Sub-Processors and Other Providers
Last Updated: 2026-08-10
Effective Date: 2026-08-10 for users first accepting the MainBook Terms on or after that date; 2026-09-10 for users who accepted an earlier version.
This page identifies the third parties used by Human Beyond LLC ("MainBook", "we", "us", "our") in connection with the MainBook service ("Service"). Section 2 lists Sub-processors that process Customer Personal Data on our behalf under our Data Processing Agreement. Section 3 separately lists providers that process Account, payment, network, authentication, or consented analytics/advertising data for MainBook's own purposes, or that may act as an independent controller for part of their service.
This page is incorporated by reference into our Privacy Policy and AI Disclosure. Only Section 2 is incorporated as the approved Sub-processor list in Schedule 3 of our DPA. Where another policy names specific providers, those references are illustrative of the list as of that policy's publication date and this page controls in the event of a conflict.
We update this page whenever our Sub-processor mix changes. The "Last Updated" date at the top reflects the most recent change.
1. Notice of Changes
1.1 Advance notice. At least thirty (30) days before an intended addition or replacement of a Section 2 Sub-processor, we specifically notify affected Customers in writing through the email associated with the Account and/or an in-product notice addressed to the Customer. Updating this page is supplemental, and no separate subscription is required. Where a Customer acts as Processor, the notice will contain enough information to be passed to the relevant Controller.
1.2 Objection window. If you reasonably object to a new Sub-processor on grounds related to data protection, you may notify us in writing at hello@human-beyond.ai within thirty (30) days of receipt of the notice. The objection and resolution mechanism is set out in Section 5.3 of our Data Processing Agreement.
1.3 Emergency changes. Where applicable law and the governing transfer terms permit shorter notice, an emergency such as an outage or sanction may require a replacement Sub-processor to maintain security or availability; in that case we provide notice as soon as reasonably practicable and preserve the objection mechanism. Where the SCCs or another binding mechanism requires the full notice period, we follow that requirement or suspend the affected processing until a compliant alternative is available.
2. DPA Sub-Processors for Customer Personal Data
These providers process Customer Personal Data on MainBook's behalf to provide the document-conversion Service, storage, support, or error monitoring. The DPA's authorization, flow-down, notice, objection, and transfer terms apply to this Section 2.
| # | Sub-processor | Category | Legal entity | Processing location | Function — what they do | Data they may process |
|---|---|---|---|---|---|---|
| 1 | Mistral AI | AI | Mistral AI SAS (France) | France and other locations used by Mistral and its documented sub-processors, subject to applicable transfer safeguards | OCR for scanned PDFs, images, and certain quality-control re-reads. Digital PDFs with a usable text layer may instead be parsed within MainBook's infrastructure | The relevant source PDF, image, or rendered page image; OCR text and layout Output |
| 2 | Google (Gemini API) | AI | Google LLC (United States) | Countries where Google or its agents maintain facilities, subject to applicable transfer safeguards | Large-language-model structured extraction — identifies transaction rows, dates, descriptions, amounts, and balances and returns structured data. We access the Gemini API directly on a paid (billed) basis | Extracted text and related structured context; model Output; and, in a limited final quality-control fallback, a rendered PNG of one source-document page. We do not transmit the original PDF file itself to Google |
| 3 | DigitalOcean | Infra | DigitalOcean, LLC (United States) | United States (region selected per service) | Application hosting (DigitalOcean App Platform), managed PostgreSQL database, and object storage (DigitalOcean Spaces) for uploaded documents and Output | All Customer Personal Data that we store (encrypted at rest), Account data, payment metadata, and audit records |
| 4 | Resend | Comms | Plus Five Five, Inc. d/b/a Resend (United States) | United States | Transactional and consented product-email delivery, including account verification, password reset, billing receipts, security notifications, support acknowledgements, lifecycle/feedback messages, and internal support-inbox delivery | Recipient, sender, and reply-to email addresses; content of messages we send or forward; support-ticket subject, message, and, where size permits, the attachment you submitted |
| 5 | Sentry | Security | Functional Software, Inc. d/b/a Sentry (United States) | United States | Application error and exception tracking. Server-side local-variable and incoming-request-body capture are disabled where applicable; request-body data is removed before transmission across browser, server, and edge events; document-content, email, filename/storage-path, institution, and common-secret fields are filtered; no session replay or performance tracing. Current event retention is up to thirty (30) days | Diagnostic metadata such as stack traces, request paths, error type, release, and pseudonymous internal identifiers. We do not intentionally send uploaded documents or Output to Sentry |
3. Other Service Providers and Independent Controllers
These providers process Account, payment, network, authentication, or consented analytics/advertising data for MainBook's own purposes. Depending on the service and applicable terms, a provider may act as MainBook's processor, as an independent controller, or in different roles for different data. They are disclosed here for transparency but are not incorporated into Schedule 3 of the DPA merely by appearing in this Section 3.
| # | Provider | Category | Legal entity | Processing location | Function — what they do | Data they may process |
|---|---|---|---|---|---|---|
| 1 | Stripe | Payments | Stripe Payments Company (United States) or a Stripe affiliate as set out in the Stripe DPA | United States; data may be processed by Stripe affiliates worldwide | Payment processing for Credit purchases (Stripe-hosted Checkout) | Your email address, IP address, payment-method information (collected directly by Stripe — we do not see your full card number), Credit-package code, payment amount, transaction identifier, consent-derived Google/Meta attribution identifiers included in checkout metadata, and an opaque consent-state marker used only to recheck consent before a deferred analytics event |
| 2 | Vercel | Frontend hosting | Vercel, Inc. (United States) | United States; globally distributed edge network | Front-end application hosting and content delivery for mainbook.ai | IP address, user-agent, request metadata, and authentication cookies in transit. Uploaded documents and Output are not routed through Vercel; browser uploads go directly to object storage and API requests go to the backend |
| 3 | Cloudflare | Anti-fraud | Cloudflare, Inc. (United States) | Globally distributed edge network | Turnstile anti-abuse challenges on signup and guest upload | IP address, user-agent, challenge result, and transient network metadata |
| 4 | GoDaddy | DNS | GoDaddy.com, LLC (United States) | United States | Domain registration and authoritative DNS | DNS query metadata. GoDaddy does not receive document content, Output, or Account application data through this function |
| 5 | Telegram | Internal operations | Telegram Messenger Inc. / Telegram FZ-LLC | Routed via Telegram's infrastructure | One-way internal operator alerts for signups, payments, conversions, support-ticket arrival, cost/security thresholds, format-review state, and Sentry issue arrival | Opaque internal user, payment, document, ticket, API-key, profile, Sentry-issue, or mailbox identifiers; event state, reason code, counts, payment/cost values, routing category, and an operator instruction. MainBook does not send names, email addresses, support text or attachments, institution names, filenames, source documents, Output rows, API key secrets or prefixes, or Sentry issue titles to Telegram |
| 6 | Google (OAuth) | Auth | Google LLC (United States) | United States | Authentication only if you choose Google OAuth | Your Google account identifier and authorized profile fields (email and name). Customer documents and Output are not sent through OAuth |
| 7 | Google (Analytics) | Analytics | Google LLC (United States) | United States | Audience, traffic, product-funnel, and purchase measurement through Google Analytics 4 browser events and consent-linked backend Measurement Protocol events. Before consent, Google Consent Mode may send cookieless event pings while storage is denied; no analytics cookie or persistent Google Analytics client identifier is set by us at that stage. Cookie-based analytics, identifiers, and consent-dependent events require effective consent | Google Analytics client ID/cookies, page URL, IP-derived approximate location, device/browser metadata, product events and counts, opaque job/transaction identifiers, Credit-package code and page quantity, and MainBook Credit purchase price/amount. We do not send uploaded statements, row-level Output, or statement transaction descriptions, amounts, or balances |
| 8 | Meta (Pixel and Conversions API) | Advertising | Meta Platforms, Inc. (United States) | United States | Consent-gated advertising conversion measurement and audience building through browser Pixel and consent-linked backend Conversions API events. Before consent, Meta consent is revoked, no event fires, and no Meta cookie is set | _fbp / _fbc online identifiers, IP address, page URL/referrer, device/browser metadata, funnel and conversion events, counts/categories, page count, document kind, export format, Credit-package code, deduplication identifier, and MainBook Credit purchase price/amount. Advanced Matching is disabled; we do not send hashed email, phone, or name, uploaded statements, row-level Output, or statement transaction descriptions, amounts, or balances |
4. Sub-Processors Used by Our Section 2 Sub-Processors
Each Section 2 Sub-processor may engage Sub-processors of its own (sometimes called "sub-sub-processors"). We rely on the applicable contractual obligations between us and our direct Sub-processors, and between them and their onward Sub-processors, for protection consistent with applicable Data Protection Laws and the Standard Contractual Clauses incorporated in our DPA.
The sub-sub-processor lists of our direct Sub-processors are publicly available on the following pages (links provided for convenience; the linked pages are maintained by the third parties and may change):
- Mistral AI — sub-processors: see Mistral's legal pages at legal.mistral.ai
- Google (Gemini API) — sub-processors: see Google's Cloud Sub-processors
- Resend — sub-processors: see Resend's DPA
- DigitalOcean — sub-processors: see DigitalOcean's Data Processing Agreement
- Sentry — sub-processors: see Sentry's Sub-Processor List
5. Additional Update Subscription
Required notices under Section 1.1 do not depend on a subscription. If you also want list-update emails sent to an address other than the email associated with your Account, send a message to hello@human-beyond.ai with the subject "subscribe sub-processor updates" and the additional address. You may remove that additional address at any time by replying with "unsubscribe sub-processor updates".
6. Historical Versions
Older versions of this Sub-processor list are retained internally for audit and recordkeeping purposes. If you need the version that was in force on a specific date, please contact us at hello@human-beyond.ai.
7. Contact
For questions about our Sub-processors:
Human Beyond LLC Email: hello@human-beyond.ai