Subprocessors
The third parties that process customer data on our behalf, what each one actually receives, and where it is held. This list is part of the Data Processing Addendum.
Infrastructure
Engaged for every customer — the product does not run without them.
| Provider | Purpose | Data received | Location |
|---|---|---|---|
| Supabase | Primary database, authentication and file storage | All customer data: contacts, publications, photographs, sign-in identities | United States (AWS us-west-1) |
| Railway | Application and background-worker hosting | All customer data in transit and in process memory | United States |
| Cloudflare | DNS, encrypted off-site backups (R2), inbound email routing | Encrypted database backups and stored files; inbound mail | United States |
| Resend (Amazon SES) | Outbound email — invitations, reminders, upload links | Recipient name and email address, message contents | United States (us-east-1) |
| Stripe | Subscription billing | Billing contact and payment details. Card numbers go directly to Stripe and are never stored by Circulr | United States |
| WorkOS | Authentication for the assistant (MCP) connection | Email address and sign-in events for users who connect an assistant | United States |
| Google Cloud | Google sign-in, and geocoding of addresses you enter | Email address for sign-in; addresses submitted for geocoding | United States |
Artificial intelligence
Engaged only for publications that have the relevant feature switched on. A publication with AI research and semantic search turned off sends nothing to any of these.
| Provider | Purpose | Data received | Location |
|---|---|---|---|
| Anthropic | Research summaries, content extraction, and matching the columns of a file you import (Claude) | Publicly available web pages about the people you track and the text of your own articles, when AI research is enabled; and, when AI import assistance is enabled, the column headings of a file you import together with up to three example values from each column — which for a contact list are real names, email addresses or phone numbers. Never the whole file. | United States |
| OpenAI | Text embeddings, which power semantic search | Article text and interview transcripts, when semantic search is enabled | United States |
| Brave | Web search used to find public sources during research | Search queries containing a person or company name | United States |
Integrations
Engaged only when a publisher connects their own account. Data flows between Circulr and a service the publisher already uses, under credentials they supply and can remove.
| Provider | Purpose | Data received | Location |
|---|---|---|---|
| Google Sheets | Importing a master list you maintain in a spreadsheet | The contents of the sheet you share with us | United States |
| Eventbrite | Importing your events and guest lists | Event and attendee records from your own Eventbrite account | United States |
| Pub Hero | Syncing contacts with your CRM | Contact records exchanged with your own CRM account | United States |
| Plaud | Fetching interview recordings and transcripts you have made | Recording metadata and transcripts from your own Plaud account | United States |
Changes to this list
We will give at least 30 days' notice before a new subprocessor starts handling customer data, by email to workspace owners. If you object on reasonable data-protection grounds within that window, write to privacy@circulr.io and we will work to address it or you may terminate the affected service.