Sub-processors

Last updated: September 10, 2026

lemongraph uses the third party providers listed below to deliver the service. Each one is bound by contract to protect your data and to use it only on our instructions. This page names every provider that receives customer data, what it receives and why it receives it.

This list supports our Privacy Policy, which explains what we collect and how we use it.

Providers that process mail and calendar content

These providers handle the content of your Gmail messages and Google Calendar events. None of them are permitted to use your data to train generalized AI or machine learning models.

OpenAI

  • Purpose: generating agent decisions and replies, and producing the embeddings used to match and retrieve prior context.
  • Receives: the message bodies, subjects, attachments and calendar events an agent is reasoning about, together with the working memory it has built for your account.
  • Location: United States.
  • Training: excluded. Our agreement does not permit your data to be used to train or improve their models.

Langfuse

  • Purpose: recording agent requests and responses so that we can debug incorrect behaviour and improve the product.
  • Receives: the same content sent to our model provider, as trace records. We remove email addresses, phone numbers, payment card numbers, IP addresses and access tokens before these records leave our systems. The surrounding text is retained, so treat these records as containing your content in de-identified form.
  • Location: European Union.

Amazon Web Services

  • Purpose: hosting the application, its database, its queues and its file storage. This is where your data lives at rest.
  • Receives: all customer data, including account information, mail and calendar content, attachments and agent memory.
  • Location: United States, in the us-east-1 region.

Providers that do not receive mail or calendar content

These providers support the service but never receive the contents of your mail or events.

Google Cloud

  • Purpose: delivering the notifications that tell us new mail has arrived, so that an agent can wake and respond.
  • Receives: notification metadata only, being your Gmail address and an opaque change marker. No message content passes through it. We fetch the messages themselves from Gmail directly.

Exa

  • Purpose: web search, when an agent needs public information to do its work.
  • Receives: the search terms the agent composed. No message or event content is sent.

PostHog

  • Purpose: product analytics, so that we can understand how the app is used.
  • Receives: your account identifier, your email address and records of activity within the app, such as signing up. No mail or calendar content.
  • Location: European Union.

Logo.dev

  • Purpose: showing your company logo in the app.
  • Receives: the domain portion of your work email address, meaning the part after the @ sign. The address itself is never sent, and personal Gmail addresses are excluded entirely.

Vercel

  • Purpose: hosting this public website.
  • Receives: ordinary web request information from visitors to our marketing pages. No customer data from the application.

Changes to this list

We update this page when a provider is added or removed. If you have a data processing agreement with us, we will notify you before adding a provider that processes your mail or calendar content, so that you have the opportunity to object.

Contact us

For questions about this list or to request notification of changes, email us at george@lemongraph.dev.