Apptonomy Subprocessor List
Last updated September 30, 2026
Version: 1.5. Effective 2026-10-02. Last reviewed: 2026-09-30. Next scheduled review: 2026-12-30.
This list identifies third parties that may process personal data on Apptonomy’s behalf when Apptonomy provides the service. The named contractual bases are standard online terms or data-processing addenda applicable through use of the service; they are not described as separately negotiated agreements.
Current inventory
| Subprocessor | Legal entity | Purpose | Data categories | Processing location | Contractual basis |
|---|---|---|---|---|---|
| Google Cloud / Firebase | Google LLC and applicable Google affiliate | Core compute, Firestore, object storage, BigQuery, logging, KMS, queues and secrets | All platform data; account/org/project records; encrypted credentials; customer store analytics; logs | United States (nam5, nam4, US, US-CENTRAL1) plus Google global services | Google Cloud Data Processing and Security Terms and incorporated Standard Contractual Clauses |
| Google Cloud Vision API | Google LLC | Screenshot OCR and localization quality validation | Customer screenshot image bytes; detected text and layout | Google global infrastructure | Google Cloud Data Processing and Security Terms |
| Google Gemini API through AI Studio | Google LLC | Paid-tier AI analysis and generation | Customer-derived prompts, listing/review text and model output | Google global infrastructure | Gemini API Additional Terms and incorporated Google terms; production key confirmed in Apptonomy's billing-enabled project |
| Cloudflare | Cloudflare, Inc. | Workers, CDN, KV, R2, Turnstile, Workers Logs, AI Gateway and Workers AI inference | Requests; client IP for bot verification; customer assets; operational state; AI request metadata and cache-eligible responses | Global edge | Cloudflare Customer Data Processing Addendum and incorporated Standard Contractual Clauses |
| OpenAI | OpenAI, LLC / OpenAI Ireland Ltd, depending customer region | Commercial API AI analysis and embeddings | Customer-derived prompts, listing and screenshot-derived text, public review text and output | United States by default | OpenAI Services Agreement / Business Terms and incorporated data-processing terms |
| Anthropic | Anthropic PBC / Anthropic Ireland, Limited, depending customer region | Commercial API AI analysis and quality review; AI-assisted operations and development sessions | Customer-derived prompts, listing/review text and output, retained by Anthropic for 30 days by default; in operations sessions, excerpts of application telemetry such as user identifiers, request paths and error messages | According to applicable entity and Anthropic terms | Commercial API: Anthropic Commercial Terms and incorporated Data Processing Addendum. Operations and development sessions: Claude subscription plans under Anthropic’s consumer terms, with the use of conversations for model training turned off |
| Perplexity Sonar | Perplexity AI, Inc. | Search-augmented AI analysis | Customer-derived queries and output | United States | Perplexity API Terms of Service |
| Clerk | Clerk, Inc. | Authentication, identity, sessions and waitlist | Name, email, auth/OAuth identifiers, session/device and waitlist data | United States infrastructure; no regional selection | Clerk standard terms and online Data Processing Addendum, incorporated into the Agreement |
| Stripe, including Global Payouts | Stripe, LLC | Billing, payment reconciliation, affiliate onboarding, tax and payouts | Billing contact, customer/subscription/payment metadata; affiliate identity, tax and payout data | United States account; global processing as necessary for the services | Stripe Services Agreement and online Data Processing Agreement |
| Resend | Plus Five Five, Inc., doing business as Resend | Transactional email | Recipient email, subject/body, attachments and delivery metadata | United States and provider subprocessor locations | Resend standard terms and online Data Processing Addendum; Pro-plan message content is retained for 30 days |
| Mixpanel | Mixpanel, Inc. | Product analytics, user profiles and consent-gated session replay | Usage events, distinct identifiers, email on user profiles, browser/session replay; for server-side events, IP address and IP-derived location | European Union ingestion, processing, storage and export endpoints | Mixpanel standard terms, online Data Processing Addendum and EU Data Residency Program |
| Slack | Slack Technologies, LLC | Customer support channels, optional workspace integration and internal operational alerting | Name-derived channel, email, support messages/context, workspace and channel identifiers, encrypted integration token; in internal alerts, user first name, country, user and session identifiers and error excerpts | United States default data center and provider subprocessor locations | Slack standard online terms and Data Processing Addendum |
| Apple App Store Connect | Apple Inc. and applicable affiliate | Connected-account listing, review, sales, analytics and publishing operations | Customer API credential/token; listings; screenshots; reviews; sales and engagement data | Apple infrastructure | Apple Developer and App Store Connect standard terms |
| Google Play / Android Publisher | Google LLC and applicable affiliate | Connected-account listing, review, sales, analytics and publishing operations | Customer authorization; listings; screenshots; reviews; installs, sales and performance data | Google infrastructure | Google APIs and Google Play standard terms plus applicable Google data-processing terms |
| Figma | Figma, Inc. | Customer-authorized design integration | OAuth grant/token, team/file identifiers and customer-selected design content | Figma infrastructure | Figma Terms and Data Processing Addendum |
| Google Workspace | Google LLC | Company email, including support and security correspondence | Sender name and email address, message content and attachments, and account identifiers included in support requests; mail is retained until deleted (no retention rule) | Google global infrastructure | Google Workspace terms and Cloud Data Processing Addendum |
| Algolia | Algolia, Inc. | App search in the product and site search on the public blog and documentation | Search queries typed in the product, with the user’s IP address and browser user agent; public app-listing and public page content in the search index | European Union (France) | Algolia Terms of Service and Data Processing Addendum |
| GitHub | GitHub, Inc. | Source hosting, continuous integration and automated operations runs | Source code and configuration; in automated operations run records, excerpts of application telemetry such as user identifiers, request paths and error messages, kept for up to 14 days in run artifacts and up to 90 days in run logs | United States | GitHub Customer Agreement and Data Protection Agreement |
| OVHcloud | OVH Hosting Inc. (Montreal, Canada) | Dedicated server that runs continuous integration, deployments and automated operations sessions | Data processed by the automated operations sessions it runs, including excerpts of application telemetry such as user identifiers, request paths and error messages | Strasbourg, France | OVHcloud terms of service and data processing agreement |
Deletion requests. When an account is deleted, the identity provider’s user record and any waitlist entry held against that email address are removed, and a compliance deletion request covering the person’s analytics profile and event history is submitted to the product-analytics provider. Billing records held at the payments provider are retained for accounting, bookkeeping, tax and audit purposes and are not removed by account deletion. Provider-side compliance interfaces report the outcome of the submitted job, not an outcome for a named person.
Change notice
Apptonomy manages this list and customer notices through info@apptonomy.ai. Apptonomy will give at least 30 days’ prior notice of an intended addition or replacement, except where an urgent security, legal or service-continuity need makes advance notice impracticable; in that case notice will be given as soon as reasonably possible. Where the Standard Contractual Clauses in Section 6 of the Data Processing Agreement govern the transfer, the advance-notice period selected for Clause 9(a) applies and prevails over this exception.
Customers may subscribe by emailing info@apptonomy.ai with the subject “Subprocessor change notices” and identifying the legal entity and service account to notify. The version, effective date, last-review date and version history on this page provide the dated change record.
Public data sources that do not receive customer identity
The following are not subprocessors in the assessed flow because Apptonomy reads public data or operates its own advertising account without sending customer identity:
- SearchAPI.io: public search and app-listing results.
- Decodo: proxy and scraper access to public search-engine and app data.
- Apple iTunes Search API: public app-catalog lookup.
- Apple Search Ads: Apptonomy’s own advertising account, not a customer-connected account.
- Google Ads API: Apptonomy’s own advertising account, not a customer-connected account.
- Reddit: public posts read as market/community signals.
- Google AI Overview: public search-result output read as a market signal.
Public review or post text may incidentally identify its author. If that content is incorporated into an audit or AI request, the receiving infrastructure and AI providers are already listed as subprocessors above.
Version history
| Version | Effective date | Summary |
|---|---|---|
| 1.5 | 2026-10-02 | Adds Google Workspace, Algolia, GitHub and OVHcloud after a review of actual data flows; extends the Anthropic, Cloudflare, Mixpanel and Slack entries to their actual purposes and data categories |
| 1.4 | 2026-09-27 | Extends the Algolia entry to cover site search over the public blog and documentation |
| 1.3 | 2026-09-11 | Removes Google Analytics 4 following retirement of browser analytics and advertising collection through Google; retains other Google services and Mixpanel |
| 1.2 | 2026-08-07 | Confirms provider account entities and online DPA bases, confirms paid Gemini, and adds verified Resend and Workers Logs retention facts |
| 1.1 | 2026-08-07 | Records the fixed 90-day application-telemetry retention control and distinguishes it from connected-account analytics without automatic expiry |
| 1.0 | 2026-08-03 | Initial production-revalidated list; adds omitted processors, corrects Mixpanel to EU endpoints, and discloses AI Gateway metadata/caching and connected-account analytics flows |