These are the third parties that process customer data so that Mestra can run.
Sub-processors that handle customer data
| Vendor | Purpose | Data processed | Location | More |
|---|---|---|---|---|
| Fly.io (Fly.io, Inc.) | Runs the Mestra application server | Request data while it's processed, including working data in memory. Operational logs, kept for 7 days (storage location not published by Fly.io). | Sydney, Australia | Security |
| Neon (Neon, LLC) | Managed Postgres database | Accounts, organisation settings, logos, run records, usage, audit log, sealed keys | AWS ap-southeast-2, Sydney, Australia | Security |
| Cloudflare (Cloudflare, Inc.) | Edge TLS and rate limiting, tunnel to the app, R2 file storage, staff access control, DNS, support email routing | All traffic in transit. Library files at rest, always encrypted by Mestra first. Inbound support email. | Global network. R2 uses an Oceania location hint (best effort, not a guarantee). | Trust hub |
| Anthropic (Anthropic, PBC) | AI layout planning and review (Claude API; currently Claude Opus 5.5) | Composition read from your master (copy, fonts, positions, image link names and paths), format and brand settings, and preview images for review | United States (inference) | Trust, commercial terms |
| Postmark (AC PM LLC) | Transactional email: sign-in links, invites and notices | Recipient name and email address, and the email content (links, organisation name) | United States | Privacy |
| Stripe (Stripe Payments Australia Pty Ltd) | Checkout, customer portal, subscriptions, invoices and tax. | Billing contact, address and tax ID. Card details are entered only on Stripe-hosted pages. | United States and other countries | Security |
| Microsoft 365 (Microsoft Corporation) | Support mailbox for support@, privacy@ and security@ email | Support, privacy and security emails: the sender's address, the message and our replies | Australia | Trust Center |
| Grafana Labs (Raintank, Inc., trading as Grafana Labs) Planned | Operational log search and monitoring (Grafana Cloud). Not yet in use; we will give at least 30 days' notice before it starts. | Operational logs only: request method, route, status and timing, IP addresses shortened to the network (not the full address), and service event types. No content, emails, tokens or headlines. | Australia (Sydney) | Security |
Providers that don't process customer data
| Vendor | Purpose | Data processed | Location | More |
|---|---|---|---|---|
| GitHub (GitHub, Inc.) | Source code hosting and CI | Source code only | United States | Security |
| UptimeRobot (UptimeRobot s.r.o.) | Uptime monitoring and the status page | No customer data. It probes public health and sign-in endpoints. | EU, with a secondary site in the United States | Security |
AI provider data use
Under Anthropic's commercial terms, customer content isn't used to train models. Anthropic deletes API inputs and outputs within 30 days by default. Content flagged for a usage-policy violation may be kept for up to 2 years (classification scores up to 7 years), or longer where the law requires. Mestra doesn't claim zero data retention.
This website
withmestra.com runs on Cloudflare Workers. Entries from the Talk to us form are stored in Cloudflare and emailed to us. Analytics use Cloudflare Web Analytics, without cookies.
Changes
We'll give at least 30 days' notice before adding or replacing a sub-processor. Organisation owners are emailed automatically, and anyone else can email privacy@withmestra.com to be added. Questions about any vendor are welcome there too. Service status is at status.withmestra.com.