Sub-processors
Last updated 2 August 2026.
The operative public list of sub-processors Moonlit engages to deliver the MCP Service, referenced by DPA Clause 3.4(c). Regions are named per provider. Updated whenever a sub-processor changes, with notice to subscribers.
Infrastructure sub-processors
https://mcp.moonlit.ai/mcp.clerk.moonlit.ai): account identifiers, sign-in credentials, session tokens. Clerk, Inc. is certified under the EU-U.S. Data Privacy Framework, including the UK Extension, and the Swiss-U.S. Data Privacy Framework; see the privacy policy §7 for the transfer basis, and Clerk's DPF notice and GDPR page.Sign-in runs through the Moonlit platform account service. The OAuth 2.1 authorisation server runs at clerk.moonlit.ai and is operated using Clerk as the underlying identity service. Individual users authenticate by signing in with their Moonlit platform account (authorisation code flow with PKCE); organisations can additionally authenticate pooled and deployed services with MCP keys, presented as Bearer tokens in the Authorization header.
GenAI sub-processors
Applicable to the hybrid_search and hybrid_search_reranked MCP Tools. The MCP Server invokes Google Vertex AI for the query embedding step used in both, and for the reranking step inside hybrid_search_reranked. No other GenAI sub-processor is invoked by the MCP Service today.
hybrid_search_reranked. Zero-data-retention posture: no retention beyond transient processing, and the data is never used for training. Accessed via an enterprise API with a data processing agreement in place; no customer identifiers are included in data sent to Vertex AI.Anthropic as MCP client
Inside Claude or any other MCP-compatible client, Anthropic processes your prompts and Moonlit's tool responses under its own privacy policy. Anthropic is not a Moonlit sub-processor in the GDPR Article 28 sense; it is the client your tool calls originate from.
Changes
Moonlit notifies subscribers of changes with at least thirty (30) days' advance notice, by updating this page and emailing the address on the account, in line with DPA Clause 3.4(c). Subscribers may object to a new sub-processor as set out in that clause.
Email privacy@moonlit.ai with sub-processor questions.