Last updated: July 5, 2026
Every vendor that touches any part of Sidebar, what each one can see, and what it keeps. We update this page before adding or changing any subprocessor that handles workspace content.
Draft — pending attorney review. This document describes how Sidebar actually operates today and is published for transparency while formal legal review is completed. It will be finalized before general availability.
| Vendor | Role | What it sees | Region | What it keeps |
|---|---|---|---|---|
| Supabase | Database & file storage | Your saved workspace: content encrypted app-layer (AES-256-GCM); titles/matter labels and uploaded original files protected by access controls and disk encryption | United States (us-east-1) | Until you delete it |
| Vercel | Application hosting | Request/response traffic in memory while serving you; server logs (metadata) | United States | Ephemeral compute; short-lived logs |
| Clerk | Authentication | Your email, identity, firm membership, sessions | United States | While your account exists |
| Serverless compute (document generation) | Runs the document-generation step | Document-generation payloads during processing (no network access from the sandbox) | United States (us-east-1) | Nothing (structural logs only) |
Backups and disaster-recovery copies are managed by our database provider within the same United States region and the same isolation and encryption boundary; they are included in deletion when you erase your data. A subprocessor list naming the specific underlying cloud providers is available to firms under a data processing agreement.
Every model is reachable in Sidebar only because a signed zero-retention agreement with that provider is in place — none is a bolt-on setting.
| Vendor | Role | What it sees | What it keeps |
|---|---|---|---|
| Anthropic (Claude), via cloud model-hosting | Default model | Prompt + response during inference, inside an isolated zero-retention cloud environment | Nothing — retention mode: none |
| OpenAI (GPT) | Selectable model | Prompt + response during inference, storage disabled (store: false) on every request | Nothing retained; never used for training |
| Google (Gemini) | Selectable model | Prompt + response during inference under a signed zero-retention agreement | Nothing retained; never used for training |
| AI Gateway (Vercel) | Routes one model variant we don't serve from our own account | Prompt + response in transit only, zero-retention mode enforced and fails closed | Nothing |
| Vendor | Role | What it sees | What it keeps |
|---|---|---|---|
| CourtListener (Free Law Project) | Case-law search & opinions | Model-composed search queries; no account or firm identifiers attached | Standard service logs on their side; retrieved opinions are public documents |
| Brave Search | Web search (when enabled) | Model-composed search queries; no account or firm identifiers attached | No-retention search tier |
Honest caveat: research queries are composed by the model from your conversation, so the query text itself can reflect matter details even though we attach no identifiers. This is inherent to any web-grounded research tool. For matters too sensitive for external queries, leave research off.
| Vendor | Role | What it sees | What it keeps |
|---|---|---|---|
| Stripe | Billing | Payment details and billing identity — never workspace content | Standard financial-records retention |
| Sentry | Error monitoring | Scrubbed error events — request bodies and personal data stripped before sending | Short-lived error events |
There is no separate email, analytics, session-replay, or customer-support subprocessor beyond the above: authentication email is handled by Clerk, and we run no third-party analytics, ad trackers, or session-recording tools on the workspace.
Questions about any vendor on this list: privacy@sidebar-ai.com. See also our Data Practices page.