fellos subprocessors
Last updated: September 29, 2026
Organizations use fellos to keep their members' data: profiles, posts, messages, events, elections, dues and store orders. For that data, each organization decides what is collected and why, and fellos processes it on the organization's behalf. The providers below help us do that. They are our subprocessors.
Our Data Processing Addendum sets the terms, and organizations accept it with our Terms of Service. We store all data in the United States, with Amazon Web Services.
Changes. At least 30 days before we add or replace a subprocessor, we email every organization's site admins and update this page. To object, write to privacy@fellos.app before the change takes effect. An organization that objects may cancel its subscription with immediate effect, and we will refund any fees it prepaid for the rest of the period.
Get updates by email. Anyone can ask to receive these notices. Email privacy@fellos.app with the subject "Subscribe to subprocessor updates".
Sections
Subprocessors for organizations' member data
| Provider | What it does for fellos | What it receives | When | Where it processes data |
|---|---|---|---|---|
| Amazon Web Services | Hosting, database and file storage | All site data and uploads | Always | United States (US East, Northern Virginia) |
| Resend | Sending email | Member email addresses and email contents | Every email a site sends | United States |
| OTTO, powered by WATTER, Inc. | AI features: search, Ask AI, Summarize, the weekly digest summary, thread summaries, and the page-writing and page-style helpers | Group posts and comments, each with its author's name and member type, the group's name and the thread's title, for search. Recent group posts, without author names, for the weekly digest. Thread posts, with their authors' names and member types, for Summarize and summary updates. Search text, Ask AI questions (with the organization's name and type, and the posts and whole threads Ask AI searches and reads, with each author's name and member type), and page content when someone uses a feature. OTTO keeps none of this content and does not train on it. | Search indexing, the weekly digest and summary updates run automatically. The rest runs when someone uses the feature. | United States |
| Google Wallet | Event tickets in Google Wallet | The ticket holder's name, the event, venue and address, the organization, ticket types, check-in time, the ticket id and its QR check-in code | When a member adds a ticket to Google Wallet | United States |
| Apple Push Notification service | Updating Apple Wallet passes | A push token, with no member details. fellos serves the pass itself. | When a member has added a ticket to Apple Wallet | United States |
| Browser push services (Google for Chrome, Mozilla for Firefox, Apple for Safari, Microsoft for Edge) | Delivering push notifications | Encrypted notification contents | When a member turns on push notifications | Wherever the browser maker runs its push service |
| USPS, UPS, FedEx and DHL | Showing shipment status for store orders | Tracking numbers only | When an organization ships a store order with tracking | United States (DHL: Germany) |
Payments from members are not on this list. When a member pays dues, buys a ticket or orders from a store, the payment goes through the organization's own Stripe account, which the organization connects to fellos. Stripe is the organization's provider, not ours: the organization is the merchant, and fellos is not a party to the payment. fellos sends the organization's Stripe account the paying member's email address and ids that link the payment to the member and the item. For store orders it also sends the member's name and, where their profile has them, phone number and home address (as billing and shipping address).
Social sign-in is not on this list either. Sign-in with Google, GitHub or Apple uses sign-in apps the organization registers with those providers itself. They are the organization's providers, not ours.
Providers we use for our own data
We also use providers for data that fellos itself controls: signing up, running each organization's fellos account, our own billing, support, and our websites fellos.app and signup.fellos.app. These are not subprocessors of organizations' member data. Our Privacy Notice describes them in full.
| Provider | What we use it for |
|---|---|
| Stripe | Billing organizations for their fellos subscription |
| Google Workspace | Our mailboxes: hello@, privacy@, security@ and legal@fellos.app |
| HeyCatch and its subprocessors (heycatch.ai/subprocessors) | Signup analytics, only with consent |
| GitHub | Our private engineering tracker, where staff may copy details of a support ticket |
| Let's Encrypt | Issuing security certificates. Every site's address is listed in a certificate, and certificates are published in public logs. |
We also use Amazon Web Services, Resend and OTTO for this data, as the Privacy Notice describes.
Questions
Write to privacy@fellos.app.