Xerg Subprocessors
Xerg uses a small set of third-party providers to operate hosted workspaces. Local CLI audits involve none of them: local audit data does not leave your machine unless you explicitly push. This page lists every provider that may process customer, account, or marketing-site visitor data for Xerg services.
Cloudflare, Inc.
Hosting for the API, dashboard, and hosted MCP; database storage; DNS and TLS.
Data involved: Pushed audit summaries, workspace configuration, encrypted workspace secrets.
Clerk, Inc.
Sign-in, workspace membership, and billing for hosted workspaces.
Data involved: Account identity (name, email), organization membership, subscription status.
Cardinal
Product-signup enrichment and sales follow-up for new hosted workspace creators.
Data involved: Workspace creator email address, available first and last name, optional organization display name, and business or professional enrichment produced from those details.
GitHub, Inc.
Source control and deployment pipeline for Xerg services.
Data involved: No customer workspace data.
Resend, Inc.
Email delivery for the waitlist, newsletter, contact forms, agent spend review notifications, and one transactional activation reminder.
Data involved: Email address; the activation reminder includes only fixed public setup-command variables and does not create a marketing contact. Contact and review submissions may also include name and details you provide such as company, role, spend range, message, or agent stack.
Lightfield, Inc.
Customer relationship management and follow-up for requested sales conversations.
Data involved: Name, work email, optional company, optional agent stack, campaign attribution, request timestamp, and follow-up records.
Cal.com, Inc.
Optional scheduling for a requested agent spend review.
Data involved: Name, work email, selected meeting time, and calendar invitation details. Cal.com loads only after you explicitly choose to schedule.
PostHog, Inc.
Consent-gated marketing-site analytics and production-only server-side hosted-product analytics, kept in separate projects.
Data involved: Marketing-site interaction data and anonymous signup/activation linkage; hosted-product events contain a pseudonymous workspace identifier plus fixed plan, boolean, count, status, and coarse consented acquisition properties. They exclude user identity, customer content, cost figures, audit-source metadata, browser metadata, IP addresses, and person profiles.
GetEmails, LLC (d/b/a Retention.com and RB2B)
Consent-gated, production-only marketing-site visitor identification and lead intelligence. It runs only when production activation and visitor consent are both in place.
Data involved: Cookie and device identifiers, IP address, user agent, current and referring page URLs, visit timestamps, and matched company or professional identity and contact information.
Changes to this list
This page is updated whenever a provider that processes customer, account, or website visitor data is added or removed. Questions can be sent to query@xerg.ai.