Everyone who touches your data, on one page.
These are the companies that process data on our behalf, what each one does, and what each one can see. It is the same list as section 5 of the privacy policy, pulled out on its own because this is the page a buyer asks for by name.
The list
| Provider | What it does | What it can see |
|---|---|---|
| Supabase | Database, authentication and file storage | Account data, your posts and media, connection records, usage data |
| Anthropic | AI features, including reading a platform error and drafting the repair | The post content and the platform error involved in that request |
| Google (Gemini) | AI features | The content you submit to a feature that uses it |
| Stripe | Payments, once paid plans are live | Billing and card data, which Stripe collects directly from you |
| Hostinger | This website, and the mailbox behind our support addresses | Anything you put in an email to us |
| Connected social platforms | Publishing, and reading back the result, at your instruction | Whatever you send them, plus the account you connected |
Our AI providers are used under terms where customer content is not used to train their models. Card numbers never reach our servers; Stripe collects them directly.
What is deliberately not on it
No advertising or tracking networks. There is no ad pixel, no data broker, and no cross-context behavioral advertising. We do not sell personal information.
No individual social platform is named yet. Each one joins the row above as its access is approved and switched on, and we are not listing a platform before that is true. The reason is the same reason there is no platform list on the features page: a support list that is really a roadmap is how this category earned its reputation.
Tools that never touch customer data are not subprocessors. Our own build and design tooling only sees our work, so putting it here would pad the page rather than inform you.
When this page changes
Adding a provider that processes your personal data means this page changes on the same day, and the change is written into the changelog like everything else. If you want to be told directly instead of checking, email support@cosmoose.io and ask to be on the notice list.
Removing a provider gets the same treatment. A subprocessor list that only ever grows is a list nobody is maintaining.
Where this stands today
Cosmoose has no paying customers yet, so most of these providers are holding our own test data and nothing else. Stripe has taken no customer charge. The list is written now because writing it after the first buyer asks is how it ends up inaccurate.
There is no signed data processing agreement on file to hand you yet. If you need one before you buy, ask, and it gets written for you rather than promised here.
Still have a question about your data?
Ask it and a person answers. The deletion path is written out in the privacy policy, and it works whether or not you ever pay us anything.