Subprocessors

中文

Last updated: 【TBD: publication date】

We use the following third-party providers (subprocessors) to help deliver our services. We carry out data protection due diligence on every subprocessor — retention period, deletion obligations, data protection agreement and location are fixed items of that review — and we publish changes on this page in accordance with Section 3 of the Data Processing Agreement. The actual status of each provider's data protection agreement (DPA) is stated accurately in the notes below; where an agreement is still under negotiation we do not describe it as concluded. Each subprocessor accesses only the categories of data necessary for its stated purpose. Locations marked with an asterisk are based on the provider's own public disclosure; we re-check and update this page regularly, and no less often than quarterly.

Infrastructure

ProviderPurposeData categoriesLocation
ZeaburApplication and database hostingAll platform dataSingapore (deployment region)
CloudflareObject storage (evidence snapshots and other artefacts)Web page snapshots, export filesGlobally distributed*【To verify: R2 storage region configuration】

Data and retrieval

ProviderPurposeData categoriesLocation
ExaSemantic web searchSearch queries (including queries derived from profile descriptions), search results【To verify】
SerperSupplementary search engine resultsSearch queries, result entries【To verify】
FirecrawlWeb page crawlingTarget page URLs and crawled contentUnited States*
JinaWeb page content extractionTarget page URLs and parsed contentGermany (registered entity)*; processing location 【To verify: its disclosure references the EU-U.S. DPF】
UnipileSocial channel account connection (LinkedIn / WhatsApp)Account connection tokens, message dataFrance

Models and sending

ProviderPurposeData categoriesLocation
OpenRouterUnified gateway for large language modelsTask inputs and outputs submitted to models【To verify】; our account is configured with logging disabled and training opt-out, and restricts the model providers that a request may be routed to (verified by configuration check before launch)
ResendTransactional and outreach email deliveryEmail content, recipient addresses, delivery logsUnited States* (its disclosed subprocessors are all located in the United States)

Observability and analytics

ProviderPurposeData categoriesLocation
SentryError monitoringError stack traces and request context (privacy fields redacted)【To verify】
AxiomStructured loggingApplication logs (credentials and raw prompt text must not be logged)【To verify】
LangfuseModel invocation observabilityModel invocation records and cost attribution【To verify: hosting region】
PostHogProduct analyticsFeature usage events (properties filtered through a redaction allowlist)【To verify: choice of US/EU instance】

Sign-in

ProviderPurposeData categoriesLocation
GoogleOAuth sign-in (optional)Email address, name (within the scope authorised)【To verify】

Notes

  1. The table above lists the subprocessors currently in use. Providers that are in commercial discussion but not yet in use are not listed — for example, the contact enrichment provider Snov.io does not participate in any customer-facing data delivery before a written agreement between the parties is in place.
  2. Data on the email sending path is processed in the United States; see Section 4 of the Privacy Policy for the cross-border explanation.
  3. Our selection of subprocessors follows data protection due diligence: retention period, deletion obligations, data protection agreement and location are fixed items of the review; review records are kept in our internal compliance documentation and are re-reviewed quarterly. Current status of data protection agreements: Exa, Jina, Unipile and Resend publish a DPA or equivalent data protection terms, which we have reviewed; OpenRouter's data processing commitments are governed by the DPA incorporated into its terms of service; the data protection agreements and retention commitments of Firecrawl and Serper are still under negotiation — until they are settled, we constrain those two providers with the most conservative configuration available (limiting retention duration, limiting the scope of export, and actively clearing data through our own deletion jobs rather than relying on their deletion).
  4. If you have questions about this list, please contact 【TBD: privacy contact email address】.
This page is derived from our internal compliance memorandum; the version mapping is kept in our release records.