Legal / service chain

Service Providers and Subprocessors

Archived list

Last updated July 28, 2026. Written for the current prelaunch product.

Version
2026-07-28
Effective
Not yet effective
Review by
Before public signup

This list reflects the current prelaunch architecture. It distinguishes vendors Wildflower engages to run the service from sandbox providers a customer selects and contracts with directly.

1. Wildflower service providers

ServicePurpose and dataRole
CloudflareWebsite and static asset delivery, same-origin API proxying, and protected PostgreSQL backups in R2. Depending on the function, this can involve network request data, cookies, API payloads in transit, and encrypted backup data.Wildflower infrastructure provider and subprocessor where applicable.
Fly.ioAPI compute and private PostgreSQL infrastructure. This can involve identity, account, project, encrypted provider credential, sandbox registry, operational, and Customer Content data needed for an API operation.Wildflower infrastructure provider and subprocessor.

2. Identity service

ServicePurpose and dataRole
Google Identity ServicesGoogle sign-in. Google can provide its account identifier, email, email-verification status, name, and profile image to Wildflower after the user completes the identity flow.Independent identity service governed by Google’s own terms and privacy practices; not a Wildflower workload subprocessor.

3. Customer-directed sandbox providers

In the current customer-connected or BYOK architecture, the customer chooses a supported sandbox provider, maintains its own provider agreement, and supplies credentials authorizing Wildflower to call that provider. Wildflower sends the provider credentials, request data, and Customer Content required to perform the requested operation.

Those sandbox providers are ordinarily customer-directed third-party services, not subprocessors Wildflower appoints on the customer’s behalf. Their terms, charges, quotas, security controls, regions, retention, and remedies apply directly to the customer. See the current provider support matrix.

If Wildflower later operates sandbox infrastructure, chooses a provider under an authorized managed-routing service, or resells provider capacity, the applicable service schedule and this list will identify the operator and legal role before that mode is offered.

4. Email and other future services

A production provider for organization invitations and other transactional email has not been selected, and Wildflower does not currently send production invitation data to one. We will add the selected provider and relevant processing details before enabling that workflow publicly.

5. Changes

Wildflower will date material changes to this list. Before the DPA becomes effective, it will define the notice and objection process for a new subprocessor. Customer-directed provider additions do not change Wildflower’s subprocessor list unless Wildflower’s role in providing that service also changes.

6. Questions

Read the Privacy Notice and prelaunch DPA framework for more detail. Email legal@wildflower.computerfor questions about this list or the future notice and objection process.