Legal
Sub-processors
Third-party services that process customer data on behalf of Thirdwatch. Provider links below describe their published data-processing terms. Service configuration and enabled integrations determine which providers process a request.
Last updated:
Active sub-processors
- Purpose
- Executes the Apify-backed subset of Thirdwatch data tools and hosts the separate Actor catalog.
- Region
- United States (with EU/Asia compute regions per actor)
- Data
- Thirdwatch service credentials, request parameters and provider results; callers do not need an Apify account for Thirdwatch MCP.
Railway
Privacy & data terms →- Purpose
- Hosts the Thirdwatch MCP server, landing site, and Postgres instance.
- Region
- United States (US-East)
- Data
- All HTTP request data, application logs, customer database (users, credit ledger, usage events).
Sentry
Privacy & data terms →- Purpose
- Error monitoring, performance tracing, alerting.
- Region
- European Union (project provisioned in eu.sentry.io)
- Data
- Error diagnostics, route templates, account identifiers, tool names and latency. Application filters limit sensitive fields; diagnostic handling also depends on provider settings.
Microsoft Clarity
Privacy & data terms →- Purpose
- Optional public website interaction metrics, heatmaps and masked session replay to improve the website.
- Region
- Microsoft processing locations described in its Privacy Statement.
- Data
- Only after analytics acceptance: public-page interactions and device/session metadata. All text is masked. Private account/OAuth pages and arbitrary URL queries are excluded. We send no Clerk identifier, email, tool inputs or results; advertising storage is denied.
PostHog
Privacy & data terms →- Purpose
- Product analytics — signup/conversion funnels, feature usage.
- Region
- European Union (eu.i.posthog.com host)
- Data
- When configured, page views and explicit research, account, usage and purchase events. Browser analytics requires consent; URL query strings are stripped, form autocapture is disabled, and the client disables IP collection. Backend events use account identifiers and aggregate metrics without raw queries or email addresses.
- Purpose
- Authentication, session management, OAuth identity.
- Region
- United States
- Data
- Email, sign-in metadata, session tokens.
Dodo Payments
Privacy & data terms →- Purpose
- One-time credit-pack payments, refunds and receipts.
- Region
- See the provider privacy policy for processing locations.
- Data
- Customer email, billing address, payment method (last 4 only).
Data subject requests
For access, deletion, correction or questions about your account data, contact support@thirdwatch.dev. Include the account email and request type, without passwords or API keys.