Section 1
Introduction
A sub-processor is a third-party service provider we engage to help us operate KleioBase - for example, hosting our database, running AI document processing, or sending transactional email. When a sub-processor handles personal data on our behalf, we remain responsible for that data and require the sub-processor to protect it under terms no less protective than our own commitments to you.
This page lists every sub-processor currently in use. It is the list referenced by Section 7.1 of our Privacy Policy and by Annex III of our Data Processing Agreement, and we keep it up to date as our vendor list changes.
Section 2
Current sub-processors
| Provider | Purpose | Data shared | Location | Transfer safeguard | Processes your records |
|---|---|---|---|---|---|
| Supabase | Database hosting, authentication, file storage | All user data, uploaded documents, AI-extracted data | USA | Standard Contractual Clauses (SCCs) and DPA | Yes |
| Google (Gemini API) | AI document transcription and data extraction; Research Companion conversations, including files you attach directly to a conversation | Uploaded documents and processing context; images/PDFs attached to a Research Companion conversation | USA | EU-US Data Privacy Framework (certified) | Yes |
| Brave Search (Brave Software, Inc.) | Primary web-search provider for the AI Research Companion in production. Our self-hosted search service is used for overflow once the monthly Brave request budget is nearly exhausted, and as a fallback if Brave errors. | Search query text derived from your Research Companion request. No account details or uploaded documents are sent. | USA | Data Processing Addendum incorporating EU Standard Contractual Clauses | Yes |
| Freemius | Payment processing (Merchant of Record) | Email address, subscription status. Freemius independently collects and controls all payment details. We never receive or store card numbers, full billing addresses, or payment method details. Freemius does pass us the billing country and postal code with a completed purchase, which we do not store (see Section 3.1). | USA | DPA. Freemius acts as independent controller for payment processing. | No |
| Mapbox | Geocoding of locations extracted from records | Place names and addresses | USA | EU-US Data Privacy Framework (certified) | Yes |
| PostHog | Product analytics and AI performance monitoring | Usage data, device info, anonymized identifiers, and AI request metadata (model, token counts, latency, cost). Prompts and AI responses are never sent. | USA | EU-US Data Privacy Framework (certified) and SCCs; consent-based | No |
| Resend | Transactional and marketing email delivery; receives inbound mail to role addresses (privacy@, contact@, support@, abuse@, security@, legal@, marketing@) and forwards it to our application via webhook | Email addresses, email content (outbound and inbound), and the acquisition channel that brought you to sign up (for example, "organic_search" or "meta_ads"), stored as a contact property so we can segment and measure marketing performance. Only the derived channel label is shared, never the underlying UTM parameters, click identifiers, or referrer. | USA | EU-US Data Privacy Framework (certified) and SCCs | Yes |
| Meta (Facebook Pixel and Conversions API) | Marketing analytics and advertising | Page views and conversion events (sign-up, pricing page view, checkout start, subscription, purchase, and your first confirmed record), plus the details Meta uses to match an event to an advertising click: your email address, your account identifier, your first and last name, the Meta browser cookies (_fbp and _fbc), your IP address and browser user-agent, and, for a purchase, the billing country and postal code, the amount and currency, and the transaction reference. Your first and last name, email address, country and postal code are hashed before transmission. Your account identifier, the _fbp and _fbc cookie values, your IP address and your browser user-agent are sent in the clear, because Meta matches them in that form. We do not send your phone number, street address, uploaded documents, or any genealogy data. Nothing is sent unless you have consented to marketing cookies. | USA | EU-US Data Privacy Framework (certified); consent-based | No |
| Railway | Application hosting and deployment | IP address, request data (server logs) | USA | DPA and SCCs | Yes |
| Sentry | Error monitoring, performance tracking, and masked session replay (only after you consent to analytics) | Error reports, which may include IP address, browser info, and application state at the time of an error; and, only if you consent to analytics, masked session replays (a reconstruction of page interactions - clicks, navigation, and DOM changes - with all text and form inputs masked) recorded for a sample of sessions and on errors, buffered in your browser's sessionStorage | USA | EU-US Data Privacy Framework (certified) and SCCs | Yes |
| incident.io | Incident management and on-call alerting; receives error and uptime alerts forwarded from Sentry so we can coordinate our response to outages and significant errors | Error and incident metadata forwarded from Sentry (error type, affected endpoint, and timestamps), which may include an IP address or user identifier embedded in an error’s context | United Kingdom (provider); data stored in the EU/EEA (Google Cloud European regions) | Data Processing Addendum; EU/UK adequacy decision (for EU/EEA-origin data) plus EU Standard Contractual Clauses and the UK Addendum for the provider's onward US sub-processors | No |
| Linear | Product issue tracking and triage of feedback you submit through the in-app feedback form | Your email address and the feedback content you submit (description, steps to reproduce, and any screenshot you attach) | USA | DPA and SCCs | No |
| Chativox | AI-powered in-app customer support chat; replies are generated using Google's Gemini AI. You control when to start a conversation, and conversations are retained by Chativox for up to 12 months (deletion available on request). | Your account identifier, name, email address, and plan tier (sent to identify you in the chat), plus the messages and any details you choose to share in the support conversation | Israel (Chativox); United States (Google Gemini, for AI replies) | Israel holds EU and UK adequacy decisions; Google is EU-US Data Privacy Framework certified | No |
| Cloudflare (Turnstile + Email Routing + media hosting) | Bot protection on forms; inbound email routing (forwards mail sent to our role addresses - e.g. privacy@, support@, contact@ - to our email provider); and hosting of static site media, such as the onboarding walkthrough video, on Cloudflare R2 | Browser interaction data and IP address for bot challenges (processed transiently); and, for email routing, the sender address and message content of mail you send to our role addresses. Static media hosting shares no personal data - the files served are fixed marketing assets, not customer content. | Global | EU-US Data Privacy Framework (certified) | No |
| Google, GitHub (OAuth) | Single sign-on authentication | Profile data you authorize during sign-in (email, name, avatar) | USA | EU-US Data Privacy Framework (Google); DPA (GitHub/Microsoft) | No |
Only the providers marked Yes in the Processes your records column process Customer Content - your uploaded documents, extracted genealogical data, profiles, and Research Companion conversations - and are sub-processors under our Data Processing Agreement. The providers marked No handle only account, billing, analytics, or support data, where KleioBase acts as an independent controller rather than as your processor.
Section 3
Change history
We record every addition, removal, or material change to our sub-processor list here, most recent first.
- 2026-08-28changedCloudflare (Turnstile + Email Routing + media hosting)
Cloudflare now also hosts static site media, such as the onboarding walkthrough video, on Cloudflare R2. This is an existing sub-processor whose account-wide DPA already covers the service; the media hosted there carries no personal data and no customer content, so nothing new is disclosed about you.
- 2026-08-06changedGoogle, GitHub (OAuth)
Apple removed from this entry. Sign in with Apple was listed at first publication but never enabled, so no data was ever shared with Apple.
- 2026-07-14addedMeta (Conversions API)
Server-side advertising measurement. Consent-gated; fires only where marketing consent is granted.
- 2026-06-08addedInitial register
Sub-processors in place at first publication of the privacy policy.
Section 4
Get notified of changes
Sign up below to be notified by email whenever we add a new sub-processor or make a material change to this list.
Section 5
Contact us
Questions about a specific sub-processor or how we use it? Email us at [email protected].