Subprocessors

Last updated:

Subprocessors

DearHim, Inc. Last Updated: 5/8/26


What is a Subprocessor?

A subprocessor is a third-party service we use to help operate the Service. Subprocessors may have access to limited categories of your personal information for specific purposes. We require all subprocessors to comply with strict data protection obligations consistent with our Privacy Policy.

This page lists every subprocessor that processes our users' personal information. We update this list when we add or remove a subprocessor.


Current Subprocessors

Infrastructure & Hosting

SubprocessorPurposeCategories of DataHosting RegionPrivacy Policy
Vercel, Inc.Application hosting, edge runtime, serverless functionsAccount info, server logs, IP addresses, request/response dataUnited States (us-east-1)vercel.com/legal/privacy-policy
Supabase, Inc.Database hosting, file storage, real-time subscriptionsAccount data, conversation data, profile data, behavioral data, match data, settingsUnited States (us-east-1)supabase.com/privacy

Authentication & Identity

SubprocessorPurposeCategories of DataHosting RegionPrivacy Policy
Clerk, Inc.User authentication, session management, MFAEmail address, login credentials, session metadata, IP addressesUnited Statesclerk.com/legal/privacy

AI Processing

SubprocessorPurposeCategories of DataHosting RegionPrivacy Policy
Anthropic, PBCAI text generation (conversation responses, Wingman analysis, fit-scoring, matchmaking compatibility analysis)Conversation messages, behavioral signals (transient — not retained for model training under our commercial agreement)United Statesanthropic.com/legal/privacy
ElevenLabs, Inc.Text-to-speech generation (AI voice notes)Text of selected messagesUnited States, EUelevenlabs.io/privacy
Replicate, Inc.AI image generation (character photos)Generation prompts (no user PII)United Statesreplicate.com/privacy

Payments

SubprocessorPurposeCategories of DataHosting RegionPrivacy Policy
Stripe, Inc.Payment processing, fraud detection, subscription managementBilling address, truncated card identifiers, transaction history, IP addressesUnited States, EUstripe.com/privacy

Communications

SubprocessorPurposeCategories of DataHosting RegionPrivacy Policy
Twilio, Inc.SMS message delivery (opt-in users only)Phone number, SMS message content, delivery metadataUnited Statestwilio.com/legal/privacy
Resend, Inc.Transactional email delivery (account confirmations, receipts, lifecycle emails, etc.)Email address, email content, delivery metadataUnited Statesresend.com/legal/privacy-policy

Analytics

SubprocessorPurposeCategories of DataHosting RegionPrivacy Policy
PostHog, Inc.Product analytics, feature engagement, A/B test attributionPseudonymous user identifier, usage events, device info, IP addressesUnited States, EU (configurable)posthog.com/privacy

Identity Verification (DearUs Only — When Launched)

<!-- ⚠️ PLACEHOLDER: identity verification vendor TBD — row 11 in table, pending vendor selection for DearUs (issue #94) -->
SubprocessorPurposeCategories of DataHosting RegionPrivacy Policy
[TBD: Stripe Identity, Persona, or Onfido]Identity verification for opt-in DearUs membersGovernment ID image, selfie photo, verification metadataUnited States, EU[link TBD]

We will update this page when we select an identity verification provider for DearUs.

Internal Use Tools (Not Customer-Facing)

These subprocessors do not process customer personal information directly, but are listed for transparency:

SubprocessorPurposeNotes
Slack TechnologiesTeam communication, internal alertsNo customer personal information shared in normal operations. Aggregate metrics may be discussed.
GitHub, Inc.Source code hostingNo customer personal information stored.
Linear, Inc.Engineering ticket trackingNo customer personal information stored.
1PasswordInternal credential managementNo customer personal information stored.
Apify, LimitedPublic web scraping for creator outreach (no DearHim user data)Used only to scrape public Instagram, TikTok, YouTube content for our creator-partnership program. No DearHim user information processed.
Hunter.ioEmail enrichment for creator outreachUsed only to find publicly-available email addresses of creators we are reaching out to. No DearHim user information processed.
Instantly.aiCold email delivery for creator outreachUsed only for our outreach to creators (not users). No DearHim user information processed.

Data Processing Agreements

We have signed Data Processing Agreements (DPAs) with all customer-facing subprocessors. Where a subprocessor processes EU/UK personal data outside the EU/UK, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, the UK Addendum to the SCCs, or another lawful transfer mechanism.

If you are an enterprise customer or regulator and would like a copy of our subprocessor DPAs, please contact privacy@dearhim.ai.


How We Add or Remove Subprocessors

We may add subprocessors or change subprocessors as the Service evolves. When we add a new subprocessor that materially changes how customer data is processed, we will:

  1. Update this page.
  2. Update the "Last Updated" date.
  3. For enterprise customers and EU/UK users where required, provide notice in advance via email or in-app notification.

You can subscribe to subprocessor change notifications by emailing privacy@dearhim.ai with subject "Subprocessor Updates".


Audit and Verification

If you are an enterprise customer or are exercising rights under the GDPR, CCPA, or another applicable privacy law and would like additional details about a specific subprocessor (e.g., security certifications, audit reports, retention practices), please contact privacy@dearhim.ai.

We will not disclose subprocessor commercial agreement terms, but we will share what is necessary to verify our compliance with applicable privacy law.


Contact

  • Email: privacy@dearhim.ai
  • Subject line: "Subprocessor Question" or "Subprocessor Updates"