Apptonomy Subprocessor List
Last updated 2026-08-04
Version: 1.2. Approved: 2026-08-04. Effective upon publication. Last reviewed: 2026-08-04. Next scheduled review: 2026-11-04.
This list identifies third parties that may process personal data on Apptonomy’s behalf when Apptonomy provides the service. The named contractual bases are standard online terms or data-processing addenda applicable through use of the service; they are not described as separately negotiated agreements.
Current inventory
| Subprocessor | Legal entity | Purpose | Data categories | Processing location | Contractual basis |
|---|---|---|---|---|---|
| Google Cloud / Firebase | Google LLC and applicable Google affiliate | Core compute, Firestore, object storage, BigQuery, logging, KMS, queues and secrets | All platform data; account/org/project records; encrypted credentials; customer store analytics; logs | United States (nam5, nam4, US, US-CENTRAL1) plus Google global services | Google Cloud Data Processing and Security Terms and incorporated Standard Contractual Clauses |
| Google Cloud Vision API | Google LLC | Screenshot OCR and localization quality validation | Customer screenshot image bytes; detected text and layout | Google global infrastructure | Google Cloud Data Processing and Security Terms |
| Google Gemini API through AI Studio | Google LLC | Paid-tier AI analysis and generation | Customer-derived prompts, listing/review text and model output | Google global infrastructure | Gemini API Additional Terms and incorporated Google terms; production key confirmed in Apptonomy's billing-enabled project |
| Google Analytics 4 | Google LLC and applicable Google affiliate | Consent-gated browser analytics | Browser/device events, page activity and consented identifiers | Google global infrastructure | Applicable Google Analytics terms and Google data-processing terms |
| Cloudflare | Cloudflare, Inc. | Workers, CDN, KV, R2, Turnstile, Workers Logs and AI Gateway | Requests; client IP for bot verification; customer assets; operational state; AI request metadata and cache-eligible responses | Global edge | Cloudflare Customer Data Processing Addendum and incorporated Standard Contractual Clauses |
| OpenAI | OpenAI, LLC / OpenAI Ireland Ltd, depending customer region | Commercial API AI analysis and embeddings | Customer-derived prompts, listing and screenshot-derived text, public review text and output | United States by default | OpenAI Services Agreement / Business Terms and incorporated data-processing terms |
| Anthropic | Anthropic PBC / Anthropic Ireland, Limited, depending customer region | Commercial API AI analysis and quality review | Customer-derived prompts, listing/review text and output | According to applicable entity and Anthropic terms | Anthropic Commercial Terms and incorporated Data Processing Addendum |
| Perplexity Sonar | Perplexity AI, Inc. | Search-augmented AI analysis | Customer-derived queries and output | United States | Perplexity API Terms of Service |
| Clerk | Clerk, Inc. | Authentication, identity, sessions and waitlist | Name, email, auth/OAuth identifiers, session/device and waitlist data | United States infrastructure; no regional selection | Clerk standard terms and online Data Processing Addendum, incorporated into the Agreement |
| Stripe, including Global Payouts | Stripe, LLC | Billing, payment reconciliation, affiliate onboarding, tax and payouts | Billing contact, customer/subscription/payment metadata; affiliate identity, tax and payout data | United States account; global processing as necessary for the services | Stripe Services Agreement and online Data Processing Agreement |
| Resend | Plus Five Five, Inc., doing business as Resend | Transactional email | Recipient email, subject/body, attachments and delivery metadata | United States and provider subprocessor locations | Resend standard terms and online Data Processing Addendum; Pro-plan message content is retained for 30 days |
| Mixpanel | Mixpanel, Inc. | Product analytics, user profiles and consent-gated session replay | Usage events, distinct identifiers, email on user profiles, browser/session replay | European Union ingestion, processing, storage and export endpoints | Mixpanel standard terms, online Data Processing Addendum and EU Data Residency Program |
| Slack | Slack Technologies, LLC | Customer support channels and optional workspace integration | Name-derived channel, email, support messages/context, workspace and channel identifiers, encrypted integration token | United States default data center and provider subprocessor locations | Slack standard online terms and Data Processing Addendum |
| Apple App Store Connect | Apple Inc. and applicable affiliate | Connected-account listing, review, sales, analytics and publishing operations | Customer API credential/token; listings; screenshots; reviews; sales and engagement data | Apple infrastructure | Apple Developer and App Store Connect standard terms |
| Google Play / Android Publisher | Google LLC and applicable affiliate | Connected-account listing, review, sales, analytics and publishing operations | Customer authorization; listings; screenshots; reviews; installs, sales and performance data | Google infrastructure | Google APIs and Google Play standard terms plus applicable Google data-processing terms |
| Figma | Figma, Inc. | Customer-authorized design integration | OAuth grant/token, team/file identifiers and customer-selected design content | Figma infrastructure | Figma Terms and Data Processing Addendum |
Deletion requests. When an account is deleted, the identity provider’s user record and any waitlist entry held against that email address are removed, and a compliance deletion request covering the person’s analytics profile and event history is submitted to the product-analytics provider. Billing records held at the payments provider are retained for accounting, bookkeeping, tax and audit purposes and are not removed by account deletion. Provider-side compliance interfaces report the outcome of the submitted job, not an outcome for a named person.
Change notice
Apptonomy manages this list and customer notices through info@apptonomy.ai. Apptonomy will give at least 30 days’ prior notice of an intended addition or replacement, except where an urgent security, legal or continuity requirement makes advance notice impracticable; in that case notice will be given as soon as reasonably possible.
Customers may subscribe by emailing info@apptonomy.ai with the subject “Subprocessor change notices” and identifying the legal entity and service account to notify. The version, effective date, last-review date and version history on this page provide the dated change record.
Public data sources that do not receive customer identity
The following are not subprocessors in the assessed flow because Apptonomy reads public data or operates its own advertising account without sending customer identity:
- SearchAPI.io: public search and app-listing results.
- Decodo: proxy and scraper access to public search-engine and app data.
- Algolia: public app-listing search index.
- Apple iTunes Search API: public app-catalog lookup.
- Apple Search Ads: Apptonomy’s own advertising account, not a customer-connected account.
- Google Ads API: Apptonomy’s own advertising account, not a customer-connected account.
- Reddit: public posts read as market/community signals.
- Google AI Overview: public search-result output read as a market signal.
Public review or post text may incidentally identify its author. If that content is incorporated into an audit or AI request, the receiving infrastructure and AI providers are already listed as subprocessors above.
Version history
| Version | Effective date | Summary |
|---|---|---|
| 1.2 | Proposed upon publication | Records TPF approval, confirms provider account entities and online DPA bases, confirms paid Gemini, and adds verified Resend and Workers Logs retention facts |
| 1.1 | Proposed upon publication | Records the fixed 90-day a7y_data.server_log retention control and distinguishes it from connected-account analytics without automatic expiry |
| 1.0 | 2026-08-03 | Initial production-revalidated list; adds omitted processors, corrects Mixpanel to EU endpoints, and discloses AI Gateway metadata/caching and connected-account analytics flows |