Skip to content

New Official SDKs for TypeScript, Python and Go

SerpKite
Get API key

Subprocessors

These are the third parties that may process personal data when we provide the Service. Each is bound by a data processing agreement with confidentiality and security obligations at least as protective as our DPA. We choose proxy vendors that provide written attestations that their networks are ethically sourced with user consent.

SubprocessorPurposeDataLocation
Cloudflare, Inc.DNS, TLS termination, DDoS protection, Cloudflare Tunnel to our servers, hosting of the website and dashboard (Pages), bot checks (Turnstile), encrypted database backups (R2)Request metadata including IP address; encrypted database backupsGlobal edge network; backups in the European Union
Contabo GmbHServer hosting for the API, dashboard backend, database and cachesAll account, usage and billing data we hold; cached results; queries in transitGermany (European Union)
PolarMerchant of record: checkout, payments, invoices, sales tax and VATEmail, name, billing details, order historyUnited States
ResendTransactional email (sign-in links and codes, alerts, receipts)Email address, email contentEuropean Union (EU sending region)
PostHog (EU Cloud)Product analytics for the website, dashboard and server-side account eventsPseudonymous ID, page paths and product events; never query text, API keys or URL query stringsEuropean Union
Better StackLog management, uptime monitoring and status pageService logs (no query text, API keys, cookies or bind parameters), node and pod metricsEuropean Union (EU region)
Proxy network providers (at least two vendors)Carry outbound requests to search engines and public web pagesQuery text and target URLs in transit only; no account or identity dataExit IPs in the country you request

We don't use third-party SERP data providers: every result is fetched and parsed by our own software. The search engines themselves receive the requests our proxies send, as any visitor's browser would, and are not our subprocessors.

Sign-in providers you choose

If you sign in with GitHub or Google, that provider authenticates you and shares your profile ID, verified email, name and avatar with us. They act under their own terms as independent controllers, not as our subprocessors.

Changes

We'll update this page at least 30 days before a new subprocessor starts processing customer personal data. Customers with a signed DPA can ask to be notified by email and may object on reasonable data protection grounds. To subscribe to change notices, email [email protected] with the subject "Subprocessor updates".

Questions: [email protected].

Last updated: 2 October 2026