Last updated23 August 2026
Subprocessors
Citerra uses a small set of providers to run the service. Each one handles a single slice of the data and nothing beyond it. This page lists every provider, what it receives, and where it operates. It also says what none of them receives, what an organization's own model endpoint changes, and how this list is kept current.
§ 1
Current subprocessors
Each provider below handles one slice of the data, and nothing beyond it.
| Provider | What it receives | Where |
|---|---|---|
| Convex | Application database and generated artifacts. | EU (Ireland) |
| Resend | Email addresses on the waitlist and the newsletter, and the content of the messages Citerra sends to them. | EU (Ireland) for delivery; provider is US-based |
| Clerk | Sign-in identity: email address, name, and organization membership. | United States |
| UploadThing | Uploaded PDF and image files. | United States |
| Fly.io | LaTeX sources during compilation, deleted after each job. | EU (Frankfurt) |
| OpenAI | Text excerpts sent for AI assistance and search indexing. The provider's API terms exclude this content from training. | United States |
| Vercel | Requests to citerra.de and the application, and their server logs. | Global edge, EU region for server rendering |
| Sentry | Error reports with personal data removed. | EU |
§ 2
What they do not receive
No provider on this list receives your library in full. When the assistant answers a question, Citerra sends only the passages relevant to that question to the model provider. The rest of the document stays in Citerra.
Citerra queries public indexes: OpenAlex, arXiv, Europe PMC, and Crossref. Searching the literature sends them the search terms, and importing a source by DOI sends them that identifier. These receive the query, never the document. They are public research indexes rather than subprocessors, because they process no personal data on Citerra's behalf.
§ 3
Your own model endpoint
An organization can point Citerra at its own model endpoint, in which case the assistant's answers are generated there instead of at OpenAI. Indexing a source and retrieving from it still reach OpenAI.
The API key for that endpoint is stored in Convex, readable only through an internal function, sent only to your own endpoint, and never logged. Deleting the override deletes the key.
§ 4
Changes to this list
A provider is added to this page in the same change that adds the integration, and removed in the same change that removes it. Organizations with a data processing agreement in place are notified before a new subprocessor begins processing.