Google Cloud Platform
Current registry · verify detailsPurpose: Application hosting, storage, loggingData category: All customer data at rest + in transitLocation: United States (us-central1)DPA: Current Google terms apply; XESO account and DPA evidence review remains openCertifications: See the provider trust centre; this is not an XESO certificationCurrent production infrastructure. Network claims remain evidence-gated.Cloud SQL for PostgreSQL
Current registry · verify detailsPurpose: Primary application databaseData category: Notes, folders, auth metadata, PIILocation: United States (inherits GCP region)DPA: Covered by the applicable Google Cloud terms; account evidence review remains openCertifications: See the Google Cloud trust centre; this is not an XESO certificationCurrent production database. Backup and network claims remain evidence-gated.Google Gemini (Generative Language API)
Current registry · verify detailsPurpose: LLM inference for chat, summaries, classificationData category: Prompt text + completions. We do not send identifiers by default.Location: Google-managed; processing location is not represented as region-fixedDPA: Current API terms reviewed; production account binding awaits attestationCertifications: Service tier and active-billing status must be deployment-attestedXESO does not use customer content for model training or evaluation. Provider handling follows the active API project's terms; no zero-retention claim is made.Provider data-use terms: Gemini API paid-services data-use termsGoogle Workspace APIs
Current registry · verify detailsPurpose: User-directed Drive, Gmail, and Calendar connectionsData category: Selected files, email content, calendar events, account identity, and OAuth metadataLocation: Google-managed; no XESO region-fixed representationDPA: User-authorized connector under the applicable Google account and API termsCertifications: See the Google trust centre; this is not an XESO certificationOAuth scopes are limited by connector and access occurs only after the user connects it.On disconnect: Disconnect deletes XESO's OAuth credential. Notes already imported remain until the user deletes them; Calendar must be reconnected for future access.Microsoft Graph
Current registry · verify detailsPurpose: Optional user-directed Microsoft calendar connectionData category: Calendar events, account identity, and OAuth metadataLocation: Per the user's Microsoft account and tenantDPA: User-authorized connector under the applicable Microsoft account termsCertifications: See the Microsoft trust centre; this is not an XESO certificationOn disconnect: Disconnect deletes XESO's OAuth credential. Previously stored calendar records follow the account deletion and export lifecycle.Tavily
Current registry · verify detailsPurpose: Web search for user-requested research answersData category: Search query and returned public-web resultsLocation: Provider-managedDPA: Current production integration; contract and transfer evidence remain under reviewCertifications: See the Tavily provider terms; this is not an XESO certificationServing revision check on 2026-09-04 found TAVILY_API_KEY bound by secret reference. Tavily's current terms permit use of customer input to improve its services, so XESO does not present Tavily as carrying a no-training guarantee.Provider data-use terms: Tavily platform data-use termsCloudflare Turnstile
Current registry · verify detailsPurpose: Automated-abuse protection on authenticationData category: Browser, network, challenge, and verification metadataLocation: Cloudflare-managedDPA: Current login protection; contractual evidence remains under reviewCertifications: See the Cloudflare trust centre; this is not an XESO certificationThe server credential is being migrated from plaintext runtime configuration to Secret Manager.FingerprintJS
Current registry · verify detailsPurpose: Configuration-dependent fraud and abuse signalsData category: Browser and device signal metadataLocation: Provider-managedDPA: Optional; do not enable without current contract and privacy evidenceCertifications: See the provider trust centre; this is not an XESO certificationUpstash / QStash
Current registry · verify detailsPurpose: Configuration-dependent queue deliveryData category: Task route, signed delivery metadata, and bounded job payloadLocation: Provider-managedDPA: Optional; no serving QSTASH_TOKEN was present on 2026-09-04Certifications: See the provider trust centre; this is not an XESO certificationZoho CRM
Current registry · verify detailsPurpose: Optional user-directed CRM import and synchronizationData category: Selected CRM contacts, deals, fields, attachments, and OAuth metadataLocation: Per the user's selected Zoho data centreDPA: The customer/controller must have a lawful basis to import CRM personal data; XESO acts only on the user's authorized requestCertifications: See the Zoho trust centre; this is not an XESO certificationServing revision check on 2026-09-04 found the connector credentials bound by secret reference.On disconnect: Disconnect removes the connection and OAuth credential. Notes already imported remain in the Library until the user deletes them.Granola and Readwise
Current registry · verify detailsPurpose: Optional user-directed import from connected knowledge servicesData category: Selected meeting notes, highlights, source links, and connector credentialsLocation: Provider-managedDPA: User-authorized source access; provider contract and transfer evidence remain under reviewCertifications: See each provider's terms; this is not an XESO certificationOn disconnect: Disconnect removes the connector credential. Content already imported remains until the user deletes it.YouTube, X/Twitter mirrors, and Wikimedia
Current registry · verify detailsPurpose: User-requested retrieval of public source materialData category: Submitted public URL, network metadata, and returned public contentLocation: Provider-managedDPA: External content sources, not represented as contracted XESO subprocessorsCertifications: No XESO certification claimRequests may reach YouTube, X/Twitter syndication or mirror services, and Wikipedia/Wikimedia only when a user asks XESO to import or retrieve that source.Groq
Current registry · verify detailsPurpose: Optional audio transcription fallback when GROQ_API_KEY is configuredData category: Audio chunks and transcripts for user-requested media importsLocation: United StatesDPA: Pending - do not enable in production without DPACertifications: Vendor review required before production enablementCode path is gated by GROQ_API_KEY; leave unset unless legal approval is complete.Provider data-use terms: Groq customer-data and model-training termsOpenAI
Current registry · verify detailsPurpose: Optional BYOK LLM inference when a user supplies their own OpenAI keyData category: User query + retrieved snippets for BYOK requestsLocation: Per OpenAI API regionDPA: User-elected provider termsCertifications: User-selected provider; account terms varyThe serving revision had no platform OPENAI_API_KEY on 2026-09-04. OpenAI is used only when a user configures their own provider key; platform TTS/transcription therefore remains unavailable.On disconnect: Removing the BYOK credential stops new requests. Existing XESO notes and answers remain until the user deletes them.Provider data-use terms: OpenAI API data-use and training termsAnthropic
Current registry · verify detailsPurpose: Optional BYOK LLM inference when a user supplies their own Anthropic keyData category: User query + retrieved snippets for BYOK requestsLocation: Per Anthropic API regionDPA: User-elected provider termsCertifications: User-selected provider; account terms varyOnly used when a user configures their own provider key.On disconnect: Removing the BYOK credential stops new requests. Existing XESO notes and answers remain until the user deletes them.Stripe
Current registry · verify detailsPurpose: Billing, subscription management, invoicingData category: Payment metadata (PANs never stored by XESO), billing emailLocation: United StatesDPA: Current Stripe terms apply; signed-evidence claim is not yet approvedCertifications: See the Stripe trust centre; this is not an XESO certificationResend
Current registry · verify detailsPurpose: Transactional email delivery (magic links, digests)Data category: Email address, email subject, bodyLocation: United StatesDPA: Current Resend terms apply; signed-evidence claim is not yet approvedCertifications: See the Resend trust centre; this is not an XESO certificationFull note bodies are never emailed.PostHog
Current registry · verify detailsPurpose: Product analytics (self-host fallback to PostHog Cloud)Data category: Pseudonymous user ID, event names, event properties (PII-stripped)Location: United StatesDPA: Conditional provider; do not enable without current contract and DPA evidenceCertifications: See the provider trust centre; this is not an XESO certificationIP addresses are anonymised at ingest; users may opt out in settings.Sentry
Current registry · verify detailsPurpose: Error monitoring and performance tracesData category: Stack traces, request metadata, scrubbed user contextLocation: United StatesDPA: Conditional provider; do not enable without current contract and DPA evidenceCertifications: See the provider trust centre; this is not an XESO certificationPII scrubbing filters applied before ingest; optional — only enabled when SENTRY_DSN is set.GitHub
Current registry · verify detailsPurpose: Source code, CI, SBOM publicationData category: Source code, commit metadata, built artifactsLocation: United StatesDPA: Development and CI provider; contract evidence remains internally reviewedCertifications: See the GitHub trust centre; this is not an XESO certification