Subprocessors
This list reflects subprocessors active as of the last-updated date, verified against the live system. We will update this list as subprocessors are added or removed, with reasonable advance notice for material additions.
Effective Date: July 9, 2026
Last Updated: August 21, 2026
This page lists the third-party subprocessors that Ficombinator LLC uses to provide the SoloSearcher Service. A subprocessor is any third party that processes personal data on our behalf. All subprocessors are contractually required to process data only as instructed, implement appropriate security measures, and comply with applicable data protection law.
A note on scope: the Service performs no AI analysis of its own and sends nothing to an AI model provider. AI work runs in the agent you connect, under your own account with your own provider — so that provider is your processor, not ours, and does not appear below. See the Privacy Policy Section 3.4.
Company data sits in two places — a shared baseline universe compiled from public records, which every user searches and which is never built from any user's workspace, and each user's private workspace, visible only to them. Company records in both describe businesses rather than Service users. Two entries below (geocoding) receive only business addresses from those records, and are listed for transparency even though they process no Service user's personal data.
Active Subprocessors
| Subprocessor | Purpose | Data Processed | Location |
|---|---|---|---|
| Clerk, Inc. | Authentication & identity | Email, name, session tokens, login metadata | United States |
| Neon, Inc. | PostgreSQL database | All application data at rest (private workspace data encrypted per user) | United States |
| Vercel, Inc. | Application hosting | Request logs, function execution metadata | United States / Global CDN |
| Vercel, Inc. (Web Analytics) | Aggregate page analytics on the public site | Page views with the address reduced to a route template; no criteria, email, or invitation token | United States / Global CDN |
| Cloudflare, Inc. (R2) | Object storage | Uploaded documents, encrypted at the application layer before storage | United States |
| Upstash, Inc. | Rate limiting | Request counters keyed by account/network identifiers — no content | United States |
| PostHog, Inc. | Product analytics | Allowlisted in-app usage events (no amounts or private deal data); allowlisted funnel events on the public site under a first-party identifier cookie, linked to the account only after sign-in (no criteria, email, or invitation token) | United States |
| U.S. Census Bureau (geocoder) | Geocoding | Business addresses from user workspaces only | United States |
| OpenStreetMap Foundation (Nominatim) | Geocoding fallback | Business addresses from user workspaces only | EU |
Subprocessor Details
Clerk, Inc.
Purpose: Authentication, session management, MFA, and invitation gating.
Data Processed: email address, display name, session tokens and device identifiers, login timestamps, IP addresses, user agents, MFA enrollment status. Passwords, where used, are stored by Clerk — never by us.
Location: United States · Certification: SOC 2 Type II
DPA / Terms: Clerk DPA · Clerk Privacy Policy
Neon, Inc.
Purpose: Primary PostgreSQL database; all application data at rest.
Data Processed: your private workspace rows — every company record and everything attached to it. Sensitive private content (document ciphertext references, extracted financials) is encrypted with your per-user key at the application layer. Tenant-scoped reads run on a restricted database role that row-level security confines to the requesting account's rows; writes and system operations run on a privileged role that row-level security does not constrain, and are scoped by the application instead. See the Privacy Policy Section 5.
Location: United States · Certification: SOC 2 Type II
DPA / Terms: Neon DPA · Neon Privacy Policy
Vercel, Inc.
Purpose: Application hosting, serverless functions, CDN.
Data Processed: HTTP request metadata (URL, status, IP, user agent), function execution logs. Application logs are written to avoid private deal content by policy and by redaction helpers.
Location: United States / Global CDN · Certification: SOC 2 Type II
DPA / Terms: Vercel DPA · Vercel Privacy Policy
Vercel, Inc. (Web Analytics)
Purpose: Aggregate page analytics on the public site.
Data Processed: page views. The page address is reduced to a route template before it is sent, so a single-use invitation link is reported as its template and never with the token in it. No search criteria, email address, or invitation token is transmitted, and no cross-site advertising identifier is used.
Location: United States / Global CDN · Certification: SOC 2 Type II
DPA / Terms: Vercel DPA · Vercel Privacy Policy
Cloudflare, Inc. (R2)
Purpose: Object storage for uploaded documents.
Data Processed: documents you upload (CIMs, financial statements). Files are sealed with application-layer encryption before storage, in addition to R2's own at-rest encryption; objects are purged on account deletion.
Location: United States · Certification: SOC 2 Type II, ISO 27001
DPA / Terms: Cloudflare DPA · Cloudflare Privacy Policy
Upstash, Inc.
Purpose: Redis-backed rate limiting and abuse prevention.
Data Processed: request counters keyed by account ID, API-key prefix, or network address. Counters only — no user content is stored.
Location: United States · Certification: SOC 2 Type II
DPA / Terms: Upstash DPA · Upstash Privacy Policy
PostHog, Inc.
Purpose: Product analytics (reintroduced after the v1 removal).
Data Processed: in-app usage events keyed by account identifier under a strict property allowlist — no dollar amounts, document content, or private deal data; on the public site, page analytics and a small set of allowlisted funnel events carrying coarse values only, recorded under a first-party identifier cookie set on our own domain and linked to the account only after sign-in — never search criteria, an email address, or an invitation token. Page addresses are reduced to route templates. Retention: up to 24 months; analytics profiles are deleted with the account. No advertising use.
Location: United States · Certification: SOC 2 Type II
DPA / Terms: PostHog DPA · PostHog Privacy Policy
U.S. Census Bureau geocoder & OpenStreetMap Nominatim
Purpose: Converting business street addresses to map coordinates for radius search.
Data Processed: business addresses only, taken from company records in the baseline universe and in users' workspaces. Nothing identifies the user: no account data, and no notes, documents, financials, contacts, or other workspace content beyond the business address itself. Nominatim usage follows the OSM Foundation's usage policy (throttled, attributed).
Location: United States (Census) / EU (OSMF)
Removed and Residual Subprocessors
The following subprocessors are no longer in use and no longer receive data: Intuit/QuickBooks (integration retired), Brave Software (research enrichment — retired from the product; any future operator-side research tooling will be re-listed if it processes personal data), Hunter.io (email discovery — retired with the outreach feature set). PostHog was removed in v1 and later reintroduced; it is listed above as an active subprocessor.
Anthropic, PBC — retired from active use
Anthropic left the active list in v4 (2026-08-18). The Service previously called Anthropic's Claude API for document extraction and hosted analysis skills. That capability is retired: we send Anthropic nothing, we hold no model credential you can spend, and we operate no hosted AI product.
AI analysis now runs in the agent you connect — Claude, ChatGPT, Gemini, or another supported agent — under your own account with that provider. If that agent is Claude, Anthropic processes your data as your provider under your agreement with them, and not as our subprocessor. Nothing about that relationship passes through us.
Unlike Stripe below, no residual Anthropic-held data sits in an account of ours on users' behalf: invocation records we kept were our own logs of which tool ran and what it cost, described in the Privacy Policy Section 3.4, and they contain no document content.
Functional Software, Inc. (Sentry) — listed in error; never received data
Sentry was named as an active error-monitoring subprocessor in v2 (2026-08-05) and v3 (2026-08-13). That listing was wrong, and wrong in the over-disclosing direction. The integration was installed and wired, but no DSN was ever configured in any deployment environment, so its initialisation was skipped on every request for the entire life of the integration. No error report, and no personal data of any kind, ever reached Sentry.
The failure mode of an unconfigured error monitor is silence, which is indistinguishable from one that is working and seeing no errors — which is why the listing survived two versions. The dependency was removed from the Service outright on 2026-08-20.
We are correcting the record here rather than deleting the entry quietly, because the two superseded versions that named Sentry remain on file.
Stripe, Inc. — removed; our copy deleted, and what Stripe keeps
Stripe left the active list in v3 (2026-08-13), when the Service became free of charge. No data is sent to Stripe, and none will be.
v3 went further than "removed" and disclosed a residue, because one existed: where someone had completed card verification for a founding-member reservation, four payment-derived fields stayed alongside that waitlist entry — a Stripe customer identifier, a verification timestamp, a card fingerprint, and the founding-member rank — and the corresponding customer and setup-intent objects remained in our Stripe account. On that basis v3 correctly said Stripe was still a processor of residual data.
Our copy is gone. On 2026-08-20 the waitlist was removed from the Service outright: every entry was deleted — including the one carrying those fields — and its table was dropped. There is no signup path left, so no such record can be created again, and no record in the Service retains payment-derived data of any kind.
What remains on Stripe's side, stated precisely. We deleted the customer record and detached its payment method. Stripe does not permit deleting the setup-intent object that records the card verification, so that object remains in Stripe's systems under Stripe's own retention terms. It references a deleted customer and carries no card number. To that limited extent Stripe still holds a record originating with us, and we would rather say so than round it down to "deleted" — v3 disclosed this residue accurately, and v4 should not be vaguer about it merely because it is now smaller.
Card numbers never reached our servers at any point, the reservation flow authorised nothing and charged nothing, and the Service has never billed anyone.
Version: v4 · Last updated: 2026-08-20 — the retired data storefront removed; the scope note rewritten around the shared baseline universe and the private workspace; Anthropic retired from the active list, because AI work runs in an agent you connect under your own provider account; Vercel Web Analytics listed as an active subprocessor; the Neon entry's row-level-security description corrected to distinguish tenant reads from privileged writes; Sentry removed from the list and from the Service, having never received data; the Stripe residue disclosed by v3 reduced to what Stripe will not delete — our copy and the customer record are gone, the setup-intent object is not deletable and is described as remaining; the waitlist removed outright, so Clerk no longer gates one. Supersedes v3 (2026-08-13).