HavaraPrivate by invitation

Havara: Subprocessors

Effective October 6, 2026

This is the complete list of vendors that touch member data, plus the one that measures visitors to our marketing site, what each one receives, and whether it is actually running today. Two vendors, PostHog and TypeSafe, are wired in but switched OFF and receive nothing; we say what would have to change before either turns on. Two vendors that carried that label have since been switched on, Resend on 2026-08-05 and Sentry on 2026-08-26. In both cases the vendor began processing before this list was updated, which broke the commitment in our Privacy Policy to update this list before switching a Conditional vendor on. This page and the DPA were not yet published, so their 30 days' notice bound no one then. Both flips are recorded in their rows rather than smoothed over.

This page lists the third-party service providers ("subprocessors") that Havara LLC, a Georgia limited liability company, uses to operate Havara, the HOA / residents' community app. A subprocessor is a vendor that processes personal data on our behalf to deliver part of the service.

Every entry carries a Status:

Current subprocessors

NameStatusPurposeData processedData-use commitmentRegion
SupabaseLivePrimary backend: Postgres database, Auth (email + password sign-in, with email magic-link and PKCE password reset as secondary flows), file Storage (documents, avatars, chat attachments, community media, request/violation/ARC photos), Edge Functions, and push-notification orchestration.All account data, community memberships, all user-generated content, documents and embeddings, AI Ask history, push tokens, notification preferences, audit/moderation records, and marketing-site waitlist entries. Also Supabase's own request and sign-in logs: for each request the app or console makes, the IP address, the user agent and the approximate location derived from the IP address (city, region, postal code, country and time zone), with the account's user id when the member is signed in and the email address on sign-in events, kept 7 days.Acts as a processor on our instructions; encrypts data at rest (AES-256) and in transit (TLS) per its published security page (read 2026-07-12). Supabase's published Data Processing Addendum (Version 1, August 1, 2026) supplements and forms part of the Supabase Terms of Service, so it applies to our account without a separate signature. It carries purpose limitation (clause 3.2) and the CCPA prohibitions on selling, sharing and out-of-purpose use (clause 3.3), and it has no clause about AI training (read 2026-09-16). Supabase's Terms of Service, section 8(b), say that to the extent Supabase uses artificial intelligence to provide features to the customer through its services, and in providing its AI Tools (the chatbots and other AI tools it offers for support and similar interactions), it will not use, or allow any third party to use, Customer Data, the customer's AI Input or any AI Output to train, fine-tune or otherwise improve any artificial intelligence or machine learning model without the customer's prior written consent (read 2026-10-02). The commitment is limited to that scope as written; those Terms define Customer Data to exclude aggregated data. Supabase's own subprocessor list (June 1, 2026) names OpenAI, LLC for natural language processing and does not say which data categories reach it.Single hosted project (ref atpkrqchznroqzbmoyap) in the United States, region us-east-2 (US East / Ohio).
OpenAILiveAI text embeddings (text-embedding-3-small) for Ask document search, and moderation screening (omni-moderation-latest), which every Ask question is sent to before it is answered; a flagged question is refused and kept in a moderation log the community's moderators can read, while a moderation call that times out or errors lets the question through. Called server-side by our Ask and document-processing services. OpenAI does NOT perform OCR; scanned PDFs go to AWS Textract (see the AWS row). OpenAI does not generate Ask answers and does not title Ask threads. Thread titles are derived on the device from the first question, with no AI call.Document text/excerpts (during indexing) and the member's Ask question text. No account identifiers are sent in the request body.OpenAI's Data Processing Addendum (updated December 1, 2025, effective January 1, 2026) supplements and is incorporated into the OpenAI Services Agreement (same dates), which applies it whenever the services are used to process personal data (section 5.3), so it applies to our account without a separate signature. Under that agreement OpenAI uses customer content only to provide the services, comply with the law, enforce its policies and prevent abuse, and does not use it to develop or improve its services unless the customer explicitly agrees (section 4.2). Both read 2026-10-02. Per OpenAI's published API data policy (read 2026-07-12): API data is not used to train OpenAI models unless the customer opts in; abuse-monitoring logs are retained up to 30 days.OpenAI API (US-based service via api.openai.com).
Amazon Web ServicesLiveOptical character recognition of scanned / image-only PDFs, via Amazon Textract's asynchronous plain-text detection (StartDocumentTextDetection). The PDF is copied to a private, encrypted, public-access-blocked S3 bucket for the duration of the scan and deleted after the scan, with a 1-day lifecycle rule as backstop. Documents that already contain selectable text are never sent. Called server-side by our document-processing service.The bytes of scanned PDFs with no text layer, and the text recognized from them. No account or community identifiers are sent; the staged object's key carries the document's internal id.The AWS Service Terms (last updated October 1, 2026; read 2026-10-02) incorporate the AWS Data Processing Addendum whenever AWS services process customer data as that addendum defines it (section 1.14.1), so it applies to our account without a separate signature. Per AWS's Textract FAQ (fetched 2026-09-22, re-read 2026-09-23): Textract may store and use document inputs to provide and maintain the service. Unless an AWS Organizations AI services opt-out policy applies, it may also use them to improve Textract and other Amazon AI services and keep some content in another AWS region. That opt-out applies: since September 23, 2026, an AWS Organizations policy has opted the AWS account that runs these scans out of every AI service the policy covers, Textract included. The staged S3 copy is deleted after the scan.AWS (US-based service, us-east-1).
AnthropicLiveGenerates the cited, documents-only Ask answer (claude-haiku-4-5) from retrieved document excerpts. Called server-side by our Ask service.The member's question, prior turns in the same conversation thread, and the retrieved document excerpts. No account identifiers are sent in the request body.Anthropic's Commercial Terms (effective June 17, 2025; read 2026-10-02) say Anthropic may not train models on customer content from its services (Section B), and incorporate Anthropic's Data Processing Addendum by reference (Section C). Anthropic's published retention terms for API customers (updated July 1, 2026; read 2026-10-02) say it deletes API inputs and outputs within 30 days of receipt or generation, with exceptions those terms list, including content its automated trust and safety systems flag as violating its Usage Policy (inputs and outputs kept for up to 2 years, classification scores for up to 7 years) and retention the law requires.Anthropic API (US-based service via api.anthropic.com).
TypeSafeConditional: currently OFF, receives no dataWould evaluate how well each of up to six permission-filtered Ask passages supports the question. The result is a test measurement only and cannot reorder passages, filter passages, change citations, or change an answer. Activation requires both a server setting and a reviewed code setting, and both are currently off.If activated: the current question, at most the preceding question needed to interpret a follow-up, and up to six retrieved excerpts with their document titles and section headings. No name, email, account id, user id, community id, or document id is added to the request, but the question and excerpt text may contain the names of people mentioned in them.TypeSafe's current model documentation says its model is not trained on customer requests or responses (read 2026-09-19). Its customer agreement (last updated 2026-09-19) lets it keep, use and share the data it receives (the questions and excerpts) in perpetuity to derive telemetry, to monitor for fraud and abuse of its services, and as necessary to comply with law, and lets it use that derived telemetry (technical logs, hashes, summary statistics, classifications, metrics and learnings) without restriction, including to improve its products. Its privacy policy says it will not train models on that data and states no fixed retention period (both read 2026-09-22). Zero data retention is an enterprise option, not the default. Before this row changes to Live, Havara will record here the data processing terms it accepted, TypeSafe's retention window for our data, the account tier, and whether zero data retention applies, and will give at least 30 days' notice (see "Changes to this list").TypeSafe API (api.typesafe.ai); hosting region to be confirmed before activation.
Expo (Expo Application Services)LiveDelivers push notifications via Expo's push service (exp.host) for new messages, notices, join decisions, and emergency alerts; EAS is also the build / distribution pipeline. From app version 2.2 (build 35), EAS Update also answers the app's update check (u.expo.dev), made by expo-updates at every app start without waiting for it; publishing an update is a deliberate step Havara takes, and none had been published as of 2026-09-23.Device Expo push tokens and the notification title/body/route payload, which may include message previews unless the member turns previews off (previews default to on). Each update check, read from expo-updates 57.0.23 (FileDownloader on iOS and Android): platform, runtime version (the app version, 2.2), channel (production), the running, embedded and recently failed update ids, any headers Expo's server asked to have sent back, EAS-Client-ID (a random UUID the library generates once and keeps in the app's own storage: UserDefaults on iOS, SharedPreferences on Android), the device's IP address as with any request, and, only after a fatal error, Expo-Fatal-Error, a text description of it cut to 1,024 characters (on iOS a fatal error of the app's code or of the update system; on Android only the update system). No account id, name, email, phone number or push token.Expo offers no separate data processing addendum. Its Terms of Service (last updated May 29, 2025, effective June 30, 2025; read 2026-10-02), section 3.2, make Expo a processor of the personal data in the content customers send through its services where the GDPR applies, bound by module two of the EU standard contractual clauses, and a controller only when it uses that data in aggregated or de-identified form to improve its products or as its privacy policy describes. Per Expo's published policies (read 2026-07-12): push receipts are cleared after 24 hours; Expo states GDPR/CCPA/Data Privacy Framework compliance. Payload-content retention is not documented, so we keep payloads minimal and let members disable previews. The EAS Update pages read on 2026-09-23 state no retention period for update checks; Expo counts each installation that downloads an update as a monthly active user for billing, and one that downloads none is not counted (EAS Update FAQ).Expo / EAS cloud (US-based service). u.expo.dev answers through Cloudflare's network, so a check is received at the edge nearest the device (response headers, 2026-09-23).
AppleLiveiOS app distribution (App Store / TestFlight) and Apple Push Notification service (APNs) for iOS push delivery.App distribution metadata and APNs push payloads relayed to iOS devices.Apple offers no data processing addendum for these services. They run under Apple's Developer Program License Agreement (last updated August 18, 2026; read 2026-10-02). For push, Apple will not access or disclose the content of a push notification unless it believes in good faith that doing so is reasonably necessary to comply with legal process, enforce the agreement, address security, fraud or technical issues, or protect the rights, property or safety of Apple, its developers, its customers or the public, and it may collect technical and diagnostic information about our use of the service (Attachment 1, section 5.6). For distribution, Apple handles App Store users' information as its own Privacy Policy describes.Apple (US-based service).
GoogleLiveAndroid push delivery through Firebase Cloud Messaging, configured in the app's production build, and Android distribution through Google Play.Android push payloads (the same title and body Expo receives, which may include message previews unless the member turns previews off) and app distribution metadata.Firebase Cloud Messaging runs under the Google APIs Terms of Service and Google's Firebase Data Processing and Security Terms (last modified August 21, 2024), which the terms for that service incorporate (Firebase's terms page, last modified September 24, 2026), so they apply to the Firebase project our Android app uses. Google Play distribution runs under the Google Play Developer Distribution Agreement (effective September 15, 2025), under which Google handles the data it collects under its own Privacy Policy and the Google Controller-Controller Data Protection Terms apply (section 9). All read 2026-10-02.Google (global infrastructure).
ResendACTIVE as of 2026-08-05. Was Conditional-OFF until thenSends transactional emails: community invitations, vendor quote-request relays, announcement email mirroring, and operator alerts to the operator's own address, and delivers the sign-in emails Supabase Auth sends (confirming an address, sign-in links, password resets and a change of address). Also the delivery path for the vendor digest, an operator-triggered commercial email to one community's board listing the vendors who bought paid placement there. Its sending key and sender address are now configured, so these no longer fail closed. This row said "receives no data" and that its keys were not configured until 2026-08-05; both statements were false from the moment the keys were set. Our Privacy Policy was corrected on 2026-08-05 in the same change as this note. Since then our push notification service has also emailed a copy of compliance notices, join-request and claim decisions and tenant access notices to members the push did not reach; since member email was switched on on September 30, 2026, only when member email does not send them (below). It never sends, before or after that switch-on, a denial to someone already a member of the community other than the denial of their unit claim, nor the denial of a unit claim to someone no longer a member, unless it cannot read the membership at that moment (below). Our operator alert service emails every waitlist submission to the operator's address.Recipient email addresses, community name and invite code, and a link carrying that code (invites; and, for a welcome a board member sends by hand to an address they give, which no screen offers, the community's name and the name they give); for sign-in emails, which Supabase Auth sends through Resend's mail server to the account's email address: that address and a single-use link or code to confirm it, sign in or reset the password, and, for a change of that address, which no screen in the app or console offers, the new address, sent to both the old and the new one (our authentication settings, read on 2026-09-30, name Resend's mail server); for a vendor quote relay: the vendor's contact email and name, the community's name, the request text, how the resident would like to be contacted, and the requesting resident's own phone number and email address, which the message carries so the business can reply to that neighbor directly, plus a single-use link the vendor opens to answer (added 2026-09-05; the service that sends it is live in production and relayed its first request by email on 2026-09-19); for a request a board writes to a vendor itself: the vendor's contact email and name, the community's name, the board's words and how the board would like to be contacted; for a vendor listing invitation: the vendor's contact email and name and the community's name, plus a single-use link to confirm its details, which is commercial email and carries the same postal address the digest does (added 2026-09-05; none sent as of 2026-09-22); announcement subject/body, the community's name and member email addresses (the address on each member's profile; mirroring); and, to the operator's own address only, the name and email of whoever creates a community, with the community's name, our reference number for it and how people join it, and the name, email and account identifier of everyone who creates an account, and when (the signup alert, added 2026-08-13), and each access request submitted on the havara.app form (name, email, community name and address, role, homes count, how the visitor heard about us, their note, which of our sites it was sent from, when, and our reference number for it); and reports a member files on a declared interest, at most one email every five minutes, each carrying one report (the declaration's words and when it was made or withdrawn, the name of the person who made it, the community and the business, the report's reason and any words sent with it, the reporter's account identifier, not their name, and our reference numbers for the report, the declaration and the community; added 2026-09-25); and the first payment Havara receives (the community, the amount, when it was paid and the payment processor's reference for it), and notices that member email has stopped sending, which carry counts only; each of these alerts can also carry running totals, such as how many accounts or communities there are; and email copies from our push notification service, sent to the email address on the member's profile, only when the push did not reach them: a compliance notice (the community, the rule cited, the board's full notice text and the due date), the answer to a request to join or a claim to a home (the community, and whether it was approved), and a change to a tenant's access (the community, and the end date, or that it no longer has one, or that access has ended), sent before member email was switched on and since then only when member email does not send them (below); and, for a board member, admin or declarant owed a reminder of a compliance calendar deadline, the email address on their profile, the community name, whether it is due soon or overdue, the due date, never the deadline's title, and a link to the calendar, sent only when the push does not reach them (live in production). The signup alert widens this row from a handful of community creators to every user of the product, which is why it is called out rather than folded into the sentence above. Vendor digest (added 2026-08-20, nothing sent yet): the email addresses of one community's board members, together with that community's paid vendor placements, and an unsubscribe link that carries the board member's email address. Unlike everything else in this row, the digest is commercial email, not transactional, because its purpose is to promote businesses that paid for placement. Open tracking and click tracking are off for the havara.app sending domain (read from the Resend account 2026-08-20), so Resend returns us no open or click data. No digest has been sent to any address, so Resend has received nothing under this heading. Member email (added 2026-09-28, switched on as of September 30, 2026): our member email service sends each member email about their own account, home and requests and about their community (Privacy Policy section 4.3): the member's confirmed sign-in email address, the community's name, and what each email shows: in the welcome, the member's name, the names of the community's current board members and links to the apps; the answer to a request to join (that it was not approved); for a tenant, the date their access is set to end, or that it no longer has an end date, or that it has ended; for a charge or payment on the member's own home, its kind (dues, a fine, a fee or interest), the amount, the board's short description and the date; for a compliance notice addressed to them, the rule and the deadline; that the board decided their appeal on a rule, naming the rule but not the outcome; the board's decision on their architectural request, approved or denied, the title of the meeting it put their reconsideration on, and that it kept its decision after reconsidering, each with the request's title; that their request was resolved or their records request answered, with its title; an emergency alert's kind and place; for a meeting, its title, time and place, and whether it was scheduled, moved or cancelled or its minutes posted, and, for a meeting scheduled or moved, its full join link (which can hold a meeting access code) and phone dial-in, unless it is held only in executive session, and whether its agenda includes a special assessment, a change to the rules on how homes may be used or an executive session, never an agenda item's title or details; for a poll, its question and closing time; for an event they said they are going to, its title, time and place and that they said they are going; and in the monthly summary, upcoming meetings and events with their times, open polls with their closing times and whether the member voted, the titles of new documents they can open, decisions logged with their dates, how many of their own requests are open and how many of their architectural requests are in review, their own home's balance, and how many members and new members the community has; and in the daily chat catch-up, how many new chat messages the member has in that community and how many of them mention them, and which of two reasons they get it (Havara cannot send notifications to their phone, or they chose to get it anyway), never a message, its author or a chat's name. Every time is shown in the member's time zone and names it. Every member email also carries a link to the member's notification settings and Havara's postal address, and each kind the member can switch off carries a link with a code that identifies the member's account and the kind of email, in its unsubscribe link and in a header mail apps read, so the unsubscribe works without signing in. A member email never carries a message, a notice's text, an alert's note or a request's text. Since the switch-on the push notification service sends its email copies of join and claim decisions, compliance notices and tenant access notices above only when member email does not send them, including whenever member email is switched off, and always for the answer, approved or denied, to a unit claim (a member's claim to a home) and the approval of any other request from someone who is already a member of the community, which member email does not send. Before and after the switch-on, the denial of any other request from someone already a member is sent by neither: the push notification service reads the membership and sends no push and no email for it, and it sends nothing either for the denial of a unit claim to someone who is no longer a member, whose words ("This does not change your membership") would be false. If that membership read fails, the service sends the usual denial, by push and, when the push does not reach them, by email, and logs the error. Member email and announcement email also carry a code that stops the same email being sent twice, which identifies no one. Nothing queued before the switch-on is ever sent.Resend's Data Processing Addendum (last updated December 31, 2025; read 2026-10-02) becomes binding when a customer accepts Resend's Terms of Service, so it applies to our account without a separate signature. Under it Resend is a processor acting on our documented instructions, deletes customer data within 90 days of account termination, and carries out its primary processing in the United States.Resend email API (US-based service via api.resend.com), and Resend's SMTP mail server (smtp.resend.com) for the sign-in emails Supabase Auth sends.
PostHogConditional: currently OFF, receives no dataWould provide product analytics via HTTP capture. Double-gated: it activates only if (1) an analytics key is set in the app's build (it is not) and (2) the individual member has turned analytics ON in-app. The per-account setting defaults to OFF and fails closed: if the preference can't be read, no events are sent.If both gates were open: event names with non-PII properties (ids, enums, counts) and a distinct user id. The enforced PII rule sends no email, phone, push tokens, or message bodies.Per PostHog's published privacy policy (read 2026-07-12): CCPA service provider; own-purpose product-development use only on aggregated or de-identified data; retains data while the customer account is active.PostHog US cloud by default (us.i.posthog.com); EU host configurable.
SentryACTIVE. Its configuration key was added on 2026-08-21, the first build carrying it was cut 2026-08-26, and the first real events arrived 2026-08-27. Was Conditional-OFF until thenCrash / error reporting over HTTP, switched on in every production build of the app. This row said "currently OFF, receives no data" until 2026-08-26; that became false the moment the key was set, and the key was set without this list being updated first, which is the step the privacy policy commits to.Handled and uncaught JavaScript errors: the error type and message, plus the stack where the call site passed a real Error. More than forty places in the app report handled errors they catch; a global error handler adds uncaught ones. The app also sends short diagnostic messages written by our developers. Every event also carries the level, the environment and the release; a grouping label derived from the caller-supplied scope string; extra details holding that scope plus occasional record ids, such as a poll's or a vendor's id; and the account's user id. Every event reaches Sentry from the device's IP address, and Sentry works out an approximate location from it (city, region and country) and keeps that with the event. From the build after app 2.2 build 36, the app asks Sentry not to store the address, so Sentry does not write it into the event; it still works out the location from the connection's address. Sentry's native SDK for the app is not installed, so there are no automatic breadcrumbs, no performance traces and no device fingerprinting. What the shipped app does contain is our own small reporter, which sends events over HTTP to Sentry's ingest address, built into every production build. Never message bodies, email, phone or push tokens.Sentry is bound by its Data Processing Addendum (version 5.1.0, May 29, 2024), and Havara's Sentry organization accepted it on October 4, 2026 (its Legal & Compliance settings, read October 4, 2026). Sentry's Terms of Service (version 3.0.0, which that organization has also accepted; read 2026-10-02) apply alongside it: Sentry may use the error data only as needed to provide, maintain and improve its service, may use elements that by their nature cannot identify anyone for its other business purposes, and may use other elements for them only where the organization's settings allow; it protects the data with reasonable technical and organizational measures described in its security policy; and it stores the data in the region the organization chose. Error events retained 30 days (free tier) / 90 days (paid); backups deleted after 90 days (published docs, read 2026-07-12). US or EU region, fixed at organization creation.Sentry ingest endpoint (o4511541325004800.ingest.us.sentry.io, US region).
StripeLiveBills the community subscription. Hosted Stripe Checkout is opened from the web console's billing card; our server-side billing services (live in production, verified 2026-08-04) create the session and receive subscription lifecycle events. Individual members are never charged.The billing administrator's payment details, entered directly on Stripe's hosted pages and never received or stored by Havara, plus the billing contact email and community identifier. Havara keeps only Stripe's customer and subscription identifiers, the subscription's status, the trial end date, the paid-until date and the date of any failed payment on the community record (confirmed against the production database 2026-08-04).Stripe's Data Processing Agreement (last updated 18 November 2025) applies to our account automatically: section 4.1 of the Stripe Services Agreement General Terms (last modified 18 November 2025) incorporates it by reference, so no separate signature is needed. The DPA includes Stripe's Data Transfers Addendum, which carries the 2021 EU Standard Contractual Clauses, the Swiss adaptation and the UK International Data Transfer Addendum. Stripe acts as our processor when it provides the service on our instructions, and as its own controller for its stated purposes, which include fraud prevention, choice of banks and payment providers, legal and anti-money-laundering compliance, and product development (DPA section 2). Stripe must notify us of a personal data incident without undue delay, and no later than 48 hours where EU or UK GDPR applies (DPA section 3.1(f)). Stripe appoints subprocessors under a general authorisation and emails 30 days' advance notice of additions only to users who subscribe on its Sub-processors List page (DPA section 3.2). Read from both primary sources on 2026-09-16.Stripe (US-based service via api.stripe.com). Havara's Stripe account is a United States account that bills in US dollars.
CloudflareLiveDNS for havara.app, TLS termination, CDN, and Pages hosting for both the marketing site and the app.havara.app web console. Also handles inbound email routing for the published contact addresses.All web traffic to both sites transits Cloudflare, including IP addresses, request metadata, and TLS-terminated request contents. Inbound email to published addresses is routed by Cloudflare.Havara uses Cloudflare's Free plan, under Cloudflare's Self-Serve Subscription Agreement (last updated September 12, 2025; read 2026-10-02). That agreement incorporates Cloudflare's Data Processing Addendum, with Cloudflare acting as processor or subprocessor, where the content includes personal data of EU or UK data subjects or personal information under the CCPA; it does not incorporate it for other data.Cloudflare global edge network. Traffic is served from the point of presence nearest the visitor, so processing is not US-only.
Cloudflare Web AnalyticsLive: Cloudflare Web Analytics is on, since the site deploy of September 23, 2026 at 01:17 UTC (the evening of September 22 in US Eastern time). This list was not published then, so no 30-day notice ran before it began processing; the Privacy Policy has disclosed it since that deploy. A Conditional row for it was drafted on 2026-09-15 and never published. It processes data about visitors to the havara.app marketing site, collected by Havara as controller for its own purposes; it receives no member dataMeasures page views and page-load performance on havara.app through a beacon script the site build embeds in every page except those whose address can carry an invite code or a single-use token (the invite page, the vendor reply and listing pages, and the not-found page), which also send no referrer. A separate integration from the Cloudflare row above, which is our hosting and DNS provider rather than this product.The page path and the referrer, not the query string; timing and Core Web Vitals metrics read from the visitor's browser Performance API, including the slowest or shifting page element; country, browser, operating system and device type derived from the request, which carries the visitor's IP address.Per Cloudflare's published Web Analytics documentation (read 2026-09-22): it does not log query strings, uses no client-side state such as cookies or local storage, does not collect or use visitors' personal data, states for its Core Web Vitals reporting (Vitals Explorer) that it does not fingerprint individuals via their IP address, user agent string or any other data, and does not track individual end users across the sites that use it. Raw beacon data is kept 7 days and aggregated to about 10 percent of its volume after that; six months are visible to us.Cloudflare's global edge network; the beacon loads from Cloudflare's own script host and reports to Cloudflare's own collection domain, not to a domain we control. The beacon loads without Subresource Integrity because Cloudflare updates the script in place and publishes no hash, and the site's security policy limits the addresses scripts on the page may connect to and where forms may submit. That policy caps two routes out and not a third: it does not stop a compromised script from sending data by navigating the page away, carrying what it collected in the destination it navigates to.

How the AI Ask subprocessors fit together

Two AI vendors currently see a slice of an Ask request (OpenAI to search, Anthropic to answer). A third, TypeSafe, is declared but switched off. None is told who asked.

When a member uses the AI "Ask" tab, the request is handled server-side and touches two live subprocessors in sequence. The declared TypeSafe test evaluation remains off:

In both cases the document content and the question text go to the provider, but no account identifiers are included in the request body. Ask conversation thread titles are not generated by any AI vendor. The app derives the title from the first question locally. Boards can toggle a document out of Ask, which deletes its text chunks and embeddings from retrieval.

Services that are not subprocessors (but you should know about)

One infrastructure service sees traffic but not your account data, and only server-to-server. (Google Fonts was listed here until the web console and havara.app began serving their own fonts; neither sends a font request to Google now.)

What we DON'T do

Changes to this list

We may add or replace subprocessors as the service evolves. When we make a material change to this list (including switching a Conditional vendor to Live), we will provide notice at least 30 days before the new or newly enabled subprocessor begins processing personal data, giving affected communities a reasonable opportunity to review and object per the DPA §7.

Two Conditional vendors were switched to Live before this list was updated: Resend on 2026-08-05 and Sentry on 2026-08-26. Our Privacy Policy commits us to update this list before switching a Conditional vendor on, and in both cases the list was corrected after processing began rather than before. Advance notice cannot be given retroactively.

Cloudflare Web Analytics has been on since the site deploy of September 23, 2026 (01:17 UTC; the evening of September 22 in US Eastern time). This list was not published then, so no 30-day notice ran before it began; the Privacy Policy has disclosed it since that deploy, and it appears on this list for the first time as Live. It processes data about visitors to the havara.app marketing site, collected by Havara as controller for its own purposes, and receives no member data.

Havara determined on 2026-08-28 that no community had accepted a DPA and none was in force. The DPA takes effect only when it is first published at havara.app/dpa, so no Customer existed to receive the §7.3 notice or to exercise the §7.4 right to object, and nothing is owed retroactively to any counterparty. What was broken is the Privacy Policy's public commitment, not this page's or the DPA's (neither had been published) and not a contract.

This list is in effect from October 6, 2026. Havara treats its first publication as the DPA §7.3 notice for every subprocessor on it: a community bound by the DPA from October 6, 2026 may object to any of them under §7.4 until November 5, 2026.

To be notified of changes, watch this page or email privacy@havara.app with the subject "subscribe: subprocessors".


This list reflects the subprocessors in use as of its effective date above. It makes no claim to any security certification or audit (such as SOC 2, ISO 27001, HIPAA, or PCI); see the Security Overview for the measures actually in place. The Data Processing Addendum that covers these subprocessors is the DPA between Havara LLC and each community; how long data is kept (on our side and each vendor's) is in the Data Retention Schedule.