Subprocessor List

Last updated: July 5, 2026

Every vendor that touches any part of Sidebar, what each one can see, and what it keeps. We update this page before adding or changing any subprocessor that handles workspace content.

Draft — pending attorney review. This document describes how Sidebar actually operates today and is published for transparency while formal legal review is completed. It will be finalized before general availability.

Core infrastructure

VendorRoleWhat it seesRegionWhat it keeps
SupabaseDatabase & file storageYour saved workspace: content encrypted app-layer (AES-256-GCM); titles/matter labels and uploaded original files protected by access controls and disk encryptionUnited States (us-east-1)Until you delete it
VercelApplication hostingRequest/response traffic in memory while serving you; server logs (metadata)United StatesEphemeral compute; short-lived logs
ClerkAuthenticationYour email, identity, firm membership, sessionsUnited StatesWhile your account exists
Serverless compute (document generation)Runs the document-generation stepDocument-generation payloads during processing (no network access from the sandbox)United States (us-east-1)Nothing (structural logs only)

Backups and disaster-recovery copies are managed by our database provider within the same United States region and the same isolation and encryption boundary; they are included in deletion when you erase your data. A subprocessor list naming the specific underlying cloud providers is available to firms under a data processing agreement.

AI model providers (zero-retention channels only)

Every model is reachable in Sidebar only because a signed zero-retention agreement with that provider is in place — none is a bolt-on setting.

VendorRoleWhat it seesWhat it keeps
Anthropic (Claude), via cloud model-hostingDefault modelPrompt + response during inference, inside an isolated zero-retention cloud environmentNothing — retention mode: none
OpenAI (GPT)Selectable modelPrompt + response during inference, storage disabled (store: false) on every requestNothing retained; never used for training
Google (Gemini)Selectable modelPrompt + response during inference under a signed zero-retention agreementNothing retained; never used for training
AI Gateway (Vercel)Routes one model variant we don't serve from our own accountPrompt + response in transit only, zero-retention mode enforced and fails closedNothing

Research services

VendorRoleWhat it seesWhat it keeps
CourtListener (Free Law Project)Case-law search & opinionsModel-composed search queries; no account or firm identifiers attachedStandard service logs on their side; retrieved opinions are public documents
Brave SearchWeb search (when enabled)Model-composed search queries; no account or firm identifiers attachedNo-retention search tier

Honest caveat: research queries are composed by the model from your conversation, so the query text itself can reflect matter details even though we attach no identifiers. This is inherent to any web-grounded research tool. For matters too sensitive for external queries, leave research off.

Operations

VendorRoleWhat it seesWhat it keeps
StripeBillingPayment details and billing identity — never workspace contentStandard financial-records retention
SentryError monitoringScrubbed error events — request bodies and personal data stripped before sendingShort-lived error events

There is no separate email, analytics, session-replay, or customer-support subprocessor beyond the above: authentication email is handled by Clerk, and we run no third-party analytics, ad trackers, or session-recording tools on the workspace.

Questions about any vendor on this list: privacy@sidebar-ai.com. See also our Data Practices page.