Vibe Co-PilotVibe Co-Pilot

Subprocessors

Last updated: August 2026 | Provider: Vibe Technologies, LLC

This page lists every third party that receives user data, prompt content, or page content through the Extension, the hosted relay, the marketing site, or our support channel, referenced from our Privacy Policy. "Active" entries below process data as part of normal operation; entries marked "only when you select this provider" or "off by default" depend on your own configuration choices.

SubprocessorPurposeData sharedRegionStatus
OpenAIAI model provider (when you configure OpenAI as your model)Prompts, page text/DOM, screenshots when the task needs them, tool call contextUnited States (global infrastructure)Active — only when you select this provider
AnthropicAI model provider (when you configure Anthropic/Claude as your model)Prompts, page text/DOM, screenshots when the task needs them, tool call contextUnited States (global infrastructure)Active — only when you select this provider
Google (Gemini)AI model provider (when you configure Gemini as your model)Prompts, page text/DOM, screenshots when the task needs them, tool call contextUnited States / global infrastructureActive — only when you select this provider
DeepSeekAI model provider (when you configure DeepSeek as your model)Prompts, page text/DOM, screenshots when the task needs them, tool call contextPeople's Republic of China. This is a materially different jurisdiction for data protection and government-access law than the other model providers on this list — evaluate this before selecting DeepSeek for sensitive tasks.Active — only when you select this provider.
OpenRouterAI model routing provider (when you configure OpenRouter as your model)Prompts, page text/DOM, screenshots when the task needs them, tool call context. OpenRouter forwards these to whichever underlying model you select through it.United States (routes to multiple underlying providers/regions)Active — only when you select this provider
LangfuseLLM tracing/observabilityPrompts, model inputs/outputs, page content captured in tracesVibe-operated, self-hosted instance at langfuse.vibebrowser.app (confirmed from the configured client's baseUrl in the currently served build; hosting region unverified). Not cloud.langfuse.com — that hostname appears only as the Langfuse SDK's generic fallback default, never as the configured destination.At the last served-artifact check on August 22, 2026, Google's Chrome Web Store build still contained Vibe's Langfuse client configuration and attempted client-side tracing to langfuse.vibebrowser.app. While the embedded credential remains valid, trace content may be sent there. A merged fix disables extension-side Langfuse initialization entirely. Release verification tracks provider-side key revocation and confirmation that Google serves the clean artifact.
SentryError tracking and crash diagnosticsError messages, stack traces, browser/extension version, sanitized error context. Session replay is disabled. Cookies and request headers are stripped before sending.United States (Sentry.io)Active whenever a Sentry DSN is configured in the build (lib/sentry-config.js). There is currently no separate opt-out toggle for error reporting — this is a disclosed gap, not a described control.
Google Analytics 4Product analyticsPseudonymous client identifier, hashed user identifier, plan tier, low-cardinality event names/properties. Routed through a first-party endpoint on api.vibebrowser.app first.United States / global infrastructure (Google)Active by default (consent-gated toggle); opt-out in Extension settings.
StripePayment processing and subscription billingBilling email, subscription status, customer identifier. Card numbers are entered on Stripe's systems directly — we never receive or store full card details.United States (global payments infrastructure)Active for all paid plans.
SupabaseAccount/auth backend for the extension's portal (sign-in, plan/entitlement state) and the marketing site's waitlist databaseAccount email, OAuth identity, subscription/plan status, waitlist signup metadata (UTM/referral fields).Hosted Supabase project (US region unless otherwise configured)Active for signed-in users and waitlist signups.
Chatwoot (self-hosted)Customer support inbox for [email protected] and in-app reportsYour support message content, email address, and any attachments you send us.Self-hosted at support.agentlabs.cc, on our own infrastructure (see Oracle/Cloudflare rows below)Active — only when you contact support.
CloudflareCDN, DNS, and Workers used to route the marketing site and the support-email-to-Chatwoot pipelineStandard request metadata (IP, headers) for traffic it proxies; email content for the support-forwarding Worker.Global edge networkActive for all vibebrowser.app web traffic and the support-email path.
Oracle Cloud Infrastructure (OCI)Control-plane hosting for backend/API infrastructure (see infra-tree)Whatever backend data those services hold at rest (account/session data described above) — OCI itself is an infrastructure host, not a separate data recipient with its own use of the data.Oracle Cloud region in use for our deploymentActive — underlying infrastructure, not user-facing.

Verification note (August 2026 audit)

This list was built by walking the codebase, not by inference: model provider configs (apps/chat4/src/constants/providers.ts, models.ts), the analytics/consent gate (lib/analytics.ts, vibe.analytics.enabled), the Supabase auth/config client (lib/shared/vibe-supabase-config.ts), and the live Chatwoot support inbox configuration. Before this update, Supabase, Chatwoot, Cloudflare, Oracle Cloud, and DeepSeek were not disclosed anywhere in the Privacy Policy even though each one is live in production today. That was the gap this page and the linked Privacy Policy updates close.

We will keep this page in sync with the Privacy Policy. If you believe a subprocessor is missing, email [email protected].