Subprocessors
v1.0_23.09.26Effective and last updated: 23 September 2026
These are the service providers that can receive data when you or your members use QREATE. Nothing here is sold, and none of the AI providers may train on your content.
Discord
Receives: account identifiers, the server content the bot is permitted to see, and the settings an administrator configures.
Why: the service cannot run without it (sign-in, Gateway and API).
Where: Discord's global infrastructure.
Terms: discord.com/terms · discord.com/privacy
Hosting and database provider
Receives: all application data, including the database, cache and backups before encryption.
Why: runs the QREATE servers.
Where: Germany.
Google Cloud (Vertex AI, Text-to-Speech, Search grounding)
Receives: the Q chat prompt, recent conversation, relevant server context and attached images; spoken-reply text in voice mode; a short search query when Q searches the web.
Why: powers the Q assistant, its voice replies and grounded web answers.
Where: Vertex AI uses Google's global processing location, so a request may be handled at any facility where Google runs that service. Text-to-speech is configured to the EU only.
Training: under Google Cloud's business terms your content is not used to train or improve models.
Terms: cloud.google.com/terms · cloud.google.com/terms/cloud-privacy-notice
Anthropic
Receives: the same kind of Q chat request as Google Cloud, when an administrator selects it or as a fallback.
Why: powers the Q assistant.
Where: United States.
Training: under Anthropic's commercial API terms your content is not used to train models.
Terms: anthropic.com/legal/commercial-terms
Cloudflare (proxy, Turnstile, R2 storage)
Receives: web traffic passing through the proxy; the Turnstile token and IP address during verification; uploaded assets; database backups, which are encrypted before upload so Cloudflare holds only ciphertext.
Why: TLS and protection, bot checks, file storage and off-site backups.
Where: Cloudflare's global network.
Terms: cloudflare.com/website-terms · cloudflare.com/privacypolicy
IPQualityScore
Receives: the IP address of a member who is verifying.
Why: VPN and proxy risk check.
When: only if a server turns this check on.
Terms: ipqualityscore.com/terms-of-service · ipqualityscore.com/privacy-policy · ipqualityscore.com/data-processing-agreement
Resend and OpenEmail
Receives: the recipient's email address and the message (sign-up, sign-in and support mail).
Why: Resend sends transactional email; OpenEmail hosts the support mailboxes you write to.
Where: Resend is established in the United States.
Terms: resend.com/legal/terms-of-service · resend.com/legal/privacy-policy
Expo and browser push services
Receives: a device push token or browser push endpoint, and the notification title, text and link.
Why: mobile and browser notifications.
When: only after you turn notifications on. Browser notifications travel through your browser's own push service (Google, Mozilla or Apple).
Where: Expo is established in the United States.
Terms: expo.dev/terms · expo.dev/privacy
Integrations an administrator switches on
Twitch, YouTube, X and other feed or link-preview services receive only what is needed to fetch public content an administrator configured, such as a channel name. They receive no member data from QREATE. A webhook an administrator configures receives the event payload that administrator chooses.
Changes to this list
We update this page before a new provider starts receiving data, and the version above changes with it. The Privacy Policy, section 5 and section 7, describes the same providers and the legal basis for international transfers. Questions or objections: [email protected].