Last updated8 September 2026
Subprocessors
The register lists Citerra's providers, the data each receives and where it operates. Later sections explain what providers do not receive, custom model endpoints and changes to the register. A final section names the governing language.
§ 1
Current subprocessors
Each provider below handles one slice of the data, and nothing beyond it.
| Provider | What it receives | Where |
|---|---|---|
| Convex | Application database and generated artifacts. | EU (Ireland) |
| Resend | Email addresses on the waitlist and the newsletter, and the content of the messages Citerra sends to them. | EU (Ireland) for delivery; provider is US-based |
| Clerk | Sign-in identity: email address, name, and organization membership. | United States |
| UploadThing | Uploaded PDF and image files. | United States |
| Fly.io | LaTeX sources during compilation, deleted after each job. | EU (Frankfurt) |
| OpenAI | Text excerpts sent for AI assistance and search indexing. The provider's API terms exclude this content from training. | United States |
| Vercel | Requests to citerra.de and the application, and their server logs. | Global edge, EU region for server rendering |
| Sentry | Error reports with personal data removed. | EU |
§ 2
What they do not receive
No provider on this list receives your library in full. When the assistant answers a question, Citerra sends only the passages relevant to that question to the model provider. The rest of the document stays in Citerra.
Citerra queries public indexes: OpenAlex, arXiv, Europe PMC, and Crossref. Searching the literature sends them the search terms, and importing a source by DOI sends them that identifier. These receive the query, never the document. They are public research indexes rather than subprocessors, because they process no personal data on Citerra's behalf.
§ 3
Your own model endpoint
An organization can point Citerra at its own model endpoint, in which case the assistant's answers are generated there instead of at OpenAI. Indexing a source and retrieving from it still reach OpenAI.
The API key for that endpoint is stored in Convex, readable only through an internal function, sent only to your own endpoint, and never logged. Deleting the override deletes the key.
§ 4
Changes to this list
Citerra updates this register when an integration is added or removed. Organizations with a data processing agreement in place are notified before a new subprocessor begins processing.
§ 5
Governing language
This register is published in English and in German, and both versions list the same providers.
The English version governs until counsel has reviewed both texts. Where the two differ before that review, the English wording applies.