We use the following third-party providers (subprocessors) to help deliver our services. We carry out data protection due diligence on every subprocessor — retention period, deletion obligations, data protection agreement and location are fixed items of that review — and we publish changes on this page in accordance with Section 3 of the Data Processing Agreement. The actual status of each provider's data protection agreement (DPA) is stated accurately in the notes below; where an agreement is still under negotiation we do not describe it as concluded. Each subprocessor accesses only the categories of data necessary for its stated purpose. Locations marked with an asterisk are based on the provider's own public disclosure; we re-check and update this page regularly, and no less often than quarterly.
Infrastructure
Provider
Purpose
Data categories
Location
Zeabur
Application and database hosting
All platform data
Singapore (deployment region)
Cloudflare
Object storage (evidence snapshots and other artefacts)
Web page snapshots, export files
Globally distributed*【To verify: R2 storage region configuration】
Data and retrieval
Provider
Purpose
Data categories
Location
Exa
Semantic web search
Search queries (including queries derived from profile descriptions), search results
【To verify】
Serper
Supplementary search engine results
Search queries, result entries
【To verify】
Firecrawl
Web page crawling
Target page URLs and crawled content
United States*
Jina
Web page content extraction
Target page URLs and parsed content
Germany (registered entity)*; processing location 【To verify: its disclosure references the EU-U.S. DPF】
Unipile
Social channel account connection (LinkedIn / WhatsApp)
Account connection tokens, message data
France
Models and sending
Provider
Purpose
Data categories
Location
OpenRouter
Unified gateway for large language models
Task inputs and outputs submitted to models
【To verify】; our account is configured with logging disabled and training opt-out, and restricts the model providers that a request may be routed to (verified by configuration check before launch)
Resend
Transactional and outreach email delivery
Email content, recipient addresses, delivery logs
United States* (its disclosed subprocessors are all located in the United States)
Observability and analytics
Provider
Purpose
Data categories
Location
Sentry
Error monitoring
Error stack traces and request context (privacy fields redacted)
【To verify】
Axiom
Structured logging
Application logs (credentials and raw prompt text must not be logged)
【To verify】
Langfuse
Model invocation observability
Model invocation records and cost attribution
【To verify: hosting region】
PostHog
Product analytics
Feature usage events (properties filtered through a redaction allowlist)
【To verify: choice of US/EU instance】
Sign-in
Provider
Purpose
Data categories
Location
Google
OAuth sign-in (optional)
Email address, name (within the scope authorised)
【To verify】
Notes
The table above lists the subprocessors currently in use. Providers that are in commercial discussion but not yet in use are not listed — for example, the contact enrichment provider Snov.io does not participate in any customer-facing data delivery before a written agreement between the parties is in place.
Data on the email sending path is processed in the United States; see Section 4 of the Privacy Policy for the cross-border explanation.
Our selection of subprocessors follows data protection due diligence: retention period, deletion obligations, data protection agreement and location are fixed items of the review; review records are kept in our internal compliance documentation and are re-reviewed quarterly. Current status of data protection agreements: Exa, Jina, Unipile and Resend publish a DPA or equivalent data protection terms, which we have reviewed; OpenRouter's data processing commitments are governed by the DPA incorporated into its terms of service; the data protection agreements and retention commitments of Firecrawl and Serper are still under negotiation — until they are settled, we constrain those two providers with the most conservative configuration available (limiting retention duration, limiting the scope of export, and actively clearing data through our own deletion jobs rather than relying on their deletion).
If you have questions about this list, please contact 【TBD: privacy contact email address】.