AmvioBack

Sub-processors

Effective 23 August 2026 · Amvio, Inc.

What this list is

Amvio cannot do what it does without sending data to other companies. This is all of them, what each one is for, and what each one actually receives. It is an annex to the privacy policy.

Every entry was taken from the running code rather than from a template. If you need this list to be contractual — with notice before it changes — that is what the data processing agreement does, and it is published and applies automatically.

Infrastructure

SupabaseDatabase, authentication and file storage

Everything Amvio stores: accounts, conversations, uploaded files, indexed documentation, and what Amvio has learned.

RailwayHosting for the Amvio API

All traffic to the service in transit, including live session data as it passes through.

VercelHosting and page-view analytics for this dashboard

Dashboard requests and their authentication cookies. Separately, a cookieless count of page views: the page, the referring site, and coarse device and country information.

SentryError tracking

The address of a page that failed and an error reference, with the browser and operating system. Not the contents of the page, and no session recording.

Model providers

Which text model answers a given conversation depends on how the workspace is configured, so a workspace may never reach some of these. Two of them are not optional, and are shaded below.

GoogleThe live voice session (Gemini Live)

Microphone audio and, where screen sharing is enabled, still frames of the shared screen, along with the text of the conversation. This is the only provider that receives audio or images.

OpenAIText generation, and all knowledge embeddings

Conversation text and excerpts of your documentation. Every piece of knowledge you give Amvio is embedded through OpenAI, whichever model answers your customers.

AnthropicText generation and structured extraction (Claude)

Conversation text and excerpts of your documentation, where a Claude model is selected.

xAIText generation (Grok)

Conversation text and excerpts of your documentation, where Grok is selected.

Voice and screen sharing go to Google. If you enable them, your users' microphone audio and pictures of whatever is on their screen leave Amvio and reach Google. That is the single most consequential thing on this page, and the reason your own notice to your users has to say so.

Content processing

FirecrawlReading documentation sites you point Amvio at

The URLs you ask it to index, and it returns their contents. It receives no conversation data.

Connected by you, or not at all

These receive nothing until you connect them, and connecting is an explicit action taken by an owner or admin in your workspace.

NotionOptional knowledge source

Nothing unless you connect it. Once connected, Amvio reads the pages you authorise.

LinearOptional integration

Nothing unless you connect it.

Changes to this list

Amvio gives at least 30 days' notice by email before adding or replacing a sub-processor, and you may object on reasonable data-protection grounds. That commitment, the transfer mechanism for each provider, and the flow-down obligations Amvio imposes on them are all set out in clauses 5 and 10 of the Data Processing Agreement, which applies automatically and needs no separate signature.

Contact

Questions about any of these documents, requests about your data, and security reports all go to hello@amvio.ai.

The other documents

Terms of ServiceThe agreement itselfAcceptable Use PolicyWhat you may not do with AmvioPrivacy PolicyWhat we collect and whyData Processing AgreementOur processor obligations to youSub-processorsEvery third party your data reachesSecurityHow the service is built and protectedNotice for end usersFor people who talk to Amvio