Subprocessors
- Last updated:
Subprocessors
DearHim, Inc. Last Updated: 5/8/26
What is a Subprocessor?
A subprocessor is a third-party service we use to help operate the Service. Subprocessors may have access to limited categories of your personal information for specific purposes. We require all subprocessors to comply with strict data protection obligations consistent with our Privacy Policy.
This page lists every subprocessor that processes our users' personal information. We update this list when we add or remove a subprocessor.
Current Subprocessors
Infrastructure & Hosting
| Subprocessor | Purpose | Categories of Data | Hosting Region | Privacy Policy |
|---|---|---|---|---|
| Vercel, Inc. | Application hosting, edge runtime, serverless functions | Account info, server logs, IP addresses, request/response data | United States (us-east-1) | vercel.com/legal/privacy-policy |
| Supabase, Inc. | Database hosting, file storage, real-time subscriptions | Account data, conversation data, profile data, behavioral data, match data, settings | United States (us-east-1) | supabase.com/privacy |
Authentication & Identity
| Subprocessor | Purpose | Categories of Data | Hosting Region | Privacy Policy |
|---|---|---|---|---|
| Clerk, Inc. | User authentication, session management, MFA | Email address, login credentials, session metadata, IP addresses | United States | clerk.com/legal/privacy |
AI Processing
| Subprocessor | Purpose | Categories of Data | Hosting Region | Privacy Policy |
|---|---|---|---|---|
| Anthropic, PBC | AI text generation (conversation responses, Wingman analysis, fit-scoring, matchmaking compatibility analysis) | Conversation messages, behavioral signals (transient — not retained for model training under our commercial agreement) | United States | anthropic.com/legal/privacy |
| ElevenLabs, Inc. | Text-to-speech generation (AI voice notes) | Text of selected messages | United States, EU | elevenlabs.io/privacy |
| Replicate, Inc. | AI image generation (character photos) | Generation prompts (no user PII) | United States | replicate.com/privacy |
Payments
| Subprocessor | Purpose | Categories of Data | Hosting Region | Privacy Policy |
|---|---|---|---|---|
| Stripe, Inc. | Payment processing, fraud detection, subscription management | Billing address, truncated card identifiers, transaction history, IP addresses | United States, EU | stripe.com/privacy |
Communications
| Subprocessor | Purpose | Categories of Data | Hosting Region | Privacy Policy |
|---|---|---|---|---|
| Twilio, Inc. | SMS message delivery (opt-in users only) | Phone number, SMS message content, delivery metadata | United States | twilio.com/legal/privacy |
| Resend, Inc. | Transactional email delivery (account confirmations, receipts, lifecycle emails, etc.) | Email address, email content, delivery metadata | United States | resend.com/legal/privacy-policy |
Analytics
| Subprocessor | Purpose | Categories of Data | Hosting Region | Privacy Policy |
|---|---|---|---|---|
| PostHog, Inc. | Product analytics, feature engagement, A/B test attribution | Pseudonymous user identifier, usage events, device info, IP addresses | United States, EU (configurable) | posthog.com/privacy |
Identity Verification (DearUs Only — When Launched)
<!-- ⚠️ PLACEHOLDER: identity verification vendor TBD — row 11 in table, pending vendor selection for DearUs (issue #94) -->| Subprocessor | Purpose | Categories of Data | Hosting Region | Privacy Policy |
|---|---|---|---|---|
| [TBD: Stripe Identity, Persona, or Onfido] | Identity verification for opt-in DearUs members | Government ID image, selfie photo, verification metadata | United States, EU | [link TBD] |
We will update this page when we select an identity verification provider for DearUs.
Internal Use Tools (Not Customer-Facing)
These subprocessors do not process customer personal information directly, but are listed for transparency:
| Subprocessor | Purpose | Notes |
|---|---|---|
| Slack Technologies | Team communication, internal alerts | No customer personal information shared in normal operations. Aggregate metrics may be discussed. |
| GitHub, Inc. | Source code hosting | No customer personal information stored. |
| Linear, Inc. | Engineering ticket tracking | No customer personal information stored. |
| 1Password | Internal credential management | No customer personal information stored. |
| Apify, Limited | Public web scraping for creator outreach (no DearHim user data) | Used only to scrape public Instagram, TikTok, YouTube content for our creator-partnership program. No DearHim user information processed. |
| Hunter.io | Email enrichment for creator outreach | Used only to find publicly-available email addresses of creators we are reaching out to. No DearHim user information processed. |
| Instantly.ai | Cold email delivery for creator outreach | Used only for our outreach to creators (not users). No DearHim user information processed. |
Data Processing Agreements
We have signed Data Processing Agreements (DPAs) with all customer-facing subprocessors. Where a subprocessor processes EU/UK personal data outside the EU/UK, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, the UK Addendum to the SCCs, or another lawful transfer mechanism.
If you are an enterprise customer or regulator and would like a copy of our subprocessor DPAs, please contact privacy@dearhim.ai.
How We Add or Remove Subprocessors
We may add subprocessors or change subprocessors as the Service evolves. When we add a new subprocessor that materially changes how customer data is processed, we will:
- Update this page.
- Update the "Last Updated" date.
- For enterprise customers and EU/UK users where required, provide notice in advance via email or in-app notification.
You can subscribe to subprocessor change notifications by emailing privacy@dearhim.ai with subject "Subprocessor Updates".
Audit and Verification
If you are an enterprise customer or are exercising rights under the GDPR, CCPA, or another applicable privacy law and would like additional details about a specific subprocessor (e.g., security certifications, audit reports, retention practices), please contact privacy@dearhim.ai.
We will not disclose subprocessor commercial agreement terms, but we will share what is necessary to verify our compliance with applicable privacy law.
Contact
- Email: privacy@dearhim.ai
- Subject line: "Subprocessor Question" or "Subprocessor Updates"