Subprocessors
Loquent runs on other companies’ infrastructure. This page names every one of them, what we send, and why — so a Leader can see exactly where their business’s information goes before they trust us with it.
This page supports our Privacy Policy. For most of what is listed here Loquent acts as a processor: the business using Loquent decides what is collected, and we hold it on their instruction.
- When it runs
- Always active means every organization. When enabled means only after a Leader turns that channel or feature on.
- What it receives
- Contact information can identify a business’s own customers. Account covers only the Leader and their team. None means no personal information by design.
Core infrastructure
Always active. Everything in Loquent lives here.
-
Railway
Railway Corp.Always active Contact information- What we send
- The entire application database — accounts, Contacts, message bodies, transcripts, teammate memory, and configuration.
- Purpose
- Application and PostgreSQL hosting.
- Where it is processed
- United States
Privacy — Railway, opens in a new tab DPA — Railway, opens in a new tab
-
Cloudflare
Cloudflare, Inc.Always active Contact information- What we send
- Call recordings, uploaded files and attachments, and hosted-page assets in object storage; visitor IP addresses and request metadata at the edge.
- Purpose
- CDN, DNS, firewall, object storage, and hosted pages.
- Where it is processed
- Global edge network
Privacy — Cloudflare, opens in a new tab DPA — Cloudflare, opens in a new tab
Communication channels
Active only for the channels a Leader connects. Each one carries live conversation content.
-
Twilio
Twilio Inc.When enabled Contact information- What we send
- Live call audio in both directions, caller and called numbers, call recordings, SMS message bodies, and the business identity documents filed for number registration.
- Purpose
- Voice telephony and SMS delivery.
- Where it is processed
- United States
Privacy — Twilio, opens in a new tab DPA — Twilio, opens in a new tab
-
Meta Platforms
WhatsApp · Messenger · Instagram · FacebookWhen enabled Contact information- What we send
- Message content in both directions, platform-scoped user identifiers, profile names and avatars, post and comment text, and lead-ad form answers.
- Purpose
- WhatsApp Business messaging, social inbox, publishing, and lead ads.
- Where it is processed
- Global
-
LinkedIn
LinkedIn CorporationWhen enabled Contact information- What we send
- Post content the Leader publishes, and the page comments we read back to draft replies.
- Purpose
- Company-page publishing and comment handling.
- Where it is processed
- Global
-
Resend
Resend, Inc.Always active Contact information- What we send
- Recipient email address and the full body of transactional email — sign-in codes, notifications, and billing notices.
- Purpose
- Transactional email delivery.
- Where it is processed
- United States
Privacy — Resend, opens in a new tab DPA — Resend, opens in a new tab
Artificial intelligence
The group that most needs saying out loud. Conversation content and Contact records leave the platform here.
-
OpenRouter
the single model gatewayAlways active Contact information- What we send
- Every prompt an AI teammate runs: conversation history, the Contact’s record and memory, knowledge-base excerpts, business configuration, and the drafted reply.
- Purpose
- Routes each request to the selected model provider — Anthropic, OpenAI, Google, DeepSeek and others.
- Where it is processed
- United States, plus the upstream provider
Privacy — OpenRouter, opens in a new tab Terms — OpenRouter, opens in a new tab
-
Deepgram
When enabled Contact information- What we send
- Live audio from phone calls and from dictation in the app.
- Purpose
- Real-time speech recognition, and batch transcription when selected.
- Where it is processed
- United States
-
ElevenLabs
When enabled Contact information- What we send
- Live and recorded call audio.
- Purpose
- Real-time speech recognition and batch transcription.
- Where it is processed
- United States
-
Cartesia
When enabled Contact information- What we send
- The words the AI teammate is about to speak — which can name the Contact and quote their details.
- Purpose
- Text-to-speech for the teammate’s voice.
- Where it is processed
- United States
-
OpenAI
When enabled Contact information- What we send
- Recorded call audio files.
- Purpose
- Batch transcription, when chosen as the transcription provider.
- Where it is processed
- United States
Privacy — OpenAI, opens in a new tab DPA — OpenAI, opens in a new tab
-
Google Cloud
Vertex AI · GeminiWhen enabled Contact information- What we send
- Recorded call audio files.
- Purpose
- Batch transcription, when chosen as the transcription provider.
- Where it is processed
- United States
Privacy — Google Cloud, opens in a new tab DPA — Google Cloud, opens in a new tab
Business services and enrichment
Billing, scheduling, research, and the location lookup behind a new lead.
-
Stripe
Always active Account information only- What we send
- Billing name, email address, and payment details, entered directly into Stripe. Loquent never receives or stores a card number.
- Purpose
- Subscriptions, credit packs, and invoicing.
- Where it is processed
- United States
Privacy — Stripe, opens in a new tab DPA — Stripe, opens in a new tab
-
Google Calendar
When enabled Contact information- What we send
- Appointment title, time, and the attendee’s name and email address.
- Purpose
- Booking appointments on the Leader’s calendar.
- Where it is processed
- United States
-
Tavily
When enabled No personal information- What we send
- Search queries and the public URLs to fetch — typically the Leader’s own website during onboarding. No Contact information by design.
- Purpose
- Web search, extraction, and site crawling for research and onboarding.
- Where it is processed
- United States
-
ipregistry
default providerWhen enabled Contact information- What we send
- The IP address of a visitor to a Loquent-hosted page or web chat.
- Purpose
- Approximate location and network context for a new lead.
- Where it is processed
- European Union and global
-
ip-api.com
fallback providerWhen enabled Contact information- What we send
- The same visitor IP address, when the primary provider is unavailable.
- Purpose
- Approximate location and network context for a new lead.
- Where it is processed
- European Union
Telemetry, mobile, and this website
How we find crashes, understand which features get used, and deliver a notification to a phone.
-
Sentry
Always active Account information only- What we send
- Error reports: stack traces, the member and organization identifier, request context.
- Purpose
- Crash and error monitoring.
- Where it is processed
- United States
-
PostHog
Always active Account information only- What we send
- Product usage events: the signed-in member’s identifier, organization identifier, pages viewed, and platform.
- Purpose
- Product analytics.
- Where it is processed
- United States or European Union
-
Google Firebase
Cloud MessagingWhen enabled Contact information- What we send
- The device push token and the notification title and body — which can quote a Contact’s name or message.
- Purpose
- Push notifications to Android devices.
- Where it is processed
- United States
-
Apple
Push Notification serviceWhen enabled Contact information- What we send
- The device push token and the notification title and body.
- Purpose
- Push notifications to iOS devices.
- Where it is processed
- United States
-
Google Analytics 4
loquent.io onlyWhen enabled No personal information- What we send
- Page views, session and device information, and approximate location — only after a visitor accepts analytics cookies.
- Purpose
- Marketing-website analytics.
- Where it is processed
- United States
Tools a Leader connects themselves
Loquent lets a Leader connect their own tool servers so an AI teammate can do more — look something up in another system, write to a spreadsheet, start a job. Whatever that tool call carries, which can include a Contact’s name, an order, or an address, goes to a third party that we do not control, have not reviewed, and cannot list here in advance.
That choice belongs to the Leader who makes the connection, and so does responsibility for it. Before connecting a tool, check what it does with what you send it.
How we announce a change
We publish a new subprocessor on this page before it starts handling any information, and we date the page when it changes.
Leaders on a signed Data Processing Addendum also receive email notice at least 30 days in advance, and may object during that window. If we cannot resolve an objection, the Leader may terminate the affected service without penalty.
Questions about this list go to hello@loquent.io.