Sub-processors

Last updated: July 15, 2026

The vendors below process personal data in connection with the Services, as described in our Privacy Policy. Business customers receive 30 days’ notice of additions or replacements via our Data Processing Addendum.

VendorRole — and what they receiveLocation
Paddle (Paddle.com Inc. / Paddle.com Market Ltd.)Merchant of record for purchases — an independent controller of transaction data: name, email, billing country, plan and transaction details. Card details are entered directly with Paddle and never reach us.US/UK
StripePayment processing for direct purchases: card details entered directly in Stripe checkout, billing name/email, transaction amount. We see only masked card data and payment status.US
AnthropicLLM API provider: product inputs and generation requests, served directly and via Google Vertex AI. Not used to train models.US
Google CloudAI/compute infrastructure (Vertex AI): generation inputs where Claude is served via Vertex.US
VercelFrontend and application hosting: request data incl. IP addresses.US
DigitalOceanBackend APIs, workers, managed PostgreSQL: account data, workspace content, encrypted connected-account tokens.US
CloudflareDNS only (traffic is not proxied): DNS lookups, no page content.US/global
ClerkAuthentication: name, email, credentials/OAuth identifiers, session and device data.US
bundle.social (Bundle sp. z o.o.)Social publishing and post analytics for connected accounts: OAuth tokens and content you publish.EU (Poland; some providers may process outside the EEA)
twitterapi.io (Prism Digital, LLC)Retrieval of public X/Twitter data: search queries derived from your product settings.US (AWS; vendor states max 48h retention)
FastLane (Possibility Studios Pty Ltd)AI short-form video generation: your product/project info.Australia (may process outside AU via providers)
Apify (Apify Technologies s.r.o.)Reddit account audit scraping: the Reddit username you submit.EU/US
ExaWeb search for product/competitor research: queries derived from your product info.US
Customer.ioTransactional and lifecycle email: contact attributes from signup/waitlist.US
SentryApplication error tracking: request metadata.US
Axiom (Axiom, Inc.)Log ingestion and querying: application logs, which may include identifiers and IPs.US/EU (AWS + Cloudflare)
AmplitudeMarketing analytics on landing pages only: page events, device/browser data.US
Google AnalyticsWebsite analytics on marketing pages: page events, device/browser data and IP.US
Upstash (Upstash, Inc.)Queues and scheduled jobs: job payloads referencing user/workspace identifiers.US/EU (AWS, region selectable)
Google WorkspaceCorporate email/support: the content of your emails to support@heycatch.ai.US/EU

© HeyCatch, Inc. All rights reserved.