Subprocessors
Last updated: July 31, 2026
Knightian Labs, LLC (“we”, “us”, or “our”) uses the third-party services listed on this page to operate the Bridge Town platform. Each service acts as a data subprocessor — it receives, stores, or processes personal data on our behalf in order for us to deliver the Service. AI providers selected by customers are not Bridge Town subprocessors: Bridge Town does not send customer prompts, model source, financial data, tool inputs, or tool results to a language model provider.
We review this list when we onboard a new vendor. If you have questions about any subprocessor, contact privacy@bridgetown.builders.
Production Subprocessors
| Vendor | Service | Data Processed | Primary Region | Retention / Deletion |
|---|---|---|---|---|
| Auth0 (Okta) | Authentication and identity management | Email address, display name, OAuth tokens, session metadata | US (Okta US region) | Deleted within 30 days of account closure on request |
| Amazon Web Services (AWS) | Cloud infrastructure — compute (ECS Fargate), relational database (RDS PostgreSQL), object storage (S3), caching (ElastiCache), CDN (CloudFront), audit logging (CloudWatch) | All data at rest and in transit | us-east-1 (primary). Data does not leave AWS US regions without explicit configuration | Per product retention schedules; infrastructure logs retained up to 12 months |
| Google (OAuth 2.0 / Google Sheets) | Social login; optional Google Sheets data integration | OAuth profile (email, display name) for social login; spreadsheet content you explicitly connect to Bridge Town models | US | OAuth tokens revoked on account closure; Sheets access removed when integration is disconnected |
| Google Analytics | Public website analytics | Page views, browser/device metadata, approximate geography. No financial model content | US | Analytics retained according to Google Analytics property settings |
| PostHog | Product analytics and session insights | Anonymised usage events, page views, session duration, browser/device metadata. No financial model content | US (us.i.posthog.com) | Analytics retained up to 2 years in aggregated form; cookies persist up to 1 year |
| Stripe | Payment processing and billing | Billing contact name, email, payment method token (card details are handled end-to-end by Stripe; we never see raw card numbers) | US | Billing records retained 7 years as required by law |
| Resend | Transactional email (account notifications, password reset, billing receipts) | Email address and the content of service notifications | US | Message logs retained up to 30 days |
| Gitea (self-hosted) | Internal Git hosting for tenant model repositories | Model source code, commit history, and metadata for all tenant models | AWS us-east-1 (within our own infrastructure) | Deleted within 30 days of account closure on request |
Data Categories Summary
| Category | Example data | Processed by |
|---|---|---|
| Identity and authentication | Email, display name, OAuth tokens | Auth0, Google OAuth |
| Infrastructure and operational | All platform data at rest and in transit | AWS |
| AI client context | Prompts and conversation handled by the client’s provider | Customer-selected AI provider; not a Bridge Town subprocessor |
| Financial model content | Python model code, CSV/Parquet snapshots, query results | AWS (storage/compute), Gitea |
| Usage analytics | Anonymised page views and feature interactions | PostHog, Google Analytics |
| Billing data | Contact details and payment tokens | Stripe |
| Service notifications | Email address and notification content | Resend |
We do not process special-category personal data (health, biometric, racial or ethnic origin, etc.) and do not invite or expect customers to upload such data.
Data Regions
All production infrastructure runs in AWS us-east-1. Auth0 processes identity data in the Okta US region. PostHog routes analytics to the US PostHog cloud (us.i.posthog.com). Google Analytics, Stripe, and Resend are headquartered in the US. A customer’s selected AI provider may process prompts under the customer’s separate agreement with that provider; that flow is outside Bridge Town’s infrastructure and subprocessors list.
If your organisation requires EU data residency, contact support@bridgetown.builders to discuss options. EU-resident data residency is not available as a standard product tier at this time.
Retention and Deletion
| Data type | Retention period | Notes |
|---|---|---|
| Account and identity data | Duration of subscription + 90 days | Kept briefly to allow account recovery |
| Financial model data | Deleted within 30 days of account closure on request | Includes Git history in Gitea |
| Usage analytics | Up to 2 years (aggregated, anonymised) | PostHog and Google Analytics |
| Billing records | 7 years | Legal / accounting requirement |
| Infrastructure logs | Up to 12 months | CloudWatch audit and application logs |
| AI client context | Governed by the customer’s selected AI provider | Outside Bridge Town’s subprocessors list |
To request deletion of your data, email privacy@bridgetown.builders with the subject line “Data Deletion Request”.
Contact
Questions about this list? Email privacy@bridgetown.builders.
For DPA requests or security review enquiries, see our Security and Compliance page.