subprocessors.co

Trust and privacy

Last updated: September 3, 2026

What this service does

subprocessors.co fetches the public subprocessor and privacy pages your vendors publish, records each fetch as a dated snapshot, detects changes against the previous snapshot, and tells you which changes are material. It keeps the record so you can show, later, that a human reviewed each one.

What we hold about you

This is the complete list. It is short because the service does not need more.

DataWhy we have it
Your email address and password credentialSign-in. Held by Supabase Auth; we never see the password.
Your workspace namesYou name them. For consultants these are usually client names.
Your notification email addressWhere digests are sent.
Which vendors each workspace watches, and the dates it started and stoppedThis is the coverage record the product produces.
Which alerts were reviewed, by which user, and whenThe audit trail you are paying for.
Vendor requests you submit, including any note you writeSo we can add vendors you need.
Your Stripe customer and subscription identifiers, plan, and statusBilling. Card details are held by Stripe and never reach us.
Your workspace names are the most sensitive thing here. A consultant with twenty client workspaces has, in effect, given us their client list. We treat it accordingly: workspace access is enforced in the database by row-level security rather than in application code, a client workspace cannot see the consultant workspace above it, and the hierarchy is limited to one level so there is no path by which access widens unexpectedly.

What we never hold

We do not connect to your systems. There is no agent, no OAuth into your vendors, and no read access to your email, your documents, your ticketing system, or your cloud accounts. We do not process personal data belonging to your customers or employees, because the service never touches it.

Everything we fetch is a page the vendor publishes to the open internet.

The model never sees your data

Change detection is deterministic: structure comes from configuration, and differences are computed in code. A language model is used for exactly two things, both of them reading public vendor pages: pulling fields out of a vendor's published table, and writing the sentence that explains a change in plain English.

The model is never given your workspace names, your email address, your client list, or which vendors you watch. It reads public documents and nothing else. Your data is not used to train any model, because it is never sent to one.

This is an architectural property, not a policy we promise to keep.

Where your data lives

WhatWhere
Database and stored snapshotsSupabase, on AWS us-west-2 (Oregon, United States)
The monitoring workerRailway, Amsterdam, Netherlands
This web applicationLovable, AWS us-west-2 (Oregon, United States)
The companyKindred AI Inc., incorporated in Canada

Our web application and database run in the United States (AWS us-west-2, Oregon). Our monitoring worker runs in the European Union (Amsterdam). We are telling you this rather than leaving you to find it, and we are reviewing whether to consolidate.

Our subprocessors

Published in the same form we expect of the vendors we monitor.

SubprocessorPurposeSees customer data?
SupabaseDatabase, authentication, snapshot storageYes: all account data above
RailwayRuns the monitoring workerTransits it; no independent store
AnthropicReads public vendor pages, writes change summariesNo
BrowserlessRenders vendor pages that need a real browserNo: receives vendor URLs only
ResendSends alert and digest emailYes: your notification address
Healthchecks.ioExternal monitoring that the daily cycle ranNo: receives a ping only
StripePayment processingYes: billing identifiers only
LovableHosts this web applicationYes
GitHubSource codeNo
We give 30 days' notice before adding a subprocessor, and you may object. This is the same commitment we tell our customers to expect from their own vendors, and it would be indefensible to ask for it while not offering it.

How long we keep things

Snapshots of vendor pages are kept permanently and never deleted. That is deliberate: the historical record is the product, and an audit trail with gaps is not an audit trail. Those snapshots contain no customer data, only public vendor documents.

On cancellation, your account data is deleted after a grace period:

PlanGrace period
Solo14 days
Team and Consultant90 days

During the grace period you can reactivate and lose nothing, or export your review record. After it, your account data is deleted.

Export before you cancel. Your review history is the artifact you paid for, and it is also personal data, so we will not keep it indefinitely on your behalf. The export is yours to retain for as long as your own policy requires.

You can request deletion at any time without cancelling, and we will do it. Email b@kindredeq.com.

Data processing agreement

We are preparing a published data processing agreement covering the EU Standard Contractual Clauses and the UK IDTA. It is not finished, and we would rather say so than imply otherwise. If you need a DPA before then, email b@kindredeq.com and we will work through it with you.

Security

Sign-in and access control are enforced by the database rather than by the application. The public endpoint that handles review links carries only a database connection and a link-signing secret; it holds no key for the AI provider, for email, for snapshot storage, or for the browser-rendering service, so compromising it does not reach any of them. Snapshot storage is a private bucket.

We do not hold SOC 2 and have not had a third-party penetration test. We would rather you read that here than discover it in a questionnaire. If your client requires either, ask us and we will tell you honestly where we are rather than promising a date.

Who we are

subprocessors.co is operated by Kindred AI Inc., incorporated in Canada and subject to PIPEDA.

Contact: b@kindredeq.com