Sub-processors
Last updated July 9, 2026 · Effective July 9, 2026. Every third-party service that processes personal data on Jobeezy’s behalf — what it does, the data it touches, where it runs, and its role. This is the complete, current list our Privacy Policy points to.
Last updated: July 9, 2026 · Effective: July 9, 2026.
Plain-language summary. A “sub-processor” is an outside company we hire to help run Jobeezy — for example, to host our servers, store your résumé, or run the AI that tailors your applications. Each one handles some of your data on our behalf, only for the job we hire it to do, and only under a contract that protects your data. This page lists all of them. We do not sell your data, we do not use advertising trackers, and your voluntary demographic (EEO) answers are kept out of every AI, analytics, and automation service on this list. The full list and details are below. If a summary sentence and the full text ever disagree, the full text controls.
How we tell you about changes. We give you at least 30 days’ advance notice before a new or replacement sub-processor that processes personal data takes effect, through our changelog and by email to customers who have a signed Data Processing Addendum (“DPA”). If you have a signed DPA, you may object as described there. See How we notify you of changes below.
1. How to read this list
This is the register of third-party services (“Sub-processors”) that process personal data on Jobeezy’s behalf under our instructions, as those terms are used in our Data Processing Addendum and the Sub-processors section of our Privacy Policy. It is complete and current as of the date above.
- Processor vs. independent controller. Most vendors below are Processors: they act only on our instructions. A few — Apple and Google Play — act as independent controllers for the subscription billing they run under their own terms; we never receive or store your full payment-card number.
- Legal entity. We name each vendor’s corporate entity for identification. Entity names should be confirmed against each executed vendor contract; brand and entity can differ.
- Region. Regions are deployment facts. Data is processed in the United States unless a broader region is noted (for example, a vendor with global edge or global model routing). See International data transfers below for how we protect data that moves outside your country.
- Data shared. Each vendor receives only the data its purpose requires. Your voluntary demographic (EEO) answers are never shared with any AI, analytics, or automation vendor on this list — see Your demographic (EEO) data is excluded.
2. The sub-processor list
All entries are Processors unless the Role column says otherwise. AI providers process your content under no-training terms — your content is never used to train any third-party model — and, where the provider supports it, under zero data retention (see Our commitments).
| Sub-processor (legal entity) | Purpose | Data shared | Region | Role |
|---|---|---|---|---|
| Cloud infrastructure & data | ||||
| RenderRender Services, Inc. | Compute (web + worker), hosting, cron scheduling, logging | All service data transits and executes here | US (Virginia) | Processor |
| MongoDB AtlasMongoDB, Inc. | Primary database | Profile, résumé metadata, applications, outcomes, quotas (EEO data isolated) | US (AWS us-east-1) | Processor |
| Cloudflare R2Cloudflare, Inc. | Object storage | Résumé files and text, generated documents, Auto-Apply screenshots and browser traces | Global edge + US | Processor |
| Authentication & identity | ||||
| ClerkClerk, Inc. | Authentication, sessions, and identity (stores your sign-in credentials) | Email, name, auth identifiers | US | Processor |
| Artificial intelligence (LLM & embeddings) | ||||
| OpenRouterOpenRouter, Inc. | Primary LLM + embeddings: job matching, résumé and cover-letter tailoring, Auto-Apply form-fill, interview prep | Résumé text, cover letters, job descriptions, intake answers, apply-form screenshots — sent under no-training terms; our AI-generation requests deny provider data collection | Global (routes to various model hosts) | Processor |
| AnthropicAnthropic, PBC | Fallback / additional LLM (direct and routed through OpenRouter) | Same prompt content as above | US | Processor |
| Google — AI Studio (Gemini)Google LLC | Conditional non-PII-only LLM generations (never résumé, cover-letter, or intake content) | Non-PII prompts only, and only when this path is enabled | US / Google infrastructure | Processor |
| Job data & assisted applications (Auto-Apply) | ||||
| ApifyApify Technologies s.r.o. | Ingestion of public job postings | No end-user PII — employer and job-posting data only | EU / US | Processor |
| BrowserbaseBrowserbase, Inc. | Managed, isolated cloud browsers that fill and submit applications you authorize | The approved application content and employer page contents, for the session only | US | Processor |
| 2captcha2Captcha operator — confirm entity | Solving CAPTCHAs encountered during Auto-Apply | The employer application page URL and CAPTCHA site key (not your profile PII) | Global | Processor |
| Billing & subscriptions | ||||
| RevenueCatRevenueCat, Inc. | Subscription entitlement and receipt validation | Pseudonymous app user id, purchase and entitlement state (no résumé data, no card data) | US | Processor |
| Apple / Google PlayApple Inc.; Google LLC | In-app subscription billing (Google Play also routes push transport) | Purchase and transaction state; some push tokens. We never receive your full card number. | US / global | Independent controllers (billing) |
| Email & push notifications | ||||
| ResendPlus Five Five, Inc. (Resend) — confirm | Transactional email, inbound and outbound (including delivery of your data export) | Recipient email address, message content | US | Processor |
| Expo Push Service650 Industries, Inc. | Push-notification delivery (routes to APNS/FCM underneath) | Device push token + notification title and body | US | Processor |
| Analytics & monitoring | ||||
| PostHogPostHog, Inc. | Product analytics and feature flags (server + mobile) | Pseudonymized usage events (configured to strip direct identifiers before send) | US | Processor |
| SentryFunctional Software, Inc. (Sentry) | Error monitoring and crash reporting (server + mobile) | Error and crash traces, configured to scrub personal data before send | US | Processor |
| Google — Analytics (GA4)Google LLC | Product and marketing analytics: marketing-site gtag (IP-anonymized) and server-side Measurement Protocol events |
Event parameters; a pseudonymous user id on server events | US / global | Processor |
| Google — FirebaseGoogle LLC | Mobile analytics and Remote Config (feature flags); Crashlytics SDK bundled | Mobile analytics events; device and app attributes | US / Google infrastructure | Processor |
A note on Google. Jobeezy moved its core stack off Google Cloud: our hosting, database, storage, authentication, and primary AI now run on Render, MongoDB Atlas, Cloudflare R2, Clerk, and OpenRouter/Anthropic. We tell you honestly what still uses Google: Google Analytics (GA4), mobile Firebase Analytics and Remote Config, and a conditional non-PII-only Gemini path remain in use, and they are listed above. We do not claim Google is fully removed.
3. Analytics services — and what they never receive
The analytics services above measure how the product and marketing site are used. None of them ever receives your résumé, cover-letter content, application content, or EEO answers. Here is exactly where each one runs and what it processes:
- Google Analytics (GA4) — marketing-site
gtag. On the marketing site (jobeezy.com) only, GA4 measures anonymous page traffic. It runs with IP anonymization, and we honor the Global Privacy Control (GPC) as an opt-out of sharing for cross-context behavioral advertising. - Google Analytics (GA4) — server-side product events. Separately, a server-side Measurement Protocol path records pseudonymized product events with a pseudonymous user id. This path processes product-usage events from signed-in users, but never your résumé, cover-letter, application content, or EEO answers.
- Firebase Analytics and Remote Config. These run inside the mobile app for usage measurement and feature flags, alongside PostHog. For signed-in users they process pseudonymized app-usage events and device and app attributes — but never your résumé text, application content, or EEO answers.
Analytics is not advertising. We do not use advertising pixels or advertising cookies, and we do not sell your personal data — not to brokers, not to recruiters, not to anyone. Our revenue comes from subscriptions.
4. Auto-Apply and onward transfer to employers
When you approve a specific job, Jobeezy acts as your agent and submits the application you reviewed by driving a managed, isolated cloud browser through Browserbase. A few things about how that works:
- Sessions are isolated and short-lived. Each Auto-Apply run uses its own browser session, which is torn down after the submission. Nothing about your session persists on the browser afterward.
- Your data is onward-transmitted to the employer. The application content you approved — for example your contact details, screening answers, and résumé — is sent to the employer’s own application system to complete the submission. Each employer and applicant-tracking system (“ATS”) is an independent controller for the data it receives; once your application reaches an employer, that employer’s own privacy practices apply.
- For most systems we apply as a guest (no account, no stored login). Only for Workday do we create a candidate account on your behalf, generate and vault-store its password, and use a Jobeezy-managed email alias. We do not automate your personal LinkedIn, Indeed, or other logins, and we do not post under your name outside the job you approved.
- 2captcha may be used to solve a CAPTCHA on the employer’s page during a run. It receives the employer page URL and the CAPTCHA site key — not your profile data.
Onward AI routing. OpenRouter routes prompts to underlying model hosts to do its work, so a zero-retention promise is only as strong as the model your request is routed to — which is why we say zero data retention applies “where the provider supports it.” In all cases, your content is under no-training terms and is never used to train a third-party model.
5. International data transfers
Jobeezy is based in the United States, and most processing happens there. Some vendors run in more than one region — for example, OpenRouter routes to various model hosts, Apify runs in the EU and the US, and Cloudflare R2 uses global edge locations. For users in the European Economic Area, the United Kingdom, and Switzerland, transfers of personal data outside your country rely on the EU Standard Contractual Clauses (Module Two), the UK International Data Transfer Addendum (IDTA), and the Swiss addendum, as described in our Data Processing Addendum. A “Region” cell alone is not a transfer basis; the DPA is.
6. Your demographic (EEO) data is excluded
EEO answers are walled off from every vendor on this list. Your voluntary equal-opportunity answers — your race, ethnicity, sex, disability, and veteran-status (EEO) information — are stored in an isolated collection and are never joined into matching, scoring, tailoring, or Auto-Apply, and are never sent to any AI, analytics, or automation service above. They reach an employer only if you explicitly approve it for a specific application, and they are erased immediately when you delete your account. This is enforced by architecture, not just policy.
This is different from fair-chance information — the criminal-record, justice-impacted, or reentry details you may choose to add. That information is treated as sensitive and is never sold, but it is not isolated the way EEO answers are: we use it to help tailor your applications and match you to jobs, and it feeds the fairness dimension of your Fit Score (which is guidance for you, never a report sent to an employer). It is shared with an employer only as you direct. See our Privacy Policy and Fair-Chance Statement for the full explanation.
7. Our commitments
- No data brokers, no ad networks. Nothing on this list buys, sells, or resells your personal data, and none of it is an advertising network.
- Purpose-bound. Each sub-processor receives only the data its listed purpose requires.
- No training on your content. Our AI providers process your content under no-training API terms; your content is never used to train any third-party model, and zero data retention applies where the provider supports it.
- Scrubbing by configuration. Analytics and error-monitoring vendors are configured to strip or scrub direct identifiers before data is sent; we describe this as a configured control, not a guarantee that every field is caught.
- Written contracts. Each Processor is bound by a data-processing agreement that limits it to our instructions and requires appropriate security.
For our security practices — encryption, access control, and monitoring — see our Security page. This page does not restate cryptography specifics; the Security page is the single source for those.
8. How we notify you of changes
We will give you at least 30 days’ advance notice before a new or replacement sub-processor that processes personal data takes effect, through our changelog and by email to customers who hold a signed DPA. If you have a signed DPA, you may object to a new sub-processor as described there; we will work with you in good faith to address a reasonable objection. Customers on a signed DPA can request to be added to our sub-processor-change notification list by emailing legal@jobeezy.com.
9. Questions and contact
Questions about a sub-processor, or want to raise an objection under a signed DPA? Email legal@jobeezy.com. For privacy requests and rights, email privacy@jobeezy.com. You can also write to us at Jobeezy, Inc., 800 Brazos St., Suite 400, Austin, TX 78701, USA.
See also our Data Processing Addendum, Privacy Policy, and California notice.