Legal

Subprocessors

Last updated: August 19, 2026

Kyvora uses the following third-party service providers (“subprocessors”) to deliver the platform. Each subprocessor is engaged only as necessary to provide their specific service. Kyvora requires subprocessors to protect personal data in accordance with applicable law and contractual obligations.

This page is updated when Kyvora adds, removes, or materially changes a subprocessor. Customers who require advance notice of subprocessor changes should contact privacy@kyvoratech.com.

Current Subprocessors

VendorPurposeData ProcessedLocationPrivacy Policy
VercelApplication hosting and serverless compute — runs every page, API route, webhook handler, and scheduled (cron) job that makes up the PlatformAll platform data in transit through an ordinary request — including candidate phone numbers, message content, and other Candidate/Customer data carried in inbound webhooks and page loads. Vercel executes this traffic as compute infrastructure; it is not the system of record for any of it (Supabase is — see below), but the data necessarily passes through Vercel to be processedUnited StatesView →
TwilioSMS deliveryCandidate phone numbers, message contentUnited StatesView →
PostHogProduct analytics (across the Kyvora website and product, including before sign-up — not limited to the authenticated dashboard)Page views and technical data for all visitors; demo-request form submissions tied to IP address for anonymous visitors; Kyvora account ID, organization ID, role, and product usage events for signed-in Customer/staff users — never candidate names, phone numbers, emails, or message content, and never used to identify candidatesUnited StatesView →
Anthropic PBCAI language model (Claude API)Conversation transcripts, candidate responses, job context, screening informationUnited StatesView →
SupabaseDatabase and infrastructureAll platform data including candidate records, conversation history, and account informationUnited StatesView →
ResendEmail delivery when email functionality is enabled or used through the PlatformCandidate email addresses, message content, and related delivery informationUnited StatesView →
StripePayment processingBilling information, subscription data (card numbers are not stored by Kyvora)United StatesView →
SentryError tracking, application monitoring, and masked session replay used for troubleshootingApplication error details, stack traces, and operational log context (internal organization/user/conversation/campaign/contact identifiers); a masked session replay of a small sample of sessions and of sessions that encounter an error, with page text and form inputs masked by default — request bodies and user info are not automatically collected, and for error/log events, PII patterns such as emails and phone numbers are redacted before transmission where technically feasibleUnited StatesView →
UpstashRate limiting and abuse preventionIP addresses and, for some limits, email addresses — stored only as short-lived rate-limit counters (minutes to hours), never candidate conversation content, screening data, or account recordsUnited StatesView →
Cloudflare (Turnstile)Bot/abuse-screening challenge used on organization sign-upVisitor IP address and standard browser/device signals inherent to completing a Turnstile challenge. Not used anywhere candidates interact with Kyvora — sign-up abuse-screening onlyUnited StatesView →
GoogleGoogle Calendar API — used only when a Customer's recruiter connects their own Google Calendar for native interview schedulingCandidate first name and email address (included on calendar events Kyvora creates), and calendar free/busy time blocks for the connecting recruiter's primary calendar (event details on existing calendar entries are not read). Only used for recruiters who explicitly connect a Google Calendar; the specific Google contracting entity depends on the recruiter's own Google account/Workspace configurationUnited StatesView →

AI Processing

Kyvora uses Anthropic's Claude API to generate AI-assisted screening messages, candidate summaries, and advisory scores. Conversation transcripts, candidate responses, job context, and related screening information are transmitted to Anthropic to generate these outputs.

Kyvora does not permit subprocessors to use Customer or Candidate data to train publicly available AI models where our agreements or provider settings allow us to restrict such use.

Data Transfers

Kyvora and its subprocessors are primarily based in the United States. If you are located outside the United States, personal data you or your candidates provide may be transferred to, stored in, or processed in the United States. For more information about international data transfers, see our Privacy Policy.

Related Documents

Questions about subprocessors?

privacy@kyvoratech.com

Kyvora Technologies LLC · San Francisco, CA 94114 · United States