Subprocessors
Last updated: August 19, 2026
Wren uses the third-party services below to run the product. Each one processes personal data on our behalf, under our instructions, and is named here so you can identify it, as referenced in Sections 4 and 9 of our Privacy Policy.
Services you connect yourself, such as LinkedIn, Readwise, and meeting recorders like Fathom, Fireflies, and Granola, are not on this list. Wren reads from them at your direction; it does not send them your data to process, and you can disconnect any of them from Settings.
Core infrastructure
Used for every Wren account.
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Railway | Application hosting and compute. The Wren app itself runs here. | All data in transit through the application, plus server logs. | United States |
| Supabase | Managed Postgres database, authentication, and file storage for generated images. | Account details, posts, drafts, ideas, context documents, connected-account tokens, analytics snapshots, generated images. | United States |
| OpenRouter | Routes AI text and image requests to the underlying model providers listed below. | The prompt content of a request: your writing, voice-profile context, chat messages, call transcripts where a feature uses them, and image prompts. | United States |
| Resend | Transactional email: sign-in links, invitations, publish reminders, and the daily brief. | Your email address, name, and the contents of the message being sent. | United States |
| Stripe | Payment processing and subscription billing. | Your email address, billing details, and subscription state. Card details go to Stripe directly and are never held by Wren. | United States, with global processing |
| Upstash | Redis-backed rate limiting, so abuse controls hold across application restarts. | Short-lived counters keyed by account ID or IP address. No content. | United States |
AI model providers
Wren does not call these providers directly. Requests go to OpenRouter, which routes them to whichever of the following serves the model in use. Which model runs depends on the feature. The text and image defaults are set by Wren.
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Anthropic | Default text model for drafting, outlining, critique, and classification. | Prompt content routed via OpenRouter. | United States |
| Default image-generation model, and a selectable text model. | Prompt content routed via OpenRouter. | United States | |
| OpenAI | A selectable text model. | Prompt content routed via OpenRouter. | United States |
Optional and surface-specific
These process data only in the specific circumstances described.
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| PostHog | Product and marketing analytics. On the public marketing pages it stores an identifier on your device to recognise a returning visit, and in the EU and UK it does so only after you accept. Inside the product, events are recorded on our servers against your account rather than through anything stored on your device. No session replays and no autocapture. | Pageview events, referrer, and coarse device information for visitors to the marketing site. | United States |
| Telegram | Delivers notifications to you, if you connect Telegram in Settings. | The contents of the notifications Wren sends you. | Operated internationally |
Changes to this list
We update this page when we add or replace a subprocessor. If you would like to be told about changes in advance, or you have a question about any entry, email us at legal@writewithwren.com.