Subprocessors
Effective August 24, 2026Last updated September 5, 2026
The third-party service providers that help operate Quodra.
Quodra uses selected third-party service providers to help deliver and secure the Service. Some of these providers may process personal information on Quodra's behalf.
The list below reflects Quodra's current production infrastructure and is updated as our service providers change.
Current Subprocessors#
| Provider | Purpose | Data involved | Region |
|---|---|---|---|
| Google Cloud (Google LLC) | Production API on Cloud Run, PostgreSQL database on Cloud SQL, object storage and operational logging | Account information, User Content, request metadata and technical information, depending on the feature used | europe-west1 (Belgium) |
| Cloudflare | Static website and application hosting and content delivery; Workers hosting for the MCP endpoint | IP addresses and request metadata; authorized MCP requests, credentials and content passing through the endpoint | Global network |
| Resend | Transactional email — verification links, invitations, sharing notifications | Recipient email address and message content | — |
| Google (Google LLC) | Sign in with Google (optional); Google Drive import (optional, reads only files you pick); business email for Quodra's own mailboxes | Identity information when you choose Google sign-in; files you choose to import; email you send us | — |
Analytics and diagnostics: conditional activation#
These integrations depend on deployment configuration. Their inclusion in the application does not establish that they are active. Optional analytics also require the user's opt-in; browser diagnostics are controlled separately. Hosting and API logs remain distinct from both.
| Provider | Purpose when active | Activation condition |
|---|---|---|
| PostHog | Optional product analytics — a fixed list of events with identifiers and technical context, without deck content, code or titles | Deployment configuration and your opt-in via Settings → Diagnostics & analytics |
| Sentry (Functional Software, Inc.) | Error and crash diagnostics with filtering of sensitive fields; reports may include an account id and technical context | Deployment configuration; separate from the usage analytics switch |
Third parties that are not subprocessors#
Two kinds of third party interact with the Service without processing personal information on Quodra's behalf:
- Content delivery for public assets. Your browser fetches typefaces from Google Fonts and the in-browser Python runtime from jsDelivr. These are direct requests from your device for public files; see the Cookie Policy for details.
- Integrations you bring. If you connect your own AI tool to Quodra through the Model Context Protocol, or use your own Materials Project API key, the provider behind your tool processes data under your relationship with them — Quodra does not select, pay or instruct that provider.
Questions#
Questions about this page may be submitted by email: hello@quodra.app
Product: Quodra