Avaplicity Subprocessors

Effective date: September 15, 2025

This page lists third-party processors ("subprocessors") that Avaplicity, Inc. engages to help deliver the Website and App. Each subprocessor processes personal information solely to provide the services we've engaged them for, under written terms that include confidentiality and data protection obligations.

Questions or objections? Email privacy@avaplicity.com.

Current subprocessors

The providers below are currently used in our MVP (U.S. only) configuration.

Infrastructure

Vercel, Inc.

Active
Purpose:

Hosting & CDN for marketing site

Data:

IP address, HTTP headers, page requests, error logs

Subjects:

Website visitors

Location:

Global edge; primarily U.S.

Notes:

Operational logs retained per provider standards

Amazon Web Services, Inc.

Active
Purpose:

Cloud infrastructure (EKS, ECR, ALB, Route53, ACM, CloudWatch, CloudTrail, KMS, Secrets Manager, STS)

Data:

IPs, service logs/metrics, network telemetry; encrypted app data at rest

Subjects:

Website visitors & App users (infra/diagnostics)

Location:

U.S. (us-east-2) and global AWS edge as applicable

Notes:

KMS encryption; OIDC/IRSA; zero-trust network policies

(self-hosted on AWS EKS)

Active
Purpose:

In-memory cache (performance)

Data:

Ephemeral session/context metadata

Subjects:

App users

Location:

U.S. (within our AWS VPC)

Notes:

No third-party managed cache; part of our own infra

Database

MongoDB, Inc.

Active
Purpose:

Primary database

Data:

Account/profile data, conversation transcripts, device/push tokens, reminder schedules

Subjects:

App users

Location:

U.S. region

Notes:

Encryption at rest; role-based access

Google LLC

Active
Purpose:

Mobile app datastore (iOS)

Data:

Profile fields, app state/metadata as configured (no payment cards)

Subjects:

App users

Location:

U.S.

Notes:

Used by iOS app per current architecture; may be reduced as backend consolidates

Monitoring

Datadog, Inc.

Active
Purpose:

Observability: logs, metrics, traces, SLOs

Data:

Service logs/metadata (may include IPs, device/app IDs, error payloads)

Subjects:

Website visitors & App users (diagnostics)

Location:

U.S./EU

Notes:

Used for reliability, security, performance monitoring

Operations

LaunchDarkly, Inc.

Active
Purpose:

Feature flags & kill-switch

Data:

Flag keys/variations, pseudonymous SDK identifiers

Subjects:

App users

Location:

U.S.

Notes:

Used for gradual rollout and safety gates

Analytics

PostHog, Inc.

Active
Purpose:

Product & website analytics

Data:

Event metadata, device/usage data, IP (per provider defaults); no conversation transcripts

Subjects:

Website visitors & App users

Location:

U.S. or EU (per workspace data residency settings)

Notes:

We disable ad-tech sharing; session replay off unless explicitly enabled

Authentication

Google LLC

Active
Purpose:

User authentication

Data:

Email, name (if provided), auth tokens, auth logs

Subjects:

App users who choose Firebase auth

Location:

U.S./Global

Notes:

Used to authenticate iOS users

Google LLC

Active
Purpose:

OAuth identity provider

Data:

Name, email, ID token

Subjects:

App users who choose Google Sign-In

Location:

U.S./Global

Notes:

For login and account linking

Apple Inc.

Active
Purpose:

OAuth identity provider

Data:

Name (if shared), email (relay or direct), ID token

Subjects:

App users who choose Apple Sign-In

Location:

U.S./Global

Notes:

For login and account linking

Communications

Apple Inc.

Active
Purpose:

Push notification delivery

Data:

Device push token; notification routing metadata

Subjects:

App users who enable notifications

Location:

U.S.

Notes:

We store tokens; Apple delivers messages via APNs

(To be determined - e.g., Postmark, SendGrid, or Resend)

Planned
Purpose:

Transactional email (account/support)

Data:

Email address, message content (service notices)

Subjects:

Website visitors & App users who contact us or receive notices

Location:

U.S.

Notes:

Replace with finalized vendor name before publishing

Payments

Apple Inc.

Active
Purpose:

In-app purchase processing

Data:

Purchase receipts/tokens, product identifiers

Subjects:

App users who subscribe

Location:

U.S./Global

Notes:

Card details handled by Apple; we receive receipts only

RevenueCat, Inc.

Active
Purpose:

Subscription entitlements & receipt validation

Data:

App/User identifiers, purchase receipts/tokens, entitlement state

Subjects:

App users who subscribe

Location:

U.S.

Notes:

Bridges App Store receipts to app entitlements

AI/ML

OpenAI OpCo, LLC

Active
Purpose:

LLM inference (text generation)

Data:

Prompts, conversation transcripts, context you share

Subjects:

App users

Location:

U.S./Global

Notes:

Configured to process content only to deliver the service; we opt out of provider training where available

Anthropic PBC

Active
Purpose:

LLM inference (text generation)

Data:

Prompts, conversation transcripts, context you share

Subjects:

App users

Location:

U.S.

Notes:

Used selectively alongside OpenAI; provider does not use API data to train models per provider terms

Cartesia

Active
Purpose:

Speech/voice (TTS/STT)

Data:

Text for synthesis; generated audio; (for STT) audio segments

Subjects:

App users who enable voice

Location:

U.S.

Notes:

Generates assistant's spoken responses; STT used for transcripts as configured

Notes on self-hosted components

  • Redis: We currently operate Redis ourselves on our AWS EKS cluster for caching/session performance. No separate third-party subprocessor is used.
  • Kubernetes tooling: ArgoCD, Kustomize, ESO, and GitHub Actions (OIDC) are build/deploy tools and do not process end-user personal data beyond what appears in build logs/secrets management.

Change management

We update this page for any addition or replacement of a subprocessor. For material changes, we will also note the update in our changelog below.

  • 2025-09-15: Expanded list to include AWS core services, MongoDB Atlas, PostHog, LaunchDarkly, Anthropic, RevenueCat, Firebase (Auth/Firestore), and clarified self-hosted Redis.

Contact

Avaplicity, Inc.
7775 Walton Parkway, Suite 100
New Albany, Ohio 43054
Email: privacy@avaplicity.com