspace (document wallet). A separate Supabase project for the marketing site holds contact sales and waitlist form submissions.United States (AWS us-west-2, Oregon)
InngestBackground job orchestration: scheduled tasks, event processing, and retries.Event payloads, which can include message content, Workspace and user identifiers, and task definitions.United States
StripePayment processing and subscription billing.Billing contact name and email, payment details entered on Stripe-hosted checkout (card numbers never reach Henry), and subscription identifiers.United States
ResendDelivery of system emails (sign-in codes, invitations, notifications) and inbound and outbound mail for the email channel.Email addresses; subject lines and bodies of messages sent to or from a Workspace's Henry email address; system notification content.United States

AI model and processing providers

Henry sends the content the model needs to answer a request (the conversation, relevant memories and knowledge, connected-tool results, and attachments) to the providers below. They are used only to provide the Service. Under our commercial terms with each provider, Customer Content is not used to train their models, and Henry does not train foundation models on Customer Content. Model requests are routed through the Vercel AI Gateway, and Henry may fall back to another listed provider when one is unavailable.

SubprocessorPurposeData processedLocation
Anthropic, PBCLarge language model inference.Prompts, including Customer Content and attachments; Output.United States
OpenAILarge language model inference, including failover.Prompts, including Customer Content and attachments; Output.United States
xAI Corp.Large language model inference.Prompts, including Customer Content and attachments; Output.United States
Baseten and Fireworks AI (serving Moonshot AI Kimi models)Inference for Kimi models. Requests are pinned to these US inference hosts; Moonshot AI does not receive Customer Content.Prompts, including Customer Content; Output.United States
Parallel (via Vercel AI Gateway)Web search, when the model chooses to search the web.The search query the model composes.United States
Voyage AIText embeddings for knowledge retrieval.Text of messages, captured channel content, memories, and files being indexed.United States
ElevenLabsSpeech to text for voice messages and audio attachments.Audio recordings sent to Henry.United States

Channel and integration providers

These providers process Customer Content only when a Customer enables the corresponding channel or integration. Using Henry inside Slack or Microsoft Teams also means those platforms handle your messages under your own agreements with them.

SubprocessorPurposeData processedLocation
SendblueiMessage and SMS relay for the texting channel, over dedicated Henry phone numbers (one per Workspace a phone is linked to).Phone numbers; text, photos, PDFs, and voice messages exchanged with Henry over text.United States
Slack (Salesforce)Delivery of the Henry Slack app.Slack user and workspace identifiers; messages in channels and direct messages where Henry is present.United States
MicrosoftDelivery of the Henry Microsoft Teams app.Teams user and tenant identifiers; messages in chats and channels where Henry is installed.United States
Apple Inc. (APNs), Google LLC (FCM), and Expo (push service)Push notification delivery to the iOS and Android apps.Device push tokens; notification titles and preview text.United States
Pipedream (Pipedream Connect)OAuth connection management and API execution for third-party tools you connect. Holds the OAuth tokens; Henry does not.OAuth tokens for connected tools; requests to and responses from those tools.United States
ComposioOAuth connection management and API execution for third-party tools you connect. Holds the OAuth tokens; Henry does not.OAuth tokens for connected tools; requests to and responses from those tools.United States

Agent Browser provider

This provider processes data only when an Authorized User runs an Agent Browser task. Websites the browser visits receive the requests any browser would send, under their own privacy policies; they are not our subprocessors.

SubprocessorPurposeData processedLocation
BrowserbaseCloud browser infrastructure for the Agent Browser: runs the isolated browser session Henry operates for a user, holds that user's browser profile (cookies and signed-in state) for each site they sign in to, provides the live view the user signs in through, records sessions for review, and routes the browser's web traffic.Web pages visited and their content; form input Henry enters at the user's direction; the user's own sign-in state for each site (credentials are typed by the user on the live view and are not received by Henry); session recordings.United States

Internal tools that may incidentally process personal data

The following tools support how we run the company. They do not process Customer Content as part of delivering the Service, but they can incidentally contain personal data such as a contact's name and email address or the text of a support request.

  • Google Workspace: email for support, privacy, legal, and security correspondence.
  • Linear: issue tracking. When a user files a report through Henry's "report issue" feature, the text the user wrote is sent to Linear.
  • GitHub: source code hosting and continuous integration.
  • Website analytics and advertising (Google Analytics and Google Tag Manager, Vercel Web Analytics, Cometly): process visitor data on usehenry.ai only, subject to the consent and opt-out controls in our Cookie Policy; they never run in the signed-in Service and never receive Customer Content.
  • Mintlify: hosts our public documentation site. Visits to the documentation are processed by Mintlify under its own privacy policy; no Customer Content is involved.
  • Slack: internal team communication, which can include discussion of support requests.

Changes

We keep a log of changes to this page. Notice of new subprocessors follows the process described at the top of this page.

DateChange
2026-09-02Initial publication, including Browserbase (Agent Browser provider, in use since 2026-08-31).

Contact

Questions about this list: privacy@usehenry.ai.