Skip to main content
Bower uses the following third-party services (“sub-processors”) to operate the platform. Almost all of them process data on our behalf under a Data Processing Agreement (DPA). Where an agreement is not yet in place, we say so on the entry rather than leaving you to assume. See Tiptap under Document conversion and Mintlify under Documentation and help search. We will update this page whenever we add or remove a sub-processor. This page covers services that process data inside Bower. Cookies and tags on our marketing website (bowerlabs.ai) are a separate matter and are listed in the cookie policy, which is also where you change a consent choice.

How our DPAs work

For most providers, the DPA is incorporated by reference into the vendor’s commercial terms: when we accept those terms to use the service, the DPA’s data-protection obligations (including GDPR Standard Contractual Clauses for international transfers, UK/Swiss equivalents, and CCPA/CPRA) apply automatically, with no separate signature required. Where a provider offers a separately executed DPA, we link it next to the service below. Separately, HIPAA protections require a signed Business Associate Agreement (BAA). Bower acts as a Business Associate, not a Covered Entity. Only providers with a signed BAA (currently Google Cloud and Google Workspace) may process data for workspaces in Restricted mode; every other provider on this page is blocked server-side for those workspaces.

Infrastructure & hosting

AI processing

When you use AI features (Bower chat, voice transcription, photo text extraction, document processing), your content is sent to one of these providers to produce a result. Bower does not use your identifiable content to train AI models, and these providers are contractually barred from training on it or retaining it for human review. Those are two separate commitments; see AI & your data. Voice transcription runs entirely on Google. Gemini on Vertex AI handles it by default, and if that call fails Bower retries automatically on Google Cloud Speech-to-Text. Both are covered by our Google Cloud BAA, so transcription stays inside the same boundary for every workspace, Restricted mode or not. Removed 2 September 2026, OpenAI. OpenAI (gpt-4o-transcribe) was previously listed here as a voice-transcription fallback for workspaces not in Restricted mode. It has been retired: Bower no longer has a model route, a network route, or configured credentials for OpenAI, and no audio or transcript is sent to it. With it gone, every AI provider Bower sends your content to is covered by our Google Cloud BAA.

Document conversion

Google Workspace is covered by a separate signed BAA (executed July 2026), distinct from the Google Cloud BAA. Legacy .doc conversion is not routed through the Restricted-mode egress gate, so this row is the record that the sub-processor handling it is BAA-covered. Word imports in Restricted-mode workspaces never reach Tiptap; Bower converts those files itself, and embedded images are not imported. This is enforced server-side. See HIPAA compliance for the full list of what changes in Restricted mode. Agreement status: Bower does not currently have a signed DPA or BAA with Tiptap. That is why Word imports are converted locally for Restricted-mode workspaces, and why no PHI workspace’s document content reaches them. If you need a DPA to be in place before using Word import on a non-Restricted workspace, contact us. You can also enable Restricted mode to keep document conversion entirely inside Bower.

Integrations & identity

When you connect external services to Bower (either letting Bower search your other tools, or letting an external AI client read your Bower workspace), these providers process the OAuth tokens that broker that access. Bower never stores the underlying access tokens itself. Connectors and external AI access are not yet available in Restricted-mode workspaces; neither provider’s BAA is signed yet. Both surfaces are blocked server-side for Restricted-mode workspaces until that’s in place. Restricted-mode workspaces never send help-search queries to Mintlify. Bower blocks the external documentation lookup server-side and instead directs you to browse the public help center without copying workspace content. Agreement status: Bower does not currently have a signed DPA or BAA with Mintlify. The help center itself contains public Bower documentation. Bower-generated help-search queries are sent to Mintlify only from non-Restricted workspaces.

Payment processing

Bower uses Stripe for all payment processing. Card numbers, CVCs, and full payment details are handled entirely by Stripe’s hosted Checkout and Customer Portal surfaces; they never touch Bower servers. Bower’s systems only see opaque Stripe IDs (cus_…, sub_…) and transaction amounts. Stripe is PCI-DSS Level 1 certified; Bower’s integration is PCI SAQ-A (the lowest-scope form). The Stripe Data Processing Agreement applies automatically to our use of the service under Australian, EU (GDPR), and UK (UK-GDPR) data-protection law, so no manual signature is required; acceptance is deemed by use of the Stripe platform.

Analytics & observability

Langfuse agreement status: Langfuse is part of ClickHouse. Two instruments apply. The ClickHouse Data Processing Addendum, which names Langfuse Cloud, applies by incorporation into the commercial terms with no separate signature, and ClickHouse’s own sub-processors apply downstream of it. Separately, a Business Associate Agreement was signed on 14 September 2026. It covers Langfuse’s dedicated HIPAA region in Oregon, which is where Bower’s data now lives; it does not extend to any other region. This is a change from our previous position. Until September 2026 there was no BAA, Bower used the EU region, and Restricted-mode workspaces were blocked from this service entirely rather than covered by an agreement. They are now covered by it, and AI quality monitoring operates in those workspaces on the same terms as everywhere else. Records held there contain unscrubbed request and response text and are deleted after 365 days under a retention policy we configure and the service enforces. See AI and your data. Google Cloud Trace is covered by the Google Cloud BAA and is available to Restricted-mode workspaces.

Research and literature lookups

When you ask Bower to find papers, resolve a DOI, or look up an author, it queries public scholarly APIs. When you ask about a specific gene, protein, compound, or structure, it queries public biology databases. Each receives the search query Bower generates from your request. These are public scholarly registries and biology databases handling public identifiers and search queries, not personal or research content, so no DPA or BAA is required. Restricted-mode workspaces never reach any of them: a fail-closed check runs before any request leaves Bower, and if it cannot confirm the workspace is allowed to contact public research services, nothing is sent. The Public sources switch in the chat composer blocks all twelve as well, for every message you send while it’s off.

Data residency

All primary data (database, files, backups) is stored in Google Cloud’s us-central1 region (Iowa, USA). AI processing may occur in the provider’s default region as listed above.

Changes to this list

We review our sub-processor list quarterly. If we add a new sub-processor that processes personal data, we will update this page. Material changes will be communicated via email to workspace owners. Last reviewed: 7 September 2026

Questions

Contact our Data Protection Officer at [email protected].