How this list was made
A sub-processor list is worth nothing if it is a list of vendors somebody assumed would be there. Every entry below was read off the machine that actually holds and serves this product, using commands whose output is kept alongside the list. If a vendor does not appear in that output, it does not appear here — however normal it would be for a product of this shape to use one.
That rule cuts both ways. It is why the list is short, and it is why the second table, of things that are not used, is as much a part of the answer as the first.
Derived, not assumed
Two rows are awaiting re-derivation
Pending re-derivation
This list was derived while the host name did not resolve and nothing was served to the public. Publishing the site changed both of those facts. The rows that depended on them are marked below, and they say what is now unknown rather than guessing a new answer. Two questions are open: whether the name is proxied through a content delivery network, which would put a party in the path of your request and let it see your address; and which authority issued the certificate that serves this page. Both belong on this list. Neither has been read off the machine by the person writing this page, so neither is stated here yet.
The rule that made this list short is the rule that keeps those two rows open: if it was not read off the machine, it does not appear.
Sub-processors in use
| Party | What it does here | Personal data it processes | How it was found |
|---|---|---|---|
| Hetzner Online GmbH | Supplies the virtual machine that holds the source, the build artefacts, and the site files. | None from any Subject, Part A, or Part B. No production service runs, so no attestation, no lookup, and no billing record exists on it. | The machine’s own firmware vendor string reads Hetzner and its product string
reads vServer. |
| Cloudflare, Inc. | Authoritative DNS for the parent zone this host name sits under. Whether it also proxies the traffic has not been re-derived since the site was published — see the note below. | Not currently derived. The name now resolves, so queries for it reach them. If the name is proxied, they also see the address of every visitor. Which of those is true is one of the two open rows above. | The parent zone’s nameserver and start-of-authority records point at Cloudflare nameservers. |
| One.com A/S | Registrar of the parent domain. Holds the registration, not any traffic. | Registrant contact details for the domain holder. No Subject, Part A, or Part B data. | The public registration record names them as registrar. |
The Cloudflare entry has changed, and this page will not pretend otherwise. Until
the site was published, sealrelay.quicktoolry.com had no address record at all, so no
request reached them and no visitor’s address was seen. That used to be the whole answer. It is no
longer true: the name resolves now. What has not been established is whether the record is proxied. A
proxied record puts Cloudflare in the path of your request and lets it see your address; an unproxied
one does not. That difference is material to anyone deciding whether to send traffic here, so it is
stated as unknown rather than assumed either way.
What is deliberately not on the list
These are the vendors a reader would reasonably expect to find. Each was checked, and each is absent. The check, not the expectation, is what decided it.
| Not used | Why not |
|---|---|
| Any content delivery network | Not currently derived. This absence was true while the host name did not resolve. Whether the published record is proxied through a delivery network is one of the two open rows above, and until that is read off the machine the absence is not claimed. |
| Any analytics or tag manager | No page loads a script from anywhere but itself. A search across every page for an absolute web address returns nothing at all: there is no counter, no pixel, no session recorder. |
| Any font or icon service | Same finding. Type is set in fonts the reader’s own device already has. |
| Any error or crash reporter | No client-side reporter is loaded, and no server collects one. |
| Any certificate authority | Not currently derived. A public site served over HTTPS has a certificate, and the authority that issued it belongs on this list. Which authority that is has not been read off the machine yet, so it is not named here. |
| Any email provider | No mailbox is provisioned for this product. The support page says the same thing rather than printing an address that would drop mail. |
| Any payment processor | Nothing is charged to anyone. The billing work is an in-process simulation against a hand-computed answer; no card, no bank, and no invoicing service is involved. |
| Any third-party database, queue, or object store | No managed data service is used. There is no bucket, no hosted database, and no message broker in the path of anything described on this site. |
| Any support desk, chat widget, or customer-data platform | One person answers, from one mailbox that does not exist yet. There is no tool between you and them. |
| Any subcontracted operations or on-call provider | There is no second person. That is stated plainly on the support page too, including what it costs you: no promised response time. |
Two things this list cannot yet state
Open decision
Where processing happens
The hosting provider is known. The region it runs in is not a committed product statement yet, and this page will not invent one by reading it off a machine that exists for development. A sub-processor list published to customers needs that line filled in by a person who has made the decision.
Open decision
Contract status
Listing a party is not the same as having a data processing agreement in place with them. No such agreement is claimed here. The data processing agreement page describes the template that governs the other direction — what is owed to a customer.
How this list changes
A party is added here before it starts processing, not after. The trigger is mechanical: when a name resolves, a certificate is issued, a mailbox is provisioned, or a managed service is put in the path of a request, that party goes on the list in the same change that puts it in the path.
The derivation is re-run when the list changes, so the two never drift apart. A list that no longer matches the machine it describes is worse than no list, because it invites reliance it has not earned.