← BeFree

Subprocessors

Last updated September 20, 2026

BeFree uses the following service providers ("subprocessors") to operate the app. This page lists each provider, what role they play, and where their data centers are. We update this list when we change a provider.

If you have questions about how any of these providers handle BeFree data, email support@heybefree.app.

ProviderRoleData Region
SupabaseAuthentication, primary database (Postgres), object storage, serverless Edge FunctionsJapan (Tokyo region, ap-northeast-1)
PowerSyncOffline-first sync between BeFree and our databaseUS
AnthropicAI language-model processing for brain-dump parsing. When Google Calendar is connected, receives upcoming-event title + start/end times as context (not description or location).US
Voyage AIEmbedding generation for in-app search and retrieval. When Google Calendar is connected, receives event title + description + location to build the search embedding.US
AppleApp distribution (App Store), in-app purchase processing, push notifications, Sign in with Apple, speech recognition for voice capture on Apple devices (may process audio on Apple's servers depending on device/language). In a web browser, speech-to-text is provided by your browser's engine instead and may be processed by the browser vendor.US / EU
GoogleSign in with Google (authentication), and speech recognition for voice capture on Android devices. If you connect Google Calendar in You → Connections, also two-way calendar sync: OAuth tokens are stored in the device Keychain; an expired refresh token is sent over TLS only to BeFree's private Supabase token-refresh function for exchange with Google and is not persisted server-side.US / EU
RevenueCatSubscription and entitlement management across devices; web checkout, recurring billing, receipts, and customer portal. Processes account identifiers, subscription/transaction details, and checkout contact and billing information.US
StripeWeb payment processing and fraud prevention. Processes payment details, checkout contact and billing information, transaction records, and technical information such as IP addresses. See Stripe's Privacy Policy.Global processing, including US
ResendEmail delivery — sign-in links and account emails, and occasional messages about the app itself, which always carry a one-click unsubscribe link; receives your email addressUS
VercelHosting for the BeFree web app and website; processes IP addresses and standard request logs. Also provides cookie-free, aggregate audience measurement (Vercel Web Analytics): always on for the heybefree.app marketing website, and in the signed-in web app at app.heybefree.app only while “Send anonymous usage data” is on in the web app’s Preferences (it is off by default). No cookies, nothing stored on your device, IP address not retained, visit identifier discarded after 24 hours, and never linked to your BeFree account.Global edge
SentryCrash reports and technical diagnostics. Always on — this is not governed by the “Usage analytics” setting, because without it we cannot tell the app is broken. Content-free: the failure or trace, the app version, the device model and OS, and a pseudonymous installation identifier. That setting governs only whether your account identifier is attached.US / EU
PostHogProduct analytics. On by default; you can turn it off at any time with the “Usage analytics” switch in You → Settings → Privacy & data.US

How we vet providers

Before we add a subprocessor, we check that:

  1. They offer a Data Processing Agreement (DPA) covering confidentiality, security, and how BeFree user data may be used. For AI providers, we additionally require terms or settings that keep BeFree user data out of provider model training. Anthropic's commercial terms contractually prohibit training on BeFree user content, and BeFree has enabled Voyage AI's organization-level training opt-out (see the AI-processing section of our Privacy Policy).
  2. They commit to a defined data-retention window for prompts and intermediate data.
  3. They support encryption in transit and at rest.
  4. They commit to notifying us of security incidents within a defined window.

We add new providers only when they meet these requirements.

Changes

When we add, remove, or change a subprocessor, we update this page. For material changes — for example, adding a new AI processor or changing where data is processed — we also notify you in-app before the change takes effect.

Contact

Email: support@heybefree.app