Skip to main content

Legal · Subprocessors

Subprocessors.

Every company that processes data for Brandlism, what it does, what it receives and where it is. If a vendor is not on this page, it does not receive your data.

Last updated · 22 September 2026

What changed in this version. First published as its own page. Cohere has been removed (no longer used). DeepSeek is listed with its location and its fallback-only role.

01Section

Infrastructure and payments

These run the service for every workspace.

  • Supabase

    United States

    Database, sign-in and file storage

    Receives: All account, workspace and client data, including voice memo recordings.

  • Vercel

    United States

    Hosting, serverless functions, cookieless page analytics

    Receives: All data in transit through the application, request logs, IP addresses.

  • Stripe

    United States

    Payments and invoices

    Receives: Billing name, email, payment method, subscription and invoice records.

  • Resend or AgentMail

    United States

    Email delivery (when enabled)

    Receives: Recipient email address and message content.

02Section

AI models

A task goes to one provider at a time, and only the content that task needs goes with it. Answer checks (asking an AI engine what it says about a brand) go to the named engine on purpose, because that engine’s answer is the measurement. We use each provider through its business API, which does not use API data to train models by default.

Which model handles what.

  • Anthropic

    United States

    Primary AI model: analysis, findings, reports and fixes, and Claude answer checks

    Receives: Website content, search results, Brand Map, intake notes and brand context for the task.

  • OpenAI

    United States

    Writing and fallback model

    Receives: Website content and brand context for the task.

  • Google

    United States

    Gemini (AI model, voice memo transcription, Gemini answer checks), Places, PageSpeed Insights, Custom Search, and sign-in and connected accounts through Google OAuth

    Receives: Brand context and website content, voice memo audio, business names and addresses, URLs, OAuth tokens and data from connected Google accounts.

  • Perplexity

    United States

    Live web search and Perplexity answer checks

    Receives: Questions about the brand and its category, brand name and domain.

  • xAI

    United States

    Grok answer checks and fallback model

    Receives: Questions about the brand and its category, brand context for the task.

  • DeepSeek

    China

    Fallback model, used only when the primary model is unavailable, for scoring, classification, website analysis and drafting. Also DeepSeek answer checks, where enabled

    Receives: Website content, public reviews and Brand Map details for the brand being worked on, the text of intake notes being sorted into the Brand Map, and questions about the brand. Voice memo audio is not sent to it.

  • Groq, Together AI, Abacus.AI

    United States

    Fallback model routing (when enabled)

    Receives: Website content and brand context for the task.

  • Mistral

    France

    Mistral answer checks (when enabled)

    Receives: Questions about the brand and its category.

03Section

Search and public data

These return public data about a brand. Most receive no personal data.

  • DataForSEO

    Ukraine

    Search volumes, rankings, AI Overviews and ChatGPT answer checks, link data

    Receives: Domains, keywords and questions about the brand. No account or client personal data.

  • Reddit

    United States

    Public data API: public posts that mention a brand

    Receives: Search terms such as the brand name.

  • SerpAPI, Oxylabs

    United States, Lithuania

    Search result and AI Overview checks (when enabled)

    Receives: Search terms such as the brand name and category.

04Section

Notice of changes

We update this page before a new subprocessor starts processing personal data, with at least 30 days’ notice for customers under the Data Processing Addendum. To be emailed when it changes, or to object to a change, write to legal@brandlism.com with the subject “Subprocessor updates”.