AssertumAssertum

Service Providers Notice

Version 1.0 · Effective and last updated: 4 August 2026

This Notice identifies the external providers Assertum uses for the version 1.0 Service and explains their roles. It should be read with our Privacy Notice.

1. Hetzner — application and database hosting

  • Provider: Hetzner Online GmbH
  • Location used by Assertum: Germany
  • Service: Cloud infrastructure for the Assertum application and PostgreSQL database
  • Role: Processor acting on Assertum’s instructions under a data processing agreement

Account/profile data, authentication records, entitlements, quota data, first-party events, test-structure fingerprints and deletion-ledger records are stored in Assertum’s PostgreSQL database hosted on this infrastructure. Database backups are overwritten within 30 days.

2. Google Sign-In — independent authentication service

  • Provider: The Google entity applicable under the user’s Google account terms
  • Service: OAuth/OpenID Connect authentication using the openid, profile and email scopes
  • Role: Google acts as an independent controller for the Google-account side of authentication and the authorised disclosure. Assertum acts as controller for the basic profile after receiving it.

Google may share the name, email address and profile picture associated with the chosen Google account, together with the stable Google provider identifier required to link the account. Google’s own terms and privacy notice govern its side of the service. Removing the Google connection stops future sign-in access but does not automatically delete data already held by Assertum.

3. Google Workspace — support email

  • Provider: Google Cloud EMEA Limited, Dublin, Ireland, for a direct Cyprus customer under Google’s published default entity table
  • Service: Google Workspace email used for messages sent to support@assertum.ai
  • Role: Processor for Workspace customer content under the Google Cloud Data Processing Addendum

Support correspondence is retained for three years after the last contact unless a longer period is required for a specific legal obligation or claim. Google Workspace may use global infrastructure and subprocessors. For restricted transfers, the Google Cloud Data Processing Addendum provides the applicable alternative transfer solution or incorporates the European Commission’s Standard Contractual Clauses.

4. Sentry — error monitoring

  • Provider: Functional Software, Inc. (Sentry)
  • Service: Server-side error and exception monitoring for the Assertum backend
  • Role: Processor acting on Assertum’s instructions

When the backend logs an error, warning or notable event, the message, the stack trace and the release and environment of the build are sent to Sentry so that we can diagnose and fix the failure. A message can include an internal identifier that the code attached to it, such as the internal account ID of the request being handled.

We do not enable Sentry’s optional collection of user IP addresses, request headers or request bodies, and error reports are not used as a product-analytics source. Test content, prompts and raw credentials are not written to ordinary application logs and are therefore not expected to appear in error reports.

Sentry may process data outside the European Economic Area. Where a transfer is restricted under applicable data-protection law, it relies on the European Commission’s Standard Contractual Clauses or another valid safeguard.

5. First-party analytics only

Assertum does not use PostHog, Amplitude, Google Analytics or another external product-analytics vendor in version 1.0. The error monitoring described in section 4 exists to keep the Service working and is not used to build product analytics.

The limited authenticated events listed in the Privacy Notice are sent to Assertum and stored in Assertum’s own PostgreSQL database on Hetzner in Germany. The per-user test-structure fingerprint is used only for duplicate/quota controls within that account and is not compared across users.

6. No Assertum AI or test-content provider

Assertum does not bundle or operate an AI-model provider and does not appoint a subprocessor to receive your underlying test content. Test content remains local.

If you independently connect an AI provider, agent, MCP server or other service to the local CLI, that service is your chosen third party. It is not an Assertum subprocessor merely because the local integration can connect to it.

7. Changes to providers

We will update this Notice when a provider, role or relevant processing location changes. If a change materially affects personal data, we will give additional notice where required.

Questions can be sent to support@assertum.ai.