Pepper — Vendor and Recipient List
Last updated August 11, 2026 · Version 1.0
This page identifies service providers Vycari Incorporated may use to operate Pepper and other third parties a Pepper feature may contact. A provider receives data only when the corresponding feature is configured and used. The exact data depends on your request and settings.
Core infrastructure
| Provider | Purpose | Data involved |
|---|---|---|
| Vycari-operated VPS and PostgreSQL | Application, database, host logs, and backups | Potentially all Pepper data. The underlying VPS and backup provider will be named here before public launch. |
| Cloudflare | DNS, secure tunnel, network delivery, and security | IP address, request metadata and headers, and content depending on network configuration. |
| Doppler | Secrets and production configuration | Service credentials, configuration, and operator metadata. Pepper does not intentionally store user content as a secret. |
AI and model providers
| Provider | Purpose | Data and provider treatment |
|---|---|---|
| Google Gemini API | Text and voice generation, embeddings, images, summaries, and search/maps grounding when enabled | Prompts, relevant conversation and tool context, files or audio, outputs, embeddings, and usage metadata. Production must use a paid API project with the applicable no-product-improvement treatment; Google safety retention and feature-specific storage may apply. |
| Anthropic API | Text generation and tool use if a Claude model is configured | Prompts, relevant context, tool results, outputs, and usage metadata. Anthropic’s commercial API terms do not use customer content to train models unless the customer opts in; ordinary API retention may apply. |
| OpenAI API | Text generation and tool use if an OpenAI model is configured | Prompts, relevant context, tool results, outputs, and usage metadata. OpenAI does not train models on API data unless the customer opts in; default abuse-monitoring logs may be kept for up to 30 days. |
Accounts and connected services
| Provider | Purpose | Data involved |
|---|---|---|
| Google OAuth and Workspace APIs | Sign-in and user-directed access to Gmail, Calendar, Contacts, profile, and directory services | Identity, OAuth grants and tokens, and connected data needed for the requested feature. Use follows the Google API Services User Data Policy, including Limited Use. |
| GitHub | GitHub connection and user-directed repository actions, including the hosted GitHub MCP endpoint when enabled | GitHub identity, grants and tokens, repository content and metadata, issues, pull requests, and tool requests/results. |
Communications and notifications
| Provider | Purpose | Data involved |
|---|---|---|
| Twilio | Phone verification and SMS delivery | Phone number, message content, delivery metadata, verification status, and consent/stop records. Telecom and compliance retention may apply. |
| Resend | Inbound and outbound email | Email addresses, headers, body, attachments, delivery events, and webhook data. Resend documents default email-data retention that may last 30 days. |
| Meta / WhatsApp Business Platform | WhatsApp messaging when enabled | Phone number, profile and channel identifiers, message content, templates, and delivery metadata. |
| Apple Push Notification service | iOS push delivery | Device token, app/topic, minimized notification payload, and delivery metadata. Content previews are off by default and separately enabled. |
| Your browser’s push service | Web push delivery | Push endpoint and public keys, encrypted minimized payload, and delivery metadata. The provider depends on your browser. |
User-selected recipients and tools
When you ask Pepper to contact a person, retrieve a website or feed, use search or maps, publish content, or call a remote MCP server, information goes to that destination. These recipients generally determine their own privacy practices and are not Vycari processors merely because Pepper can contact them. Review the destination before sending personal or confidential information.
Professional and legal recipients
Vycari may provide minimized, case-specific information to counsel, auditors, insurers, incident responders, law enforcement, courts, or regulators where reasonably necessary and lawful. Before Pepper is offered in the EEA, this page and the privacy notices will also identify Vycari’s appointed Article 27 representative.
Changes and questions
We update this list before adding a provider that materially changes how personal information is processed, and provide additional notice where required. Questions may be sent to [email protected].
User Privacy Notice · Non-user Privacy Notice · Terms of Service