Legal
Subprocessors and services
This page lists every third party that processes data on our behalf to run Novix, and what each one receives. It is the current list our Privacy Policy refers to.
Subprocessors
Each acts on our instructions and receives only what it needs to do its job.
- Anthropic: AI analysis. Receives ticket content and the code and context pulled for a ticket, in order to classify, diagnose, and draft fixes and replies. Per Anthropic’s commercial terms, data submitted through its API is not used to train its models. Anthropic deletes API inputs and outputs within 30 days, and keeps content its safety systems flag for up to 2 years.
- Supabase: managed Postgres database. Stores the Service’s data at rest: accounts, workspaces, tickets, diagnoses, audit logs, and encrypted integration credentials. Connections are made over TLS.
- Render: backend hosting. Runs the API server that processes every request and webhook.
- Supabase Storage: uploaded ticket attachments, in a private bucket in the same Supabase project as the database. The bucket is not public and its objects are not reachable without a credential. Deleting a ticket, or the retention sweep aging one out, deletes the stored bytes as well as the row.
- Vercel: frontend hosting. Serves the dashboard and this site, and proxies traffic between your browser and the backend on the same origin.
- Resend: account and notification email. Receives the recipient address and the message body. That is verification codes, sign-in codes, password resets, workspace invitations and billing notices, and also the ticket alerts and the daily digest a workspace turns on, which name a ticket and link to it. What leaves this way is a title, a count and a link. The diagnosis, the patch, the attachments and your customer’s own words stay in the product, behind your workspace’s access control.
- Stripe: billing. When you subscribe, Stripe receives your billing email and payment details (entered on Stripe’s own pages, never ours) to process the subscription. Novix never sees or stores card numbers.
- E2B: the isolated container Novix builds and tests every drafted fix in, before a pull request is opened. This runs on each drafted fix and is not optional. The container receives a clone of the repository you connected, the drafted patch, and briefly the access token used to clone it, which Novix removes from the container before any build command runs and refuses to continue if it cannot confirm the removal. Your own build and test commands run there. The container is destroyed once the result is in; if you turn on the live preview it stays up for a short, stated period so you can click through the fix, then stops. Logs kept on the ticket are scrubbed of credentials.
If you bring your own inference key
A workspace can route AI processing to its own account at Anthropic, OpenAI, Google Gemini, DeepSeek, OpenRouter, or Kimi instead of ours. That provider then receives what Anthropic receives above: ticket content, and the code and context pulled for a ticket. It is your account and your agreement with them, so it is not a subprocessor of ours and we cannot make commitments about its training, retention, or where it processes data. Some of those providers operate outside the United States and the EEA. Novix’s own key runs on Anthropic, and that is what a workspace uses unless it configures otherwise.
Services you connect
The integrations you connect, such as help desks, code hosts, and chat tools, are not subprocessors. You choose them, you hold the account, and data flows to and from them under your agreement with each provider. Novix reads tickets from and posts replies, pull requests, and notifications to the services you have connected, and nothing else.
Changes to this list
We update this page and its effective date before a new subprocessor starts handling your data. A way to subscribe to these changes will exist before general availability; until then, email support@getnovix.ai and we will notify you directly.
Contact
Questions about a vendor on this list?
Email support@getnovix.ai. See also our Privacy Policy and Terms of Service.