Kinship Public Subprocessor List
Effective date: 2026-06-05
Last updated: 2026-08-31
Version: v1.7
What this page is
A subprocessor is a third party we allow to process personal data for us. Under Terms of Service §6 we owe you a named, current list of every subprocessor that touches your data, and at least 30 days' notice before we add or replace an AI subprocessor. As a matter of policy we give the same 30 days for any subprocessor that would newly touch identifiable contact, note, or life-event data.
We update this page whenever the list changes and record the change in the changelog at the bottom. This page — its version number, its "last updated" date, and its changelog — is the canonical public record. Our source repository is private, so it is not something you can watch. We also email paid-plan account holders about any change that adds or replaces a subprocessor handling identifiable content (see "Notification of changes").
If the law where you live requires us to get your prior consent before sending your data to a new subprocessor — as some EU member states read GDPR Art. 28 — tell us and we will pause processing your data through any added vendor until you have consented.
Active subprocessors
Categories: (P) platform, hosting, database; (AI) AI model providers; (C) integrations and connected accounts; (O) operations — billing, email, error monitoring, rate limiting.
| # | Subprocessor (legal entity) | Category | What they do for Kinship | What they receive | Where they process it | How long they keep it | Their DPA and privacy documents |
|---|---|---|---|---|---|---|---|
| 1 | Supabase, Inc. (Delaware) | P | Our main database, sign-in (OAuth handling and token signing), and file storage for avatars. | All account data, everything you write about your contacts, all AI summaries and embeddings, and sign-in metadata. | United States (us-east-2). | In the database: as long as your account exists, then per our retention schedule. In backups: Supabase keeps the last 7 days of daily backups on the Pro plan we are on. Point-in-time recovery is a paid add-on we have not enabled, so there is no recovery window beyond those daily backups. | DPA · Privacy Policy |
| 2 | Vercel, Inc. (Delaware) | P | Hosting, edge runtime, preview deployments, scheduled jobs, and platform logging. | All HTTP request metadata (IP, user-agent, path, referrer, timing), any request body that passes through a server function — effectively every action you take — and runtime logs that may hold redacted error context. We do not send identifiable contact content into Vercel's own product analytics. | United States. Static assets and edge middleware may be served from the edge location nearest you. | Runtime logs: 24 hours rolling, the figure Vercel documents for the Pro plan, which is our plan. Build logs: Vercel documents these as stored indefinitely for each deployment. | DPA · Privacy Policy |
| 3 | Anthropic, PBC (Delaware) | AI | The language model behind our paid AI features — note summaries, follow-up prompts, search reranking, relationship-health digests. Model claude-sonnet-4-6, called through the Anthropic Messages API. | Only the note, activity, or query you point an AI feature at, plus the minimum account metadata needed to scope the request. Sent only when your plan is paid, you have AI features on, and the contact is not marked do-not-summarise. Never sent: your full address book, OAuth tokens, payment data, or another user's content. | United States. Anthropic's API would otherwise run inference in any available geography, so we mark every request for U.S. inference and refuse to send a request that cannot carry that instruction. Data at rest in Anthropic's workspace is U.S.-only. | The Anthropic Commercial Terms in force say "Anthropic may not train models on Customer Content from Services." Anthropic deletes inputs and outputs within 30 days. Exception: where Anthropic's automated trust-and-safety systems flag content as a Usage Policy violation, it may keep the inputs and outputs for up to 2 years and the classification scores for up to 7 years. Anthropic says this applies even under a zero-retention arrangement. We have not signed one. | Commercial Terms · Privacy Policy · DPA · Sub-Processor List |
| 4 | Voyage AI Innovations, Inc. (Delaware) | AI | The embedding model behind natural-language search (model voyage-3). Every call passes the same plan, consent, age and kill-switch checks as Anthropic. | The structured contact document we build from your saved contact: usually the name, current role and organisation, tags, AI summaries (or the raw notes where there is no summary) for up to 20 activities, and the title and description of any life events on that contact. | Not confirmed as U.S.-only by Voyage's published terms. Voyage's Privacy Policy says only that non-U.S. user data "may" be transferred to and processed in the United States, and its DPA names three subprocessors — Amazon Web Services, Google LLC, and Baseten Labs, Inc. — with no region commitment for any of them. Unlike Anthropic, the Voyage API has no residency setting we could pin. | Voyage's terms permit training by default. Voyage's Terms of Service (§3, last updated 2026-05-27) give it a licence to use Customer Content “to train, improve, and otherwise further develop the Service (such as by training the artificial intelligence models we use).” Voyage offers a dashboard opt-out, but it is prospective only — Voyage says “any data provided prior to your opt out may continue to be subject” to that licence. Without the opt-out Voyage publishes no retention period; with it, Voyage says Customer Content “will be immediately deleted… after it is processed for you.” Status as of 2026-08-09: we have the opt-out enabled. Our founder verified it directly in the Voyage dashboard; Voyage publishes no API or receipt for the setting, so that check is the basis for the statement. Because the opt-out only works going forward and we cannot establish when it was first switched on, we do not claim that anything sent to Voyage before 2026-08-09 falls outside that licence. To keep your data away from Voyage entirely, turn AI features off in settings — the same gate that stops Anthropic calls stops these. | Terms of Service · Privacy Policy |
| 5 | Google LLC (Delaware) | C / O | (a) Sign-in with Google. (b) Read-only Contacts, Gmail, Calendar and Tasks sync, only if you connect a Google account. (c) Google Analytics 4 for aggregate usage measurement, behind the cookie banner and with no ad signals. | (a) Your Google email, profile name, picture URL, and OAuth refresh token. (b) Your Google Contacts entries; the subject, snippet, sender, recipients and date of messages we read; the title, attendees and times of events we read. We store no message bodies and send nothing to Google. (c) Page views, anonymised IP, referrer, broad geography — no advertising identifiers. | United States. Google may transfer data for processing under its processor terms. | Tokens until you disconnect. Google Analytics raw events: 2 months. | A personal Google account you connect is governed by the Google API Services User Data Policy and its Limited Use rules, and the Google Privacy Policy. Google's enterprise data-processing addenda cover Google Cloud and Workspace customers; we do not claim they cover consumer-account OAuth access. |
| 6 | Microsoft Corporation (Washington) | C | Sign-in with Microsoft, and read-only Outlook Contacts, Mail, Calendar and Tasks sync through Microsoft Graph, only if you connect a Microsoft account. | Your Microsoft email, profile name, and OAuth refresh token, plus the same mail and calendar metadata as row 5. No bodies stored, nothing written back. | United States by default; a work or school tenant may sit in its own region. | Tokens until you disconnect. | A personal Microsoft account is governed by the Microsoft Services Agreement and the Microsoft Privacy Statement. For a work or school account, Microsoft's Data Protection Addendum runs between Microsoft and that organisation, not between Microsoft and us. |
| 7 | Stripe, Inc. (Delaware) | O | Subscription billing and the billing portal for paid plans. | Your account email, your Stripe customer ID, and the price you are subscribing to. Stripe handles your card directly — we never see or store card numbers. | United States. | Stripe publishes no fixed retention period for card data. Its DPA commits only that Stripe "implements and maintains data retention policies and procedures related to Personal Data and reviews these policies and procedures as appropriate." | DPA · Privacy Policy |
| 8 | Resend, Inc. (Delaware) | O | Transactional email — today, the one-time codes we send to verify your identity on a data-rights request. We will move longer data-rights receipts and account notifications onto Resend before paid general availability. | The recipient email address, the code, and one line of account context. We never send notes, contacts, or AI output through Resend. | United States. Resend's regions documentation says all account data — email metadata, logs, API records — is stored in the United States whichever sending region is selected. | Send logs and delivery telemetry: 30 days. Resend publishes the same 30 days on its Free, Pro and Scale plans, so the figure does not depend on our tier. | DPA · Privacy Policy |
| 9 | Functional Software, Inc. d/b/a Sentry (California) | O | Error monitoring for the site and the app. We strip email, name, and IP from every payload before it leaves us. | Redacted stack traces, the route name, browser and runtime metadata, a request ID, and a plan-tier flag. No identifiable note or contact content. | United States. | 30 days on the Sentry free tier. | DPA · Privacy Policy |
| 10 | Upstash, Inc. (Delaware) | O | The Redis store behind our rate limits and passcode throttling. We may interchangeably use Vercel KV, which Upstash also backs. | Hashed identifiers (IP, email hash, account ID) and short-lived counters and timestamps. No identifiable user content. | United States (us-east-1). | Counters expire automatically, within minutes to hours. | DPA · Privacy Policy |
Subprocessors used only by the kinshiprm.app marketing site
Listed for completeness. These are not part of the product data path.
| Subprocessor | Role | Data |
|---|---|---|
| Google LLC (Analytics 4) | Aggregate marketing-site measurement | Anonymised IP and page views; no ad signals; cookies behind the banner |
| Vercel, Inc. | Hosting the marketing site | Same as row 2 above |
| Sentry | Error monitoring | Same as row 9 above |
Not subprocessors (clarifications)
- Cloudflare, Inc. — our DNS provider for
kinshiprm.app. DNS resolution is not personal-data processing in our setup, and we do not run Cloudflare as a CDN or proxy in front of the app. If we ever put Cloudflare, or any other CDN, in front of the application, we will add it to this list before that reaches production. - GitHub, Inc. — hosts our source code. Application code is processed there; your personal data is not.
- Paperclip — the issue tracker we run ourselves for engineering and operational work, including privacy and support requests once triaged. It is not a third party at all, because S4 operates the infrastructure it runs on. Separately, no user-facing intake form files into it automatically, and copying identifying information into it is prohibited by policy: requests are recorded by internal reference only, with the identifying details left in the intake system. If either fact changes — identifying content is stored there, or it moves to a third-party host — we will update this page before the change takes effect. (Our previous tracker, Plane, has been decommissioned.)
- LinkedIn — not a subprocessor. We never call LinkedIn APIs. LinkedIn data only enters Kinship as an export file you upload yourself; your browser parses it and we store the result in Supabase.
- Clearbit, Proxycurl, Phantombuster, Dux-Soup, Apify — not subprocessors. We hold no account with any of them and make no call to any of them.
- Apollo.io, Inc. — the vendor we have selected for the planned job-change-alert feature, and not a subprocessor today. We name it because the integration code is already in our application. It is held off by a kill switch set in the source code, not in configuration, so no environment change can turn it on; the scheduled job that would have called Apollo has been removed; and our production database holds no enrichment records of any kind. No contact data has been sent to Apollo. Before that changes, Apollo moves to the active table above and the 30-day notice below runs first.
Roadmap subprocessors (added on 30 days' notice before any production use)
- Apollo.io, Inc. — enrichment vendor for the job-change-alert feature. Selected and written, but disabled (see the clarification above). If the feature ships, Apollo would receive a contact's name, email address, and current employer name, and return that person's job title, employer, and general location. We would store Apollo's full response for that contact alongside those three fields, so any further profile detail Apollo chose to return would be kept too. We will update this page and let the 30 days' notice run before any production enrichment call.
- A vendor for longer transactional email beyond data-rights passcodes — most likely an expansion of Resend. If we add a second vendor, it appears here first.
Notification of changes
We give at least 30 days' notice before adding or replacing any AI subprocessor (per Terms of Service §6) or any subprocessor that would newly receive identifiable contact, note, or life-event data. We give that notice three ways: on this page, with a new version number and a changelog entry; by email to every paid-plan account holder; and by an in-product banner on your first session after the notice goes out. For lower-impact changes — swapping the rate-limit provider, say — we update this page within 7 days with a changelog entry.
Changelog
- 2026-08-31 — v1.7. Removed a stale operational-status sentence from the Voyage AI row. The region/transfer cell said "Voyage traffic is currently switched off in production." That described the state of an internal kill switch, not a legal commitment, and would go stale the moment that switch changes. No subprocessor was added, removed, or replaced, and nothing changed about what any vendor receives, where it is processed, or how long it is kept, so the Terms §6 30-day notice was not triggered.
- 2026-08-28 — v1.6. Corrected the Vercel Privacy Policy link. The link pointed at
vercel.com/legal/privacy-policy, a URL Vercel now redirects tovercel.com/legal/privacy-notice. It now points directly at the current page. No subprocessor was added, removed, or replaced; nothing changed about what any vendor receives, where it is processed, or how long it is kept. - 2026-08-24 — v1.5. Plain-language rewrite. Shorter sentences and plainer wording throughout, and we removed links to our source code that pointed at a private repository and so could not be opened by any reader. No subprocessor was added, removed, or replaced; nothing changed about what any vendor receives, where it is processed, or how long it is kept.
- 2026-08-09 — v1.4. Correction to the Voyage AI row: the opt-out is enabled. The row said we had not executed the opt-out Voyage's terms otherwise require. That understated our actual protections: our founder verified on 2026-08-09 in the Voyage dashboard that it is on, and reported it was on before that date. Voyage publishes no receipt, so the row now states the basis for the claim rather than a date we cannot establish. Because the opt-out only works going forward, the row does not claim it covers anything sent before 2026-08-09. No subprocessor was added, removed, or replaced, so the Terms §6 30-day notice was not triggered.
- 2026-08-07 — v1.3. Resend citation and Apollo disclosure. No vendor gained or lost access to data. The Resend row now cites the documentation its storage-location claim rests on, and states the 30-day retention as applying to Resend's Free, Pro and Scale plans, which is how Resend describes it. Earlier versions grouped Apollo.io with five enrichment services we have no relationship with — accurate about data flow, but it understated Apollo's status, since Apollo is the vendor we have selected and its integration code is in the application behind a source-level kill switch. Apollo now has its own clarification, and the roadmap entry names it and the data it would receive and retain.
- 2026-08-05 — v1.2. Correction to the Voyage AI row: training and retention. The row said Voyage did not train on request payloads and kept them up to 30 days for abuse detection. That was wrong: Voyage's terms permit training by default unless the opt-out is executed, and Voyage publishes no retention period without it. The Voyage terms link was also corrected, the old URL having started returning 404. No subprocessor was added, removed, or replaced, so the Terms §6 30-day notice was not triggered.
- 2026-07-28 — v1.1. Accuracy pass against live vendor terms. Every row re-checked against the vendor document that actually resolves today. No subprocessor was added or removed; every change was a correction to how an existing entry was described. Supabase: region corrected, and the point-in-time-recovery claim removed — it is a paid add-on we do not have, and the 7-day figure belongs to daily backups. Vercel: stale plan note removed, build-log retention corrected to indefinite. Anthropic: dead link replaced, API description fixed, trust-and-safety exception added. Google and Microsoft: we had cited enterprise addenda that do not govern consumer-account OAuth access. Stripe: removed a reference to a card-retention schedule Stripe does not publish. Resend: storage location corrected and an incorrect tier condition removed. Upstash: dead DPA link replaced. Clarifications: Plane replaced by Paperclip. This page also used to offer "watch our public commit history" as a way to hear about changes and linked to source files on GitHub — our repository is private, so none of those links opened. They were removed and this page named as the canonical public record; the email and in-product notice commitments were unchanged.
- 2026-06-05 — v1.0. First publication of the full-product Subprocessor List, superseding the earlier page that covered only job-change alerts.
Questions
Reach us through our privacy contact form or our legal contact form.