Sub-processors
Last updated 20 September 2026
These are the companies that handle data on our behalf, what they do, and what actually reaches them. The list is taken from our own deployment configuration rather than from a template, so it is what is running, not what we intend to run.
Who processes data on our behalf
| Who | What they do for us | What reaches them |
|---|---|---|
| Render | Hosting, database and cache | Everything the product stores |
| Clerk | Sign-in and sessions | Customer name, email, session |
| Stripe | Payments and metered billing | Billing contact, plan, usage counts |
| OpenRouter (running DeepSeek), with OpenAI as fallback | Judging whether a post shows buying intent, and drafting suggested replies | The text of public posts, which can contain personal data |
| Apollo | Company details, and matching a name to a work address | Company domains; a name where one is known |
| ZeroBounce | Checking whether an address accepts mail | One email address per check |
| Resend | Our own email to customers, invites, resets, digests | Customer email addresses only |
| Upstash | Scheduling runs | Job identifiers, no personal data |
Tools you connect yourself
Separately, you can connect your own HubSpot, Pipedrive, Salesforce, Slack, Google or Microsoft account. Those are your tools and your choice, not ours: we push leads into them and read outcomes back, and mail and calendar permissions are requested read-only. They are not sub-processors of ours, because we are not the ones processing anything there.
Changes
We will update this page when a sub-processor is added or removed. It is generated from the same list the privacy policy uses, so the two cannot drift apart.