Subprocessors
Every vendor that touches personal data on Oat's behalf, what it does, and what it receives. Providers you connect yourself are listed separately.
Last updated 23 September 2026
Always in use
| Vendor | What it does for Oat | What it receives |
|---|---|---|
| Vercel | Hosts the web app and serves every request | Requests and responses, technical logs, server-side environment |
| Vercel AI Gateway | Routes calls to the configured writer model and to Dollop, Oat's checker, which runs on Jev by TypeSafe AI; the model providers sit behind it | The draft, its brief, voice rules and evidence for the call in hand. Never credentials or tokens |
| Neon | Postgres database and the private object storage bucket | All workspace records and files, and access and contact requests |
| Clerk | Sign-in, sessions and user records | Name, email address, sign-in method, session data |
| Tavily | Web research for drafts | Search queries derived from the topic. Not your archive |
| Railway | Runs the worker that prepares, assesses, renders and publishes | The job in hand: the draft, its context, and the encrypted connection it needs for a delivery |
| Resend | Sends a notification email when a request arrives through this site, only where configured | The contents of that request |
Model providers behind the gateway are configurable per deployment; the desk shows the model identifier in use on every draft. The location of each vendor and the transfer mechanism for data leaving the UK and the EEA will be added here once confirmed by counsel.
Only when you connect them
These receive data only after a member of your workspace connects the account, and only what that connection needs. Disconnecting stops the flow and deletes the stored token.
| Provider | Connection | What it receives |
|---|---|---|
| Google Analytics, Search Console, YouTube | Your sign-in for the OAuth grant; for uploads, the approved video and its title and description | |
| Meta | Your sign-in for the OAuth grant; approved captions and images for publishing | |
| Your sign-in for the OAuth grant; approved posts for sharing | ||
| HeyGen | Video renders | The approved script and the avatar and voice you chose in your own HeyGen account |
| Kapso | WhatsApp, on Oat's shared number | Messages between you and Oat, and your linked phone number |
| Apple | Messages for Business | Messages between you and Oat in that conversation |
| GitHub | Repository publishing | Approved pieces as files committed to the repository, branch and folder you chose |
| Your site host | WordPress or Vercel deploy hook | Approved pieces as posts, or a build trigger |
Changes
When a vendor is added or removed, this page changes and the date at the top changes with it. Workspace Owners are told by email before a new always-in-use vendor receives their data. Questions go through the contact page.

