Sub-processors
Last updated 31 July 2026
These are the companies Fillo uses to run the service. Fillo runs on EU servers, and the responses your forms collect are stored in the EU too. Some of these providers are US companies — the hosting platform itself is one — and a few features, such as email delivery or AI drafting, send just the data that feature needs outside the EEA. Every transfer is covered by the safeguards listed below.
Railway
EU infrastructure; US-based providerRuns the Fillo application and managed PostgreSQL database.
Legal entity: Railway Corporation
When used: Core service
What they receive: Account data, form definitions, response data and metadata.
Safeguards: Fillo's production app and database run in Railway's EU region. Railway is a US company, so its DPA incorporates the EU Standard Contractual Clauses (2021/914) for any processing or access from the US, alongside the Data Privacy Framework where certified.
Resend
United States (SCCs)Sends service emails such as account verification, password resets, owner notifications, respondent receipts, resume links, and workspace claim links.
Legal entity: Plus Five Five, Inc.
When used: Transactional email
What they receive: Recipient email address, email content, and delivery metadata.
Safeguards: Used only to deliver the email; transfer covered by Resend's DPA and Standard Contractual Clauses.
Anthropic
United States (SCCs)Turns your prompt into a draft form when you choose Draft with AI.
Legal entity: Anthropic, PBC
When used: Optional AI drafting
What they receive: The prompt and context you submit for drafting. Anthropic does not receive submitted form responses through this feature.
Safeguards: Only used when you ask Fillo to draft a form with AI; transfer covered by Anthropic's commercial terms, DPA, and Standard Contractual Clauses.
PostHog
European Union (PostHog Cloud EU) by defaultHelps us notice server errors, improve reliability, and understand which documentation paths and features need work.
Legal entity: PostHog, Inc.
When used: Diagnostics, product analytics, and coarse documentation usage, if enabled
What they receive: Error messages, stack traces, request ids, routes, coarse operational events, documentation paths, coarse search-length and word-count ranges, result counts and zero-result indicators, feedback votes, guide filters, page views and page actions on the website and app, and, for signed-in team members, the account id, email, name, and workspace. Documentation search text, hashes, and query fingerprints are not sent.
Safeguards: Server-side events use a shared workspace-level identifier, never a person. In the browser, marketing and app pages use PostHog analytics: anonymous visitors are measured without a person profile, and signed-in team members are identified by account id with email and name so product usage can be understood per workspace. Session recording is off unless we explicitly enable it. Hosted form pages and respondent flows load no analytics at all, so form answers and respondent profiles are never collected, and nothing is used for advertising or cross-site tracking. PostHog Cloud EU keeps this data on EU infrastructure by default.
Not sub-processors: your own storage and tools
You can connect your own Google Drive, Box, or S3-compatible bucket (including AWS S3 and Cloudflare R2) for file storage. Files upload browser-direct to that storage; Fillo controls multipart completion and cleanup, and may stream authenticated Drive or Box downloads for workspace members. You can also send responses to destinations you control, such as Google Sheets, Notion, Zapier, or custom webhook URLs. Those providers are controlled by you, not engaged by us. Google is also an optional sign-in provider; sign-in uses the basic openid email profile scopes. Connecting Google Drive or Sheets adds drive.file, which only sees files this app creates.
Changes
Before we add or replace a sub-processor we’ll update this page. Account holders can ask to be notified of changes at hello@fillo.so.