Version: v1.3 Streamlined
Operator: Bobby Built Ventures LLC d/b/a QuillCaddie
Applies to: All users and customers who want to understand the third-party providers QuillCaddie may use to operate the Service.
Quick summary
QuillCaddie uses third-party providers for hosting, database, storage, authentication, billing, email, support, analytics, transcription, AI processing, security, and customer-enabled integrations. We try to use providers in ways that match our privacy, no-training, retention, and security commitments. Not every provider is used for every user, plan, workspace, region, or feature.
1. What this page covers
A subprocessor is a third party that helps QuillCaddie process user or customer data to provide the Service. A customer-enabled integration is a third-party service that a user or workspace admin connects or chooses to send data to, such as GitHub, Linear, Slack, Google Drive, Notion, or an external AI client.
This page is informational and works together with the Privacy Policy, AI and Data Use Policy, DPA, Security Policy, Business Terms, and Integrations and Connected Tools Policy.
2. Core infrastructure and operations providers
QuillCaddie may use the following types of providers:
| Provider / category | Purpose | Data categories |
|---|---|---|
| Vercel | Website/application hosting, serverless or edge runtime, deployment, operational logs | Account data, request metadata, usage and operational metadata, limited content only where technically necessary |
| Supabase | Authentication, Postgres database, row-level security, storage, backend services | Account data, workspace data, captures, assets, transcripts, AI outputs, metadata |
| Stripe | Payment processing, subscriptions, invoices, taxes, billing portal | Billing contact details, payment metadata, invoices, subscription status; QuillCaddie does not store full card numbers |
| Email and support providers | Transactional email, account notices, support communications | Contact details, support message content, message metadata |
| Analytics and observability providers | Product analytics, reliability, performance, error monitoring | Content-free usage, performance, and sanitized error metadata where feasible |
| Security and abuse-prevention providers | Security monitoring, spam/abuse prevention, incident response | Account, device, network, event, and security metadata |
3. AI and transcription providers
QuillCaddie may route AI and transcription work through different providers based on feature, plan, workspace settings, reliability, cost, privacy controls, region, and customer configuration.
| Provider | Possible purpose | Notes |
|---|---|---|
| Deepgram | Audio transcription and diarization where enabled | Intended transcription route when configured for a workspace or feature |
| OpenAI | AI output generation, transcript processing, or transcription fallback where configured | Used according to routing and data-use settings |
| Anthropic | AI output generation where configured | Used according to routing and data-use settings |
| AssemblyAI | Transcription comparison, fallback, or optional routing where configured | May be used for supported transcription workflows |
| Google AI / Gemini / Speech services | AI, vision, or transcription where configured | Used only where enabled for the relevant feature or workspace |
| Vercel AI Gateway or similar routing layer | AI routing, failover, observability, or provider abstraction | Used only if enabled in the app architecture or workspace settings |
QuillCaddie configures provider accounts to avoid provider model-improvement use of Customer Content where QuillCaddie controls that setting. Customer-managed providers and BYOK are governed by the customer’s provider account settings, contract, and choices.
4. Customer-enabled integrations
When a user or workspace administrator connects a third-party service, that service may receive the content the user or workspace chooses to send or authorize. Examples include:
| Provider / surface | Typical purpose |
|---|---|
| GitHub | Create issues, link repositories, attach selected generated artifacts, or use selected repository context where enabled |
| Linear | Create issues/project drafts or link external items |
| Slack | Post selected summaries or artifacts to channels or direct messages |
| Google Drive | Export Markdown/ZIP files or use selected files as context where enabled |
| Notion | Export selected pages, summaries, or generated artifacts |
| Jira / Confluence / Microsoft Teams / SharePoint / OneDrive | Business or enterprise integrations where enabled |
| MCP host clients, AI clients, and local agents | Search, get, export, or use selected QuillCaddie content through scoped tools where enabled |
Third-party services are governed by their own terms and privacy policies. QuillCaddie does not control their data handling after a user or workspace sends content to them.
5. Google API Services Limited Use
Where QuillCaddie accesses Google user data through Google APIs, QuillCaddie uses that data only to provide or improve user-facing features that are visible in the application, such as exporting to Google Drive or using selected Google Drive files as user-authorized context. QuillCaddie does not use Google user data for advertising, sale, unrelated purposes, or generalized AI/ML model training.
6. Provider changes
We may add, remove, or replace providers as the Service evolves. We update this page when material providers change. Business customers with signed agreements may receive additional notice, objection, or termination rights if their agreement provides them.
7. Data location and transfers
Providers may process data in the United States and other countries where they operate. Where required, QuillCaddie uses appropriate transfer mechanisms and contractual safeguards.
8. Business and enterprise controls
Business and enterprise workspaces may receive additional controls such as provider allowlists/blocklists, BYOK or customer-managed providers, region settings, admin approval for connectors, audit logs, or contractual subprocessor notice rights. Availability depends on plan, workspace settings, and signed agreements.
Contact
Support: support@quillcaddie.com
Privacy requests: privacy@quillcaddie.com
Security reports: security@quillcaddie.com
Legal notices: legal@quillcaddie.com
DMCA notices: dmca@quillcaddie.com
Mail: Bobby Built Ventures LLC d/b/a QuillCaddie, 1500 N Grand St, STE R, Denver, CO 80203