Subprocessors
The outside services that can receive data from your SelfConstruct instance — what each one gets, and whether it runs by default or only when you turn a feature on.
Because every customer runs an isolated instance, the list that actually applies to you depends on which features and integrations are enabled on your instance. A provider marked "only when enabled" receives nothing until you connect or configure it.
Always active
| Provider | Purpose | What it receives | Status |
|---|---|---|---|
| Railway | Runs your instance and stores its database and uploaded files | All data you put into SelfConstruct, at rest on your instance's volume | Core |
| OpenStreetMap (Nominatim) | Turns a job or lead address into map coordinates, which power the maps, weather on daily logs, and time-clock geofencing | The street address you enter on a job or lead. No name, no financial data. | Core |
| OpenStreetMap (tile servers) | Draws the map itself once coordinates are known — the picture behind the pins on jobs, leads and the land map | Only the map square being viewed. No address, no name, no financial data; the tile request carries the area of the world on screen, not what you are looking at. | Core |
| Open-Meteo | Supplies the forecast and the recorded conditions on daily logs, and the weather shown on a job | The job's coordinates and the date. No address, no name, no financial data. | Core |
| unpkg | Delivers the mapping library (Leaflet) that draws maps in the page. Your browser fetches it directly; your instance never sends anything to it. | What any web request carries: your browser's address and version, and the address of the page you are on. None of your company's data. | Core |
Active when configured
These are set up for most instances, but each is independently configurable and inert until a key is present.
| Provider | Purpose | What it receives | Status |
|---|---|---|---|
| Anthropic | Powers every AI feature: reading receipts and plans, drafting bids and messages, suggesting transaction categories, and web research | Customer content you submit to an AI feature — uploaded documents and receipt images, the project or financial details in your question, and the text of your prompts. Only what a given feature sends; AI features you don't use send nothing. On this public website, separately from any instance: a question you type into the site assistant is sent with passages from these public pages, and with the earlier turns of that conversation so a follow-up can be understood. Your IP address is not sent, and neither the question nor the answer is stored. | Configurable |
| Resend | Sends outbound email: client bid links, portal invitations, invoice reminders, lead replies, and encrypted backup copies | Recipient addresses and the content of those emails. Backup emails carry the encrypted backup file as an attachment. | Configurable |
| Cloudflare R2 or Amazon S3 | Stores your encrypted offsite backups | Encrypted backup files only. The provider cannot read them — see Security. | Configurable |
| Google (Gmail) | Used instead of Resend on instances configured with a Gmail account, and to read the inbox that collects website leads and emailed receipts | The same outbound email content as Resend, plus the inbound lead and receipt emails it reads | Configurable |
Only when you enable the feature
| Provider | Purpose | What it receives | Status |
|---|---|---|---|
| Intuit (QuickBooks Online) | Pushes customers and invoices to QuickBooks and reads payments back, if you connect it | Customer names and contact details, invoice numbers, dates, amounts, and descriptions. Nothing is sent unless you connect QuickBooks. | Opt-in |
| Twilio | Sends the automatic text to new website leads and forwards their replies to you | Lead phone numbers and message content | Opt-in |
| SerpApi | Looks up live retail product listings and prices (Home Depot) for selections and the cost catalog | Search terms — product names and your cost-catalog item names. No customer or financial records. | Opt-in |
| Esri / ArcGIS | Retrieves public county parcel records for Land Prospecting | The county and state you configure. Data flows in from public records; none of your business data goes out. | Opt-in |
| State GIS portals | Statewide parcel cross-reference during Land Prospecting scans | Parcel and county lookup parameters. Inbound public data only. | Opt-in |
| Zippopotam.us · FCC Census Area API | One-time lookup while setting up a Land Prospecting county | A ZIP code and the coordinates derived from it. Setup only. | Opt-in |
| ElevenLabs | Generates spoken narration for training videos when narration text is customized or translated | Narration script text only. No customer, project, or financial data. | Opt-in |
On this website
The marketing site you're reading is separate from the application. It runs on Cloudflare (hosting and its database for lead forms), and it loads two typefaces from Google Fonts, which means your browser requests those font files from Google and Google receives your IP address and browser type in the process. The site sets no advertising or analytics cookies and runs no third-party analytics scripts. If you submit the walkthrough request form on the homepage, your details are stored to respond to you and emailed to us through Resend.
Changes to this list
We maintain this page as the current, accurate list. When we add a subprocessor that receives customer data, we update this page and note it in the version history below. If you have a written agreement with us that requires advance notice of new subprocessors, that agreement governs.
Version history
- 2026-08-22 — First complete published list, compiled by auditing the application's actual outbound calls. Adds Intuit/QuickBooks, Google/Gmail transport, Twilio, Esri/ArcGIS, state GIS portals, OpenStreetMap geocoding, and the ZIP/county lookup services, which were not itemized in the previous version. Corrects the description of SerpApi, which was labeled "web research" but performs product and price lookup; web research is performed by Anthropic.
- 2026-09-07 — Adds the public website assistant. Anthropic already appeared on this list for in-product AI features; this notes the separate flow in which a question typed into the assistant on this marketing site is sent for an answer. No new provider was added.
- 2026-09-12 — Geocoding: the endpoint is now configurable per instance (public OpenStreetMap by default, a self-hosted geocoder when set), each distinct address is looked up once and cached with the company's data, and lookups are paced one at a time. Same data sent, fewer times.
Questions about any provider on this list: hello@selfconstruct.app.