Subprocessors

The outside services that can receive data from your SelfConstruct instance — what each one gets, and whether it runs by default or only when you turn a feature on.

Version 2026-08-22 · Last updated September 7, 2026

Because every customer runs an isolated instance, the list that actually applies to you depends on which features and integrations are enabled on your instance. A provider marked "only when enabled" receives nothing until you connect or configure it.

Always active

ProviderPurposeWhat it receivesStatus
Railway
Hosting / compute
Runs your instance and stores its database and uploaded filesAll data you put into SelfConstruct, at rest on your instance's volumeCore
OpenStreetMap (Nominatim)
Geocoding
Turns a job or lead address into map coordinates, which power the maps, weather on daily logs, and time-clock geofencingThe street address you enter on a job or lead. No name, no financial data.Core
OpenStreetMap (tile servers)
Map images
Draws the map itself once coordinates are known — the picture behind the pins on jobs, leads and the land mapOnly the map square being viewed. No address, no name, no financial data; the tile request carries the area of the world on screen, not what you are looking at.Core
Open-Meteo
Weather
Supplies the forecast and the recorded conditions on daily logs, and the weather shown on a jobThe job's coordinates and the date. No address, no name, no financial data.Core
unpkg
Map library, loaded by your browser
Delivers the mapping library (Leaflet) that draws maps in the page. Your browser fetches it directly; your instance never sends anything to it.What any web request carries: your browser's address and version, and the address of the page you are on. None of your company's data.Core
About geocoding: when you save a job or lead that has an address, that address is sent to a geocoding service to look up coordinates: OpenStreetMap's public Nominatim service by default, or a self-hosted geocoder when an instance is configured with one. Each distinct address is looked up once and the coordinates are kept with your company's data, so a repeated address is not sent again; lookups leave one at a time, spaced apart, and a save never waits on them. This happens automatically and has no on/off switch today. If you would rather it didn't, leave the address field empty — the rest of the record works normally, you just won't get map, weather, or geofence features for that job.

Active when configured

These are set up for most instances, but each is independently configurable and inert until a key is present.

ProviderPurposeWhat it receivesStatus
Anthropic
AI features
Powers every AI feature: reading receipts and plans, drafting bids and messages, suggesting transaction categories, and web researchCustomer content you submit to an AI feature — uploaded documents and receipt images, the project or financial details in your question, and the text of your prompts. Only what a given feature sends; AI features you don't use send nothing. On this public website, separately from any instance: a question you type into the site assistant is sent with passages from these public pages, and with the earlier turns of that conversation so a follow-up can be understood. Your IP address is not sent, and neither the question nor the answer is stored.Configurable
Resend
Email delivery
Sends outbound email: client bid links, portal invitations, invoice reminders, lead replies, and encrypted backup copiesRecipient addresses and the content of those emails. Backup emails carry the encrypted backup file as an attachment.Configurable
Cloudflare R2 or Amazon S3
Offsite backup storage
Stores your encrypted offsite backupsEncrypted backup files only. The provider cannot read them — see Security.Configurable
Google (Gmail)
Alternate email transport
Used instead of Resend on instances configured with a Gmail account, and to read the inbox that collects website leads and emailed receiptsThe same outbound email content as Resend, plus the inbound lead and receipt emails it readsConfigurable

Only when you enable the feature

ProviderPurposeWhat it receivesStatus
Intuit (QuickBooks Online)
Accounting sync
Pushes customers and invoices to QuickBooks and reads payments back, if you connect itCustomer names and contact details, invoice numbers, dates, amounts, and descriptions. Nothing is sent unless you connect QuickBooks.Opt-in
Twilio
Text messaging
Sends the automatic text to new website leads and forwards their replies to youLead phone numbers and message contentOpt-in
SerpApi
Product and price lookup
Looks up live retail product listings and prices (Home Depot) for selections and the cost catalogSearch terms — product names and your cost-catalog item names. No customer or financial records.Opt-in
Esri / ArcGIS
County parcel data
Retrieves public county parcel records for Land ProspectingThe county and state you configure. Data flows in from public records; none of your business data goes out.Opt-in
State GIS portals
e.g. gis.colorado.gov
Statewide parcel cross-reference during Land Prospecting scansParcel and county lookup parameters. Inbound public data only.Opt-in
Zippopotam.us · FCC Census Area API
ZIP and county lookup
One-time lookup while setting up a Land Prospecting countyA ZIP code and the coordinates derived from it. Setup only.Opt-in
ElevenLabs
Training narration
Generates spoken narration for training videos when narration text is customized or translatedNarration script text only. No customer, project, or financial data.Opt-in

On this website

The marketing site you're reading is separate from the application. It runs on Cloudflare (hosting and its database for lead forms), and it loads two typefaces from Google Fonts, which means your browser requests those font files from Google and Google receives your IP address and browser type in the process. The site sets no advertising or analytics cookies and runs no third-party analytics scripts. If you submit the walkthrough request form on the homepage, your details are stored to respond to you and emailed to us through Resend.

Changes to this list

We maintain this page as the current, accurate list. When we add a subprocessor that receives customer data, we update this page and note it in the version history below. If you have a written agreement with us that requires advance notice of new subprocessors, that agreement governs.

Version history

Questions about any provider on this list: hello@selfconstruct.app.