Legal
Sub-processors
The complete list of third parties that may process customer data on our behalf. We give at least 30 days' notice before adding to it.
| Sub-processor | What it's used for | Processing location |
|---|---|---|
| Google Cloud Platform | Application hosting, task queues, and object storage for run evidence. | United States |
| Firebase (Google) | Authentication and account records. | United States |
| Daytona | Ephemeral per-task sandboxes in which runs execute. | United States |
| Anthropic | Model inference for research, code generation, and review passes. | United States |
| Stripe | Billing and payment processing. Stripe never receives repository content. | United States |
| Vercel | Hosting for the web application. | United States |
What this list does not include
The services you connect — GitHub, Notion, Slack, Vercel, Google Workspace, Figma, PostHog — are not sub-processors. Elisha acts on your existing accounts with those providers under your own agreements with them; data doesn't flow to them through us.
Notice of changes
We'll give at least 30 days' notice before adding or replacing a sub-processor. Under the DPA you may object on reasonable data protection grounds. To be notified, email legal@elisha.dev and ask to be added to the list.
Last updated: July 12, 2026