Subprocessors
Last updated: September 16, 2026
1. About this list
Escalate Labs uses the third-party subprocessors below to provide the Escalate service. A subprocessor processes customer personal data on our behalf and on our instructions, only for the purpose listed, and is required to protect it with appropriate security measures. This list is referenced by our Privacy Policy and by our data processing agreement with customers.
2. Current subprocessors
| Subprocessor | Purpose | Personal data processed | Location |
|---|---|---|---|
| Google Cloud Platform (Google LLC) | Hosting, compute, databases, object storage, and key management for the Escalate service | All customer data stored in or processed by the service | United States |
| Anthropic (Anthropic, PBC) | AI model inference when Escalate supplies the model for a request | The request content needed to produce the answer | United States |
| E2B | Hosted sandbox compute for chat workspaces | Files, commands, and content in hosted chat workspaces | United States |
| Resend | Transactional email, such as sign-in links, invitations, and approval notifications | Name, email address, and message content | United States |
| Stripe (Stripe, Inc.) | Payment processing and payment fraud prevention | Billing contact and payment details | United States |
| PayPal (PayPal, Inc.) | Payment processing, when you choose to pay with PayPal | Billing contact and payment details | United States |
| Apple Push Notification service (Apple Inc.) | Delivering notifications to the Escalate iOS app | Device token and notification content | United States |
| Google Workspace (Google LLC) | Company email, including support, security, and privacy requests you send us | Content of messages you send to an escalate.me address | United States |
3. Services you choose
The following are not Escalate subprocessors. You or your organization choose them and direct what is sent to them, and their own terms apply:
- Services you connect, such as Gmail, Slack, or GitHub, which receive only the actions you or your agents request.
- Your own AI model provider or gateway, when your organization connects its own account or API key.
- Notification channels you configure, such as Telegram, WhatsApp, Slack, or a webhook URL.
- Identity providers you sign in with, such as Google, GitHub, or your company single sign-on.
- Compute you run, when your organization connects its own cluster or self-hosted model.
4. Changes and notifications
We update this page at least 30 days before a new subprocessor begins processing customer personal data, and we notify customers who have asked to be told. Where we must replace a subprocessor urgently to keep the service running or secure, we update this page as soon as possible and explain why.
To be notified of changes, email privacy@escalate.me with the subject "Subscribe to subprocessor updates" from the address that should receive the notices. Customers with a data processing agreement may object to a new subprocessor on reasonable data protection grounds as described in that agreement.
See also our Cookie Policy and Security pages.
What escalate does
escalate is an AI agent workspace. You connect the accounts you already use, then ask agents to handle real tasks: summarize and triage your inbox, schedule meetings, organize files, draft documents, update spreadsheets, file tickets, or run multi-step workflows across several tools at once. Every agent runs under your account, with your permissions, and nothing irreversible happens without you.
How escalate uses your Google account
When you connect Google, escalate requests only the scopes the connectors you enable actually need, and no others: Gmail (read, search, organize and send mail you have reviewed, plus a metadata-only view of labels and headers), Google Calendar (view and manage events and calendars), Google Drive, Docs, Sheets and Slides (find, read, create and update files), and Google Photos (browse and search your library, upload new photos and create albums). It does not request Contacts, Tasks, Meet, Home/Nest, Fit, YouTube or Wallet. Your data is fetched per request to fulfill the task you asked for, is never sold, is never used for advertising or to train models, and every write action (sending mail, editing files, changing events) requires your explicit in-product approval first.
escalate's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide or improve the user-facing features that are prominent in the escalate interface. It is used for no other purpose: not for advertising, not for advertising or marketing profiles, not for market research, not for product analytics or usage statistics, not for credit or lending decisions, and never to develop, improve or train generalized or non-personalized AI or machine learning models. It is not transferred to anyone except as needed to provide those features, for security purposes, to comply with applicable law, or in a merger or acquisition with your prior notice and consent, and never to advertisers, data brokers, or information resellers. No human reads it except where you have affirmatively agreed to have specific messages or files viewed, for security purposes, or to comply with applicable law. An agent cannot answer a question about your mail, files or photos without a model reading that content, so the content a request needs is sent to the model serving it and to nothing else: an escalate-supplied model on the provider's business or API tier, your organization's own provider account, a gateway it selects, an attested confidential-computing endpoint, or a model your organization hosts itself — in which case the content stays on your organization's own infrastructure and never reaches a model vendor at all. No Workspace or Photos data, raw or aggregated, goes to any service that trains generalized models on it. The full policy is at escalate.me/privacy.
Agent proposes. You authorize. escalate executes.
Agents draft a plan you can inspect, each sensitive step waits for your approval, and everything the agent did is recorded in a full audit trail. Connections can be revoked at any time from your dashboard or from your Google account settings.
escalate is built by Escalate Labs. Privacy policy · Terms of service
Connect 200+ tools through one catalog
escalate ships a catalog of more than 200 connectors covering email, calendars, files and docs, team chat, project management, CRM, finance and payments, developer tools, e-commerce, smart home, and more: Gmail, Google Calendar, Google Drive, Docs, Sheets, Slack, GitHub, GitLab, Linear, Jira, Notion, Stripe, PayPal, Shopify, Square, Salesforce, HubSpot, Dropbox, Figma, Discord, Telegram, Spotify, Zoom, and the long tail of SaaS. Each connector is a typed, sandboxed service wrapping one external API, with a pinned network allowlist so it can only reach the hosts it declares. Browse the full catalog at escalate.me/explore.
A policy gate, not just a chatbot
Hosted chat products let a model act with your full credentials. escalate gates what an agent can actually do: a policy engine classifies every proposed action, read-only calls can flow automatically, and every write (sending mail, editing files, moving money, changing events) queues for explicit human approval with full context. Organizations can set per-agent quotas, per-tool budgets, and approval rules. Every tool call, approval, denial, and result lands in an audit trail you can review per agent, per connector, and per organization.
Security and confidential computing
Credentials live in an encrypted locker and are injected into the connector at call time only; the agent sees tool results, never tokens. Sensitive workloads run inside hardware-attested confidential computing environments (AMD SEV-SNP trusted execution), and escalate publishes cryptographic measurements so you can verify exactly what code handled your data. Connections are revocable at any time. Read more at escalate.me/security.
Where you use escalate
The web dashboard gives you agent chat, connector and credential management, an approval inbox, the audit log, and shareable dashboard apps that render live data from your connectors. iOS and Android apps handle chat and one-tap approvals via push notification. The open-source escalate CLI doubles as an MCP server, so local AI tools such as Claude, Claude Code, and Cursor can call escalate-gated tools while policy, approvals, and audit stay enforced server-side. Scheduled routines run agents on a cron without a human at the keyboard, still subject to the same gates.
Plans
escalate offers a Free tier, paid Pro and Team tiers with higher rate limits, write access, and more seats, and an Enterprise tier with dedicated or self-hosted workers, SSO, and custom SLAs. Current details at escalate.me/pricing.
Frequently asked questions
What is escalate?
escalate is an AI agent workspace by Escalate Labs. You connect the accounts you already use and AI agents do real work across them: triage email, schedule meetings, organize files, update spreadsheets, file tickets, and run multi-step workflows spanning several tools. Agents propose, you authorize, escalate executes with a full audit trail.
Is my data safe?
Every connector runs in an isolated container with a pinned egress allowlist; credentials are injected at call time and never enter the agent's context. Your data is fetched per request to fulfill the task you asked for, is never sold, is never used for advertising, and is never used to train models.
How is escalate different from using Claude or ChatGPT directly?
Chat products talk to you; escalate gates what your agent can actually do. It adds the connector catalog, a policy engine, human-approval flows, per-tool isolation, and an audit trail, and it works with your existing AI tools through MCP rather than replacing them.
Is there a mobile app?
Yes. iOS and Android apps cover chat, notifications, and the approval inbox, so a push notification and one tap approve an agent's pending action.
Can I self-host?
Enterprise customers can run escalate workers on their own Kubernetes cluster; the standard plans are fully managed SaaS.
Machine-readable overview for LLMs and crawlers: escalate.me/llms.txt · full connector directory: escalate.me/llms-full.txt