Subprocessors
Last updated: September 26, 2026 · Version 2026-09-26
These are the service providers that process personal data to run Keyleads. Each one is bound by a contract that limits its use of the data to providing its service to us. See our Privacy Policy and Data Processing Agreement for how they fit in.
| Provider | What it does for us | Personal data | Location |
|---|---|---|---|
| Supabase | Database, sign-in and realtime updates | Account, workspace and lead data; indexed public posts | AWS region chosen in our Supabase project settings |
| Vercel | Web hosting and server functions | Requests to the site and app, including IP address and request logs | Global edge network; server functions in the region chosen in our Vercel project settings |
| Anthropic | AI scoring of public posts and suggested replies | Public post text and title, your product description and tracked terms, and your website's homepage text during setup | United States |
| Stripe | Payments, invoices, tax and the billing portal | Billing name, email, address, tax ID, payment method, invoices | United States and other Stripe locations |
| Resend | Sending email (sign-in links, invites, billing and product notices) | Email address and message content | United States |
| Inngest | Background jobs (collection, scoring, alerts, retention) | Job payloads: workspace and lead identifiers, event metadata | United States |
| PostHog | Product analytics: in the browser only with your consent; cookie-less server events for signed-in accounts (legitimate interests). Session replay off | Pseudonymous user and workspace IDs, email domain, plan, pages and features used; no post or lead content | European Union (EU cloud) |
| Sign in with Google (OAuth). If you sign in with Google. | Name, email address and Google account ID | Worldwide | |
| Telegram | Lead alerts to your Telegram chat. If you connect Telegram. | Chat ID and alert content (post excerpt, author handle, score) | Worldwide |
| Browser push services (Google, Apple, Mozilla, Microsoft) | Delivering web push alerts to your browser. If you turn on push alerts. | Push endpoint and encrypted alert content | Worldwide |
| Reddit (Data API) | Source of public Reddit posts | Your tracked search terms (sent as search queries) | United States |
| Meta (Threads API) | Source of public Threads posts | Your tracked search terms (sent as search queries) | United States |
| Slack or Discord (operator alerts) | Alerts to the Keyleads team when a collector or job fails | Error summaries; no customer content by design | United States |
Changes to this list
We add a provider to this page at least 30 days before it starts processing customer personal data, and email workspace owners who have asked for notice. Future providers for X and LinkedIn data will be listed here 30 days before use. To ask for change notices, or to object to a new provider, email hello@keyleads.app.