Troi — Sub-processor List
Draft pending attorney review. This is a usable draft; confirm the exact vendor legal entity names and processing regions with counsel before publication.
Effective date: 9 July 2026 · Version: Draft 1.0 · Last updated: 9 July 2026
In short
- A sub-processor is a third party that processes personal data to help us run Troi.
- Group A are sub-processors we engage to operate the Service (hosting, payments, messaging, AI). They process data for everyone.
- Group B are services you choose to connect. We only exchange data with them if you connect them, and only to provide that feature.
- We give 30 days' advance notice before adding or replacing a Group A (Troi-operated) sub-processor, so you can object.
- Watch this page for changes, or ask us to notify you at info@kanah.app.
This page lists the third parties that process personal data on behalf of Kanah LLC (operating Troi). It supports our commitments in the Privacy Policy and Data Processing Addendum. "Personal data," "process," and "controller/processor" have the meanings given in the GDPR and equivalent laws.
The EU-specific contracting entities named below apply only if and when an EU processing region is enabled; today the primary region is the United States. Exact entity names and regions should be confirmed with counsel before publication.
Group A — Troi-operated sub-processors
We engage these providers to deliver the Service. They process personal data under a data-processing agreement and, for transfers of EU/UK data, under Standard Contractual Clauses and/or the EU-US Data Privacy Framework (see DPA and the Privacy Policy's international-transfers section).
Infrastructure
| Sub-processor (legal entity) | Purpose | Data categories | Primary region |
|---|---|---|---|
| Microsoft Corporation — Microsoft Azure (EU customers: Microsoft Ireland Operations Limited, if an EU region is enabled) | Cloud hosting, application infrastructure, database and blob storage; Azure Communication Services for transactional email | All personal data categories processed by the Service (account data, user content, sensitive Life data, device/technical data); email address + email content for ACS | United States (EU-region option planned, not yet live) |
| Stripe, Inc. (engaged only once paid plans launch — not while the Service is free; EU customers: Stripe Payments Europe, Ltd.) | Payment processing, billing, and fraud prevention. Card details are handled by Stripe and never touch Troi servers | Billing metadata (plan, status, country), payment/transaction data, email; card data held by Stripe | United States / Ireland |
AI providers — usually your own accounts, not Troi sub-processors
How AI works in Troi matters here. By default, Troi uses your own AI-provider credentials ("bring your own key"): you configure a provider (such as Anthropic or OpenAI) and supply your own API key, and your prompts are sent to your own account with that provider, executed on your own runner. In that mode, the AI provider is your processor under your agreement with them — not a Troi sub-processor — and that provider's own retention/training settings (which you control) govern. Troi acts as a conduit and does not set those terms.
The only time Troi routes AI itself is a temporary launch gateway [[FOUNDER: remove this row once the gateway is disabled — active < 1 week after launch]]: for a brief period after launch, Troi offers a free AI gateway funded by its Microsoft Azure resources (routing to the OpenAI / Azure OpenAI API). Because this runs through Microsoft Azure — already listed above as a sub-processor — and on a no-training basis, it adds no new standing sub-processor relationship. It is switched off shortly after launch, after which AI is bring-your-own-key only and no AI provider is a Troi sub-processor.
| Temporary launch sub-processor | Purpose | Data categories | Primary region |
|---|---|---|---|
| Microsoft Azure — Azure OpenAI / OpenAI API (launch gateway only, < 1 week; then removed) | Free trial AI gateway so users can try AI before adding their own key | Prompt content submitted during the launch window (no-training) | United States |
Group B — User-initiated connections
These services are not engaged by Troi as sub-processors in the ordinary course. Troi exchanges data with them only if you choose to connect your own account, and only to provide the feature you connected them for (for example, importing your calendar or publishing a post you created). When you connect one, you authorize that data exchange, and the third party's own terms and privacy policy also apply.
| Service | Engaged only if you connect it, to |
|---|---|
| Google (Google LLC) | Sign-in, email, calendar, storage/Drive, and YouTube publishing where you connect them |
| Microsoft (Microsoft Corporation) | Sign-in, email, calendar, and storage where you connect them |
| Apple (Apple Inc.) | Sign-in and Apple platform features where you connect them |
| Slack (Slack Technologies, LLC / Salesforce) | Messaging and workspace integration where you connect it |
| Meta / Instagram (Meta Platforms, Inc.) | Publishing content you create to your Instagram / Meta accounts |
| TikTok (TikTok / ByteDance) | Publishing content you create to your TikTok account |
| X (X Corp.) | Publishing content you create to your X account |
| LinkedIn (LinkedIn Corporation / Microsoft) | Publishing content you create to your LinkedIn account |
| YouTube (Google LLC) | Publishing video content you create to your YouTube channel |
| Twilio (Twilio Inc.) | SMS/messaging only if you connect your own Twilio account (e.g. messaging features in an app you build). Troi does not send SMS for its own service and holds no Troi-operated Twilio account. |
Other services you link from within Troi are handled the same way: data flows only if you connect them, and only for the connected feature. (Note: the Reddit-based "App Ideas" scraping feature is disabled; Troi does not scrape Reddit.)
Change notice
We maintain this page as the authoritative list of Troi-operated sub-processors. Before we add or replace a Group A (Troi-operated) sub-processor, we will post the change here and provide at least 30 days' advance notice, so that customers can review and, where they have a legitimate objection, raise it as described in the DPA. To be notified of changes by email, contact info@kanah.app [[FOUNDER: set up a sub-processor change-notification mechanism (subscribe page or email announcement)]].
Changes to Group B are driven by which integrations you choose to connect; connecting or disconnecting a service is under your control in the app.
Questions about this list: info@kanah.app · Kanah LLC, 1603 Capitol Avenue, Suite 413A, #2280, Cheyenne, WY 82001, USA.