We commit to giving you advance notice before any vendor on this list changes in a way that affects how your data is processed.
Questions about a specific vendor? Email human@emaration.ai. A founder answers every one — we aim to respond within one business day. If you need a security questionnaire response, or a written confirmation of a sub-processor's status signed by us, ask and we will send one.
Corrections to this list
The notice above only means something if the list it protects is complete. It has not always been. GitHub and MailChannels were reachable from shipped code and named nowhere on this page: GitHub had been receiving member-authorized repository access since that channel shipped, and MailChannels was a wired fallback we have no record of using. Mozilla was the next one. Every run of our free security scan sends the hostname someone typed to Mozilla's HTTP Observatory, and this register did not name Mozilla anywhere — while four of our own published pages credited it by name as the tool behind that scan, and the machine-readable file we publish for AI answer engines told them the same thing.
Sign in with Google came next, and it is the one we are least comfortable with, because our own automated check had already found it. The "Continue with Google" button on the member sign-in page sends a member to Google and brings their email address back. The check that reads our source had recorded both Google addresses that flow touches — and they were filed under the read-only analytics permission you grant us, which is a different permission, for a different purpose, about a different person. The machine found it. A person mis-filed it, and the file read like a finished answer. It has its own card above now, and the check can no longer be satisfied by an explanation that happens to be wrong.
We added each vendor the day we found it, which means the advance notice above was not given for GitHub, Mozilla, or Google sign-in. We could not give notice in advance of a disclosure we had already missed, and we would rather record that here than let a clean page imply a clean history.
What changed so it does not recur: this page and our internal register carry the same machine-readable key on every vendor, and an automated test fails our build whenever one names a vendor the other does not. That test could only ever compare two lists we had already written, which is how Mozilla stayed off both. So a second one now reads our own source instead: it collects every outside address our code names — including anything a page would load from a third party in your browser — and fails the build unless the register accounts for each one. And because Google sign-in proved that accounting for an address can still be wrong, our register may no longer wave one away with an explanation alone: where our own code contradicts the explanation, the build fails. A list that only a person remembers to update is the failure we had.