Avaplicity Subprocessors
Effective date: September 15, 2025
This page lists third-party processors ("subprocessors") that Avaplicity, Inc. engages to help deliver the Website and App. Each subprocessor processes personal information solely to provide the services we've engaged them for, under written terms that include confidentiality and data protection obligations.
Questions or objections? Email privacy@avaplicity.com.
Current subprocessors
The providers below are currently used in our MVP (U.S. only) configuration.
Infrastructure
Vercel, Inc.
ActiveHosting & CDN for marketing site
IP address, HTTP headers, page requests, error logs
Website visitors
Global edge; primarily U.S.
Operational logs retained per provider standards
Amazon Web Services, Inc.
ActiveCloud infrastructure (EKS, ECR, ALB, Route53, ACM, CloudWatch, CloudTrail, KMS, Secrets Manager, STS)
IPs, service logs/metrics, network telemetry; encrypted app data at rest
Website visitors & App users (infra/diagnostics)
U.S. (us-east-2) and global AWS edge as applicable
KMS encryption; OIDC/IRSA; zero-trust network policies
(self-hosted on AWS EKS)
ActiveIn-memory cache (performance)
Ephemeral session/context metadata
App users
U.S. (within our AWS VPC)
No third-party managed cache; part of our own infra
Database
MongoDB, Inc.
ActivePrimary database
Account/profile data, conversation transcripts, device/push tokens, reminder schedules
App users
U.S. region
Encryption at rest; role-based access
Google LLC
ActiveMobile app datastore (iOS)
Profile fields, app state/metadata as configured (no payment cards)
App users
U.S.
Used by iOS app per current architecture; may be reduced as backend consolidates
Monitoring
Datadog, Inc.
ActiveObservability: logs, metrics, traces, SLOs
Service logs/metadata (may include IPs, device/app IDs, error payloads)
Website visitors & App users (diagnostics)
U.S./EU
Used for reliability, security, performance monitoring
Operations
LaunchDarkly, Inc.
ActiveFeature flags & kill-switch
Flag keys/variations, pseudonymous SDK identifiers
App users
U.S.
Used for gradual rollout and safety gates
Analytics
PostHog, Inc.
ActiveProduct & website analytics
Event metadata, device/usage data, IP (per provider defaults); no conversation transcripts
Website visitors & App users
U.S. or EU (per workspace data residency settings)
We disable ad-tech sharing; session replay off unless explicitly enabled
Authentication
Google LLC
ActiveUser authentication
Email, name (if provided), auth tokens, auth logs
App users who choose Firebase auth
U.S./Global
Used to authenticate iOS users
Google LLC
ActiveOAuth identity provider
Name, email, ID token
App users who choose Google Sign-In
U.S./Global
For login and account linking
Apple Inc.
ActiveOAuth identity provider
Name (if shared), email (relay or direct), ID token
App users who choose Apple Sign-In
U.S./Global
For login and account linking
Communications
Apple Inc.
ActivePush notification delivery
Device push token; notification routing metadata
App users who enable notifications
U.S.
We store tokens; Apple delivers messages via APNs
(To be determined - e.g., Postmark, SendGrid, or Resend)
PlannedTransactional email (account/support)
Email address, message content (service notices)
Website visitors & App users who contact us or receive notices
U.S.
Replace with finalized vendor name before publishing
Payments
Apple Inc.
ActiveIn-app purchase processing
Purchase receipts/tokens, product identifiers
App users who subscribe
U.S./Global
Card details handled by Apple; we receive receipts only
RevenueCat, Inc.
ActiveSubscription entitlements & receipt validation
App/User identifiers, purchase receipts/tokens, entitlement state
App users who subscribe
U.S.
Bridges App Store receipts to app entitlements
AI/ML
OpenAI OpCo, LLC
ActiveLLM inference (text generation)
Prompts, conversation transcripts, context you share
App users
U.S./Global
Configured to process content only to deliver the service; we opt out of provider training where available
Anthropic PBC
ActiveLLM inference (text generation)
Prompts, conversation transcripts, context you share
App users
U.S.
Used selectively alongside OpenAI; provider does not use API data to train models per provider terms
Cartesia
ActiveSpeech/voice (TTS/STT)
Text for synthesis; generated audio; (for STT) audio segments
App users who enable voice
U.S.
Generates assistant's spoken responses; STT used for transcripts as configured
Notes on self-hosted components
- •Redis: We currently operate Redis ourselves on our AWS EKS cluster for caching/session performance. No separate third-party subprocessor is used.
- •Kubernetes tooling: ArgoCD, Kustomize, ESO, and GitHub Actions (OIDC) are build/deploy tools and do not process end-user personal data beyond what appears in build logs/secrets management.
Change management
We update this page for any addition or replacement of a subprocessor. For material changes, we will also note the update in our changelog below.
- •2025-09-15: Expanded list to include AWS core services, MongoDB Atlas, PostHog, LaunchDarkly, Anthropic, RevenueCat, Firebase (Auth/Firestore), and clarified self-hosted Redis.
Contact
Avaplicity, Inc.
7775 Walton Parkway, Suite 100
New Albany, Ohio 43054
Email: privacy@avaplicity.com