Subprocessors and Data Sources
Last updated: 30 July 2026
This page lists the service providers, subprocessors, data sources, and optional integrations Big Ears AI uses to provide the Service.
Overview
We do not sell personal data. Where a provider processes personal data on our behalf, we require appropriate contractual, security, and data protection commitments.
Some providers are core to the platform. Others are optional and are used only if a client or user enables the relevant feature.
Core subprocessors
| Provider | Purpose | Data categories | Location/notes |
|---|---|---|---|
| Supabase | Database, authentication, file storage, and backend services | Account data, client content, workspace data, contact records, application data, logs | Current client data at rest is stored in the UK Supabase region used by Big Ears AI. |
| Vercel | Hosting, deployment, web traffic handling, and server-side processing | Web requests, application traffic, server logs, limited account/session data | US and global infrastructure. |
| OpenAI | AI text processing, summarisation, recommendations, and drafting | Prompts, excerpts, public-source metadata, client context, draft content | No model training by default for API inputs/outputs. Standard API retention may apply unless eligible retention controls are approved and enabled. |
| Anthropic | AI article generation, content refinement, voice-of-customer, thought-leadership, and style-analysis workflows | Prompts, client context, style guides, uploaded materials, draft content, user instructions | Used for selected AI-assisted drafting and analysis features. Commercial/API retention and security terms apply. |
| Google AI, Gemini, Imagen, and Vertex AI | AI text, image, and video processing for selected social content and media generation workflows | Prompts, brand or report context, generated outputs, media prompts, image previews, related user instructions | Used for selected content and media generation features. We use these services for client data only where paid/commercial API or Google Cloud data processing terms apply. |
| Perplexity | Domain and publication source discovery | Queries, public-source metadata, publication and domain information | Active for selected research workflows. We do not send Client Content or connected mailbox data to Perplexity in the current configuration. |
| Sentry | Error tracking and service monitoring | Error logs, stack traces, browser/device information, limited user/account identifiers where included in logs | Used to maintain reliability and investigate errors. |
Optional integrations
| Provider | Purpose | Data categories | Notes |
|---|---|---|---|
| Google Workspace / Gmail APIs | Connected mailbox sending, reply sync, mailbox aliases, and outreach history | OAuth tokens, mailbox address, aliases, sent outreach, replies, message metadata, relevant message content | Optional. Clients can use core monitoring and intelligence without connecting Gmail. |
| Microsoft Graph / Outlook | Connected mailbox sending, reply sync, mailbox aliases, and outreach history | OAuth tokens, mailbox address, aliases, sent outreach, replies, message metadata, relevant message content | Optional. Clients can use core monitoring and intelligence without connecting Outlook. |
| Slack | Internal or client-selected notifications | Notification content, workspace/channel identifiers, limited account data | Optional depending on configuration. |
| Google Calendar | Demo booking or scheduling workflows | Name, email address, meeting metadata | Optional where scheduling is used. |
| Meta | Advertising and conversion measurement | Website interaction data and conversion events | Used only where enabled and consented to. |
| Advertising and conversion measurement | Website interaction data and conversion events | Used only where enabled and consented to. | |
| SMTP/email delivery provider | Platform notifications and email delivery | Email address, message metadata, message content where sent through the provider | The production SMTP provider is available on request and will be named here once confirmed. |
Data sources and independent providers
| Source | Purpose | Data categories | Notes |
|---|---|---|---|
| Public websites and publishers | News, public articles, public author pages, public contact pages, podcast pages, and public source metadata | Public article metadata, links, short excerpts, bylines, public professional contact details | We do not display full article bodies as a clippings service. |
| Public social platforms | Public posts, bios, handles, engagement signals, and public professional context | Public profile information, public posts, handles, metrics | We do not access content behind login walls or paywalls. |
| Hunter | Professional contact discovery and email verification | Names, domains, company/publication names, professional email addresses, verification results | Hunter provides an EU and UK DPA and a public subprocessor list. |
| Companies House API | UK company records | Company information and public officer/director information where available | Official UK government source. |
| Apple iTunes API | Podcast discovery and metadata | Podcast titles, publisher names, public podcast metadata | Public podcast data source. |
International transfers
Some providers process personal data outside the United Kingdom. Where required, transfers are protected by an adequacy decision, the UK Extension to the EU-US Data Privacy Framework, the UK International Data Transfer Agreement, standard contractual clauses, or equivalent safeguards.
Changes to this list
We review this list regularly. If we add or replace a material subprocessor for Client Personal Data, we will update this page and provide notice with an opportunity to object where required by our Data Processing Addendum or client agreement.
Contact
Questions about subprocessors, data sources, or international transfers can be sent to james@bigears.ai.