Subprocessors
Last Updated: August 15, 2026
1. Scope
OXYGEN GTM Inc. uses subprocessors to provide hosting, identity, billing, analytics, AI, integration, enrichment, observability, and support functions for OXYGEN. Actual subprocessors vary based on the integrations, workflows, providers, and done-for-you services a customer enables.
2. Current Subprocessors
| Provider | Purpose |
|---|---|
| Clerk | Authentication, user identity, OAuth |
| Neon | Managed Postgres for control and tenant databases |
| Vercel | Application hosting, web analytics where enabled |
| Fly.io | Background worker compute for table, workflow, and provider runs |
| Hetzner Online | Object storage for table import files |
| Stripe | Billing and payment processing |
| PostHog | Product and website analytics; session recording of the signed-in application, which can capture workspace content displayed on screen; and MCP tool-call telemetry, which carries the arguments sent to a tool and the result it returned and can therefore contain workspace content |
| Axiom | Operational logs, traces, and telemetry |
| Anthropic and other AI model providers | AI model processing where configured or instructed |
| Unipile | Email, LinkedIn, and messaging integration access where configured |
| Composio | CRM and productivity integration access where configured |
| Enrichment and data providers | Contact, company, email, phone, and account enrichment where selected |
Session recording applies to the signed-in OXYGEN application only, and only where a user has allowed optional analytics. It is excluded on authentication, credential, API-token, vault, billing, and payment screens, and a recording captures the rendered page rather than network traffic, so request and response bodies, provider payloads, and AI prompts do not appear in a recording.
MCP tool-call telemetry is a separate transmission and is not limited in the same way. When a tool on the OXYGEN MCP server is called, the arguments sent to that tool and the result it returned are transmitted to PostHog alongside the tool name, timing, and outcome, and can therefore contain workspace content such as contact records, search terms, and message content. It is processed server-side and is not governed by the cookie banner. An automated filter redacts fields named like credentials, omits a fixed set of bulk-content field names, scans remaining text for credential material such as bearer tokens and database URLs, and truncates the payload by length, breadth, and nesting depth; that filter works on field names and credential shapes, so it does not remove personal data written into free-text fields and is not a guarantee that every secret is caught. AI prompts and model outputs, server logs and stack traces, and payment card data are not transmitted to PostHog at all. Section 13 of the Privacy Policy describes both in full.
3. Provider-Specific Tools
OXYGEN also exposes customer-selected tool and enrichment providers. When Customer runs a provider tool, the provider receives the input necessary to perform that operation. Customer is responsible for selecting providers appropriate for its legal basis, jurisdictions, and data-protection obligations.
4. Notices & Objections
OXYGEN will update this page before a new subprocessor processes customer personal data, and before an existing subprocessor begins processing a materially new category of it. The August 15, 2026 update is of the second kind: PostHog already processed analytics and session recordings, and now also receives MCP tool-call arguments and results. Customers may object on reasonable data protection grounds within 30 days of the update by contacting philipp@oxygen-agent.com.