Νομικά & Απόρρητο
Sub-processors
This page lists the third-party sub-processors and recipients that the operator of filterit (the "Operator") engages to provide the AI chat and data-masking gateway service (the "Service", "Filterit"). It is a living document; see Section 3 for change notifications. It supplements the Privacy Policy.
Important: pseudonymisation, not anonymisation. Content sent to AI providers is masked/pseudonymised (detected identifiers replaced with reversible tokens such as [NAME_1]). It remains personal data; the token to value mapping is retained encrypted in the Vault for 30 days. Detection is best-effort and may be incomplete.
1. Current Sub-processors and Recipients
| Sub-processor | Service provided | Data processed | Primary location | Transfer safeguard | Engaged when |
|---|---|---|---|---|---|
| Anthropic, PBC (Claude API) | LLM inference on masked content | Masked/pseudonymised prompts, masked document/OCR text, masked email-draft context, masked meeting transcripts and review-grid documents | United States | Standard Contractual Clauses contained in Anthropic's data processing agreement; content pseudonymised before transfer | Every request that reaches an AI model (chat, documents, email drafts, mail automation, meetings, review grid) |
| Hetzner Online GmbH | Hosting, compute, storage; database backups kept on the server for up to 14 days | All stored Service data (masked and encrypted content, encrypted Vault, account data, logs) | Germany (Falkenstein), EU | EEA hosting, no third-country transfer | Always |
| Google LLC (Gmail API, Google sign-in) | Email Assistant (Gmail API) and Sign in with Google (identity) | OAuth tokens (encrypted at rest by the Operator); live email content (not persisted); for sign-in: e-mail, name, picture address | United States | Standard Contractual Clauses contained in Google's data processing terms | Opt-in only (Users who connect a Gmail mailbox) / when you choose Google sign-in |
| Microsoft Corporation (Outlook / Microsoft Graph) | Email Assistant: fetch threads, send user-reviewed drafts | OAuth tokens (encrypted at rest by the Operator); live email content (not persisted) | United States / EU | Standard Contractual Clauses contained in Microsoft's data processing terms | Opt-in only (Users who connect an Outlook mailbox) |
| Stripe | Payment processing, Stripe-hosted checkout and billing portal | Account e-mail, plan, internal customer reference; card data handled by Stripe only | Per Stripe's terms (EU entity for European merchants) | Standard Contractual Clauses contained in Stripe's data processing agreement, where a transfer occurs | Paid plans only |
| Brevo (SMTP relay) | Transactional e-mail: verification, one-time codes, password reset, invitations, contact-form messages | Recipient address, message content | France, EU | EEA processing, no third-country transfer | Always (when an e-mail is sent) |
| Public search engines (through a SearXNG instance we run) | Web search tool | Model-written search queries with placeholders removed; nothing stored | Various | Public queries, no contract | When web search is on in a conversation (default on) |
Operator-run infrastructure (not third-party sub-processors)
| Component | Role |
|---|---|
| PostgreSQL | Encrypted Vault (AES-256-GCM token to value mappings), HMAC-indexed search terms, masked content encrypted at rest (AES-256-GCM), account data. Operated by the Operator |
| Redis | Cache (30 minutes) of the encrypted Vault rows for fast un-masking; decryption happens only in the application's memory. Also rate-limit counters and ephemeral session state. Operated by the Operator |
| Presidio, GLiNER, OCR and transcription services | Identifier detection, OCR, speech-to-text on the Operator's own servers; your plaintext does not leave our infrastructure for these steps |
2. Notes
- Anthropic is the only AI provider in use. We do not use OpenAI, Google Gemini or GitHub Copilot.
- AI providers receive masked content only; original personal data is not sent to them in identifiable form (subject to the best-effort limits of detection).
- Web search: when web search is on in a conversation (on by default, switchable off in the chat settings), the model writes the search query itself; placeholders are removed from it but it is not run through masking. The query goes from our server through the SearXNG aggregator to public search engines (Google, Bing, DuckDuckGo and others in the default set); the results come back to the model unmasked; the query is not written to the egress log.
- Email content is fetched live and not persisted; only encrypted OAuth tokens, masked and encrypted drafts and, for mailboxes with the automation switched on, masked and encrypted automation items are stored.
3. Reservation and Change Notification
3.1 The Operator may add, replace, or remove sub-processors as the Service evolves. Any added AI provider is subject to the same flow-down obligations (see Terms of Service Section 5 and the Acceptable Use Policy Section 6).
3.2 The Operator will update this page and, where required by law or contract, provide reasonable prior notice of material changes (and, for data-protection-significant changes, an opportunity to object). The "Last updated" date at the top reflects the current version.
3.3 To subscribe to change notifications or ask questions: contact@filterit.app (no Data Protection Officer has been appointed).