Legal
Subprocessors
Last updated: August 19, 2026
Kyvora uses the following third-party service providers (“subprocessors”) to deliver the platform. Each subprocessor is engaged only as necessary to provide their specific service. Kyvora requires subprocessors to protect personal data in accordance with applicable law and contractual obligations.
This page is updated when Kyvora adds, removes, or materially changes a subprocessor. Customers who require advance notice of subprocessor changes should contact privacy@kyvoratech.com.
Current Subprocessors
| Vendor | Purpose | Data Processed | Location | Privacy Policy |
|---|---|---|---|---|
| Vercel | Application hosting and serverless compute — runs every page, API route, webhook handler, and scheduled (cron) job that makes up the Platform | All platform data in transit through an ordinary request — including candidate phone numbers, message content, and other Candidate/Customer data carried in inbound webhooks and page loads. Vercel executes this traffic as compute infrastructure; it is not the system of record for any of it (Supabase is — see below), but the data necessarily passes through Vercel to be processed | United States | View → |
| Twilio | SMS delivery | Candidate phone numbers, message content | United States | View → |
| PostHog | Product analytics (across the Kyvora website and product, including before sign-up — not limited to the authenticated dashboard) | Page views and technical data for all visitors; demo-request form submissions tied to IP address for anonymous visitors; Kyvora account ID, organization ID, role, and product usage events for signed-in Customer/staff users — never candidate names, phone numbers, emails, or message content, and never used to identify candidates | United States | View → |
| Anthropic PBC | AI language model (Claude API) | Conversation transcripts, candidate responses, job context, screening information | United States | View → |
| Supabase | Database and infrastructure | All platform data including candidate records, conversation history, and account information | United States | View → |
| Resend | Email delivery when email functionality is enabled or used through the Platform | Candidate email addresses, message content, and related delivery information | United States | View → |
| Stripe | Payment processing | Billing information, subscription data (card numbers are not stored by Kyvora) | United States | View → |
| Sentry | Error tracking, application monitoring, and masked session replay used for troubleshooting | Application error details, stack traces, and operational log context (internal organization/user/conversation/campaign/contact identifiers); a masked session replay of a small sample of sessions and of sessions that encounter an error, with page text and form inputs masked by default — request bodies and user info are not automatically collected, and for error/log events, PII patterns such as emails and phone numbers are redacted before transmission where technically feasible | United States | View → |
| Upstash | Rate limiting and abuse prevention | IP addresses and, for some limits, email addresses — stored only as short-lived rate-limit counters (minutes to hours), never candidate conversation content, screening data, or account records | United States | View → |
| Cloudflare (Turnstile) | Bot/abuse-screening challenge used on organization sign-up | Visitor IP address and standard browser/device signals inherent to completing a Turnstile challenge. Not used anywhere candidates interact with Kyvora — sign-up abuse-screening only | United States | View → |
| Google Calendar API — used only when a Customer's recruiter connects their own Google Calendar for native interview scheduling | Candidate first name and email address (included on calendar events Kyvora creates), and calendar free/busy time blocks for the connecting recruiter's primary calendar (event details on existing calendar entries are not read). Only used for recruiters who explicitly connect a Google Calendar; the specific Google contracting entity depends on the recruiter's own Google account/Workspace configuration | United States | View → |
AI Processing
Kyvora uses Anthropic's Claude API to generate AI-assisted screening messages, candidate summaries, and advisory scores. Conversation transcripts, candidate responses, job context, and related screening information are transmitted to Anthropic to generate these outputs.
Kyvora does not permit subprocessors to use Customer or Candidate data to train publicly available AI models where our agreements or provider settings allow us to restrict such use.
Data Transfers
Kyvora and its subprocessors are primarily based in the United States. If you are located outside the United States, personal data you or your candidates provide may be transferred to, stored in, or processed in the United States. For more information about international data transfers, see our Privacy Policy.
Related Documents
Questions about subprocessors?
privacy@kyvoratech.comKyvora Technologies LLC · San Francisco, CA 94114 · United States