Skip to main content
A sub-processor is a third-party company that ModuleX uses to run the service, and that may process some of your data while doing its part of the job. ModuleX’s Privacy Policy calls these companies “Service Providers”; under the GDPR they are your data processors’ processors. This page lists them, says what each one does, and explains how ModuleX tells you when the list changes. For the wider picture of how your data is handled and what compliance commitments apply, see Trust & data handling and Compliance.

A short, purposeful list

Each third party does one job, such as hosting, payments, email, or AI model calls.

Limited by design

A sub-processor only ever sees the data it needs for its task, and cannot use it for anything else.

Changes are announced

When the list changes, ModuleX updates the Privacy Policy and notifies you before it takes effect.

Who processes your data

The list below comes from ModuleX’s published Privacy Policy (last updated May 22, 2026). It is grouped by what each third party does. The Privacy Policy is the authoritative, dated version of this list; the table here is a plain-language summary that points back to it.
ModuleX is operated by ModulexAI, LLC. The list here reflects the Service Providers named in the Privacy Policy. If you need a formal, signed sub-processor schedule or a Data Processing Agreement for a contract, see Compliance or contact the ModuleX team.

Cloud infrastructure

Hosts the application, databases, and stored files that keep ModuleX running.Provider: Amazon Web Services

Payments

Processes subscription and top-up payments. ModuleX never stores your card details; they go straight to the processor.Provider: Stripe

Email delivery

Sends transactional email such as sign-in, billing, and notification messages.Providers: SendGrid, Postmark

Product analytics

Measures how the product is used so ModuleX can improve it. Tied to usage, not to your workflow content.Provider: PostHog

Error monitoring

Captures application errors so ModuleX can find and fix problems.Provider: Sentry

AI model providers

Run the language models behind ModuleX-managed AI features. Bound by their no-training commitments for API customers.Providers: OpenAI, Anthropic, Google Gemini

What each one can touch

Sub-processors are not given open access to your account. Each one only handles the slice of data its job requires.
Every third party above can access your information only to perform its specific task for ModuleX, and is contractually obligated not to disclose it or use it for any other purpose. A payment processor sees billing data, not your workflow content; an email provider sees the message it sends, not your knowledge base.

When BYOK keeps a provider off this list

When you bring your own model or tool provider with BYOK (Bring Your Own Key), your data goes directly to that provider under your own account, governed by your agreement with them. In that case the provider is not acting as a ModuleX sub-processor for that traffic.

Managed usage

When you use ModuleX-managed models, calls run through ModuleX’s provider accounts, so those AI providers are sub-processors and the list above applies.

Your own keys (BYOK)

When you connect your own provider key, your data flows directly to that provider under your account and terms. That provider is yours to manage, not a ModuleX sub-processor.

How changes are announced

ModuleX maintains this list through its Privacy Policy, which carries a dated “Last updated” header so you can see when it last changed.
1

The Privacy Policy is updated

The new or removed third party is reflected in the published Privacy Policy, and the “Last updated” date at the top is changed.
2

You are notified before it takes effect

ModuleX states that it will notify you by email and/or a prominent notice in the service before a material change becomes effective.
3

You decide what to do

Review the change. If you have a question or a contractual notice requirement, raise it through the contacts on the Compliance page before the change takes effect.
Want advance notice in writing, or a formal way to object to a new sub-processor? Those terms belong in a Data Processing Agreement rather than the public Privacy Policy. See Compliance for how to request one.

Open points to verify

ModuleX does not invent facts in these docs. A few details about the sub-processor list are not fully settled in the verified sources, so they are flagged here rather than stated as fact.
Cloud infrastructure provider — TBD. The public Privacy Policy names Amazon Web Services as the cloud infrastructure provider, while ModuleX’s backend configuration references Microsoft Azure services (managed secret storage and file storage) and Clerk for sign-in. These sources do not currently agree, and Azure and Clerk are not listed in the Privacy Policy. Treat the published Privacy Policy list as authoritative for now, and confirm the operative infrastructure, secret-storage, and identity providers with the ModuleX team before relying on a specific vendor. This will be reconciled on the Compliance page.
Regions, retention, and a signed schedule — TBD. This page does not assert where each sub-processor stores data, how long it retains it, or a contractually binding sub-processor schedule. Those belong in a Data Processing Agreement and the Compliance page. Confirm them there, or with the ModuleX team, before relying on them.

Where to go next

Compliance

ModuleX’s compliance posture, certifications, and how to request a Data Processing Agreement.

Trust & data handling

How ModuleX isolates, protects, and retains your data, in plain language.

Data security & encryption

How credentials and secrets are encrypted, plus key management and production checks.