Quodra
Home Docs Open Quodra
Legal

Subprocessors

Effective August 24, 2026Last updated September 5, 2026

The third-party service providers that help operate Quodra.

Quodra uses selected third-party service providers to help deliver and secure the Service. Some of these providers may process personal information on Quodra's behalf.

The list below reflects Quodra's current production infrastructure and is updated as our service providers change.

Current Subprocessors#

ProviderPurposeData involvedRegion
Google Cloud (Google LLC)Production API on Cloud Run, PostgreSQL database on Cloud SQL, object storage and operational loggingAccount information, User Content, request metadata and technical information, depending on the feature usedeurope-west1 (Belgium)
CloudflareStatic website and application hosting and content delivery; Workers hosting for the MCP endpointIP addresses and request metadata; authorized MCP requests, credentials and content passing through the endpointGlobal network
ResendTransactional email — verification links, invitations, sharing notificationsRecipient email address and message content
Google (Google LLC)Sign in with Google (optional); Google Drive import (optional, reads only files you pick); business email for Quodra's own mailboxesIdentity information when you choose Google sign-in; files you choose to import; email you send us

Analytics and diagnostics: conditional activation#

These integrations depend on deployment configuration. Their inclusion in the application does not establish that they are active. Optional analytics also require the user's opt-in; browser diagnostics are controlled separately. Hosting and API logs remain distinct from both.

ProviderPurpose when activeActivation condition
PostHogOptional product analytics — a fixed list of events with identifiers and technical context, without deck content, code or titlesDeployment configuration and your opt-in via Settings → Diagnostics & analytics
Sentry (Functional Software, Inc.)Error and crash diagnostics with filtering of sensitive fields; reports may include an account id and technical contextDeployment configuration; separate from the usage analytics switch

Third parties that are not subprocessors#

Two kinds of third party interact with the Service without processing personal information on Quodra's behalf:

  • Content delivery for public assets. Your browser fetches typefaces from Google Fonts and the in-browser Python runtime from jsDelivr. These are direct requests from your device for public files; see the Cookie Policy for details.
  • Integrations you bring. If you connect your own AI tool to Quodra through the Model Context Protocol, or use your own Materials Project API key, the provider behind your tool processes data under your relationship with them — Quodra does not select, pay or instruct that provider.

Questions#

Questions about this page may be submitted by email: hello@quodra.app

Product: Quodra