Last updated: September 3, 2026
subprocessors.co fetches the public subprocessor and privacy pages your vendors publish, records each fetch as a dated snapshot, detects changes against the previous snapshot, and tells you which changes are material. It keeps the record so you can show, later, that a human reviewed each one.
This is the complete list. It is short because the service does not need more.
| Data | Why we have it |
|---|---|
| Your email address and password credential | Sign-in. Held by Supabase Auth; we never see the password. |
| Your workspace names | You name them. For consultants these are usually client names. |
| Your notification email address | Where digests are sent. |
| Which vendors each workspace watches, and the dates it started and stopped | This is the coverage record the product produces. |
| Which alerts were reviewed, by which user, and when | The audit trail you are paying for. |
| Vendor requests you submit, including any note you write | So we can add vendors you need. |
| Your Stripe customer and subscription identifiers, plan, and status | Billing. Card details are held by Stripe and never reach us. |
We do not connect to your systems. There is no agent, no OAuth into your vendors, and no read access to your email, your documents, your ticketing system, or your cloud accounts. We do not process personal data belonging to your customers or employees, because the service never touches it.
Everything we fetch is a page the vendor publishes to the open internet.
Change detection is deterministic: structure comes from configuration, and differences are computed in code. A language model is used for exactly two things, both of them reading public vendor pages: pulling fields out of a vendor's published table, and writing the sentence that explains a change in plain English.
The model is never given your workspace names, your email address, your client list, or which vendors you watch. It reads public documents and nothing else. Your data is not used to train any model, because it is never sent to one.
This is an architectural property, not a policy we promise to keep.
| What | Where |
|---|---|
| Database and stored snapshots | Supabase, on AWS us-west-2 (Oregon, United States) |
| The monitoring worker | Railway, Amsterdam, Netherlands |
| This web application | Lovable, AWS us-west-2 (Oregon, United States) |
| The company | Kindred AI Inc., incorporated in Canada |
Our web application and database run in the United States (AWS us-west-2, Oregon). Our monitoring worker runs in the European Union (Amsterdam). We are telling you this rather than leaving you to find it, and we are reviewing whether to consolidate.
Published in the same form we expect of the vendors we monitor.
| Subprocessor | Purpose | Sees customer data? |
|---|---|---|
| Supabase | Database, authentication, snapshot storage | Yes: all account data above |
| Railway | Runs the monitoring worker | Transits it; no independent store |
| Anthropic | Reads public vendor pages, writes change summaries | No |
| Browserless | Renders vendor pages that need a real browser | No: receives vendor URLs only |
| Resend | Sends alert and digest email | Yes: your notification address |
| Healthchecks.io | External monitoring that the daily cycle ran | No: receives a ping only |
| Stripe | Payment processing | Yes: billing identifiers only |
| Lovable | Hosts this web application | Yes |
| GitHub | Source code | No |
Snapshots of vendor pages are kept permanently and never deleted. That is deliberate: the historical record is the product, and an audit trail with gaps is not an audit trail. Those snapshots contain no customer data, only public vendor documents.
On cancellation, your account data is deleted after a grace period:
| Plan | Grace period |
|---|---|
| Solo | 14 days |
| Team and Consultant | 90 days |
During the grace period you can reactivate and lose nothing, or export your review record. After it, your account data is deleted.
Export before you cancel. Your review history is the artifact you paid for, and it is also personal data, so we will not keep it indefinitely on your behalf. The export is yours to retain for as long as your own policy requires.
You can request deletion at any time without cancelling, and we will do it. Email b@kindredeq.com.
We are preparing a published data processing agreement covering the EU Standard Contractual Clauses and the UK IDTA. It is not finished, and we would rather say so than imply otherwise. If you need a DPA before then, email b@kindredeq.com and we will work through it with you.
Sign-in and access control are enforced by the database rather than by the application. The public endpoint that handles review links carries only a database connection and a link-signing secret; it holds no key for the AI provider, for email, for snapshot storage, or for the browser-rendering service, so compromising it does not reach any of them. Snapshot storage is a private bucket.
subprocessors.co is operated by Kindred AI Inc., incorporated in Canada and subject to PIPEDA.
Contact: b@kindredeq.com