Last updated: September 11, 2026
Service providers that help Botchi operate the product.
Sealo S.r.l., Strada Trossi 41, 13871 Verrone (BI), Italy, VAT number IT 02777410024, REA BI-310965 operates Botchi. This page describes the providers that support the Service, their roles, and the data needed for their functions. Read it alongside the Privacy Policy. It does not override any signed data processing agreement or enterprise order form.
Botchi uses multiple providers to offer a choice of models and features. The services involved depend on the feature, user or administrator selections, and applicable defaults. A request is not sent to every listed provider. The list distinguishes recipient categories and does not automatically assign identical GDPR roles to all providers: roles depend on activities and applicable agreements, including for payments and connected services. For processing on business customers' behalf, the DPA governs subprocessor authorization and changes to the processing chain.
| Provider | Purpose | Data and transfer notes |
|---|---|---|
| WorkOS | Authentication, AuthKit hosted sign-in, sessions, and identity management. | Account identifiers, email addresses, session data, and authentication metadata. Global provider; transfer safeguards apply where required. |
| Convex | Primary database, file storage, realtime sync, and backend data services. | Chats, files, memories, account settings, tasks, tool records, and service metadata. Regions depend on deployment configuration and customer/service needs. |
| Vercel | Hosting, deployment, backend execution, Blob storage, Sandbox environments for code and applications, observability, and AI Gateway routing. | Application traffic, files and code processed in relevant environments, request metadata, logs, deployments, and prompts and outputs where AI Gateway is used. Global provider, including the United States and European Union; transfer safeguards apply where required. |
| Amazon Web Services, KMS | Encryption key management for business data. | Cryptographic material and metadata needed for key management; distinct from Bedrock inference. |
| Resend | Service email notifications when enabled. | Recipient address, notification content, identifiers, and delivery status. Delivered emails also remain with recipients. |
| PostHog | Product analytics, usage telemetry, reliability events, and error diagnostics. | Account identifiers, feature usage, event metadata, AI usage telemetry, and reliability events. EU region where applicable. |
| RevenueCat | Mobile subscription entitlement management and store subscription status. | App user identifiers, product identifiers, entitlement status, and subscription metadata. Global provider; transfer safeguards apply where required. |
| Stripe | Business or web checkout, subscription, invoice, and payment processing where available. | Customer, checkout, invoice, subscription, and payment metadata. Botchi does not store payment card details. Global provider; transfer safeguards apply where required. |
| Expo | Mobile app delivery, over-the-air updates, and push notification routing. | Device/app metadata, update metadata, and push tokens where notifications are enabled. Global provider; transfer safeguards apply where required. |
Routing services forward requests to the provider performing inference. Inference services run models; specialized services perform functions such as transcription and document reading. A model's developer may differ from the entity receiving data to run it.
| Provider group | Purpose | Data |
|---|---|---|
| Vercel AI Gateway | AI request routing, provider controls, usage tracking, and gateway-level retention controls. | Prompts, outputs, model parameters, routing metadata, token usage, and cost metadata. |
| OpenRouter, Inc. | Routing AI requests to the providers that perform inference and metering usage. | Prompts, retrieved context, attachments or media needed for the request, outputs, model parameters, and routing, usage, and cost metadata. |
| Amazon Web Services, Amazon Bedrock | Inference for models available through Bedrock, including models developed by third parties. | Prompts, context, necessary attachments or media, outputs, and request and usage metadata. |
| Google Cloud, Vertex AI | Inference for models available through Vertex AI, including Google and third-party models. | Prompts, context, necessary attachments or media, outputs, and request and usage metadata. |
| Mistral AI | Inference and document reading through text recognition. | Prompts, documents, page images, extracted text, outputs, and usage metadata needed for the feature. |
| Deepgram | Audio transcription. |
Conditions depend on the service, model, endpoint, and applicable agreements. Protections provided by one service are not attributed to every provider.
| Service | Configuration and scope |
|---|---|
| Vercel AI Gateway | For production traffic, where supported, we use zero data retention, training restrictions, allowed-provider selection, and log minimization. |
| Amazon Bedrock and Google Vertex AI | The service and region depend on the configured route. Using a third-party model does not, by itself, mean sending content to its developer. Retention and controls depend on the service and model used. |
| OpenRouter | Inference requests require endpoints with zero data retention policies and no prompt training. The integration uses the EU endpoint; regional processing also depends on account enablement and applicable terms. |
| Mistral AI and Deepgram | Data and controls depend on the requested feature, such as inference, document reading, or audio transcription, and the configuration of the relevant service. |
Zero data retention concerns inference content within the provider's scope. It does not exclude operational or billing metadata or automatically extend to additional tools. Configuring an EU endpoint does not guarantee EU-only processing for the entire Service.
The conditions in this table are those declared by each provider in its documentation and in its agreements with Sealo. Botchi enforces them per request through provider selection, retention, and training flags, and relies on the provider's commitments for their fulfilment.
Provider documentation: Amazon Bedrock, Google Vertex AI, , , , .
When you connect a third-party account or configure an integration, Botchi calls that service on your behalf. These providers may act under their own terms and privacy policies, not solely as Botchi subprocessors.
We update this list when providers change. For customers with a DPA, new or replacement subprocessors follow its notice and objection procedures; merely updating this page does not replace required communications. Choosing a gateway does not authorize every possible recipient or transfer.
For information about providers actually involved in your processing and applicable safeguards, contact hello@botchi.ai. Product names in this table do not replace identification of contractual counterparties and further subprocessors required in the DPA and supporting documentation.
| Audio submitted for transcription, transcribed text, and request and usage metadata. |
| Firecrawl | Web-page reading and extraction for functions using it. | URLs, extraction parameters, page content, and results needed for the operation. |
| Inference providers reached through Vercel AI Gateway or OpenRouter | Running the model selected for a request: the model developer or a cloud platform hosting it, such as Amazon Bedrock, Google Vertex AI, or Microsoft Azure. The providers eligible to serve each enabled model are shown in the model settings before selection, and the enabled set changes as the catalog evolves. OpenRouter routes only to endpoints with zero data retention and no-training policies, listed on the model's OpenRouter page. | Prompt content, retrieved context, attachments or media where needed, outputs, and usage metadata. |