Sub-processors.
The companies that process your organisation's data on Mercury Labs' behalf so that MLX can run: who they are, what each one does, and when it applies.
Last updated: 1 October 2026
What this list covers
A sub-processor is a company Mercury Labs uses to handle the data your organisation puts into MLX: the records your Twin reads, the questions your team asks, the answers, and your members' account details.
Which of them handle your data depends on how your deployment is set up. We agree the model provider and the optional features with you before setup.
Used for every deployment
| Provider | What it does | Data it handles |
|---|---|---|
| Hetzner | Servers, databases, file storage and backups. | Everything your deployment stores: connected records, files, sessions and their backups. |
| Clerk | Sign-in, invitations and organisation membership. | Your members' names, email addresses, sign-in details and roles. |
| Vercel | Hosts this website, and passes sign-in requests and the messages between your Twin and Slack or Microsoft Teams on to MLX's servers. | Those requests and messages, as they pass through. |
| Sentry | Error monitoring for the app and the services behind it. | Error reports. They are technical, but an error message can carry a fragment of the data being handled when the fault happened. |
AI model providers
More than one model provider can be involved in a request: one generates the answer, and others do supporting work. Which ones depends on how your deployment is configured and on the model a member chooses.
| Provider | What it does | Data it handles |
|---|---|---|
| Gemini models, through the Gemini API. On current deployments they answer questions, run tasks and help build your Twin. Where web research is on, Gemini can also search Google for a public question. | The request, and the business information needed for the task. | |
| OpenAI | Reads each request to decide how your Twin should handle it, writes session titles, explains how an answer was reached and transcribes dictated prompts. Its models also help build your Twin, and answer questions where a deployment or a member chooses them. | The request, the business information needed for the task, and dictated audio. |
| Anthropic | Answers questions, and proposes rules and measures for your Twin, where a deployment or a member uses its models. | The request, and the business information needed for the task. |
| Together AI | Answers questions where a member chooses the open model it hosts. | The request, and the business information needed for the task. |
| Modal | Runs Mercury Labs' own models, Venus, where a deployment uses them. | The request, and the business information needed for the task. |
Used only where switched on
| Provider | What it does | Data it handles |
|---|---|---|
| Composio | Connects apps that MLX does not connect to directly, for organisations that add one. | The connection's authorisation, and the requests and results that pass between your Twin and the app. |
| Reducto | Reads PDFs and images so your Twin can use what is in them. | The whole file and its name. |
| Mistral | A second document reader, used only when a request asks for it. | The whole file. |
| Exa | Web research, for organisations that have it switched on. | The search queries your Twin writes and the public addresses it opens. |
| TypeSafe | Typed judgments inside workflows, for organisations that have it set up. | The question and the working state the workflow passes to the judge. |
| PostHog | Product analytics in the web app, where it is switched on. | Page views, errors and screen recordings in which all text and inputs are masked. |
Not on this list
- Systems you connect. Xero, Microsoft 365, Google Workspace, Slack and the other systems your organisation connects are yours. Your organisation chooses them and holds its own agreement with each.
- AI tools you use your Twin from. ChatGPT, Claude, Gemini and Microsoft 365 Copilot handle those conversations under your organisation's own agreement with each.
- This website. The privacy policy covers the information this site collects.
Where data is processed
- Servers, databases, files and backups are held with Hetzner in Germany, unless we have agreed another region with you.
- PostHog stores analytics on its service in the European Union.
- The other providers process data on their own infrastructure, which may be outside the United Kingdom and the European Union.
Changes
We update this page when a provider is added, replaced or removed, and change the date at the top.
Questions
Email privacy@mlx.systems to ask about a provider, or which of these apply to your deployment.