Subprocessors
Version 1.0 — effective August 23, 2026. All humanizes policies.
Applies to: Customers and visitors whose personal data is processed through the Service, including business and enterprise customers using the Data Processing Agreement.
In plain language
- The Service depends on providers for hosting, AI processing, authentication, payments, email, fonts and referral attribution.
- Processing is principally in the United States; contractual and technical transfer safeguards apply where required.
- AI processors receive the text needed for the operation you request, under terms that do not permit training on it.
- We publish this list before a new subprocessor begins processing customer personal data and provide DPA notices where required.
Contents
- 1. Introduction and status of this list
- 2. Customer-facing subprocessors and providers
- 3. Limits on AI processing
- 4. Internal-only processing and infrastructure
- 5. International transfers
- 6. How we choose and review providers
- 7. Change notice
- 8. Version history
- 9. Contact
1. Introduction and status of this list
Current as at 23 August 2026. This page is the subprocessor list maintained by humanizes, the operator of humanizes.com and referenced in the Privacy Policy and Data Processing Agreement. The effective date at the top is the date of the current list.
A subprocessor is another organisation engaged to process personal data on our behalf when we act as a processor for a customer. Some listed providers also act as independent controllers for parts of their service, such as Stripe’s direct collection of payment-card details. Listing a provider here describes its operational role and does not change the legal allocation in its terms or applicable law.
2. Customer-facing subprocessors and providers
| Subprocessor | What it does | Data it receives | Where it processes |
|---|---|---|---|
| Replit | Hosts the application and PostgreSQL database and provides the AI Integrations proxy through which OpenAI is called. | Account and service records, submitted and generated content, usage and technical data, and AI requests transiting its proxy. | United States |
| OpenAI, via the Replit AI Integrations proxy | Produces rewrites and generated drafts and supplies model signals used in detector-perplexity analysis. | Text submitted for processing, writing samples, style profiles, and chat or writer messages needed for the requested operation. | United States |
| StealthGPT | Performs a secondary structural rewrite pass on paid plans. | Candidate text requiring that secondary rewrite. | United States |
| GPTZero | Scores generated candidates during paid humanization and returns provider-backed AI-detection results. | Submitted or generated text sent for scoring. | United States |
| Clerk | Provides authentication, session and account management. | Identity and authentication data, including email address and user identifier. | Provider infrastructure, including the United States |
| Stripe | Processes checkout, payments, subscriptions, billing-portal access and related billing administration. | Billing identifiers, transaction and subscription details, checkout metadata, and card data collected directly from you. We do not receive or store full card numbers. | Provider infrastructure, including the United States |
| Resend | Delivers transactional emails, including quota notices, contact-form replies and privacy-request verification. | Recipient email address and the body and delivery metadata of the message. | Provider infrastructure, including the United States |
| Google Fonts | Delivers webfont stylesheets and font files requested by the site and its service worker. | IP address, user-agent and ordinary HTTP request metadata inherent in requesting the resource. We do not set a Google Fonts cookie. | Google’s global infrastructure, including the United States |
| Insert Affiliate — not currently active | Would provide browser-side referral attribution. Referral attribution is not strictly necessary to run the Service, so it is disabled until a consent choice exists and the visitor allows it. | While inactive, nothing. Once enabled with consent: the insertAffiliate URL value, validated referral short code and related identifier pair, with the pair passed into Stripe Checkout metadata if the referred visitor purchases. Organic visitors are a no-op. | Provider infrastructure, including the United States |
3. Limits on AI processing
Text is used to fulfil your request, not to train models
OpenAI, StealthGPT and GPTZero receive only the text needed to perform the requested feature or its delivery workflow. During paid humanization, GPTZero may receive generated candidate text for scoring; for a provider-backed detector request, it receives the submitted text to be scored. We engage AI processors on terms that do not permit them to train on that text. We do not use submitted text to train or fine-tune our own models.
The particular recipients depend on the feature and plan used. For example, StealthGPT is used for a secondary pass on paid plans, while writing samples and style profiles are relevant only to personal writing-style matching. The Privacy Policy explains the purposes and retention periods in more detail.
4. Internal-only processing and infrastructure
For completeness, the following systems support restricted internal functions or infrastructure. They are not additional customer-facing AI recipients and receive no end-user text.
| System | Internal role | Data it receives | Status |
|---|---|---|---|
| Rewardful | Legacy REST API used only by an owner-gated affiliate dashboard. | Affiliate-program records needed by that internal dashboard; no end-user text. | Internal-only provider |
| Redis | Optional queue and rate-limit infrastructure. | Transient job-control, lease and rate-limit state; no end-user text. | Self-managed infrastructure, not an independent data vendor |
5. International transfers
Processing by the providers above is principally in the United States. This means personal data originating elsewhere may be transferred to a country whose data-protection law is not considered equivalent to the law where the individual lives.
For restricted transfers from the European Economic Area, we rely on the European Commission’s Standard Contractual Clauses (SCCs) where an adequacy decision or another valid transfer mechanism does not apply. For restricted transfers from the United Kingdom, we use the SCCs together with the UK International Data Transfer Addendum. Swiss transfers use the SCCs as adapted for Swiss law.
We supplement those contractual measures with a transfer risk assessment and technical and organisational measures appropriate to the transfer, including encryption in transit, access controls and least-privilege scoping, authenticated and caller-scoped endpoints, secrets management, request validation, rate limits, and tamper-evident audit records. No safeguard can eliminate every transfer risk.
6. How we choose and review providers
Before engaging a provider to process personal data, we assess the service it supplies, the data it needs, its security posture, processing locations and data-protection terms. We seek written processing terms appropriate to the role, including confidentiality, security, deletion or return, incident assistance, onward-processing and transfer provisions where applicable.
We limit each provider to the categories of data needed for its function, restrict production and administrative access, and review the arrangement when the service, risk, terms or processing materially changes. Due diligence reduces risk but is not a guarantee that a provider will never experience an incident.
7. Change notice
Notice before a new subprocessor starts
We will publish an update to this page before a new subprocessor starts processing customer personal data. Business and enterprise customers will receive advance notice where and within the period required by their Data Processing Agreement.
A business or enterprise customer may object to a new subprocessor on reasonable data-protection grounds using the procedure and deadline in the Data Processing Agreement, by writing to jakemorris@humanizes.com. We will review the concern in good faith and follow the options set out in the DPA; an objection does not necessarily require us to withdraw a provider.
To subscribe to subprocessor changes, contact jakemorris@humanizes.com from the address at which you want to receive notices and ask to be added to the subprocessor-change list.
8. Version history
The effective date at the top of this page is the date of the current provider list. The changelog records published versions so customers can identify when the list changed.
9. Contact
Questions about a provider, transfer safeguard or change notice can be sent to jakemorris@humanizes.com. The operator’s website is https://humanizes.com.
Version history
- v1.0 — August 23, 2026: First version establishing the current customer-facing and internal processor lists, international-transfer safeguards, review standards and change-notice process.