Subprocessors
The outside companies that process customer data for Kyub, what they receive, and why.
Updated . This list is a draft; legal review is pending and it may change before it is final.
AI provider
AI features are off until a company admin turns them on, and any project can turn them off for its own data. Kyub calls the AI provider under Kyub's own account.
Anthropic
AI provider- Purpose
- Runs Chief (explanations, bid review, commands, chat, the morning brief), reading of vendor quotes, and AI plan reading in Takeoff.
- Data received
- Plan page images and text, project facts (quantities, estimate lines and totals), and quote documents you ask Kyub to read.
- When
- Only when your company has AI features turned on and the project has not turned AI off. With AI off, nothing is sent.
- Region
- Not documented
- Retention
- Not used to train AI models under Anthropic’s commercial terms. Standard API inputs and outputs are deleted within 30 days (confirmed September 28, 2026). Zero data retention applies where arranged by agreement.
- Terms
- privacy.claude.com
Infrastructure
The services Kyub runs on for every customer.
Neon
Database- Purpose
- Stores Kyub’s application data.
- Data received
- All account and project data: users, companies, takeoffs, quantities, estimates, and settings.
- Region
- United States (AWS us-east-1)
- Retention
- Not documented
Railway
API and background worker hosting- Purpose
- Runs Kyub’s API and the worker that processes plan sets.
- Data received
- Project data and uploaded files while they are processed.
- Region
- Not documented
- Retention
- Not documented
Vercel
Web hosting- Purpose
- Serves the Kyub web app and kyub.ai.
- Data received
- Page requests, including IP address and browser details.
- Region
- Not documented
- Retention
- Not documented
Cloudflare (R2)
File storage and access-log archive- Purpose
- Stores uploaded files, and keeps Kyub’s access logs for one year as a security and legal record.
- Data received
- Plan sets, drawings, signatures, and other files you upload. Access logs: the time, the kind of request (never record contents, query strings or files), its status and duration, the company and internal user id, the IP address and the browser’s user agent.
- Region
- Not documented
- Retention
- Access logs: 1 year, write-once (they cannot be changed or deleted during that year), then deleted.
WorkOS
Sign-in- Purpose
- Authenticates users.
- Data received
- Names, email addresses, and sign-in events.
- Region
- Not documented
- Retention
- Not documented
Better Stack
Uptime monitoring, error tracking and access logs- Purpose
- Alerts Kyub when something breaks, and keeps a security record of who used Kyub, when and from where.
- Data received
- Errors: error details with the company id; request bodies, cookies, sign-in details and user identity are removed before sending. Access logs: the time, the kind of request (never record contents, query strings or files), its status and duration, the company and internal user id, the IP address and the browser’s user agent.
- Region
- United States
- Retention
- 90 days (error tracking); 3 days (access logs, for live search; the 1-year record is kept in Kyub’s own storage)
Resend
Email delivery- Purpose
- Sends invitations, bid invitations, and notifications.
- Data received
- Recipient email addresses and the email content.
- Region
- Not documented
- Retention
- Not documented
Used by specific features
These receive data only when you use the feature named.
Mapbox
Address search and maps- Purpose
- Suggests addresses and shows map locations as you type or place a pin.
- Data received
- The address text you type and map locations.
- When
- Only on address and map fields.
- Region
- Not documented
- Retention
- Not documented
CloudConvert
CAD file conversion- Purpose
- Converts DWG drawings so Takeoff can read them.
- Data received
- The DWG files you upload for conversion.
- When
- Only when a DWG file is converted.
- Region
- Not documented
- Retention
- Not documented
Tomorrow.io
Weather forecasts- Purpose
- Provides forecasts for Operations projects.
- Data received
- Project coordinates.
- When
- Only for Operations projects with a location.
- Region
- Not documented
- Retention
- Not documented
Modal
Plan-detection model hosting- Purpose
- Runs Kyub’s own plan-detection models.
- Data received
- Plan page images.
- When
- Only when Kyub’s plan-detection models are enabled.
- Region
- Not documented
- Retention
- Not documented