01
Core providers and research sources are different
Core providers help Phantom Helix host, secure, bill, communicate, or operate the service. An external research source receives a request because a user or investigation workflow selects a capability that uses that source. Some providers process data for Phantom Helix; others independently determine how they operate their service under their own terms.
Location descriptions below reflect current provider information and the latest deployment review available to Phantom Helix. Global networks, support, failover, and customer-selected sources may involve additional countries. A provider policy link is supplied for current detail.
02
Hosting, identity, and service security
Core Phantom Agent hosting: primarily United States; Firebase Authentication: Google-managed global service
Core hosting, authentication, database, object storage, and compute
Account identifiers, authentication records, Helix and Phantom Agent content, reports, graphs, assets, run metadata, and operational records needed to provide the hosted services.
Provider-managed cloud region; deployment configuration applies
Authentication state, rate limiting, and abuse prevention
Short-lived authentication codes, login locks, rate-limit keys, and related account, email, IP, or request identifiers used by authentication and access-review flows.
Google-managed global service
Automated sign-in abuse and bot protection
Browser, device, network, IP, interaction, and risk information processed by Google when the sign-in security check runs.
03
Model processing
Primarily United States; provider may route to Europe or Singapore
Cloud model inference for requested AI-assisted workflows
Prompts, investigation context, tool definitions, and model responses needed to execute a request. Ollama states that cloud prompt and response data is processed transiently and is not used for model training.
A local Ollama runtime keeps model inputs on the machine running that local service. Phantom Agent's hosted worker uses configured cloud model access; users should not assume hosted Phantom Agent inference is local.
04
Payments, analytics, and communications
Global payment service; provider policy and transaction routing apply
Checkout, subscriptions, payment records, tax, and fraud prevention
Name, email, billing address, payment method, transaction, subscription, receipt, and fraud-prevention information. Full card numbers and CVCs do not reach Phantom Helix.
Project region is deployment-specific
Public-site analytics and content-free service lifecycle measurement
Pseudonymous browser identifiers, page and interaction events, public-page session recordings, browser information, and content-free run status, stage, limit, outcome, and error metadata. Private Helix and Phantom Agent browser routes disable capture.
Provider-managed global email infrastructure
Transactional email delivery
Recipient email, message content, delivery identifiers, status, and error records for invitations, access requests, account, and run-status messages.
Provider-managed global marketing service
Optional newsletter subscription and delivery
Newsletter email address, subscription status, delivery, engagement, and unsubscribe information managed by Mailchimp.
05
Customer-directed external research sources
Cloud Invokers and Phantom Agent capabilities can query public websites, government registers, search and archive services, company and property registers, threat-intelligence APIs, network and domain services, transport and geospatial sources, social and media platforms, blockchain services, and other research databases. The exact receiver depends on the capability and investigation pivot.
These sources may receive identifiers or query fields such as a name, company, address, domain, IP address, email, username, registration number, wallet, location, or other target supplied for that request. Results and provider metadata may be stored in the investigation. Source availability, country, retention, secondary use, and terms vary.
This page does not represent every public website as a Phantom Helix subprocessor. Until a complete runtime provider registry is available, customers must review the named capability and source before submitting information that has destination or use restrictions.
06
Changes and contact
Updates
Phantom Helix updates this directory when a core service provider or material data flow changes. External research sources change more frequently and may be unavailable, replaced, or added as capabilities evolve. The Privacy Policy controls if this directory conflicts with the current general disclosure.
Questions
For provider, destination, or privacy questions, contact [email protected].
