Legal
Subprocessors
Effective: June 2026
COSai uses the third-party subprocessors below to provide the service. Each operates under a contract requiring appropriate safeguards for the data it processes on our behalf. We give notice before adding or replacing a subprocessor so you can object. See our Privacy Policy and DPA for how this fits the broader data-processing terms.
| Subprocessor | Purpose | Data |
|---|---|---|
| Anthropic | AI processing of financial data (zero-retention; no model training) | Financial transactions, documents |
| Amazon Web Services | Cloud hosting, database, and encrypted storage (US) | All service data (encrypted) |
| Plaid | Read-only bank transaction data | Bank transactions |
| Read-only Gmail access for financial-document extraction | Email content (mailboxes you connect) | |
| Microsoft | Read-only Outlook / Microsoft 365 mail access | Email content (mailboxes you connect) |
| Finch | Payroll data aggregation | Payroll records |
| Stripe | Subscription billing and payments | Billing contact + payment metadata |
| Clerk | Authentication and identity (incl. multi-factor) | Account credentials, login metadata |
| Twilio | SMS notifications (only if you opt in) | Phone number, message content |
All subprocessors are US-based or process data in the US; COSai is currently a US-only service. Questions: privacy@cosai.tech.