Subprocessors

Last updated: September 28, 2026 · Version 1.3

A subprocessor is a third-party service VoiceBloom uses to operate the platform. We're transparent about every subprocessor, what data they handle, where they're located, and the compliance certifications they hold. We'll notify subscribers by email at least 30 days before adding a new subprocessor that handles personal data.

Why this matters

Under GDPR Article 28, CCPA, PIPEDA, and HIPAA, organizations that process personal data must list every third-party service they share data with, the purpose of each, and the safeguards in place. This page is that list.

Current Subprocessors

ProviderPurposeData locationCertifications / safeguards
Supabase
supabase.com
Database (Postgres), user authentication, file storage, real-time sync United States (AWS us-east region) SOC 2 Type II · HIPAA-eligible with BAA · GDPR DPA available · ISO 27001
Vercel
vercel.com
Application hosting, edge functions, serverless API routes United States (multi-region edge); Europe for EEA traffic SOC 2 Type II · HIPAA-eligible with BAA · GDPR DPA · CCPA-aligned
Vercel Analytics
vercel.com/analytics
Page-view and custom event tracking on marketing pages. Loaded only after the user accepts optional cookies. Pseudonymous; no advertising identifiers United States; Europe for EEA traffic GDPR DPA · CCPA-aligned · cookieless by design
Vercel Speed Insights
vercel.com/docs/speed-insights
Real-user web-vitals telemetry (LCP, CLS, INP) to monitor site performance. Loaded only after the user accepts optional cookies United States; Europe for EEA traffic GDPR DPA · CCPA-aligned · no PII
Google Analytics 4 / Firebase Analytics
marketingplatform.google.com/about/analytics
Aggregate usage analytics for the website (Google Analytics 4) and the iOS / Android apps (Firebase Analytics): page and screen views, sessions, and feature and conversion events. Advertising signals disabled, Google Signals and ad personalization off, no advertising identifier (IDFA) collected, no names / emails / symbol-tap content sent. On the website, loaded only after the user accepts optional cookies, with sensitive URL parameters redacted United States GDPR DPA · Google Consent Mode (ad signals denied) · IP anonymized
HeyCatch
heycatch.ai
Product analytics on the public website and the signed-in account, clinic, and school pages: page views, clicks, and conversion events such as sign-up, trial start, and subscription. Loaded only after the user accepts optional cookies. Not loaded in the communication board or in the iOS and Android apps, so no symbol taps, board vocabulary, or child-composed phrases are ever sent. Receives the account holder's email address and internal user id as account properties; no child names and no child data. Session replay and form-input capture are disabled United States (HeyCatch on DigitalOcean and Vercel; end-user analytics events stored by HeyCatch's own subprocessor PostHog, US Cloud) GDPR DPA · EU SCCs 2021/914 Module Two · UK IDTA and Swiss addenda · session replay and input capture disabled · no SOC 2 or ISO 27001 certification
Cloudflare (Turnstile)
cloudflare.com/products/turnstile
Privacy-preserving anti-bot challenge on the contact, login, and newsletter forms. Receives visitor IP and user-agent; no advertising tracking United States; global edge network SOC 2 Type II · GDPR DPA · ISO 27001 · CCPA-aligned
beehiiv
beehiiv.com
Newsletter and product emails, and the subscriber list they are sent from: the welcome series, getting-started tips during a trial, product news, and reminders such as an unfinished setup or a checkout left open. Receives email address, first name, and flags for trial status, setup completion and discount claims; no child data. Every email carries an unsubscribe link United States GDPR data protection addendum · Standard Contractual Clauses for transfers · CCPA rights honoured
Mandrill (Mailchimp, Intuit)
mailchimp.com
Standby sender for transactional email (receipts, password resets, report notifications). Not in use today: it is kept configured, with its SPF record in place, so sending can be switched over quickly during a Resend outage. If switched on it receives email address and message content, and no child data beyond what that email itself contains United States SOC 2 Type II · GDPR DPA · CCPA-aligned · CAN-SPAM compliant
Stripe
stripe.com
Payment processing, subscription billing, invoicing. VoiceBloom never stores card details United States, EU, UK (regional routing) PCI DSS Level 1 · SOC 1/2 · GDPR DPA · Strong Customer Authentication (PSD2)
Anthropic (Claude API)
anthropic.com
AI text generation for Coach replies (the request includes a summary and a timestamped list of that day's symbol taps), weekly and daily report drafts, and IEP note drafts (the student's name is replaced with a placeholder before sending and restored on-device). The child's communication board sends nothing: character replies are generated on the device. Sent inputs are not used to train Anthropic's models per our API agreement United States SOC 2 Type II · HIPAA-eligible with BAA · ISO 27001 · inputs and outputs deleted within 30 days under standard commercial terms (zero-retention is a separate arrangement we have not entered)
Google Cloud Text-to-Speech
cloud.google.com/text-to-speech
Optional premium ("natural") voices. When a premium voice is selected, the text being spoken (which can include a child's composed phrases) is sent to Google to synthesize audio, then cached on the device. The default on-device voice sends nothing. Inputs are not used to train Google's models per the Cloud API terms United States SOC 1/2/3 · ISO 27001/27017/27018 · HIPAA-eligible with BAA · GDPR DPA · Cloud inputs not used for training
Resend
resend.com
Transactional email delivery (receipts, trial reminders, password resets, weekly reports, access notifications) United States SOC 2 Type II · GDPR DPA · sender domain authenticated (SPF, DKIM, DMARC)
Sentry
sentry.io
Error and crash monitoring. Receives stack traces, page URL, anonymous user ID. No symbol-tap content, no child names, no PII United States SOC 2 Type II · ISO 27001 · GDPR DPA · data-scrubbing enabled by default
Google Fonts
fonts.google.com
Web font (Nunito) on public marketing pages only. The in-app experience uses bundled fonts and does not call Google Fonts Google global CDN No cookies set · IP address visible to Google for font fetch
Google Gemini (image generation)
ai.google.dev
Used during development to generate the bundled symbol illustrations. Not called at runtime by end users United States Used for static asset generation only · no end-user data sent
GitHub
github.com
Source code hosting. Does not process end-user data United States SOC 2 Type II · ISO 27001 · two-factor authentication enforced

International Transfers

Several subprocessors are based in the United States. Where data is transferred outside Canada or outside the EEA, transfers are governed by:

Notification of Changes

We will notify subscribers by email at least 30 days before:

If you object to a new subprocessor and the change is material to your use of VoiceBloom, you may cancel your subscription before the change takes effect and we will refund any prepaid amounts covering the period after the change.

Version History

  • v1.0 · May 14, 2026: Initial subprocessor list published for launch.
  • v1.2 · August 27, 2026: Added HeyCatch (product analytics for the website and signed-in account pages, consent-gated, not used in the communication board or the mobile apps).

How to request a DPA or BAA

Therapy and Education plan subscribers may request a Data Processing Agreement (GDPR Article 28) or a Business Associate Agreement (HIPAA) at any time. Email info@voicebloom.ca with your account email and we will route the request to the right team.