GramGrow
Beta

Subprocessors

Current subprocessor and integration-provider overview for hosting, messaging, payments, ads, AI, and operations.

Last updated: May 2, 2026

Provider list

The table below identifies core providers by status, purpose, data category, and region/transfer note. Optional providers only process data when a workspace enables the relevant integration.

ProviderStatusPurposeDataRegion / transfer
SupabaseCore providerAuthentication, PostgreSQL database, row-level access controls, storage primitivesAccount, workspace, CRM, audit, and product dataConfigured project region
TelegramCustomer-connected integration providerMessaging transport, bot delivery, Telegram account infrastructure, and optional TDLib personal-session capabilities through customer-connected Telegram credentialsTelegram IDs, usernames, chat content, message metadata as used by connected workspacesTelegram-controlled infrastructure
Stripe; optional PayPal / Digistore24 / GumroadStripe for GramGrow billing; others when customer-configuredGramGrow subscription billing through Stripe, plus optional customer-selected payment processing, checkout, purchase verification, and webhook ingestionBilling metadata, checkout/session IDs, purchase and webhook recordsProvider-controlled regions and transfer safeguards
OpenAI / Anthropic / Google GeminiOptional when customer-configured or plan-enabledOptional AI drafts, enrichment, auto-reply, and incident assistance when enabledPrompt context selected by workspace configuration; customer API keys stay encrypted in GramGrow, and platform keys are used only when the plan explicitly enables GramGrow-metered AIProvider-controlled regions and enterprise terms
HetznerCore production hosting providerContainer runtime for web, API, workers, Caddy, Redis, and local service volumes in the guarded production deployment pathApplication runtime data, service logs, cached queue data, TDLib session volume, and deployment metadata depending on the selected hostGermany
ResendTransactional email providerTransactional authentication email such as signup confirmation, magic links, invites, password reset, and account security noticesEmail address, authentication email metadata, delivery metadata, and message templatesProvider-controlled regions and transfer safeguards
Self-hosted observability stackOperator-controlled operations stackMetrics, logs, traces, dashboards, alert routing, and public/internal health probes through OpenTelemetry, Prometheus, Loki, Tempo, Grafana, Alloy, Alertmanager, and Blackbox ExporterService metrics, container logs, traces, health check results, alert payloads, and operational metadata; secrets must not be loggedStored on operator-controlled deployment volumes unless an external observability backend is later configured

Change handling

Subprocessor changes should be published with date, purpose, and objection/contact path before production reliance.