← BeFree

Subprocessors

Last updated August 21, 2026

BeFree uses the following service providers ("subprocessors") to operate the app. This page lists each provider, what role they play, and where their data centers are. We update this list when we change a provider.

If you have questions about how any of these providers handle BeFree data, email support@heybefree.app.

ProviderRoleData Region
SupabaseAuthentication, primary database (Postgres), object storage, serverless Edge FunctionsUS
PowerSyncOffline-first sync between BeFree and our databaseUS
AnthropicAI language-model processing for brain-dump parsing. When Google Calendar is connected, receives upcoming-event title + start/end times as context (not description or location).US
Voyage AIEmbedding generation for in-app search and retrieval. When Google Calendar is connected, receives event title + description + location to build the search embedding.US
AppleApp distribution (App Store), in-app purchase processing, push notifications, Sign in with Apple, speech recognition for voice capture on Apple devices (may process audio on Apple's servers depending on device/language). In a web browser, speech-to-text is provided by your browser's engine instead and may be processed by the browser vendor.US / EU
GoogleSign in with Google (authentication), and speech recognition for voice capture on Android devices. If you connect Google Calendar in You → Connections, also two-way calendar sync: OAuth tokens are stored in the device Keychain; an expired refresh token is sent over TLS only to BeFree's private Supabase token-refresh function for exchange with Google and is not persisted server-side.US / EU
RevenueCatSubscription entitlement managementUS
ResendTransactional email delivery — sign-in links and account emails; receives your email addressUS
VercelHosting for the BeFree web app and website; processes IP addresses and standard request logs. Also provides cookie-free, aggregate audience measurement (Vercel Web Analytics) on the heybefree.app marketing website only — no cookies, nothing stored on your device, IP address not retained, visit identifier discarded after 24 hours, and never linked to your BeFree account.Global edge
SentryCrash diagnostics (only when "Help improve BeFree" is enabled)US / EU
PostHogProduct analytics (only when "Help improve BeFree" is enabled)US

How we vet providers

Before we add a subprocessor, we check that:

  1. They offer a Data Processing Agreement (DPA) covering confidentiality, security, and how BeFree user data may be used. For AI providers, we additionally require terms or settings that keep BeFree user data out of provider model training. Anthropic's commercial terms contractually prohibit training on BeFree user content, and BeFree has enabled Voyage AI's organization-level training opt-out (see the AI-processing section of our Privacy Policy).
  2. They commit to a defined data-retention window for prompts and intermediate data.
  3. They support encryption in transit and at rest.
  4. They commit to notifying us of security incidents within a defined window.

We add new providers only when they meet these requirements.

Changes

When we add, remove, or change a subprocessor, we update this page. For material changes — for example, adding a new AI processor or changing where data is processed — we also notify you in-app before the change takes effect.

Contact

Email: support@heybefree.app