Skip to content
  • Docs
  • Pricing
  • FAQ
Run Free Audit Log In

Subprocessors

This page summarizes the third-party providers repod uses or may use to provide, secure, operate, bill, email, and improve the service.

Data Demon does not sell customer data. Subprocessors receive only the information needed for their service category. GitHub is normally the customer-selected source platform for the customer GitHub organisation and is not treated as Data Demon's subprocessor for that customer-controlled environment.

Current Provider Register

Provider Purpose Data categories Location / transfer basis
Amazon Web Services (AWS) Application hosting, infrastructure, networking, operational storage, database/Redis hosting where deployed on AWS, backups, and service availability. Account data, GitHub metadata, encrypted credential records, audit records, logs, and operational telemetry needed to run repod. UK/EU and other AWS regions as configured. Restricted transfers rely on AWS data processing terms, UK Addendum/SCCs or other lawful safeguards where required.
Stripe Hosted checkout, subscription management, invoicing metadata, tax ID collection, and payment processing. Billing contact details, customer identifiers, plan/subscription metadata, tax IDs, payment status, and invoice/payment information. repod does not store full card details. United Kingdom, EEA, United States, and other Stripe processing locations. Stripe may act as an independent controller for some regulated payment activity.
Namecheap Private Email / configured SMTP provider Transactional email delivery, including verification, password reset, invites, service notifications, and support communications where email delivery is enabled. Email addresses, message metadata, transactional message content, and delivery status. Provider processing locations depend on the configured mailbox/SMTP service. Restricted transfers require appropriate provider data terms or safeguards.
Google Analytics 4 Optional website and product analytics on non-sensitive pages after analytics consent. Pseudonymous analytics identifiers, page/event metadata, coarse device/source data, and consent-state metadata. repod does not send email addresses, PATs, repository names, team names, or org names to GA4. Google processing locations including the United States. Restricted transfers rely on Google data processing terms and applicable safeguards where required.

Provider Changes

Data Demon may add or replace subprocessors as repod evolves. For material changes affecting customer processor data, Data Demon will update this page and, where reasonably practicable, provide in-app notice or email notice before the new subprocessor materially processes customer personal data. Customers may object on reasonable data-protection grounds by contacting support@repod.dev.

Data Shared

Plaintext GitHub PATs, GitHub App private keys, and installation tokens are not intentionally shared with analytics providers, billing providers, or email providers. Repository source files, repository contents, commit diffs, issue or pull-request body text, Actions logs, and build artifacts are not part of repod's normal customer-data set.

Current List

For processor terms, review the Data Processing Addendum. For deployment-specific subprocessor questions, contact support@repod.dev.

© 2026 Data Demon Systems Limited. repod.dev is a business SaaS product for GitHub access operations.
Docs Pricing Contact Terms DPA Privacy Cookies Subprocessors Security Vulnerability Disclosure Data Demon Systems LinkedIn

Data Demon Systems Limited is registered in England and Wales with company number 16158110.

Help improve repod Allow session analytics so we can understand which workflows are useful. Optional analytics begins only after consent in production. Sensitive GitHub data is never sent. Privacy details