Subprocessors
Benchwright LLC relies on the vendors listed below to provide parts of the Service. Each vendor is contractually obligated to handle your data only to perform the services we buy from them.
1. Core infrastructure subprocessors
These vendors process data for every Benchwright customer as part of the core Service.
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| DigitalOcean, LLCInfrastructure hosting | Runs the Benchwright web application and API, and hosts the self-hosted sandbox compute runtime (sandbox0) we operate on DigitalOcean infrastructure. | Account metadata, HTTP logs, anything in transit to the app; for sandbox0-backed runs, benchmark inputs, generated code, model I/O, and credentials injected for the run. | United States |
| Supabase, Inc.Database, authentication, object storage | Stores user profiles, stored credentials (encrypted), benchmark runs, trace events, billing state, and authentication sessions. | Account info, stored credentials, run traces, billing records. | United States (primary); other regions if elected |
| Stripe, Inc.Payments | Processes credit-card top-ups and stores payment methods. | Name, email, billing address, payment method details, transaction amounts. | United States (globally replicated) |
| Cloudflare, Inc.Edge, DNS, DDoS protection | Serves DNS, terminates TLS, and mitigates abusive traffic at the edge. | IP addresses, HTTP request metadata, user-agent strings. | Global edge |
2. Model providers (customer-elected)
When a benchmark run targets a third-party large language model, we relay prompts and associated context to that provider using credentials you supply or that we make available to you. These providers process data only for the runs you direct.
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Google LLC (Gemini API, Google Cloud) | Serves Gemini model inference for runs you target at Google models. | Prompts, completions, and any context included in the request. | Global (per Google’s policies) |
| OpenAI, LLC | Serves OpenAI model inference for runs you target at OpenAI models. | Prompts, completions, and any context included in the request. | United States |
| Anthropic, PBC | Serves Claude model inference for runs you target at Anthropic models. | Prompts, completions, and any context included in the request. | United States |
| OpenRouter, Inc. | Routes model inference to upstream providers for runs you target through OpenRouter. | Prompts, completions, and any context included in the request. | United States (routes to upstream providers per their policies) |
| Together AI (Together Computer, Inc.) | Serves model inference for runs you target at Together-hosted models. | Prompts, completions, and any context included in the request. | United States |
| Other providers you configure | Any additional model or API endpoint you route traffic to through the Service, using credentials you supply. | Whatever you send through the configured endpoint. | As disclosed by the provider you select. |
Third-party model providers have their own privacy and data-retention practices, which are independent of this policy. You should review the terms of any provider you target.
3. Communication & support
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Google Workspace (Google LLC) | Email for the benchwright.ai domain (hello@, legal@, etc.). |
Email contents that you send to or receive from us. | United States |
| Twilio Inc. | Carries WhatsApp messages between you and your operator when you use Benchwright’s messaging number. Does not apply if you bring your own messaging number. | Message contents you send to or receive from the operator, and the sending/receiving phone number. | United States |
4. Future additions
We run our own first-party traffic counter (see the Cookie Notice for details) and do not send analytics data to any third party. If we ever do add a vendor in this category, we will list it here before it goes live.
5. Notice of changes
We will update this page when we add, remove, or materially change a subprocessor that processes customer personal information. You can subscribe to change notifications by emailing legal@benchwright.ai with the subject line “Subscribe: subprocessor updates.”
6. Contact
Questions about our subprocessors or requests for a data processing addendum: legal@benchwright.ai.