Subprocessors

Last updated: April 23, 2026 — Private Beta

Nicole Assist uses the third-party providers below to run the Service. Each receives only the data it needs for the described purpose. For context on how your data flows through the Service, see our Privacy Policy.

VendorPurposeData sharedRegion
Anthropic (Claude API)Large language model that powers the scheduling agent and chat assistant.Scheduling thread contents (subject + body of the active thread), tenant rules, calendar availability windows for the requested window. Not persisted by Anthropic for training.United States
Microsoft (Graph API, Entra ID)Calendar free/busy reads and event create/update/cancel on your behalf.OAuth access + refresh tokens, calendar ids, free/busy windows, event bodies we create. Your mailbox/calendar remain in your own Microsoft 365 tenant; we do not mirror them.Customer-chosen Microsoft 365 region
Supabase (Postgres + Vault)Primary database for tenant metadata, threads, messages, audit log, and encrypted refresh tokens.All tenant-scoped records. Refresh tokens and MFA secrets are column-encrypted with per-tenant keys before storage.United States (us-east-1)
ResendInbound email receipt (wildcard forwarding on the scheduling domain) plus outbound transactional email for scheduling replies and auth emails.Inbound: full email payloads — headers, body, attachments — retained by Resend while we ingest them, then stored in Supabase. Outbound: From/To/Subject, rendered body, message-id, briefly retained by Resend for delivery analytics.United States
InngestScheduled and event-driven background jobs (token refresh, follow-ups, digests, usage rollup).Job event payloads — tenant id, thread id, message id — that reference records in our database.United States
VercelHosting for the Next.js application (tenant dashboard, admin console, marketing site).Request logs (tenant id tag, trace id, path, status) retained for 30 days.United States
SentryError monitoring.Unhandled exceptions with tenant id tag. PII is scrubbed before send; refresh tokens, session tokens, and email bodies are not included.United States
AxiomStructured application logs.JSON log lines tagged with tenant id and trace id, retained for 30 days.United States

Material changes to this list will be emailed to the address on file before they take effect. Questions: support@nicoleassist.com.