Skip to content

Sub-processors

Effective: May 9, 2026

Restorae uses a small number of third-party service providers to operate the Service. Each one is bound by a written data-processing agreement, acts as a sub-processor under the GDPR, acts as a service provider under the CCPA/CPRA, and does not sell your data. None of them is an advertising network or data broker.

Two Premium features — AI insight narration and program personalization — call Anthropic's Claude API. We send those features the minimum they need: emotion words, derived signals, truncated note excerpts, and journal keywords. We never send full journal entries, and Anthropic does not train its models on Restorae data. The rest of the language-model work — written reflections and personalized program generation — runs on a server we operate inside DigitalOcean, on our own VPC, behind authentication and a strict firewall; those prompts and responses do not leave our infrastructure. We do not use OpenAI, Google AI Studio, Cohere, Hugging Face inference endpoints, or any other third-party language-model API.

Current list

Apple, Inc.

Purpose
App Store billing, Sign in with Apple, push notification delivery (APNs).
Data shared
Subscription state, Apple user identifier, push notification token.
Processing region
United States
In use since
2026-04-22
Their privacy policy
https://www.apple.com/legal/privacy/

Google LLC (incl. Firebase)

Purpose
Play Store billing, Google Sign-In, push notification delivery (FCM), crash reporting (Firebase Crashlytics).
Data shared
Subscription state, Google user identifier, FCM push token, crash traces, Firebase installation identifier.
Processing region
United States
In use since
2026-04-22
Their privacy policy
https://policies.google.com/privacy

RevenueCat, Inc.

Purpose
Subscription entitlement reconciliation across iOS and Android.
Data shared
Restorae user identifier, store transaction metadata.
Processing region
United States
In use since
2026-04-22
Their privacy policy
https://www.revenuecat.com/privacy/

DigitalOcean, LLC

Purpose
Cloud hosting for the backend, the database, the object store (audio + avatars), and a dedicated server inside our network that runs the local language model used for written reflections and personalized programs.
Data shared
All Restorae backend data, including user accounts, encrypted check-in notes, encrypted journal entries, encrypted reflections, encrypted companion messages, and encrypted device sync secrets.
Processing region
United States
In use since
2026-04-22
Their privacy policy
https://www.digitalocean.com/legal/privacy-policy

Anthropic PBC

Purpose
AI insight narration and program personalization (Claude API).
Data shared
emotion words, derived signals, truncated note excerpts, journal keywords — never full journal entries
Processing region
United States
In use since
2026-06-12
Their privacy policy
https://www.anthropic.com/legal/privacy

Twilio Inc. (SendGrid)

Purpose
Transactional email only: account verification, password reset, account-deletion confirmation, and security alerts. Restorae does not send marketing email.
Data shared
Email address, message body.
Processing region
United States
In use since
2026-05-09
Their privacy policy
https://www.twilio.com/legal/privacy

International transfers

All sub-processors above are based in the United States. For users in the EU, UK, or Switzerland, transfers rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) signed with each sub-processor.

Notice of changes

We may add, remove, or replace a sub-processor from time to time. We will update this page on or before the effective date of any change, and — if the change is material — notify active users in-app at least 14 days before it takes effect. If you object to a new sub-processor, your remedy is to delete your account; the in-app and email paths for deletion are described at restorae.app/delete-account.

Contact

Questions about sub-processors or data-processing agreements: privacy@restorae.app.