Skip to content
Discuss your first workflow
Legal

Sub-processors.

The companies that process your organisation's data on Mercury Labs' behalf so that MLX can run: who they are, what each one does, and when it applies.

Last updated: 1 October 2026

What this list covers

A sub-processor is a company Mercury Labs uses to handle the data your organisation puts into MLX: the records your Twin reads, the questions your team asks, the answers, and your members' account details.

Which of them handle your data depends on how your deployment is set up. We agree the model provider and the optional features with you before setup.

Used for every deployment

ProviderWhat it doesData it handles
HetznerServers, databases, file storage and backups.Everything your deployment stores: connected records, files, sessions and their backups.
ClerkSign-in, invitations and organisation membership.Your members' names, email addresses, sign-in details and roles.
VercelHosts this website, and passes sign-in requests and the messages between your Twin and Slack or Microsoft Teams on to MLX's servers.Those requests and messages, as they pass through.
SentryError monitoring for the app and the services behind it.Error reports. They are technical, but an error message can carry a fragment of the data being handled when the fault happened.

AI model providers

More than one model provider can be involved in a request: one generates the answer, and others do supporting work. Which ones depends on how your deployment is configured and on the model a member chooses.

ProviderWhat it doesData it handles
GoogleGemini models, through the Gemini API. On current deployments they answer questions, run tasks and help build your Twin. Where web research is on, Gemini can also search Google for a public question.The request, and the business information needed for the task.
OpenAIReads each request to decide how your Twin should handle it, writes session titles, explains how an answer was reached and transcribes dictated prompts. Its models also help build your Twin, and answer questions where a deployment or a member chooses them.The request, the business information needed for the task, and dictated audio.
AnthropicAnswers questions, and proposes rules and measures for your Twin, where a deployment or a member uses its models.The request, and the business information needed for the task.
Together AIAnswers questions where a member chooses the open model it hosts.The request, and the business information needed for the task.
ModalRuns Mercury Labs' own models, Venus, where a deployment uses them.The request, and the business information needed for the task.

Used only where switched on

ProviderWhat it doesData it handles
ComposioConnects apps that MLX does not connect to directly, for organisations that add one.The connection's authorisation, and the requests and results that pass between your Twin and the app.
ReductoReads PDFs and images so your Twin can use what is in them.The whole file and its name.
MistralA second document reader, used only when a request asks for it.The whole file.
ExaWeb research, for organisations that have it switched on.The search queries your Twin writes and the public addresses it opens.
TypeSafeTyped judgments inside workflows, for organisations that have it set up.The question and the working state the workflow passes to the judge.
PostHogProduct analytics in the web app, where it is switched on.Page views, errors and screen recordings in which all text and inputs are masked.

Not on this list

  • Systems you connect. Xero, Microsoft 365, Google Workspace, Slack and the other systems your organisation connects are yours. Your organisation chooses them and holds its own agreement with each.
  • AI tools you use your Twin from. ChatGPT, Claude, Gemini and Microsoft 365 Copilot handle those conversations under your organisation's own agreement with each.
  • This website. The privacy policy covers the information this site collects.

Where data is processed

  • Servers, databases, files and backups are held with Hetzner in Germany, unless we have agreed another region with you.
  • PostHog stores analytics on its service in the European Union.
  • The other providers process data on their own infrastructure, which may be outside the United Kingdom and the European Union.

Changes

We update this page when a provider is added, replaced or removed, and change the date at the top.

Questions

Email privacy@mlx.systems to ask about a provider, or which of these apply to your deployment.