Sub-processors
Who else touches your data
Last reviewed: July 16, 2026
A “sub-processor” is any company we hire to do part of the work of running Belong — storage, AI inference, payments, sign-in, and so on. We try to keep this list as short as the product allows.
Each entry below tells you what the sub-processor receives, where they run it, why we use them, how long they keep it, and whether they train AI models on what we send. If the answer to the last column is anything other than “No,” we’ll say so plainly.
None of these companies are advertising networks or data brokers. We do not use ad networks, attribution SDKs, or third-party trackers anywhere in the app or on the website.
Current sub-processors
| Name | What they get | Where | Why | Retention | Trains on it? |
|---|---|---|---|---|---|
| Anthropic | Your transcripts, synthesized profile, recent chat context, and relevant memory snippets — sent at the time of each AI request that uses Claude. Claude is Belong’s normal route: Haiku for the normal free tier and Sonnet for the normal Pro tier, with feature-level overrides. Claude always handles the Day 7 challenge profile extraction and capstone reflection. | United States | Generates reflections, reports, chat responses, and memory extractions via the Claude API. | Inputs and outputs are deleted within 30 days under Anthropic’s standard API retention policy, except when longer retention is required for Usage Policy enforcement, legal obligations, or a feature with separate storage behavior. | No by default — Anthropic does not train on commercial API data without express permission. |
| Your transcripts, synthesized profile, recent chat context, and relevant memory snippets — only when an existing stored Gemini preference or a limited Anthropic continuity fallback routes that request to Google. Gemini is not Belong’s normal route and never handles the Day 7 challenge profile extraction or capstone reflection. | United States | Limited continuity for certain retryable Anthropic service interruptions and support for an existing stored Gemini preference. | Google may retain Gemini API prompts and responses for abuse monitoring, safety-policy enforcement, and legal obligations. Its public terms describe the purposes but do not promise deletion after a specific public time limit. | Depends on service tier — paid-service content is not used to improve Google products; unpaid-service content may be used for improvement and human review. Belong will not expand Gemini routing until paid-service configuration is verified. | |
| Supabase | Account, profile, journal entries, transcripts, audio recordings, AI content, embeddings, and logs. | United States (us-west-1) | Primary database, file storage, authentication, and edge functions. | Life of your account; encrypted backups roll off after 30 days. | No. |
| RevenueCat | An anonymous app-user identifier and Apple StoreKit transaction metadata (state, dates). | United States | Manages subscription state across devices and reinstalls. | Life of your subscription, plus their internal log retention. | No. |
| WhisperKit (on-device) | No third party receives the audio for this path. WhisperKit processes eligible shorter recordings locally on your iPhone when the model is ready. | Your device | Provides the on-device transcription path for eligible recordings. | No separate provider retention. The recording is still uploaded to Belong’s private Supabase storage for replay and may use the OpenAI server path described below. | No. |
| Apple — Sign in with Apple | Your Apple ID identifier and (only if you choose to share it) your email and name. | United States | Authenticates you without us seeing a password. | Per Apple's policy. | No. |
| Apple — Push Notification Service (APNs) | A device push token and a generic notification payload (e.g., "Your reflection is ready"). Payloads never contain entry, reflection, or chat content. | United States | Delivers push notifications to your iPhone. | Token rotates on reinstall or revocation; per Apple's policy otherwise. | No. |
| Google — Sign-In | Your Google account identifier and your email and name. | United States | Authenticates you without us seeing a password. | Per Google's policy. | No. |
| OpenAI — Embeddings, TTS & server-side transcription | Your chat messages, short summaries or excerpts of entries, and extracted memory snippets for embeddings; AI-generated reflection text for text-to-speech; and audio recordings routed to server-side transcription. Recordings around three minutes or longer normally use this server path, and shorter recordings can use it when the on-device model is unavailable or fails. OpenAI does not generate your reflections or chat. | United States | text-embedding-3-small produces vectors for memory search; gpt-4o-mini-tts produces reflection audio; whisper-1 provides Belong’s server-side transcription path. | OpenAI currently lists no abuse-monitoring or application-state retention for /v1/audio/transcriptions. Embeddings and text-to-speech requests may be retained for up to 30 days for abuse monitoring unless a legal exception applies. | No by default — OpenAI does not train on API data unless the customer explicitly opts in. |
| Resend | Recipient email address, subject line, and email body for transactional messages (deletion confirmations, beta-feedback acknowledgements). | United States | Sends transactional email from noreply@belongjournal.ai. No marketing tracking pixels. | Send logs retained for proof of delivery; per Resend's policy. | No. |
| Vercel | Aggregate, cookie-less page-view counts on belongjournal.ai. No per-user identifiers, no cross-site tracking. | United States | Hosts the marketing site and provides aggregate analytics. | Per Vercel's policy. | No. |
Notice before we add a new sub-processor
Before we route customer data to a new sub-processor that handles journal content, transcripts, AI inference, audio storage, embeddings, or push notifications, we will:
- Update this page at least 30 days in advance, with the new entry and the planned go-live date.
- Update the “Last reviewed” date at the top.
- Post a dated changelog entry below describing what changed and why.
- Send a one-time email via Resend to the address on file for active accounts when the change is material (i.e., adds a new vendor that touches journal content or AI inputs).
Adding an infrastructure provider that does not touch journal content (e.g., a CDN, status-page host, or error-monitoring tool processing only non-content metadata) will be reflected on this page but may not trigger a 30-day email notice.
Changelog
- June 22, 2026 — Reviewed launch list and kept RevenueCat, Resend, and Vercel listed because they remain active service providers for subscriptions, transactional email, hosting, and aggregate analytics.
- May 4, 2026 — Initial publication of this page.
Questions about any sub-processor on this list? Email matthewericesposito@gmail.com.
