Subprocessors
The providers that help Fous run the Service, what each one does, and the data it receives.
Effective
Fous uses cloud providers to host the Service, run workflows in sandboxes and browsers, reach websites through proxy networks, and run AI models, plus providers for payments, email, and analytics. Each one gets only the data it needs. Subscribe to updates by email.
On this page
About this list
These are the Providers that process personal data, including Customer Content, when Fous runs the Service. Each receives only the data it needs for its task. Capitalized words have the meanings given in our Terms of Service, and our Data Processing Addendum explains how we add and change Providers.
Fous and most of these Providers process data in the United States. Proxy networks carry requests through exit points in many countries, and some Providers run global networks.
Hosting, storage, and security
| Provider | What it does for Fous | Data it receives |
|---|---|---|
Vercel | Hosts fous.com, Studio, our documentation, and our APIs, and runs scheduled jobs. | All traffic to and from the Service, including requests, results, and Credentials in transit, and server logs. |
Supabase | Our database and file storage. | Account, Organization, billing, Workflow, and log data that we store, and Organization photos. |
Cloudflare | Encrypted storage for Build recordings and large payloads; private storage for AI Training Data in an R2 region in North America; sign-in checks with Turnstile. | Encrypted recordings and payloads, AI Training Data, and browser signals and IP address at sign-in. |
Running Workflows
| Provider | What it does for Fous | Data it receives |
|---|---|---|
E2B | Isolated sandboxes that build, test, and run Workflow code. | Workflow code and inputs, Target Site responses, and short-lived access for Credentials. |
Kernel | Cloud browsers, including signing in to Connected Accounts and keeping their sign-in details and browser profiles. | Pages visited, Connected Account sign-in details, cookies, and browser profiles. |
Browser Use | Cloud browsers that explore Target Sites during Builds and pass site challenges for Workflow calls. | Pages visited and steps taken during Builds, and URLs requested by Workflow calls. |
DataImpulse and other proxy network providers | Proxy networks that carry requests to Target Sites. | Destination addresses and request traffic, which is encrypted when the Target Site uses HTTPS. |
AI models
| Provider | What it does for Fous | Data it receives |
|---|---|---|
OpenAI | Builds and repairs, request checks, Router planning and result mapping, search, and voice transcription. | Prompts, search text, page content, Workflow descriptions, samples of inputs and Output, and audio. |
Google (Gemini API) | Models for Builds, and backup models for request checks, the Router, and voice transcription. | The same kinds of data as OpenAI. |
Anthropic | Models for Builds and repairs. | Build prompts, page content, and samples of inputs and Output. |
Typesafe (Jev) | Request checks, Router plans, search ranking, result mapping, catalog matching during Builds, content checks during repairs, and checks of pages returned by failed Workflow calls. | Prompts, Workflow descriptions, samples of inputs and Output, and Target Site page content. |
Payments, email, analytics, and accounting
| Provider | What it does for Fous | Data it receives |
|---|---|---|
Stripe | Payments, plans, and auto-recharge. | Organization name and ID, billing details, card details you enter directly with Stripe, and amounts. |
Resend | Service emails, such as sign-in codes, invitations, and billing alerts. | Email addresses, names, Organization names, and the content of those emails. |
PostHog | Product analytics, in the browser only with your consent, and Organization-level events from our servers. | Analytics events, pseudonymous identifiers, and masked session recordings if enabled. |
Intuit (QuickBooks) | Our accounting. | Customer names and amounts in accounting entries. |
Other recipients
These recipients are not subprocessors:
- Target Sites, which receive requests, and possibly inputs and Credentials, when you direct a Workflow to them.
- Stripe, for processing it does as an independent controller, such as fraud prevention.
- Google, when you choose to sign in with Google.
- Search engines, which we notify of new public Workflow pages by sending the page address.
Changes and notifications
We update this page before a new Provider starts processing Customer Content. To receive an email at least 15 days before such a change, write to [email protected] with the subject “Subprocessor updates.” If we must replace a Provider urgently for security or continuity, we will tell subscribers as soon as we can. Customers can object to a change as described in the Data Processing Addendum.