OnNumbers
Subprocessors & AI Data Use
Effective date: June 22, 2026 · Last updated: July 21, 2026
1. Why this page exists
OnNumbers uses third-party AI providers and cloud infrastructure to deliver the Services. This page lists the providers we currently use in production and the categories of information that may reach each one. We update this page when providers or data uses change.
This list reflects production usage. Providers or models that exist in our internal catalog but are not currently used to process customer data are not listed here.
We minimise personal information submitted to AI service providers and apply data-reduction, access-control and de-identification measures where technically appropriate. The summary below is the detail behind that commitment; our Privacy Policy states the same position at a policy level.
2. Current providers
OpenAI
AI / LLM providerPurpose: Primary language model for AI features (summaries, Ask AI, classification) and embeddings.
Data that may be processed: Operational and financial data required for the feature in use (for example amounts, dates, categories, and transaction descriptions). Depending on the feature, this may also include operational identifiers such as customer or vendor names. Feature-level controls are described in Section 3.
Anthropic
AI / LLM providerPurpose: Language model used for select AI features.
Data that may be processed: Operational and financial data required for the feature in use (for example amounts, dates, categories, and transaction descriptions). Depending on the feature, this may also include operational identifiers such as customer or vendor names. Feature-level controls are described in Section 3.
Google (Gemini)
AI / LLM providerPurpose: Language model used for select AI features.
Data that may be processed: Operational and financial data required for the feature in use (for example amounts, dates, categories, and transaction descriptions). Depending on the feature, this may also include operational identifiers such as customer or vendor names. Feature-level controls are described in Section 3.
Weaviate
Vector databasePurpose: Stores vector embeddings of your data to power semantic search and retrieval for AI features.
Data that may be processed: Embeddings derived from operational and financial data connected to the platform.
Amazon Web Services (AWS)
Cloud infrastructurePurpose: Hosting, storage, and compute for the platform and website.
Data that may be processed: All data stored or processed by the Services.
3. Feature-level controls
Controls vary by feature. We do not claim that every AI feature applies the same de-identification steps.
Ask AI and CFO Assessment: for these two features, customer, vendor, and employee identifiers are replaced with ephemeral tokens before the prompt reaches any AI provider listed above, and the real names are restored only in the response shown to you in the product.
Other AI features (AI Pulse, AI Assessment, AI Work Planning, automated categorization and anomaly detection) receive only the operational and financial data needed for that specific feature — not your full dataset, and not banking or account-access secrets. Those features do not carry the same identifier tokenization guarantee, so operational identifiers may be processed by the provider when required for the feature to work.
Providers process data under our commercial agreements with them. Where we have separately confirmed that a provider does not train models on our customer data, we show that confirmation above.
Questions about a specific provider or feature? Contact us at hello@onnumbers.com.