Last updated: October 6, 2026
A subprocessor is a third-party service that processes data on our behalf so Querent can work. Privacy-first means being specific about who touches what, so this page lists every one of them, what each receives, and what happens to that data afterward. If we add or remove a provider, we update this page in the same release.
The common thread: no provider on this list uses your content to train AI models, none of them receives more than its job requires, and none of them keeps your documents as a stored copy - the retention lines below say exactly how long each one holds what passes through it. The details of how we handle your data are in the Privacy Policy.
Receives: All stored account data: your email address, encrypted document text and conversations, and search embeddings. Document content is encrypted at the application layer before it reaches the database. Hosted in Canada (ca-central-1).
Retention: Stored until you delete the content or your account.
supabase.com/privacyReceives: At upload: a short excerpt of each document (to generate its tags and summary), and the full content of photos, scanned pages, and the pictures in Word and PowerPoint files that are mostly images, which Claude’s vision models read to extract their text and screen for prohibited content. Per question: your question, your first name, and the most relevant stored passages, never your whole library; each passage is labeled with the name of the document it came from, which is how an answer can cite its sources. Inside a conversation, its most recent turns are sent again so follow-ups make sense, and they can quote documents your latest question did not match. For folder suggestions: document names, tags, and summaries, plus the names of the folders you already have, so an existing folder can be suggested when one fits. For a study set or a report: the most relevant passages from the documents you selected, up to 25 documents at a time, labeled with their document names the same way. For key dates: the passages of one document that contain dates, labeled the same way. The help page’s question widget: the question typed into it, with our own documentation, never account data.
Retention: Not used to train models. Inputs and outputs are retained for a limited period for safety and abuse monitoring, governed by Anthropic’s data retention policy.
anthropic.com/privacyReceives: At upload: each document’s text chunks, to compute the embeddings that power meaning-based search. Per question: the text of your question, to compute the embedding used to find the matching passages. In report and compare mode the question is sent once per document you selected, up to 25 at a time.
Retention: Querent has opted out of data training; retention of processed content is governed by Voyage AI’s own policy.
voyageai.comReceives: Your email address and the contents of account emails we send you; documents you email in transit through SendGrid on their way to Querent; and, on their way to our support inbox, questions typed into the help widget and in-app feature requests (a feature request carries your email address so we can reply).
Retention: Inbound messages are held only long enough to deliver; failed deliveries are retried for up to about 72 hours, then dropped. Outbound email activity (addresses, subject lines, delivery status) is retained for a limited period under SendGrid’s own policy. When you delete your Querent account, we also ask SendGrid to remove your address from its suppression lists.
twilio.com/legal/privacyReceives: Your email address and an internal account number, so payments match your account, and your card details, entered directly with Stripe at checkout - they never pass through Querent’s servers. We store only subscription status.
Retention: Governed by Stripe’s own policies, including financial-regulation retention of transaction records.
stripe.com/privacyReceives: Runs the Querent API. Your documents pass through it while requests are processed: held in memory or, for uploads over 1MB, in an unnamed temporary file that is deleted when the request ends. Railway also records each request’s IP address and path (paths carry record ids, never document text or anything you type). When something goes wrong, Querent writes an error line to Railway’s log, which can include identifiers and, in a few cases, a short piece of the text involved, such as a question typed into the help widget when its email forward fails; Railway keeps those logs for about 30 days. No documents, chunks, or account records are stored on Railway.
Retention: Transient for your documents: in memory or a temporary file only for the length of a request. Request and error logs are kept about 30 days by Railway, then deleted.
railway.com/legal/privacyReceives: Serves this website and the app’s pages. Standard web server logs (IP address, request paths). Your documents are never sent to Vercel.
Retention: Standard infrastructure log retention.
vercel.com/legal/privacy-policyReceives: IP address and basic browser information when the public landing page loads, like any embedded third-party content. Never present inside the app; no access to documents or account data.
Retention: Governed by Senja’s own policies.
senja.io/privacyReceives: Email you send to querentapp.com addresses (like support@ or security@), and the help-widget questions and feature requests our own server sends to support@, forwarded to the inbox where we read it.
Retention: Forwarding only; governed by Forward Email’s policies.
forwardemail.net/privacyQuerent can import files from Google Drive, and Google is deliberately not a subprocessor. A subprocessor handles data for us; in a Drive import, your own Google account serves your own files to your own browser, which then uploads them to Querent like any other upload. Querent's servers never hold a Google credential and never call Google, and the permission you grant covers only the files you pick in Google's chooser. How that works, and how to revoke it, is in the Privacy Policy.
Questions about any of this? Email support@querentapp.com. To report a security issue, see the security page.