Sub-processor DPA + Sub-processor Register

This page names every provider ("sub-processor") that processes personal information on our behalf. The Sub-processor register at the bottom is the current, published source of truth for the Privacy Policy §5.1 list and the Notice at Collection page. The Addendum body sets out the standard data-processing terms we apply with each provider, tied to our Privacy Policy commitments around Sensitive Personal Information (SPI), the AI-tier carve-out, and CCPA/GDPR audit obligations.

Last updated: 2026-08-11


Addendum body

These are the standard data-processing terms we apply with each sub-processor named in the register below. Bracketed fields (e.g. [SUB-PROCESSOR LEGAL NAME]) are completed for the specific provider when the terms are executed. The current list of sub-processors is the Sub-processor register at the end of this page.

This Sub-processor Data Processing Addendum ("Addendum") is entered into between All You Can App, Inc., a Delaware corporation ("Controller"), and [SUB-PROCESSOR LEGAL NAME] ("Processor"), and supplements the [BASE AGREEMENT TITLE AND DATE] between the parties. In the event of conflict, this Addendum controls with respect to the processing of Personal Information on Controller's behalf.

1. Definitions

Terms not defined here have the meanings given in the Base Agreement or in the applicable Data Protection Laws.

2. Scope and roles

For the Personal Information that Controller transmits to Processor under the Base Agreement:

Processor will Process Personal Information only on Controller's documented instructions, only for the permitted purposes in Section 4, and only for the duration of the Base Agreement (plus any period required for deletion or return under Section 11).

3. Categories of Personal Information processed

Processor processes the following categories on Controller's behalf:

Category (CCPA §1798.140)ExamplesSPI?
IdentifiersName, email, account ID, IP addressNo
Customer recordsBilling name, address, payment-method metadataNo
Commercial informationSubscription tier, purchase historyNo
Internet activityPages visited, errors, basic telemetryNo
Approximate geolocationCity-level only, IP-inferredNo
InferencesZone classification, stage-of-changeYes (derived from SPI)
Sensitive Personal InformationSelf-reported mental/physical health: sleep, energy, focus, mood, chronic conditions, recovery actionsYes

The actual scope for this Processor is narrower than the full list above. The specific categories Processor receives are listed in Schedule A.

4. Permitted purposes

Processor may Process Personal Information only:

Processor will not:

5. Sensitive Personal Information — additional restrictions

For SPI (the categories marked "Yes" in Section 3), Processor will additionally:

6. Data subject rights

Processor will assist Controller in responding to verifiable data subject requests under CCPA §1798.110–106 and GDPR Arts. 15–22 (access, deletion, correction, portability, restriction, objection, and limitation of SPI use) by:

7. Security

Processor will implement and maintain appropriate technical and organisational measures designed to protect Personal Information, including at minimum:

8. Sub-processors

Processor may engage Sub-processors only if:

9. International transfers

For transfers of Personal Information from the EEA, the UK, or Switzerland to a third country that has not received an adequacy decision, the parties incorporate by reference the EU Standard Contractual Clauses (Implementing Decision 2021/914), UK International Data Transfer Addendum, and Swiss equivalents, with the modules and roles selected per Schedule C.

For data subjects in California or other US states with comprehensive privacy laws, Processor confirms that it is bound by this Addendum to provide privacy protections at least equivalent to those available in the originating jurisdiction.

10. Incident response

Processor will:

11. Return and deletion

On termination of the Base Agreement, or earlier on Controller's written request, Processor will, at Controller's option, return or securely delete all Personal Information in Processor's possession or control:

12. Audits

Controller (or an independent third-party auditor under reasonable confidentiality terms) may audit Processor's compliance with this Addendum once per calendar year on at least 30 days' written notice, plus any time after a confirmed security incident materially affecting Controller's Personal Information.

Processor's then-current SOC 2 / ISO 27001 / equivalent report satisfies the routine audit right, provided the scope is sufficient to evaluate compliance with this Addendum.

13. Liability and indemnification

The liability and indemnification provisions in the Base Agreement apply. Notwithstanding any general liability cap in the Base Agreement, Processor's liability for breach of this Addendum, to the extent the breach involves a violation of Data Protection Laws or a confirmed unauthorised disclosure of SPI, is not subject to the general cap and is in addition to any statutory remedies available to Controller or affected data subjects.

14. Order of precedence

If there is a conflict between this Addendum and the Base Agreement, this Addendum controls with respect to the Processing of Personal Information.

15. Governing law and disputes

This Addendum is governed by the law of Delaware, USA, and any dispute is resolved under the dispute-resolution mechanism set out in the Base Agreement. The choice of law does not deprive a data subject of the protections of their local law where mandatory.

16. Signatures

For Controller — All You Can App, Inc.:

Name: ____________________________ Title: ____________________________ Signature: _______________________ Date: _____________________________

For Processor — [SUB-PROCESSOR LEGAL NAME]:

Name: ____________________________ Title: ____________________________ Signature: _______________________ Date: _____________________________


Schedule A — Categories of Personal Information processed by this Processor

Fill in per-processor. Below is the recommended starting list for each sub-processor in our current Privacy Policy §5.1. Strike through any category the Processor does not in fact receive.

Supabase (database, authentication, file storage)

Vercel (web hosting, edge compute)

Stripe (payment processing)

RevenueCat (cross-channel subscription & entitlement management; mobile in-app purchases + Stripe reconciliation)

Resend (transactional email)

Anthropic (AI features on Always-on AI / Calibration Burst tiers only)

Deepgram (voice input — speech-to-text on all tiers)

OpenAI (text-to-speech on Always-on AI / Calibration Burst tiers only)

Twilio (SMS notifications on all tiers, opt-in; per-tier monthly caps)

Expo (Expo Application Services — mobile push notification delivery proxy)

Google LLC (Google Calendar API; only when Director authorises calendar integration)

Discord Inc. (community server hosting; only when Director voluntarily links their Discord account)


Schedule B — Data subject request handling mechanism

Per-processor. Describe whether requests are handled via:

For each, list the SLA (e.g. "within 7 days of receipt") and the escalation path if the SLA is missed.


Schedule C — International transfer mechanism

For each Processor, identify the operative transfer mechanism:

Originating regionReceiving regionMechanism
EEAUSAEU SCCs (2021/914), Module 2 (controller → processor)
UKUSAUK International Data Transfer Addendum
SwitzerlandUSASwiss FADP equivalents
California / other USUSAThis Addendum + Processor's base DPA

Confirm Transfer Impact Assessment (TIA) is on file for each non- adequacy-decision route.


Sub-processor register

The current source of truth for the Privacy Policy §5.1 list and the Notice at Collection page. The Governing DPA column names the standard DPA under which each provider processes personal information on our behalf. "Last reviewed" is the date this register row was last checked.

Sub-processorServiceGoverning DPA (standard terms)Last reviewedSensitive PI?Region
SupabaseDB / auth / storageSupabase DPA2026-08-11YesUSA / EU
VercelHostingVercel DPA2026-08-11NoUSA
StripePaymentsStripe DPA / Services Agreement2026-08-11NoUSA
RevenueCatCross-channel subscription & entitlement management (mobile Apple/Google in-app purchases + Stripe reconciliation → onward: Apple App Store + Google Play Billing)RevenueCat DPA2026-08-11Identifiers + commercial info (subscription / entitlement / purchase history); no Director content, email, or IP transmittedUSA
ResendEmailResend DPA2026-08-11NoUSA
AnthropicAI inferenceStandard commercial terms (custom DPA / ZDR declined 2026-05-26 — see docs/ANTHROPIC_DPA_REQUEST.md)2026-05-26Yes (in-session only)USA
DeepgramVoice speech-to-textDeepgram DPA (mip_opt_out=true sent on every request)2026-08-11Yes (in-session only)USA
OpenAIText-to-speechOpenAI DPA (zero-retention for audio / TTS)2026-08-11No (response text only, no Director input)USA
TwilioSMS notificationsTwilio DPA2026-08-11Identifiers (phone) + notification copy; TCPA-relevantUSA
Google LLCGoogle Calendar APIGoogle Cloud Platform / API Data Processing Terms2026-08-11Calendar metadata (opt-in); written events reference task names onlyUSA
Expo (Expo Application Services)Native mobile push delivery proxy → Apple APNs (iOS) + Google FCM (Android) as onward sub-processorsExpo / EAS Terms of Service2026-08-11Push token (opaque per-install identifier) + notification payload (structural strings only, no free-write text); no email/account ID/IP transmittedUSA
Discord Inc.Community server hosting (opt-in: directors linking Discord in Settings → Subscription)Discord Developer Terms + Data Processing Addendum2026-08-11Identifier only (Discord user ID + username + role state derived from Director's All You Can App tier); no Director content, email, or IP transmitted; role tied to All You Can App subscription state, not a Discord-side purchase; not a sale or sponsorship — voluntary community accessUSA

Owner: All You Can App, Inc. — support@allyoucan.app Cadence: review on every new sub-processor; full audit annually.

The current list of sub-processors above is the published disclosure; it is kept in sync with the Privacy Policy §5.1 list and the Notice at Collection page.