01In your deployment's data path: none
Anyray is self-hosted, so no Anyray subprocessor processes your content — there is no vendor in the data path to enumerate. For prompt and response content there is no Anyray processing. For the content-free metering rollup, Anyray is your processor.
One clarification a reviewer should note. Your upstream LLM providers (OpenAI, Anthropic, and the cloud model APIs) do receive prompts — but those are providers you select and contract with directly. They are your processors, not Anyray subprocessors; Anyray only forwards to the endpoints you configure.
02Vendor-operated surface — Anyray Portal
The single Anyray-operated surface is the Portal account plane. It exists for sign-in, tenant membership, billing, and metering. No prompt or response content ever reaches it; the non-billing data is content-free metadata only — operator sign-in identities, memberships, content-free usage rollups, and pseudonymous seat hashes. Billing itself runs through Stripe — see the table below. The Portal backend is hosted on Amazon Web Services in the EU (Frankfurt), encrypted in transit and at rest, behind a web application firewall — it is the only vendor infrastructure that touches deployment-derived metadata. See Data Protection for exactly what the metering rollup carries.
03Website, billing & corporate processors
These providers process data related to our website, forms, and Portal accounts — not your deployment's data. They are listed for completeness and mirror our Privacy Policy.
| Processor | Purpose | Data |
|---|---|---|
| Amazon Web Services / CloudFront | Website hosting, content delivery, form endpoints, private storage for uploaded CVs and NDA-gated reports | Server/security logs (e.g. IP, browser, pages requested); form submissions in transit; CV files |
| Amazon Web Services (EU, Frankfurt) | Anyray Portal & metering backend hosting | Content-free usage rollups, pseudonymous seat hashes, operator sign-in identities — no prompt/response content |
| Stripe | Billing & payment processing for Anyray Portal accounts | Billing contact details, payment method — Anyray does not store card numbers |
| Plausible Analytics | Cookieless, aggregate web analytics | Anonymous, aggregate metrics — no personal data |
| Google Analytics | Usage analytics, loaded only with your consent | Pages viewed, session data, measurement cookies — see the Cookie Notice |
| Slack | Internal notifications for waitlist, demo, careers, and Trust Center submissions; Slack Connect channels for demo customers | Name, work email, company, and the content of the submission |
| Cal.com | Meeting scheduling on the demo page | Name, email, chosen time slot |
| WorkOS | Portal sign-in (Google, email code, or enterprise SSO) | Sign-in identity: name, email, identity provider |
| Resend | Transactional email from the Portal and the hiring process | Recipient name and email, message content |
| Google Fonts | Web-font delivery | IP address at font-serve time |
04Changes to this list
We keep this list current as our providers change. Customers under an agreement with Anyray receive prior notice of any new subprocessor of metering data, and a reasonable chance to object on data-protection grounds, as set out in the processor terms of that agreement.
05Contact
Email: hi@anyray.ai
Mail: Othentic Labs Ltd, 2 Kaplan Street, Tel Aviv–Yafo 6473403, Israel (company number 516743945)