Skip to policy

ThoughtBubble Development, LLC

Third-Party Services and Subprocessors

This register names external services that may receive data when Tallpine provides its core service or when you enable a particular workflow.

Effective August 28, 2026

1. How to read this register

A service listed here may act as our service provider or subprocessor, as an independent business under its own terms, or as a recipient you direct us to use. The role depends on the service and processing. This register does not mean every optional provider receives your data.

Tallpine sends only the data needed for the relevant operation. Provider processing locations and retention may vary by provider, account, and configuration. See the provider's terms and privacy documentation for its independent practices.

2. Core production services

Core production services
ServicePurpose and dataWhen used
CloudflarePublic website delivery, TLS, network protection, and request security. IP address, request headers, requested URL, device/network metadata, and security signals.When a Tallpine deployment routes production traffic through Cloudflare.
Google OAuthProduction account authentication. Google account identifier, name, email address, profile image, and authentication metadata.When you sign in.
StripeCheckout, subscriptions, invoices, payment methods, tax, and billing portal. Billing contact, Customer and Subscription records, paid Site quantity, invoice and payment status; payment credentials are collected by Stripe.When you start a trial, subscribe, change paid Site quantity, or manage billing.
Backblaze B2Private S3-compatible object storage. Uploaded Sources and reference files, uploaded and generated Images, publishing or export artifacts, and object metadata.When configured as the deployment's S3-compatible media store; local development may use local storage instead.

3. AI, research, and media services

AI, research, and media services
ServicePurpose and dataWhen used
Z.aiSelectable AI text generation through its OpenAI-compatible API. Prompts, selected Source or public-web excerpts, tool results, generated material, and request metadata needed for an Agent workflow.When a Z.ai model is selected for the requested workflow.
OpenAISelectable text generation and embeddings; generated-image creation and rendered-image quality review. Prompts, selected content or text for embedding, generated output, image descriptions, and enabled reference or generated Image pixels.When the relevant OpenAI-backed feature is configured and used.
OpenRouter and the selected model providerSelectable routing for AI text generation. Prompts, selected Source or public-web excerpts, tool results, generated material, model selection, and request metadata needed for an Agent workflow.When an OpenRouter-routed model is selected; the chosen upstream model provider may also process the request.
Google GeminiAlternate generated-image service. Image prompts, requested image settings, and generated image responses.When Gemini is configured as the image provider.
Brave Search, Tavily, or SerpAPIPublic web search, extraction, crawling, mapping, and research. Search queries, public URLs, locale or result settings, and public page content required for a requested research workflow.Only when the applicable search or Tavily integration is enabled and the workflow uses it.
DataForSEOKeyword ideas and search metrics. Keyword strings, language, locale, and metric request settings.Only when keyword-data enrichment is enabled.
UnsplashStock-image search and attribution. Bounded stock-image search queries, result requests, and selected-image attribution events.Only when Unsplash is explicitly enabled and a stock-image workflow uses it.
Configured Ollama operatorText embeddings for Source and content retrieval. Text chunks submitted for embedding, model selection, and request metadata.When Ollama embeddings are configured outside the local Tallpine deployment; a local or self-hosted instance is not a separate recipient.

4. Communications and product operations

Communications and product operations
ServicePurpose and dataWhen used
Notifuse and Amazon SESTransactional email through the Notifuse API, with Amazon SES as Notifuse's documented downstream delivery service. Recipient name and email, message template and data, deep links, external message identifiers, and delivery, bounce, or complaint status.When transactional email delivery is enabled.
Umami deploymentCookie-free product analytics and aggregate reporting. Normalized page paths, referrer, browser, operating system, device type, country, and bounded product-event fields without account identifiers or workspace content.Only when a complete Tallpine analytics configuration is present.
Google FontsPublic-site typeface delivery. IP address, browser request metadata, and requested font resources.When your browser loads Tallpine pages that request the configured fonts.
Configured OpenTelemetry collector and observability backendRequest tracing, performance monitoring, and incident diagnosis. Service, request, network, database-operation, timing, error, and other bounded trace metadata; Tallpine's instrumentation is designed to avoid request bodies and credentials.Only when tracing export is configured; a self-hosted collector is not by itself a separate recipient.

5. Customer-selected publishing destinations

WordPress and Payload CMS destinations are connected and controlled by the customer. When you test a connection or publish, Tallpine sends the authentication data required by that connection and the selected Article, metadata, and Image content directly to that destination. Tallpine stores managed connection credentials encrypted at rest. Those destinations are not Tallpine subprocessors merely because you connect them; their operators process data under your instructions and their own terms. Disconnecting a destination does not delete content already delivered there.

6. Local and self-hosted components

Tallpine also uses application-owned or self-hosted components such as PostgreSQL, pgvector, locally operated Ollama embeddings by default, and an OpenTelemetry collector when tracing is configured. These components do not by themselves identify a separate third-party recipient. A deployment may use infrastructure suppliers that support those components.

7. Changes and questions

We update this register when a material provider or processing purpose changes. Where required, we will provide additional notice before a new subprocessor begins processing covered customer data. Questions or objections may be sent to [email protected]. See the Privacy Policy for rights and request information.