01
Core providers and research sources are different
External research sources are separate from those core services.
Core providers help Phantom Helix host, secure, bill, communicate, and operate the service. An external source receives a request when a user or investigation workflow selects a capability that uses it. Some providers process data for Phantom Helix. Others decide how to operate their own service under their own terms.
The locations below reflect current provider information and our latest deployment review. Global networks, support, failover, and customer-selected sources may involve other countries. Use each policy link for the provider's current details.
02
Hosting, identity, and service security
Core Phantom Agent hosting: primarily United States; Firebase Authentication: Google-managed global service
Core hosting, authentication, database, object storage, and compute
Data may include account identifiers, authentication records, and operational records. It may also include Helix and Phantom Agent content, reports, graphs, assets, and run metadata needed to provide the hosted services.
Provider-managed cloud region; deployment configuration applies
Authentication state, rate limiting, and abuse prevention
Data may include short-lived authentication codes, login locks, and rate-limit keys. It may also include account, email, IP, or request identifiers used for authentication and access review.
Google-managed global service
Automated sign-in abuse and bot protection
Google processes browser, device, network, IP, interaction, and risk information when the sign-in security check runs.
03
Model processing
Primarily United States; provider may route to Europe or Singapore
Cloud model inference for requested AI-assisted workflows
Ollama receives the prompts, investigation context, tool definitions, and model responses needed to run a request. Ollama states that it processes cloud prompt and response data only while running the request. It also states that it does not use this data for model training.
Provider and downstream model processing locations vary by the selected route
Optional model routing for administrator-selected Phantom Agent inference profiles
OpenRouter receives the prompts, investigation context, tool definitions, images when supported, and model responses needed to run a request. OpenRouter states that prompt and response content is not stored by default, while request metadata is retained; the selected downstream model provider can have its own processing and retention terms.
A local Ollama runtime keeps model inputs on the machine that runs it. Phantom Agent's hosted worker uses the inference profile selected by an internal administrator. Do not assume that hosted Phantom Agent inference is local or always processed by the same provider.
04
Payments, analytics, and communications
Global payment service; provider policy and transaction routing apply
Checkout, subscriptions, payment records, tax, and fraud prevention
Name, email, billing address, payment method, transaction, subscription, receipt, and fraud-prevention information. Full card numbers and CVCs do not reach Phantom Helix.
Project region is deployment-specific
Public-site analytics and content-free service lifecycle measurement
PostHog receives pseudonymous browser identifiers, page and interaction events, public-page session recordings, and browser information. It also receives content-free run status, stage, limit, outcome, and error metadata. Private Helix and Phantom Agent browser routes disable capture.
Provider-managed global email infrastructure
Transactional email delivery
Data may include the recipient email, message content, delivery identifiers, status, and error records. This applies to login links, invitations, access requests, account notices, and run-status messages.
Provider-managed global marketing service
Optional newsletter subscription and delivery
Newsletter email address, subscription status, delivery, engagement, and unsubscribe information managed by Mailchimp.
05
Customer-directed external research sources
Cloud Invokers and Phantom Agent capabilities can query many types of external sources. These include public websites and government registers. They also include company and property registers, search and archive services, and threat-intelligence APIs. Other sources cover networks, domains, transport, geospatial data, social media, blockchain, and other research databases. The selected capability and each investigation pivot decide which source receives a request.
A source may receive identifiers or query fields needed for the request. These can include a name, company, address, domain, IP address, email, username, registration number, wallet, location, or another target. The investigation may store results and provider metadata. Availability, country, retention, secondary use, and terms vary by source.
This page does not represent every public website as a Phantom Helix subprocessor. A complete runtime provider registry is not yet available. Before sending restricted information, customers must review the named capability, source, destination, and permitted use.
06
Changes and contact
Updates
Phantom Helix updates this directory when a core provider or material data flow changes. External research sources change more often. They may be unavailable, replaced, or added as capabilities evolve. The Privacy Policy controls if this directory conflicts with the current general disclosure.
Questions
For provider, destination, or privacy questions, contact support@phantomhelix.com.