Legal

Subprocessors

Last updated: September 24, 2026

A subprocessor is an outside company that handles data on Starproof's behalf. This is every one we use, what each one receives, and whether it's in use today. It matches what ourprivacy policy says.

In use means it handles data now. At launch means it will once Starproof opens to customers, but isn't yet. We only state a data location where we've confirmed it.

  • Supabase

    In use

    Hosts our database and handles sign-in. Also sends the sign-up confirmation and password-reset emails.

    What it receives

    • Email address and sign-in method
    • Business and location names
    • Reviews (text, star rating, reviewer name) and replies
    • Voice settings
    • Subscription plan and status
    • Encrypted Google connection tokens

    Data location: United States (us-east-1)

  • Vercel

    In use

    Hosts the application and delivers it to your browser.

    What it receives

    • Everything sent to or from the app in transit
    • IP address and standard request logs
  • Cloudflare (Turnstile)

    In use

    Checks that a person, not a bot, is using the login, sign-up and password-reset forms.

    Loaded only on the login, sign-up and password-reset pages.

    What it receives

    • IP address
    • Browser and device signals
    • The challenge result
  • Google (sign-in)

    In use

    Lets you sign in with “Continue with Google”.

    What it receives

    • Your Google account’s email address and basic profile
  • Google (Business Profile API)

    At launch

    Reads new reviews on your Google Business Profile and posts replies to them.

    Not connected yet: this starts at launch, once Google approves our access.

    What it receives

    • Reviews left on your connected locations
    • Replies posted on your behalf
    • An OAuth token that we store encrypted
  • Anthropic

    At launch

    Writes the draft of each reply, using the Claude model.

    Reply drafting isn’t running in production yet.

    What it receives

    • Your business name
    • The review’s star rating, text and reviewer name
    • Your reply tone and always-mention notes
    • Replies you have previously edited, as style examples
  • Paddle

    At launch

    Merchant of record for your subscription: takes payment, handles tax and VAT, and issues invoices.

    Payments run in Paddle’s test environment until launch. Paddle’s script is loaded only when you start a checkout from the Account page.

    What it receives

    • Your name, email, billing address and payment details, entered directly into Paddle’s checkout (Starproof never sees card details)
    • We store only your plan, its status and Paddle’s reference numbers
  • Resend

    In use

    Sends email from Starproof.

    Today Resend only delivers internal operational alerts to Starproof’s operator. Emails to customers, such as approval notifications, start at launch.

    What it receives

    • Recipient email address
    • The content of the email (today: internal operational alerts)
  • Have I Been Pwned (Pwned Passwords)

    In use

    Checks a new password against known data breaches when you sign up or reset it.

    What it receives

    • The first 5 characters of a hash of the password. Never the password itself, and never your email address

We update this page when the list changes; the date above shows when it last did. Questions? Write to privacy@starproof.app.