Last updated September 20, 2026
BeFree uses the following service providers ("subprocessors") to operate the app. This page lists each provider, what role they play, and where their data centers are. We update this list when we change a provider.
If you have questions about how any of these providers handle BeFree data, email support@heybefree.app.
| Provider | Role | Data Region |
|---|---|---|
| Supabase | Authentication, primary database (Postgres), object storage, serverless Edge Functions | Japan (Tokyo region, ap-northeast-1) |
| PowerSync | Offline-first sync between BeFree and our database | US |
| Anthropic | AI language-model processing for brain-dump parsing. When Google Calendar is connected, receives upcoming-event title + start/end times as context (not description or location). | US |
| Voyage AI | Embedding generation for in-app search and retrieval. When Google Calendar is connected, receives event title + description + location to build the search embedding. | US |
| Apple | App distribution (App Store), in-app purchase processing, push notifications, Sign in with Apple, speech recognition for voice capture on Apple devices (may process audio on Apple's servers depending on device/language). In a web browser, speech-to-text is provided by your browser's engine instead and may be processed by the browser vendor. | US / EU |
| Sign in with Google (authentication), and speech recognition for voice capture on Android devices. If you connect Google Calendar in You → Connections, also two-way calendar sync: OAuth tokens are stored in the device Keychain; an expired refresh token is sent over TLS only to BeFree's private Supabase token-refresh function for exchange with Google and is not persisted server-side. | US / EU | |
| RevenueCat | Subscription and entitlement management across devices; web checkout, recurring billing, receipts, and customer portal. Processes account identifiers, subscription/transaction details, and checkout contact and billing information. | US |
| Stripe | Web payment processing and fraud prevention. Processes payment details, checkout contact and billing information, transaction records, and technical information such as IP addresses. See Stripe's Privacy Policy. | Global processing, including US |
| Resend | Email delivery — sign-in links and account emails, and occasional messages about the app itself, which always carry a one-click unsubscribe link; receives your email address | US |
| Vercel | Hosting for the BeFree web app and website; processes IP addresses and standard request logs. Also provides cookie-free, aggregate audience measurement (Vercel Web Analytics): always on for the heybefree.app marketing website, and in the signed-in web app at app.heybefree.app only while “Send anonymous usage data” is on in the web app’s Preferences (it is off by default). No cookies, nothing stored on your device, IP address not retained, visit identifier discarded after 24 hours, and never linked to your BeFree account. | Global edge |
| Sentry | Crash reports and technical diagnostics. Always on — this is not governed by the “Usage analytics” setting, because without it we cannot tell the app is broken. Content-free: the failure or trace, the app version, the device model and OS, and a pseudonymous installation identifier. That setting governs only whether your account identifier is attached. | US / EU |
| PostHog | Product analytics. On by default; you can turn it off at any time with the “Usage analytics” switch in You → Settings → Privacy & data. | US |
Before we add a subprocessor, we check that:
We add new providers only when they meet these requirements.
When we add, remove, or change a subprocessor, we update this page. For material changes — for example, adding a new AI processor or changing where data is processed — we also notify you in-app before the change takes effect.
Email: support@heybefree.app