Subprocessor List
Services involved in the current native app, followed by the separate web service provider list.
Last updated September 9, 2026
- Apple provides the device platform and private iCloud sync.
- OpenRouter and serving model providers process chat; Composio supports optional integrations.
- Connected services process data according to the permissions and requests you authorize.
- Apple: app distribution, device frameworks, local speech and text recognition, Keychain, and private iCloud synchronization.
- OpenRouter and the serving model providers: chat inference, model routing, request metadata, optional web search, and account services under your OpenRouter connection.
- Composio and services you connect: authorization, connection management, integration tools, arguments, and results.
- Vercel: the memrov.app support and policy website and web callback continuity. Visiting these pages involves the website hosting and operational data path.
- Your email provider: delivery of support reports you choose to send. Memrov receives the email and uses it to handle your request. Earlier native TestFlight support uploads used Memrov services on AWS and Amazon Simple Email Service for authenticated report delivery.
- Auth0, Stripe, AWS-backed web imports, and Memrov Cloud billing described below are separate web service paths. They are not the account, chat, or billing path of the current native launch.
- OpenRouter processes chat content and request metadata, including the model, token usage, timing, and identifiers used to associate requests with your provider account and conversation. Retention and training depend on your OpenRouter settings and the provider or endpoint that serves the request. Memrov does not enforce a universal zero-retention setting.
- When Web search is enabled in Chat, OpenRouter can process search queries and return web results through its search tool. Relevant conversation context and search results may be included in the model request.
- Optional integrations connect through Composio. Composio and the services you authorize process connection information, tool requests, arguments, and results needed for the integration. This can include content from a connected service, such as messages or documents, depending on the permissions and action you choose. Results used in chat are also sent to the AI provider.
- OpenRouter and Composio authorization credentials are kept in the device Keychain using device-only protection. Connecting a provider requires its authorization flow. Disconnecting locally does not delete your provider account or guarantee revocation of every permission at that provider.
The sections below describe the Memrov web service, including Auth0 accounts, web imports, Safe AI, and Stripe billing where available. They were last updated May 25, 2026. Those account and billing workflows do not describe the current native iOS launch. General company, rights, acceptable-use, and legal-contact provisions still apply where relevant.
- Amazon Web Services: hosting, storage, databases, logs, messaging, secrets, queues, API infrastructure, and security controls.
- Vercel: frontend hosting, serverless functions, deployments, logs, and edge delivery.
- Auth0 by Okta: authentication, social login, account identity, sessions, and token issuance.
- Stripe: pricing, checkout, subscriptions, included Safe AI credits, invoices, taxes, fraud prevention, and customer billing portal.
- Google Cloud: narrowly scoped NLP, Gemini, Vertex AI, and evaluation workloads when enabled for processing or validation.
- Bedrock: managed model inference for Safe AI when enabled.
- Discord and Telegram: optional channel connectors when a user chooses to connect those services.
- Apple and Google app platforms: mobile distribution, app review, in-app platform controls, and platform compliance where applicable.
ChatGPT, Claude, and other AI providers are usually sources of data you choose to import or connect. They may also become service destinations when you grant a connector. Their own terms and privacy policies continue to apply to your direct relationship with them.
- Security posture and managed controls.
- Ability to scope access by tenant, user, environment, and purpose.
- Data retention, deletion, logging, and audit controls.
- Contractual privacy and security commitments.
- Operational necessity for Memrov's product and mission.
We may add or replace subprocessors as the product changes. For business customers with a signed agreement, notice and objection rights are handled through the applicable agreement or DPA.
Memrov, Inc.
admin@memrov.com
Registered agent
Legalinc Corporate Services Inc.
131 Continental Dr
Suite 305
Newark, DE 19713
United States
