Sub-processors
Last updated: 22 September 2026
A sub-processor is a third party we use to help run Pharos. This page lists every one of them, what they do, and where they're based. We keep this page current so you always know who is involved in processing your data.
If you have a Data Processing Agreement (DPA) with us, we'll notify you at least 30 days before we add a new sub-processor, unless the change is required for security reasons.
Core infrastructure
| Sub-processor | What they do | Location | Privacy policy |
|---|---|---|---|
| Supabase | Managed PostgreSQL database, authentication, file storage | USA (AWS us-east-1, N. Virginia) | supabase.com/privacy |
| Vercel | Web hosting and CDN for heypharos.com and app | Global edge | vercel.com/legal/privacy-policy |
| Stripe | Payment processing, subscription billing, tax | USA + EU | stripe.com/privacy |
| Resend | Transactional and onboarding email delivery | USA | resend.com/legal/privacy-policy |
Analytics
| Sub-processor | What they do | Location | Privacy policy |
|---|---|---|---|
| PostHog | Product analytics (feature usage, funnels) | USA / EU | posthog.com/privacy |
| Microsoft Clarity | Session recording and heatmaps | USA | privacy.microsoft.com/privacystatement |
AI traffic tracking
If you add Pharos's AI-traffic tracking to your website, we record visits from AI assistants and their crawlers. To show which country and city those visits come from, we may send the visitor's IP address to an IP-geolocation service when the request does not already carry a location. We store the resulting country and city, not the IP address itself (bot verification keeps only a one-way hash of it).
| Sub-processor | What they do | Location | Privacy policy |
|---|---|---|---|
| ipapi.co (Kloudend, Inc.) | Looks up the approximate country and city of a website visitor's IP address for AI-traffic reports | USA | ipapi.co/privacy |
AI platforms (queried on your behalf)
These are the services Pharos uses to put your prompts to AI platforms and collect the answers that make up your brand-visibility data. What we send is the prompt text you set up in your dashboard (which includes the brand and competitor names you track), the language, and the country or city we ask the answer to reflect. We do not send your account details or any personal data about your customers.
How answers are collected. For ChatGPT, Gemini and Google AI Mode, we collect the answer the public consumer app gives a logged-out user, through a data-collection provider (DataForSEO, with Bright Data as a backup). If neither can return an answer, we ask the AI provider's own API instead. Claude and Perplexity answers come from their providers' APIs.
| Sub-processor | What they do | Location | Privacy policy |
|---|---|---|---|
| DataForSEO | Sends your prompts to the consumer ChatGPT, Gemini and Google AI Mode apps and returns the answers to us (our main route for those three) | Estonia (EU); servers in Germany and the USA | dataforseo.com/privacy-policy |
| Bright Data | Backup route for the same: sends your prompts to the consumer apps when DataForSEO cannot return an answer | Israel | brightdata.com/privacy |
| OpenAI | ChatGPT prompt → response through the OpenAI API, when the consumer-app route is unavailable. Also analyses your data and writes content: see the next section | USA | openai.com/policies/privacy-policy |
| Gemini prompt → response through the Gemini API, when the consumer-app route is unavailable. Also analyses your data and writes content: see the next section | USA + EU | policies.google.com/privacy | |
| Anthropic | Claude prompt → response. Also analyses your data and writes content: see the next section | USA | anthropic.com/legal/privacy |
| Perplexity | Perplexity prompt → response | USA | perplexity.ai/hub/legal/privacy-policy |
AI models that analyse your data and write content
Beyond collecting answers, Pharos uses AI models to work with your account data: to analyse the collected answers (mentions, sentiment, how your brand and competitors are framed, citations), to generate prompts, recommendations, insights, report summaries and content drafts, and to answer questions in the in-app assistant. What these models receive is your brand data (brand, competitor and topic names, prompts), the collected AI answers and the pages they cite, content you write or ask us to optimise (including text from your own website), and messages you send to the assistant. We do not send your account details or payment data.
| Sub-processor | What they do | Location | Privacy policy |
|---|---|---|---|
| Google (Gemini API) | Main model for analysis and generation: recommendations, insights, report summaries, content drafts and optimisation, prompt suggestions and translation, and the in-app assistant | USA + EU | policies.google.com/privacy |
| Anthropic (Claude API) | Analyses collected answers (sentiment, framing, rankings); reviews generated recommendations; backup for generation | USA | anthropic.com/legal/privacy |
| OpenAI (API) | Backup for analysis and generation when the models above are unavailable | USA | openai.com/policies/privacy-policy |
| TypeSafe (TypeSafe AI, Inc.; api.typesafe.ai) | Answers narrow, fixed-choice questions about your data, such as the intent of a prompt, what kind of page a cited source is, whether a name in an answer refers to your brand, and how a recommendation should be classified. It receives the short piece of text being judged (for example an excerpt of an AI answer, a brand or competitor name, a prompt, or a cited page's title and address) | USA | typesafe.ai/legal/privacy-policy |
Where we use an AI provider's API, we send traffic through zero-retention / no-training endpoints where the provider offers them, so your prompts aren't used to train its models. TypeSafe's terms commit it not to train or fine-tune models on what we send it. Answers collected from consumer apps are collected logged out, with no account of yours. If you have a specific compliance requirement, email privacy@heypharos.com.
International transfers
Our primary database (Supabase) and several other sub-processors are in the United States, and one (Bright Data) is in Israel, which the European Commission and the UK recognise as providing adequate protection for personal data. For other transfers we rely on:
- EU Standard Contractual Clauses (SCCs) approved by the European Commission for transfers from the EEA.
- UK International Data Transfer Addendum for transfers from the UK.
- Swiss data protection framework for transfers from Switzerland.
Change notifications
Enterprise customers with a signed DPA: we'll email your designated privacy contact at least 30 days before any new sub-processor is added, unless the addition is required to respond to a security incident.
Everyone else: this page is the authoritative list. Watch the "Last updated" date.
Contact
Questions: privacy@heypharos.com.
Adapted from Basecamp's open-source policies (CC BY 4.0).