Subprocessors

Last updated 20 September 2026

These providers process information to run Mattercite and measure public website usage. Their roles are listed below. Not every provider receives workspace content.

Current subprocessors
ProviderRoleRegion
Amazon Web Services Hosting, Postgres, private object storage for uploads, logs, and Amazon Bedrock for answer generation, plus the Bedrock knowledge base that indexes your documents for retrieval. All of it runs inside our own AWS account. us-east-1
Cloudflare DNS, CDN, TLS at the edge, and reverse proxy to the application Global edge
Stripe Card and ACH payment processing and invoicing. Stripe receives billing contact details and payment instrument data. It never receives uploaded documents or answers. United States
Google Analytics Public website analytics, including visits, trial-start clicks, browser/device information and analytics cookies. Not installed in the application; no uploaded documents, answers or workspace activity are sent. Global processing

No other subprocessors are in use as of the date above.

What a subprocessor is

A subprocessor is a third party that processes customer data on our behalf so that we can run the service. For Mattercite that means the companies whose infrastructure stores your uploaded documents, holds the extracted text and drafted answers, runs the retrieval and drafting that produces an answer, or bills you for the plan. Companies that only see traffic metadata, such as the edge network that terminates TLS, are listed too, because they sit in the request path. A subprocessor is not a customer, a person you invite to your workspace, or a public data source.

How this list is maintained

This page is the canonical subprocessor list for the hosted service at mattercite.com. It is versioned with the site and updated in the same change that introduces or removes a provider, so the "last updated" date above reflects the most recent change to the list itself. We add a provider before it starts handling customer data, not after. If a provider is removed, the row is removed and the date is updated.

Updates to this list

We update this page when our subprocessors change.

Data handled

The providers above handle the categories described in the privacy policy: account data (email, name, password hash, session cookies), workspace content you upload or generate (documents, questionnaires, answers, citations, and branding), usage counters, basic request logs, and billing details. Original uploads sit in a private S3 bucket with encryption at rest. Extracted text and answers are stored in Postgres. Answer generation uses models on Amazon Bedrock, and retrieval runs over a Bedrock knowledge base filtered to your workspace and matter, both inside our AWS account in us-east-1. Stripe holds billing contact and payment instrument data only. We do not use your documents or answers to train models, and we do not sell personal data.

Questions

Questions about this list, or a request for a copy of it dated for your records, go to hello@mattercite.com. Related pages: terms of use, and privacy policy.