Subprocessors

Infrastructure providers and data boundaries

See which infrastructure providers ZipPigeon can use, what operational data they process, and where deployment-specific residency evidence is still required.

Railway

ZipPigeon uses Railway for application hosting and may use Railway-managed PostgreSQL. Railway processes encrypted application traffic, operational metadata, logs, deployment configuration, and database records according to the selected deployment and region.

Cloudflare

Cloudflare R2 stores client-encrypted file chunks and public signed CLI release bundles. Cloudflare Turnstile processes browser and network signals on protected public forms when enabled. R2 bucket access, credential scope, lifecycle, CORS, backup, and region evidence are deployment controls.

Amazon Web Services

Amazon SES sends transactional verification, invitation, recovery, and security email when SES is the configured provider. Email necessarily includes delivery addresses and the minimum message content required for that workflow.

Stripe

Stripe processes billing identity, subscription, invoice, and payment information when paid billing is enabled. ZipPigeon stores Stripe references and entitlement state rather than full payment-card details.

Residency and changes

Provider regions and optional integrations vary by deployment. ZipPigeon does not currently promise a fixed residency region or formal DPA on this public page. Material provider or processing-boundary changes belong in the security changelog before release.

Send the file. Keep control of the link.

Use ZipPigeon when a file needs to reach the right person without becoming another attachment or shared folder to clean up later.

Open signed-in sender