Subprocessors and Data Sources

Last updated: 30 July 2026

This page lists the service providers, subprocessors, data sources, and optional integrations Big Ears AI uses to provide the Service.

Overview

We do not sell personal data. Where a provider processes personal data on our behalf, we require appropriate contractual, security, and data protection commitments.

Some providers are core to the platform. Others are optional and are used only if a client or user enables the relevant feature.

Core subprocessors

ProviderPurposeData categoriesLocation/notes
SupabaseDatabase, authentication, file storage, and backend servicesAccount data, client content, workspace data, contact records, application data, logsCurrent client data at rest is stored in the UK Supabase region used by Big Ears AI.
VercelHosting, deployment, web traffic handling, and server-side processingWeb requests, application traffic, server logs, limited account/session dataUS and global infrastructure.
OpenAIAI text processing, summarisation, recommendations, and draftingPrompts, excerpts, public-source metadata, client context, draft contentNo model training by default for API inputs/outputs. Standard API retention may apply unless eligible retention controls are approved and enabled.
AnthropicAI article generation, content refinement, voice-of-customer, thought-leadership, and style-analysis workflowsPrompts, client context, style guides, uploaded materials, draft content, user instructionsUsed for selected AI-assisted drafting and analysis features. Commercial/API retention and security terms apply.
Google AI, Gemini, Imagen, and Vertex AIAI text, image, and video processing for selected social content and media generation workflowsPrompts, brand or report context, generated outputs, media prompts, image previews, related user instructionsUsed for selected content and media generation features. We use these services for client data only where paid/commercial API or Google Cloud data processing terms apply.
PerplexityDomain and publication source discoveryQueries, public-source metadata, publication and domain informationActive for selected research workflows. We do not send Client Content or connected mailbox data to Perplexity in the current configuration.
SentryError tracking and service monitoringError logs, stack traces, browser/device information, limited user/account identifiers where included in logsUsed to maintain reliability and investigate errors.

Optional integrations

ProviderPurposeData categoriesNotes
Google Workspace / Gmail APIsConnected mailbox sending, reply sync, mailbox aliases, and outreach historyOAuth tokens, mailbox address, aliases, sent outreach, replies, message metadata, relevant message contentOptional. Clients can use core monitoring and intelligence without connecting Gmail.
Microsoft Graph / OutlookConnected mailbox sending, reply sync, mailbox aliases, and outreach historyOAuth tokens, mailbox address, aliases, sent outreach, replies, message metadata, relevant message contentOptional. Clients can use core monitoring and intelligence without connecting Outlook.
SlackInternal or client-selected notificationsNotification content, workspace/channel identifiers, limited account dataOptional depending on configuration.
Google CalendarDemo booking or scheduling workflowsName, email address, meeting metadataOptional where scheduling is used.
MetaAdvertising and conversion measurementWebsite interaction data and conversion eventsUsed only where enabled and consented to.
LinkedInAdvertising and conversion measurementWebsite interaction data and conversion eventsUsed only where enabled and consented to.
SMTP/email delivery providerPlatform notifications and email deliveryEmail address, message metadata, message content where sent through the providerThe production SMTP provider is available on request and will be named here once confirmed.

Data sources and independent providers

SourcePurposeData categoriesNotes
Public websites and publishersNews, public articles, public author pages, public contact pages, podcast pages, and public source metadataPublic article metadata, links, short excerpts, bylines, public professional contact detailsWe do not display full article bodies as a clippings service.
Public social platformsPublic posts, bios, handles, engagement signals, and public professional contextPublic profile information, public posts, handles, metricsWe do not access content behind login walls or paywalls.
HunterProfessional contact discovery and email verificationNames, domains, company/publication names, professional email addresses, verification resultsHunter provides an EU and UK DPA and a public subprocessor list.
Companies House APIUK company recordsCompany information and public officer/director information where availableOfficial UK government source.
Apple iTunes APIPodcast discovery and metadataPodcast titles, publisher names, public podcast metadataPublic podcast data source.

International transfers

Some providers process personal data outside the United Kingdom. Where required, transfers are protected by an adequacy decision, the UK Extension to the EU-US Data Privacy Framework, the UK International Data Transfer Agreement, standard contractual clauses, or equivalent safeguards.

Changes to this list

We review this list regularly. If we add or replace a material subprocessor for Client Personal Data, we will update this page and provide notice with an opportunity to object where required by our Data Processing Addendum or client agreement.

Contact

Questions about subprocessors, data sources, or international transfers can be sent to james@bigears.ai.