Apptonomy Subprocessor List

Last updated 2026-08-04

Version: 1.2. Approved: 2026-08-04. Effective upon publication. Last reviewed: 2026-08-04. Next scheduled review: 2026-11-04.

This list identifies third parties that may process personal data on Apptonomy’s behalf when Apptonomy provides the service. The named contractual bases are standard online terms or data-processing addenda applicable through use of the service; they are not described as separately negotiated agreements.

Current inventory

Apptonomy subprocessors
SubprocessorLegal entityPurposeData categoriesProcessing locationContractual basis
Google Cloud / FirebaseGoogle LLC and applicable Google affiliateCore compute, Firestore, object storage, BigQuery, logging, KMS, queues and secretsAll platform data; account/org/project records; encrypted credentials; customer store analytics; logsUnited States (nam5, nam4, US, US-CENTRAL1) plus Google global servicesGoogle Cloud Data Processing and Security Terms and incorporated Standard Contractual Clauses
Google Cloud Vision APIGoogle LLCScreenshot OCR and localization quality validationCustomer screenshot image bytes; detected text and layoutGoogle global infrastructureGoogle Cloud Data Processing and Security Terms
Google Gemini API through AI StudioGoogle LLCPaid-tier AI analysis and generationCustomer-derived prompts, listing/review text and model outputGoogle global infrastructureGemini API Additional Terms and incorporated Google terms; production key confirmed in Apptonomy's billing-enabled project
Google Analytics 4Google LLC and applicable Google affiliateConsent-gated browser analyticsBrowser/device events, page activity and consented identifiersGoogle global infrastructureApplicable Google Analytics terms and Google data-processing terms
CloudflareCloudflare, Inc.Workers, CDN, KV, R2, Turnstile, Workers Logs and AI GatewayRequests; client IP for bot verification; customer assets; operational state; AI request metadata and cache-eligible responsesGlobal edgeCloudflare Customer Data Processing Addendum and incorporated Standard Contractual Clauses
OpenAIOpenAI, LLC / OpenAI Ireland Ltd, depending customer regionCommercial API AI analysis and embeddingsCustomer-derived prompts, listing and screenshot-derived text, public review text and outputUnited States by defaultOpenAI Services Agreement / Business Terms and incorporated data-processing terms
AnthropicAnthropic PBC / Anthropic Ireland, Limited, depending customer regionCommercial API AI analysis and quality reviewCustomer-derived prompts, listing/review text and outputAccording to applicable entity and Anthropic termsAnthropic Commercial Terms and incorporated Data Processing Addendum
Perplexity SonarPerplexity AI, Inc.Search-augmented AI analysisCustomer-derived queries and outputUnited StatesPerplexity API Terms of Service
ClerkClerk, Inc.Authentication, identity, sessions and waitlistName, email, auth/OAuth identifiers, session/device and waitlist dataUnited States infrastructure; no regional selectionClerk standard terms and online Data Processing Addendum, incorporated into the Agreement
Stripe, including Global PayoutsStripe, LLCBilling, payment reconciliation, affiliate onboarding, tax and payoutsBilling contact, customer/subscription/payment metadata; affiliate identity, tax and payout dataUnited States account; global processing as necessary for the servicesStripe Services Agreement and online Data Processing Agreement
ResendPlus Five Five, Inc., doing business as ResendTransactional emailRecipient email, subject/body, attachments and delivery metadataUnited States and provider subprocessor locationsResend standard terms and online Data Processing Addendum; Pro-plan message content is retained for 30 days
MixpanelMixpanel, Inc.Product analytics, user profiles and consent-gated session replayUsage events, distinct identifiers, email on user profiles, browser/session replayEuropean Union ingestion, processing, storage and export endpointsMixpanel standard terms, online Data Processing Addendum and EU Data Residency Program
SlackSlack Technologies, LLCCustomer support channels and optional workspace integrationName-derived channel, email, support messages/context, workspace and channel identifiers, encrypted integration tokenUnited States default data center and provider subprocessor locationsSlack standard online terms and Data Processing Addendum
Apple App Store ConnectApple Inc. and applicable affiliateConnected-account listing, review, sales, analytics and publishing operationsCustomer API credential/token; listings; screenshots; reviews; sales and engagement dataApple infrastructureApple Developer and App Store Connect standard terms
Google Play / Android PublisherGoogle LLC and applicable affiliateConnected-account listing, review, sales, analytics and publishing operationsCustomer authorization; listings; screenshots; reviews; installs, sales and performance dataGoogle infrastructureGoogle APIs and Google Play standard terms plus applicable Google data-processing terms
FigmaFigma, Inc.Customer-authorized design integrationOAuth grant/token, team/file identifiers and customer-selected design contentFigma infrastructureFigma Terms and Data Processing Addendum

Deletion requests. When an account is deleted, the identity provider’s user record and any waitlist entry held against that email address are removed, and a compliance deletion request covering the person’s analytics profile and event history is submitted to the product-analytics provider. Billing records held at the payments provider are retained for accounting, bookkeeping, tax and audit purposes and are not removed by account deletion. Provider-side compliance interfaces report the outcome of the submitted job, not an outcome for a named person.

Change notice

Apptonomy manages this list and customer notices through info@apptonomy.ai. Apptonomy will give at least 30 days’ prior notice of an intended addition or replacement, except where an urgent security, legal or continuity requirement makes advance notice impracticable; in that case notice will be given as soon as reasonably possible.

Customers may subscribe by emailing info@apptonomy.ai with the subject “Subprocessor change notices” and identifying the legal entity and service account to notify. The version, effective date, last-review date and version history on this page provide the dated change record.

Public data sources that do not receive customer identity

The following are not subprocessors in the assessed flow because Apptonomy reads public data or operates its own advertising account without sending customer identity:

  • SearchAPI.io: public search and app-listing results.
  • Decodo: proxy and scraper access to public search-engine and app data.
  • Algolia: public app-listing search index.
  • Apple iTunes Search API: public app-catalog lookup.
  • Apple Search Ads: Apptonomy’s own advertising account, not a customer-connected account.
  • Google Ads API: Apptonomy’s own advertising account, not a customer-connected account.
  • Reddit: public posts read as market/community signals.
  • Google AI Overview: public search-result output read as a market signal.

Public review or post text may incidentally identify its author. If that content is incorporated into an audit or AI request, the receiving infrastructure and AI providers are already listed as subprocessors above.

Version history

VersionEffective dateSummary
1.2Proposed upon publicationRecords TPF approval, confirms provider account entities and online DPA bases, confirms paid Gemini, and adds verified Resend and Workers Logs retention facts
1.1Proposed upon publicationRecords the fixed 90-day a7y_data.server_log retention control and distinguishes it from connected-account analytics without automatic expiry
1.02026-08-03Initial production-revalidated list; adds omitted processors, corrects Mixpanel to EU endpoints, and discloses AI Gateway metadata/caching and connected-account analytics flows