Sub-processors

Effective 17 August 2026 · Amvio, Inc.

What this list is

Amvio cannot do what it does without sending data to other companies. This is all of them, what each one is for, and what each one actually receives. It is an annex to the privacy policy.

Every entry was taken from the running code rather than from a template. If you are evaluating Amvio and need this list to be contractual — with notice before it changes — that belongs in a data processing agreement, which is noted as outstanding below.

Infrastructure

SupabaseDatabase, authentication and file storage

Everything Amvio stores: accounts, conversations, uploaded files, indexed documentation, and what Amvio has learned.

RailwayHosting for the Amvio API

All traffic to the service in transit, including live session data as it passes through.

VercelHosting for this dashboard

Dashboard requests and their authentication cookies.

Model providers

Which text model answers a given conversation depends on how the workspace is configured, so a workspace may never reach some of these. Two of them are not optional, and are shaded below.

GoogleThe live voice session (Gemini Live)

Microphone audio and, where screen sharing is enabled, still frames of the shared screen, along with the text of the conversation. This is the only provider that receives audio or images.

OpenAIText generation, and all knowledge embeddings

Conversation text and excerpts of your documentation. Every piece of knowledge you give Amvio is embedded through OpenAI, whichever model answers your customers.

AnthropicText generation and structured extraction (Claude)

Conversation text and excerpts of your documentation, where a Claude model is selected.

xAIText generation (Grok)

Conversation text and excerpts of your documentation, where Grok is selected.

Voice and screen sharing go to Google. If you enable them, your users' microphone audio and pictures of whatever is on their screen leave Amvio and reach Google. That is the single most consequential thing on this page, and the reason your own notice to your users has to say so.

Content processing

FirecrawlReading documentation sites you point Amvio at

The URLs you ask it to index, and it returns their contents. It receives no conversation data.

Connected by you, or not at all

These receive nothing until you connect them, and connecting is an explicit action taken by an owner or admin in your workspace.

NotionOptional knowledge source

Nothing unless you connect it. Once connected, Amvio reads the pages you authorise.

LinearOptional integration

Nothing unless you connect it.

Changes to this list

Amvio gives at least 30 days' notice by email before adding or replacing a sub-processor, and you may object on reasonable data-protection grounds. That commitment, the transfer mechanism for each provider, and the flow-down obligations Amvio imposes on them are all set out in clauses 5 and 10 of the Data Processing Agreement, which applies automatically and needs no separate signature.