LEGAL · SUBPROCESSORSEvery vendor that touches your data.
LADLE uses six subprocessors to deliver the Services. Every one is listed below with purpose, data categories, region, and a link to their public DPA. We notify Customers 30 days before adding or replacing a subprocessor.
VERSION 1.0EFFECTIVE 2026-08-05
PURPOSEAI model inference (Claude Haiku and Claude Sonnet)
DATA CATEGORIESUser prompts + generated responses. Standard commercial API terms: not used for model training; a limited abuse-monitoring retention window applies. No zero-data-retention addendum in place yet.
REGIONUnited States (AWS us-east-1 / us-west-2)
PURPOSEApplication database + authentication
DATA CATEGORIESAccount records, chat history, project metadata, workspace membership.
REGIONUnited States (AWS us-east-1)
PURPOSEPayment processing
DATA CATEGORIESPayment card data (tokenized), billing address, subscription and invoice records. PCI DSS Level 1.
REGIONUnited States
PURPOSEWeb hosting + edge network
DATA CATEGORIESHTTP request logs, IP addresses (transient, ≤30 days), static asset delivery.
REGIONUnited States (global edge for static assets)
PURPOSETransactional email delivery (pending activation — currently not sending)
DATA CATEGORIESWhen active: recipient email addresses, email content (receipts, notifications, impact statements). Not currently transmitting data — the integration is code-complete but the account is not yet live. See changelog below for activation date.
REGIONUnited States
PURPOSETarget donation partner — meal-fund earmarks ship as real partner donations once LADLE clears the $50,000/year corporate-partnership threshold. Not yet transmitting funds.
DATA CATEGORIESWhen active: aggregate donation amount only. No Customer Personal Data is transmitted. Currently pre-threshold — no transfers made yet.
REGIONPublished with the partner announcement
PURPOSEProduct analytics (pageviews + click events only)
DATA CATEGORIESPseudonymous user identifier, page URLs visited, button/link click targets, browser + device metadata (from user-agent string). NEVER form input values, NEVER chat content, NEVER session recordings. Users can opt out from Settings → Data → Product analytics.
REGIONUnited States (PostHog US Cloud)
PURPOSEError monitoring + source-map upload
DATA CATEGORIESUncaught JavaScript exceptions (stack trace, browser + device metadata), server error traces (route path + non-sensitive request context — chat request bodies are redacted at capture time). Sampled at 20% of transactions to minimize noise.
REGIONUnited States
CHANGE NOTIFICATIONHow you find out when this list changes.
When we intend to add or replace a subprocessor, we notify Customers at least thirty (30) days in advance via two channels: (1) email to your workspace’s designated privacy contact, and (2) an update to the changelog at the bottom of this page. If you object to a new subprocessor on reasonable data-protection grounds and we cannot resolve the concern within 30 days, you may terminate the affected Services without penalty, per the DPA at /legal/dpa.
To subscribe to changes without needing to check this page: email privacy@ladle.chat with your organization name; we’ll add you to the notification list.
CHANGELOGEvery change to this page, dated.
- 2026-09-01Added PostHog (US Cloud, product analytics, pageviews + clicks only) and Sentry (US, error monitoring, chat bodies redacted). Both are opt-out-respecting; PostHog toggleable from Settings → Data.
- 2026-08-31Resend listed as pending activation — code integration is complete but the account is not yet transmitting data. Will update to active on go-live.
- 2026-08-05Initial published list. Six subprocessors as documented above.
Your organization's privacy contact can subscribe to change notifications.
Email privacy@ladle.chat — we'll add you to the notification list within one business day.
$20/MO · CANCEL ANYTIME · $0.80/MEAL · RECEIPTS MONTHLY
Read the ledger →