About this list
A subprocessor is a third party that may process customer data on our behalf. This list was compiled from the services the application actually integrates with.
Some of these are optional in a given deployment — if billing or email alerting is not configured, that provider processes nothing. They are listed because the integration exists and may be enabled.
Current subprocessors
| Provider | Purpose | Data involved | Policy |
|---|---|---|---|
| Supabase | Database hosting and user authentication | Account identifiers, email addresses, and all application records | View |
| GitHub | Repository access, branch and pull request creation | Repository metadata and source code accessed during scans and migrations | View |
| Anthropic | Generating migration patches | The specific finding and the contents of the single file being changed | View |
| Groq | Summarising public repository scans | Scan findings for public repositories only | View |
| Upstash | Redis-backed background job queues | Job payloads containing repository and record identifiers | View |
| Resend | Transactional email alerts and digests | Alert recipient email addresses and alert contents | View |
| Polar | Subscription billing and checkout | Billing contact and subscription status | View |
Processing locations
Processing locations depend on the provider and account configuration. Data may be processed outside your country. We do not currently publish a verified region-by-region list. Contact privacy@shimpilot.com for questions about processing locations.
Changes to this list
We will update this page when we add or remove a subprocessor. Customers with a written agreement requiring advance notice will be notified per that agreement.
Contact
Questions about subprocessors: privacy@shimpilot.com.