Sub-processors
Last updated: 2026-05-23.
This page lists every third-party service that may process customer personal data on Safe to Publish's behalf. It is referenced from our Privacy Policy §5 and our Data Processing Addendum §3.
We will provide thirty (30) days' advance notice by email before adding a new sub-processor or replacing one of those listed below. To subscribe to that notice list, email support@safetopublish.com.
Current sub-processors
Anthropic
United StatesPurpose: Reviewer model inference (Claude Sonnet 4.6 + Haiku 4.5)
Data accessed: Submitted draft text, after PII auto-redaction. Retained by Anthropic for up to 30 days for trust & safety monitoring, then deleted; not used to train any model.
Voyage AI
United StatesPurpose: Embedding generation for the rule corpus
Data accessed: No customer-submitted content. Embeddings are computed only over our own SEC rule corpus, not over your drafts.
Clerk
United StatesPurpose: Authentication and session management
Data accessed: Email address, name, hashed credentials, IP and user-agent for session security.
Stripe
United StatesPurpose: Subscription billing and customer portal
Data accessed: Email address, billing name, payment method (held by Stripe — we never see card numbers), subscription status.
Resend
United StatesPurpose: Transactional email (sending) and inbound email forwarding
Data accessed: Recipient email address, message body of transactional emails (e.g. quota-warning notices, trial-ending notices, team invitations).
Vercel
United States (primary), global edge cachePurpose: Application hosting and edge network
Data accessed: All HTTP request metadata (IP, path, user-agent, timestamps). Encrypted database traffic transits Vercel’s network but Vercel does not have access to plaintext database contents.
Supabase
Canada (ca-central-1)Purpose: Managed Postgres database (with pgvector for corpus retrieval)
Data accessed: All persisted application data: account records, firm records, submitted drafts, review results, audit-event chain.
Sentry
United StatesPurpose: Error monitoring and performance tracing
Data accessed: Stack traces and request metadata (path, status code, timestamps). Sentry is configured not to auto-capture session bodies, cookies, or browser-side PII. Individual error events do attach small operational identifiers needed to triage the failure — typically your firm id, a Stripe subscription id on billing-flow errors, or the email address of a waitlist or invitation record being processed when the error occurred. Draft text and review results are not attached. The PII redactor that strips SSNs, email addresses, phone numbers, and dates of birth runs on the path between your draft and the reviewer model; it does not transform Sentry payloads, so error extras are deliberately kept small.
PostHog
United StatesPurpose: Product analytics (page-views, feature usage)
Data accessed: When you are signed in and have granted analytics consent, your Clerk user id, email address, first name, and the name of your firm are sent to PostHog so events can be mapped back to a known account. Event payloads carry the event name plus a small set of derived properties — for example, content type (such as "linkedin" or "newsletter"), severity counts of flags raised on a review, review latency, current plan, and counts of redaction substitutions. The full draft text, the full text of flagged spans, suggested rewrites, and the user's flag dispositions are never sent.
Google LLC
United States (primary), global edgePurpose: Web analytics (Google Analytics 4) and ad conversion measurement (Google Ads, including Enhanced Conversions for Web). Loaded only after the visitor grants analytics or marketing consent under Google Consent Mode v2.
Data accessed: Anonymous client identifier, page paths, event names, and aggregate device/region metadata. For Enhanced Conversions: hashed (SHA-256) email submitted via the public waitlist form, only when marketing consent has been granted. No plaintext PII, draft text, or review results are shared.
Notes
- PII auto-redaction. Before draft text leaves our infrastructure for the Anthropic reviewer call, the application substitutes detected SSNs, email addresses, phone numbers, and dates of birth with same-length placeholders. The redaction is reversed only when rendering the result back to you.
- Customer drafts are not used to train any model. Drafts are retained by Anthropic for up to 30 days for trust & safety monitoring, then deleted.
- Production database (Supabase) is hosted in Canada (ca-central-1). All other listed sub-processors host customer-touching data in the United States.
Questions: support@safetopublish.com.