Legal
Subprocessors
Last updated: September 24, 2026
A subprocessor is an outside company that handles data on Starproof's behalf. This is every one we use, what each one receives, and whether it's in use today. It matches what ourprivacy policy says.
In use means it handles data now. At launch means it will once Starproof opens to customers, but isn't yet. We only state a data location where we've confirmed it.
Supabase
In useHosts our database and handles sign-in. Also sends the sign-up confirmation and password-reset emails.
What it receives
- Email address and sign-in method
- Business and location names
- Reviews (text, star rating, reviewer name) and replies
- Voice settings
- Subscription plan and status
- Encrypted Google connection tokens
Data location: United States (us-east-1)
Vercel
In useHosts the application and delivers it to your browser.
What it receives
- Everything sent to or from the app in transit
- IP address and standard request logs
Cloudflare (Turnstile)
In useChecks that a person, not a bot, is using the login, sign-up and password-reset forms.
Loaded only on the login, sign-up and password-reset pages.
What it receives
- IP address
- Browser and device signals
- The challenge result
Google (sign-in)
In useLets you sign in with “Continue with Google”.
What it receives
- Your Google account’s email address and basic profile
Google (Business Profile API)
At launchReads new reviews on your Google Business Profile and posts replies to them.
Not connected yet: this starts at launch, once Google approves our access.
What it receives
- Reviews left on your connected locations
- Replies posted on your behalf
- An OAuth token that we store encrypted
Anthropic
At launchWrites the draft of each reply, using the Claude model.
Reply drafting isn’t running in production yet.
What it receives
- Your business name
- The review’s star rating, text and reviewer name
- Your reply tone and always-mention notes
- Replies you have previously edited, as style examples
Paddle
At launchMerchant of record for your subscription: takes payment, handles tax and VAT, and issues invoices.
Payments run in Paddle’s test environment until launch. Paddle’s script is loaded only when you start a checkout from the Account page.
What it receives
- Your name, email, billing address and payment details, entered directly into Paddle’s checkout (Starproof never sees card details)
- We store only your plan, its status and Paddle’s reference numbers
Resend
In useSends email from Starproof.
Today Resend only delivers internal operational alerts to Starproof’s operator. Emails to customers, such as approval notifications, start at launch.
What it receives
- Recipient email address
- The content of the email (today: internal operational alerts)
Have I Been Pwned (Pwned Passwords)
In useChecks a new password against known data breaches when you sign up or reset it.
What it receives
- The first 5 characters of a hash of the password. Never the password itself, and never your email address
We update this page when the list changes; the date above shows when it last did. Questions? Write to privacy@starproof.app.