← Back to Security

Sub-processors

Michi uses these third-party providers to operate the service. We publish this list publicly and update it whenever a provider is added, replaced, or removed. Material changes are announced by email to all billing contacts at least 30 days in advance.

Last updated: 2026-05-21 — 16 active sub-processors.

ProviderPurposeData processedRegionDPA
SupabasePrimary database, auth, file storageAll customer data — encrypted at restEUView ↗
VercelApplication hosting, edge functionsRequest metadata, no persistent customer dataEUView ↗
StripeSubscription billing & paymentsBilling email, payment method, invoicesEUView ↗
AnthropicClaude LLM for transcript and email extractionTransient prompt text only — not retained, not used for trainingUSView ↗
ResendTransactional email deliveryRecipient email, subject, body of system emailsEUView ↗
SentryError monitoring & performance tracesStack traces, user ID (no PII in error context)EUView ↗
PostHogProduct analytics (cookieless by default)Anonymous events; identified events only after consentEUView ↗
CrispCustomer support chat widgetEmail, name, chat transcripts (only when user initiates)EUView ↗
Google (Gmail API + Pub/Sub)Gmail integration & push notificationsCustomer-authorised mailbox messages (read-only)GlobalView ↗
Microsoft (Graph + Outlook)Microsoft 365 mail integrationCustomer-authorised mailbox messages (read-only)EUView ↗
Otter.aiMeeting transcript ingestion (customer-initiated)Meeting transcripts the customer chooses to forwardUSView ↗
Fireflies.aiMeeting transcript ingestionMeeting transcripts the customer chooses to forwardUSView ↗
FathomMeeting transcript ingestionMeeting transcripts the customer chooses to forwardUSView ↗
Read.aiMeeting transcript ingestionMeeting transcripts the customer chooses to forwardUSView ↗
GranolaMeeting note ingestion via email forwardingMeeting notes the customer chooses to forwardUSView ↗
GitHubSource code repository (not customer data)No customer data — code onlyUSView ↗

Change notification

When we add, replace, or remove a sub-processor, we email every organisation owner at least 30 days in advance. You can object to a change by writing to dpo@michiplatform.com. If we can't resolve the objection, you have the right to terminate your subscription and receive a pro-rata refund.

Data residency

All primary storage (Supabase) and email delivery (Resend) is in the EU. Some sub-processors are US-based — when EU customers use them, transfers rely on the EU-US Data Privacy Framework and the relevant Standard Contractual Clauses. See our DPA for details.