Effective date: 2026-09-03
To support the delivery of Sleev’s hosted control-plane services, account management, organization administration, and subscription billing, Sleev Labs Inc. (“Sleev”) engages third-party service providers (“Subprocessors”) that may process Customer Personal Data.
This page provides a current list of all authorized Subprocessors, explains their role, and outlines our process for notifying customers of proposed changes in accordance with our Data Processing Addendum (DPA).
1. Local Gateway vs. Hosted Services
As detailed in our Privacy Policy, the Sleev software operates as a local-first gateway residing on the customer’s machine (127.0.0.1).
- Local Processing: Prompt text, repository source code, AST representations, file modifications, tool executions, and model responses stay strictly local. They do not pass through or get stored on Sleev cloud infrastructure or Subprocessor servers.
- Hosted Processing: The Subprocessors listed below process only the operational metadata, user identity details, license serving leases, and billing data necessary to provide cloud-managed accounts, organization controls, and subscription services.
2. Infrastructure & Service Subprocessors
The following third-party entities are currently engaged by Sleev Labs Inc. to process personal data:
| Subprocessor | Entity Location | Processing Nature & Purpose | Processing Location |
|---|---|---|---|
| Google Cloud Platform (Google LLC) | United States | Cloud infrastructure hosting, control-plane API servers, managed PostgreSQL database (Cloud SQL), encrypted storage buckets (GCS) for temporary diagnostic logs | United States (Global Tier) |
| WorkOS, Inc. | United States | Enterprise Single Sign-On (SAML / OIDC), SCIM directory sync, user identity and authentication management | United States |
| Stripe, Inc. | United States | Payment card processing, subscription management, invoicing, tax calculation, and transaction fraud prevention | United States / Global |
| Resend, Inc. | United States | Transactional email delivery, account verification emails, login link dispatch, security notices, and team invitation delivery | United States |
3. Direct Upstream AI Model Providers
When using Sleev, customers configure their own client-side API credentials, custom base URLs, or internal proxy gateways for upstream model providers (for example, Anthropic, OpenAI, Google, DeepSeek, OpenRouter, self-hosted vLLM/Ollama instances, or any other custom LLM provider or endpoint).
Important Distinction: All upstream model providers and custom endpoints configured by the customer are Direct Service Providers contracted directly by Customer, not Subprocessors of Sleev.
The local Sleev gateway routes LLM prompt completions directly between the developer’s workstation and the provider’s API endpoint. Model API keys, custom headers, and prompt payloads are transmitted directly from your machine to the configured provider over encrypted TLS connections and never traverse Sleev Labs servers.
4. Subprocessor Security & Due Diligence
Before engaging third-party Subprocessors to handle customer data, Sleev evaluates their security posture and contractual commitments:
- Security Standards: Verifying that vendors maintain recognized security certifications (such as SOC 2 Type II or ISO 27001) and industry-standard operational safeguards.
- Data Protection Agreements: Ensuring written data processing terms and standard contractual clauses (SCCs) are in place to safeguard personal data.
- Access Controls & Encryption: Ensuring administrative access is restricted to authorized personnel under least-privilege principles, and data is protected by encryption in transit (TLS) and at rest (AES-256).
5. Notification & Objection Process
Sleev provides customers with advance notice of any planned addition or replacement of a Subprocessor:
- Notice Period: Sleev will notify customers at least thirty (30) days prior to authorizing any new Subprocessor to process Customer Personal Data.
- Notification Method: Updates will be published to this directory page and sent directly via email notice to all registered users and organization administrators.
- Objection Procedure: In accordance with Section 6.4 of the DPA, Customer may object to a new Subprocessor on reasonable data protection grounds by providing written notice within thirty (30) days of receiving notice.
6. Questions & Inquiries
If you have questions regarding our Subprocessors, compliance, or third-party risk management practices, please contact:
Sleev Labs Inc.
Attention: Compliance & Data Protection
Email: support@sleev.ai