Last updated: August 21, 2026
A subprocessor is a third-party service that processes data on our behalf so Querent can work. Privacy-first means being specific about who touches what, so this page lists every one of them, what each receives, and what happens to that data afterward. If we add or remove a provider, we update this page in the same release.
The common thread: no provider on this list uses your content to train AI models, none of them receives more than its job requires, and none of them retains your documents. The details of how we handle your data are in the Privacy Policy.
Receives: All stored account data: your email address, encrypted document text and conversations, and search embeddings. Document content is encrypted at the application layer before it reaches the database. Hosted in Canada (ca-central-1).
Retention: Stored until you delete the content or your account.
supabase.com/privacyReceives: Your question and the most relevant stored passages from your documents, sent per query to generate the answer. Never your whole library.
Retention: Not used to train models. Retained only briefly for safety and abuse monitoring, then purged.
anthropic.com/privacyReceives: Each document’s text chunks at upload time, to compute the embeddings that power meaning-based search.
Retention: Querent has opted out of data training; content is deleted once processed.
voyageai.comReceives: The complete bytes of every uploaded or emailed-in file, before it enters your library. This is the one step where a third party receives the full file.
Retention: Per their security documentation and DPA, processing is stateless and in-memory; files are not stored or retained after the scan.
cloudmersive.com/privacy-policyReceives: Your email address and the contents of account emails we send you; documents you email in transit through SendGrid on their way to Querent.
Retention: Inbound message content is not retained after delivery to Querent.
twilio.com/legal/privacyReceives: Your card details, entered directly with Stripe at checkout - they never pass through Querent’s servers. We store only subscription status.
Retention: Governed by Stripe’s own policies, including financial-regulation retention of transaction records.
stripe.com/privacyReceives: Runs the Querent API. Your data passes through it in memory while requests are processed; no user content is stored at rest on Railway.
Retention: Transient processing only.
railway.com/legal/privacyReceives: Serves this website and the app’s pages. Standard web server logs (IP address, request paths). Your documents are never sent to Vercel.
Retention: Standard infrastructure log retention.
vercel.com/legal/privacy-policyReceives: IP address and basic browser information when the public landing page loads, like any embedded third-party content. Never present inside the app; no access to documents or account data.
Retention: Governed by Senja’s own policies.
senja.io/privacyReceives: Email you send to querentapp.com addresses (like support@ or security@), forwarded to the inbox where we read it.
Retention: Forwarding only; governed by Forward Email’s policies.
forwardemail.net/privacyQuestions about any of this? Email support@querentapp.com. To report a security issue, see the security page.