Sub-processors
Last updated 23 August 2026
These are the third parties that process data on our behalf. Every one of them is bound to use what they receive only to provide their service to us. This list is complete as of the date above.
| Sub-processor | Purpose | What they receive | Location |
|---|---|---|---|
| Anthropic | AI inference for research synthesis, and server-side web search for some sources | Subject names and public identifiers, plus text retrieved from public sources | United States |
| Supabase | Database, authentication, and file storage | Account data, subject records, generated alerts and Briefs | United States |
| Vercel | Application hosting and web analytics | Application traffic and aggregate, non-identifying page analytics | United States |
| Inngest | Background job scheduling and orchestration | Job metadata and record identifiers | United States |
| Brave Search | Public web search retrieval | Search queries containing a subject name and public identifiers such as employer or city | United States |
| ProPublica Nonprofit Explorer | IRS Form 990 lookup for organization financials and foundation identification | Search queries containing an organization name or a subject name, and nothing else | United States |
| Fly.io | Worker that fetches and renders public source pages | Requests to public sources, and the public content returned | United States |
| Resend | Transactional and digest email delivery | Account holder email addresses and organization name, plus digest content | United States |
| Stripe | Payment processing, invoicing, and the customer billing portal | Billing contact details and payment card data, collected and stored by Stripe | United States |
| Sentry | Application error tracking on the web application | Error diagnostics, filtered through an allowlist so that record contents are not sent | United States |
| Amazon Web Services | Encrypted off-site database backups | Encrypted backup archives, which we encrypt before upload | United States |
What we send, and what we hold back
Search and AI vendors receive the minimum needed to find a public signal, which is normally a name plus a public identifier such as an employer or a city. A customer’s own internal context, including giving history, capacity ratings, and officer assignments, stays inside our systems and is never sent to a search provider.
Anthropic does not train on data we send and deletes API inputs and outputs within 30 days. Brave does not use query data to train models. ProPublica operates a free public API and has no commercial agreement with us, so no negotiated confidentiality term exists there; the queries we send them carry a name and nothing more, which is why they are listed on the same basis as Brave.
We sell no personal information, share none for advertising, buy none from data brokers, and never contact or solicit the individuals our customers ask us to research.
Changes to this list
Adding a sub-processor that handles customer or subject data means updating this page when the change ships. Customers with a signed data processing agreement receive notice of a new sub-processor as that agreement provides.
To be notified of changes, or to ask about a specific vendor, write to support@benefactorintelligence.com.
Where the sources come from
Sub-processors are vendors that handle data for us. They are distinct from the public sources our research draws on, which are described in the privacy policy.