Xerg Subprocessors
Xerg uses a small set of third-party providers to operate hosted workspaces. Local CLI audits involve none of them: local audit data does not leave your machine unless you explicitly push. This page lists every provider that may process customer, account, or marketing-site visitor data for Xerg services.
Cloudflare, Inc.
Hosting for the API, dashboard, and hosted MCP; database storage; DNS and TLS.
Data involved: Pushed audit summaries, workspace configuration, encrypted workspace secrets.
Clerk, Inc.
Sign-in, workspace membership, and billing for hosted workspaces.
Data involved: Account identity (name, email), organization membership, subscription status.
Cardinal
Sales follow-up for new hosted workspace creators and sales workflows associated with consented marketing-site visitor matches.
Data involved: Workspace creator email address, available first and last name, optional organization display name, business or professional enrichment produced from those details, and matched sales lead information supplied by the visitor-identification provider.
GitHub, Inc.
Source control and deployment pipeline for Xerg services.
Data involved: No customer workspace data.
Resend, Inc.
Email delivery for the waitlist, newsletter, agent spend review notifications, and one transactional activation reminder.
Data involved: Email address; the activation reminder includes a Clerk organization ID in fixed setup commands plus a closed recovery state, and does not create a marketing contact. Review submissions may also include name, company, and agent stack.
Lightfield, Inc.
Customer relationship management and follow-up for requested sales conversations.
Data involved: Name, work email, optional company, optional agent stack, campaign attribution, request timestamp, and follow-up records.
Cal.com, Inc.
Optional scheduling for a requested agent spend review or product demo.
Data involved: Name, work email, selected meeting time, calendar invitation details, optional agent stack, and optional monthly agent inference spend range. Cal.com loads when the public demo page opens; in the agent spend review flow, it loads only after you explicitly choose to schedule.
PostHog, Inc.
Regional-consent production marketing-site analytics and production-only server-side hosted-product analytics, kept in separate projects. Marketing session replay requires explicit Analytics acceptance everywhere; local and staging builds omit the browser SDK.
Data involved: Marketing-site interaction data and anonymous signup/activation linkage; hosted-product events contain a pseudonymous workspace identifier plus fixed plan, boolean, count, status, and coarse consented acquisition properties. They exclude user identity, customer content, cost figures, audit-source metadata, browser metadata, IP addresses, and person profiles.
GetEmails, LLC (d/b/a Retention.com and RB2B)
Downstream visitor-identification provider for Cardinal Website Visitors. It is production-only, classified as sale/share advertising, blocked by GPC, default-on with opt-out in the United States, and opt-in everywhere else.
Data involved: Cookie and device identifiers, IP address, user agent, current and referring page URLs, visit timestamps, and matched company or professional identity and contact information.
Slack Technologies, LLC
Optional delivery of workspace audit and optimization notifications to channels selected by workspace administrators.
Data involved: Workspace and channel identifiers, encrypted integration credential, and the bounded audit or optimization notification selected for delivery.
Linear Orbit, Inc.
Optional one-way creation of an issue from an Optimization when a workspace administrator connects Linear and requests the handoff.
Data involved: Linear workspace and team identifiers, encrypted OAuth credentials retained by Xerg, and a bounded issue title and description containing the safe Optimization handoff and Xerg link. Prompts, responses, tool arguments or results, headers, arbitrary attributes, and Cedar policy text are excluded.
CookieYes Limited
Cookie consent collection and enforcement on the marketing site.
Data involved: Consent selections and ordinary request metadata needed to serve the consent manager.
X Corp.
Regional-consent advertising conversion measurement on the marketing site.
Data involved: Marketing-site visit and conversion metadata while Advertisement is allowed and GPC is not active.
Meta Platforms, Inc.
Regional-consent advertising conversion measurement on the marketing site.
Data involved: Marketing-site visit and conversion metadata while Advertisement is allowed and GPC is not active.
Reddit, Inc.
Regional-consent advertising conversion measurement on the marketing site.
Data involved: Marketing-site visit and conversion metadata while Advertisement is allowed and GPC is not active.
LinkedIn Corporation
Regional-consent advertising conversion measurement on the marketing site.
Data involved: Marketing-site visit and conversion metadata while Advertisement is allowed and GPC is not active.
Google LLC
Corporate email used to receive and respond to customer and privacy/security inquiries.
Data involved: Email addresses and message content voluntarily sent to Xerg email addresses.
Better Stack, Inc.
Public service-status page, site footer status badge, uptime monitoring, and incidents.
Data involved: Service-health data and ordinary request metadata for status-page visitors.
Mintlify, Inc.
Hosting for Xerg public documentation.
Data involved: Ordinary request metadata from documentation visitors; no customer workspace payloads.
Changes to this list
This page is updated whenever a provider that processes customer, account, or website visitor data is added or removed. Questions can be sent to hello@xerg.ai.