Sub-processors

Last updated: 2026-10-03 (Sentry removed — never activated; errors now go to Google Cloud Error Reporting, already a listed sub-processor)

Tacit, built and operated by Kiwana AI, Inc., uses the following sub-processors to operate the Service.

Sub-processorServiceLocationData
Google (Firebase Authentication)Identity & sign-inUS/GlobalEmail, password hash, OAuth identity, custom claims (tenant_id, role)
Neon Inc.Managed PostgresUS (AWS us-east-2, Ohio)All workspace data
Google Cloud (Cloud Run, GCS, Secret Manager, Cloud Logging, Cloud Monitoring, Error Reporting)Application hosting + object storage + secret/log/metric services + error reportingUS Central (default)Application traffic, logs, metrics, agent manifest files, master KEK; error reports (error message, stack trace, page path — no cookies, tokens or request bodies), kept 3 days
Anthropic (via Google Cloud Vertex AI, or direct API)Large language model inferenceUS (Vertex region)Prompts and tool inputs sent to the model; outputs returned. We can route to Anthropic direct API or Vertex AI per deployment.
Google (Google AI / Gemini API)Text embeddings (primary) + Gemini inferenceUS/GlobalKnowledge/corpus text and prompts sent to generate embeddings and, where configured, Gemini completions.
OpenAI, L.L.C.Text embeddings (fallback) + model inference where configuredUS/GlobalKnowledge/corpus text and prompts sent for embeddings/inference when the OpenAI provider path is used.
Stripe, Inc.Subscription billingUS / GlobalCustomer email, billing address, card token, subscription state. Statement descriptor: **Kiwana AI*tacitrun.com**
Resend, Inc.Transactional emailUSRecipient email, subject, body of notifications
Twilio Inc. (SendGrid)Transactional email (welcome and account notifications)US (Global endpoint)Recipient email, subject, body of notifications
Better Stack (formerly Logtail)Status page + uptime monitoringEU / GlobalService health metrics, public status page content
AWS (Amazon Web Services)Customer-side: Tier 1 manifest upload (S3) + Tier 2 Bedrock AgentCore deployCustomer's AWS account / regionManifest JSON + agent spec when the customer chooses AWS deploy

Bring your own model / your own project (Enterprise). An Enterprise workspace may route model inference to Claude models on Vertex AI in the customer's own Google Cloud project, or to the customer's own OpenAI or Azure OpenAI account, and may run its deployed agents as Cloud Run services in the customer's own Google Cloud project. Those calls and services run under the customer's own agreement with Google, OpenAI or Microsoft; the vendor acts for the customer, not as a Tacit sub-processor. An OpenAI / Azure OpenAI key the customer provides is stored encrypted in the credential vault and used only for that workspace.

Notice: Kiwana AI, Inc. will provide at least 30 days' notice via email and in-product banner before adding a new sub-processor.

Contact: privacy@kiwana.ai · www.kiwana.ai